Legal

Privacy policy

What we collect, why, and what we'll never do with it. Last updated July 7, 2026.

1. What we collect

Account data: your name, email, and authentication details, handled by our identity provider (Clerk).

Connected-account data: with your authorization, the posts, mentions, and engagement metrics needed to build your voice profile and operate the inbox. OAuth tokens are stored encrypted and used only for the actions you've enabled.

Product data: the drafts you approve, edit, or dismiss — this feedback tunes your voice profile.

Usage data: standard logs and diagnostics that help us keep the service reliable.

2. What we use it for

To run the product: learning your voice, drafting replies, publishing what you approve, and computing your analytics.

To improve your own experience: your edits train your profile. We do not use your content or voice profile to train models for other customers.

To communicate with you about the service — receipts, security notices, and (only if you opt in) product updates.

3. What we never do

We never sell your data. We never post without an action you configured. We never read your data for advertising. We never train shared models on your writing.

4. Third parties we rely on

Authentication (Clerk), database hosting, AI inference for draft generation, and payment processing (Stripe, when you subscribe). Each receives only what it needs to perform its function, under its own contractual safeguards.

When drafts are generated, the relevant mention text and your voice-profile summary are sent to our AI provider for inference. They are not used to train that provider's models under our agreement.

5. Retention and deletion

We keep your data while your account is active. Deleting your account deletes your voice profiles, drafts, connected-account tokens, and analytics from our production systems within 30 days, with backups aging out on their regular cycle.

You can export your data (JSON) at any time from the dashboard, and disconnect any social account instantly — which deletes the stored credentials for it, so we can no longer act on your behalf. To end the authorization at the platform itself, remove Rysonance from that platform's connected-apps settings.

6. Your rights

Wherever you live, we honor requests to access, correct, export, or delete your personal data. GDPR and CCPA requests go through the contact page and are answered within the statutory windows.

7. Security

OAuth tokens are encrypted at rest, transport is TLS everywhere, and access to production data is limited to the small set of people who operate the service. If a breach affects your data, we'll notify you without undue delay.

8. Changes

If this policy changes materially, we'll email you before the change takes effect. The current version always lives at this address.

privacy question or request? use the contact page and pick “something else” — we answer within one business day.