Trust · Privacy
Privacy Policy
Effective date: July 18, 2026Last updated: July 18, 2026
ran ("ran," "we," "us") is operated by The Prompt Department, and this policy explains what data we collect, how we use it, and the choices you have. It applies to the ran web application and this website — questions: hello@thepromptdepartment.org.
01
What we collect
Account data. Your email address and name when you sign up, and authentication records needed to sign you in (we use magic-link email authentication).
Connected content. Documents, messages, and files from the sources you connect — for example your Notion pages, Slack channels, Google Drive files, Gmail or Outlook messages, or a code repository. We follow a reference, don't upload model: the original document never leaves its home system.
We read connected sources via their APIs, store a derived, searchable copy (text chunks, embeddings, and a knowledge map) plus a pointer back to the original, and re-sync when the source changes.
Content you author in ran. Notes, questions you ask, and approvals or corrections you make.
Usage and technical data. Standard server logs (IP address, browser type, timestamps) and product event records (for example, that a task was proposed, approved, or executed) kept for security, audit, and reliability.
Waitlist signups. If you request early access on this site, we store the email address and company details you submit, and use them only to contact you about ran.
02
How we use data
- To provide the product: keeping a derived copy of your connected sources current, answering questions with citations, and executing tasks you have approved.
- To secure and operate the service: authentication, audit trails, abuse prevention, debugging.
- To communicate with you about your account or early access.
We do not sell your data. We do not use your content to train AI models — ours or anyone else's. Content is processed for retrieval and inference only: it is embedded for search and passed to our AI providers at question-answering time to generate your answer, under contracts that prohibit those providers from training on it.
03
Google user data (Limited Use disclosure)
If you connect Google Drive, Google Docs, Google Sheets, or Gmail, ran accesses that data only to provide user-facing features you request: reading the files and messages in the folders or labels you choose, answering your questions about them with citations, and — only after your explicit per-action approval — sending or editing content on your behalf.
ran's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:
- Google user data is used only to provide the features described above — never for advertising, never sold, and never used to train AI or machine-learning models.
- Humans do not read your Google data except with your explicit permission (for example, when you share a citation with someone), when required for security or legal compliance, or when the data is aggregated and anonymised.
- Google user data is transferred to third parties only as necessary to provide these features (the subprocessors in §5), for security and compliance, or with your consent.
You can disconnect a Google source at any time in the app (Sources → disconnect), which stops all access and deletes the derived copy for that source, and you can additionally revoke ran's access at myaccount.google.com/permissions.
04
Other connected sources
The same principles govern every connector (Notion, Slack, Microsoft Outlook, and connectors provided through our integration platform): access is scoped to what you connect, used only for retrieval and user-requested actions, and revocable at any time by disconnecting the source, which deletes its derived copy.
Outbound actions (sending a message, editing a document, creating an issue) run only through ran's plan-and-approve gate: nothing is written to an external system without an explicit approval recorded in your audit trail.
05
Subprocessors
We share data only with the service providers needed to run ran, each bound by contract to process it solely on our instructions:
- Supabase
- database and authentication hosting
- Vercel
- application and website hosting
- Anthropic
- AI answer and task generation (inference only; no training on your data)
- Voyage AI
- text embeddings and search reranking (inference only; no training on your data)
- Integration platform provider
- brokered connections to third-party tools for catalog integrations
This list matches the in-product Trust page and will be updated there and here before any new subprocessor receives customer data.
06
Retention and deletion
Derived copies exist only while their source stays connected: disconnecting a source deletes its chunks, embeddings, and map entries. Deleting your account deletes its content.
Operational records (audit trails of approvals and executions) are retained as part of your account's history. Backups age out on our hosting providers' standard cycles, and waitlist data is deleted on request.
07
Security
Access tokens for connected sources are encrypted at rest (AES-GCM) and never exposed to the browser. All traffic is encrypted in transit (TLS).
Your data is isolated per account with database-level row security, and visibility controls restrict private documents to their owner. Report security issues to hello@thepromptdepartment.org.
08
Your rights
Depending on where you live (including under GDPR and UK GDPR), you may have rights to access, correct, export, or delete your personal data, and to object to or restrict processing. Contact hello@thepromptdepartment.org and we will respond within the legally required window.
09
Children
ran is a business tool, not directed at children under 16, and we do not knowingly collect their data.
10
Changes
We will post any changes to this policy on this page and update the date above. Material changes affecting connected-source data will be announced to account holders before they take effect.