Trust · Privacy

Privacy Policy

Effective date: July 18, 2026Last updated: July 18, 2026

ran ("ran," "we," "us") is operated by The Prompt Department, and this policy explains what data we collect, how we use it, and the choices you have. It applies to the ran web application and this website — questions: hello@thepromptdepartment.org.

01

What we collect

Account data. Your email address and name when you sign up, and authentication records needed to sign you in (we use magic-link email authentication).

Connected content. Documents, messages, and files from the sources you connect — for example your Notion pages, Slack channels, Google Drive files, Gmail or Outlook messages, or a code repository. We follow a reference, don't upload model: the original document never leaves its home system.

We read connected sources via their APIs, store a derived, searchable copy (text chunks, embeddings, and a knowledge map) plus a pointer back to the original, and re-sync when the source changes.

Content you author in ran. Notes, questions you ask, and approvals or corrections you make.

Usage and technical data. Standard server logs (IP address, browser type, timestamps) and product event records (for example, that a task was proposed, approved, or executed) kept for security, audit, and reliability.

Waitlist signups. If you request early access on this site, we store the email address and company details you submit, and use them only to contact you about ran.

02

How we use data

  • To provide the product: keeping a derived copy of your connected sources current, answering questions with citations, and executing tasks you have approved.
  • To secure and operate the service: authentication, audit trails, abuse prevention, debugging.
  • To communicate with you about your account or early access.

We do not sell your data. We do not use your content to train AI models — ours or anyone else's. Content is processed for retrieval and inference only: it is embedded for search and passed to our AI providers at question-answering time to generate your answer, under contracts that prohibit those providers from training on it.

03

Google user data (Limited Use disclosure)

If you connect Google Drive, Google Docs, Google Sheets, or Gmail, ran accesses that data only to provide user-facing features you request: reading the files and messages in the folders or labels you choose, answering your questions about them with citations, and — only after your explicit per-action approval — sending or editing content on your behalf.

ran's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:

  • Google user data is used only to provide the features described above — never for advertising, never sold, and never used to train AI or machine-learning models.
  • Humans do not read your Google data except with your explicit permission (for example, when you share a citation with someone), when required for security or legal compliance, or when the data is aggregated and anonymised.
  • Google user data is transferred to third parties only as necessary to provide these features (the subprocessors in §5), for security and compliance, or with your consent.

You can disconnect a Google source at any time in the app (Sources → disconnect), which stops all access and deletes the derived copy for that source, and you can additionally revoke ran's access at myaccount.google.com/permissions.

04

Other connected sources

The same principles govern every connector (Notion, Slack, Microsoft Outlook, and connectors provided through our integration platform): access is scoped to what you connect, used only for retrieval and user-requested actions, and revocable at any time by disconnecting the source, which deletes its derived copy.

Outbound actions (sending a message, editing a document, creating an issue) run only through ran's plan-and-approve gate: nothing is written to an external system without an explicit approval recorded in your audit trail.

05

Subprocessors

We share data only with the service providers needed to run ran, each bound by contract to process it solely on our instructions:

Supabase
database and authentication hosting
Vercel
application and website hosting
Anthropic
AI answer and task generation (inference only; no training on your data)
Voyage AI
text embeddings and search reranking (inference only; no training on your data)
Integration platform provider
brokered connections to third-party tools for catalog integrations

This list matches the in-product Trust page and will be updated there and here before any new subprocessor receives customer data.

06

Retention and deletion

Derived copies exist only while their source stays connected: disconnecting a source deletes its chunks, embeddings, and map entries. Deleting your account deletes its content.

Operational records (audit trails of approvals and executions) are retained as part of your account's history. Backups age out on our hosting providers' standard cycles, and waitlist data is deleted on request.

07

Security

Access tokens for connected sources are encrypted at rest (AES-GCM) and never exposed to the browser. All traffic is encrypted in transit (TLS).

Your data is isolated per account with database-level row security, and visibility controls restrict private documents to their owner. Report security issues to hello@thepromptdepartment.org.

08

Your rights

Depending on where you live (including under GDPR and UK GDPR), you may have rights to access, correct, export, or delete your personal data, and to object to or restrict processing. Contact hello@thepromptdepartment.org and we will respond within the legally required window.

09

Children

ran is a business tool, not directed at children under 16, and we do not knowingly collect their data.

10

Changes

We will post any changes to this policy on this page and update the date above. Material changes affecting connected-source data will be announced to account holders before they take effect.