Privacy Policy
Last updated: September 2, 2026
This Privacy Policy explains how Ruligent, currently a free, pre-commercial service operated by its founder as an individual in New York, United States, collects, uses, discloses, and retains information when you use www.ruligent.com, app.ruligent.com, api.ruligent.com, and the Ruligent service. No separately registered Ruligent entity or completed assumed-name filing is represented.
1. Information we collect
- Account information. Name, email address, organization name, authentication records, and password-derived hashes. We do not store plaintext passwords.
- Recovery and transactional-email data. When enabled, password-recovery delivery may send your name, email address, and a short-lived reset link through Resend. Reset links expire and are invalidated after successful password changes.
- Agent and governance activity. Guard requests may create records containing agent ID, tool, action, decision, reason, risk level, estimated cost, timestamps, policy matches, approval metadata, and a bounded payload summary. Customers should minimize personal or regulated data in guard payloads.
- Billing information. New paid enrollment is currently closed. For any existing authorized billing state, Stripe processes payment details and Ruligent stores the subscription state and provider references needed to manage it; complete payment-card numbers are not stored by Ruligent.
- Support and sales information. Information you submit through contact forms, support requests, security reports, or sales conversations.
- Operational telemetry. Hosting, security, error, performance, and product-analytics information may be processed by configured providers such as Vercel, Sentry, and PostHog.
2. How we use information
- Provide, authenticate, secure, support, and improve Ruligent.
- Evaluate guarded actions, run approval workflows, maintain audit records, apply spend limits and kill switches, and deliver configured webhooks.
- Operate subscriptions, billing, account recovery, and customer communications.
- Detect abuse, investigate security events, maintain reliability, and comply with law.
- Analyze product usage where analytics are enabled.
3. Data minimization and restricted data
Ruligent is designed to operate on governance metadata and bounded summaries, not unrestricted copies of customer payloads. Do not intentionally send payment-card data, protected health information, government secrets, export-controlled technical data, or other specially regulated information unless a separate written agreement expressly authorizes that processing.
4. Retention
- Audit and governance records are retained according to the active self-service plan: 7 days on Free, 30 days on Founder, 180 days on Operator, and 365 days on Business. Enterprise retention may be set by contract.
- Account information is generally retained while an account is active and for a limited period afterward as needed for security, legal, tax, dispute, or backup purposes.
- Billing records may be retained as required for tax, accounting, fraud-prevention, and legal obligations.
- Support and security records may be retained as reasonably necessary to resolve requests, investigate incidents, and maintain an audit trail.
5. Service providers and disclosures
Ruligent uses service providers to operate the product, including Vercel for hosting, Supabase/Postgres infrastructure for data storage, Stripe for payments, and Resend for transactional email when enabled. Sentry and PostHog may be used where configured. The current list is maintained at /legal/subprocessors. We may also disclose information when required by law, to protect rights or security, in connection with a business transaction, or with your direction or consent.
6. What we do not do
- We do not sell personal information for money.
- We do not use customer agent-activity data to train public foundation models.
- We do not intentionally collect complete payment-card numbers through the Ruligent application.
7. Your choices and rights
Depending on your location, you may have rights to access, correct, delete, export, restrict, or object to certain processing. Submit requests through the Ruligent contact page. We may need to verify your identity before acting on a request. Authorized-agent requests may require proof of authority where applicable.
8. Customer and processor roles
For account, billing, security, and direct business-contact information, the Ruligent service operator generally acts as an independent business/controller. For personal data contained in customer-controlled agent activity processed on behalf of an organization, Ruligent may act as a processor/service provider under the Data Processing Addendum.
9. Security
Ruligent uses controls including TLS in transit, organization-scoped access controls, password hashing, credential digests, signed webhooks, security headers, and operational monitoring. No security program can guarantee absolute security. See the Security Policy for current practices and limitations.
10. International users
Ruligent is operated from the United States and its providers may process information in the United States and other countries. Where required, contractual and other transfer mechanisms may be used for customer personal data.
11. Children
Ruligent is intended for business users and is not directed to children under 13. We do not knowingly solicit personal information from children.
12. Commercial identity notice
Ruligent is currently operated by its founder as an individual. No separately registered Ruligent entity or completed assumed-name filing is represented. Privacy obligations described here are undertaken by the individual service operator until the approved commercial identity is completed and this notice is updated.
13. Changes and contact
We may update this policy as the service, providers, or legal requirements change. Material updates will be posted here and communicated where appropriate. Contact the Ruligent operator through the contact page.