Privacy Policy
— Version 1.0 —April 14, 2026
At RightAsk AI, Inc. ("RightAsk," "we," "our," or "us"), we take privacy seriously. This Privacy Policy explains how we collect, use, share, and protect information when you access or use the RightAsk platform and associated services. By using our platform, you agree to the practices described here.
1. Information We Collect
2. How We Use Your Information
3. Legal Basis for Processing (GDPR)
4. How We Share Your Information
5. Cookies & Tracking Technologies
6. Data Retention
7. Your Privacy Rights
8. International Data Transfers
9. Data Security
10. Children's Privacy
11. Third-Party Links & Services
12. Changes to This Policy
13. Contact Us
1. Information We Collect
1.1 Information You Provide Directly
Account registration details: name, email address, username, password
Profile and business information: company name, role, billing address
Payment information, processed via Stripe (we do not store full card details)
Content and files you upload to the platform, including intellectual property documents and agreements
Communications with us, including support requests and correspondence
1.2 Information Collected Automatically
IP address and approximate geolocation
Browser type, version, and settings
Device type and operating system
Pages visited, clickstream data, and session duration
Referring URLs and exit pages
Cookie identifiers and similar tracking technologies
1.3 Information from Third-Party Integrations
Where you connect third-party services to the platform (e.g., Google Drive, Dropbox, DocuSign, Square), we may receive data from those services in accordance with their respective privacy policies and your authorization. We only access data necessary to provide the integration functionality you request.
1.4 AI Interactions
Conversations, prompts, and inputs submitted to the AI assistant on the platform are processed by Anthropic and OpenAI on our behalf. RightAsk does not independently store conversation content beyond what is necessary to provide platform functionality (e.g., session logs and analytics summaries). Please do not submit sensitive personal data — such as financial account numbers, government-issued identification, or health information — through AI input fields.
You are solely responsible for the content you input. RightAsk cannot monitor all files or prompts submitted and adheres to the usage policies set by Anthropic and OpenAI. By using AI features, you acknowledge that your inputs may be processed by those providers subject to their respective privacy policies.
2. How We Use Your Information
We use the information we collect for the following purposes:
To create, maintain, and manage your account
To provide, operate, and improve the platform and its features
To process payments and manage subscription billing through Stripe
To power AI-assisted functionality via Anthropic and OpenAI
To send transactional communications (e.g., receipts, password resets, service alerts)
To send marketing communications where you have consented or where permitted by applicable law
To analyze usage patterns and improve platform performance and user experience
To detect, prevent, and respond to fraud, abuse, or security incidents
To enforce our Terms of Service and other agreements
To comply with legal obligations and respond to lawful requests from authorities
3. Legal Basis for Processing (GDPR)
For users located in the European Economic Area (EEA) or the United Kingdom, we process personal data under the following legal bases:
Contract performance: Processing necessary to fulfill our obligations under the Terms of Service.
Legitimate interests: Analytics, security, fraud prevention, and product improvement, where these interests are not overridden by your rights.
Legal obligation: Compliance with applicable laws and regulations.
Consent: Marketing communications and non-essential cookies, where we have obtained your explicit consent.
You have the right to withdraw consent at any time without affecting the lawfulness of processing prior to withdrawal.
4. How We Share Your Information
4.1 Authorized Sub-Processors
We share information with trusted third-party service providers who assist in operating the platform. These providers are contractually obligated to protect your data and may only use it as directed by us. The following sub-processors are authorized as of the effective date of this policy:
Anthropic | AI model inference and safety processing |
Amazon Web Services (AWS) | Cloud hosting, storage, and compute infrastructure |
Auth0 (Okta) | User authentication and identity access management |
Clay Labs, Inc. | Data enrichment and analytics |
DocuSign | Electronic signature and document execution workflows |
Dropbox | Optional cloud storage integration |
Google Drive | Optional cloud storage integration |
Intercom, Inc. | Customer support and email communications |
Microsoft | Cloud services and internal tooling |
OpenAI | AI capabilities and natural language processing |
Prisma | Database access layer and data management |
Reditus | Affiliate and referral program management |
SendGrid (Twilio) | Transactional email delivery |
Square | Contract generation and payment workflows |
Stripe, Inc. | Subscription billing and payment processing |
Vercel | Frontend hosting and deployment infrastructure |
All sub-processors are located in the United States. A complete and current list is maintained in our Data Processing Agreement (DPA), available at rightask.ai/legal.
4.2 Legal Requirements
We may disclose your information if required to do so by law or in the good-faith belief that such action is necessary to: (a) comply with a legal obligation; (b) protect and defend the rights or property of RightAsk; (c) prevent fraud or address security issues; or (d) protect the personal safety of users or the public.
4.3 Business Transfers
In the event of a merger, acquisition, reorganization, or sale of assets, your information may be transferred to the successor entity. We will notify you via email or prominent notice on the platform before your information becomes subject to a materially different privacy policy.
4.4 No Sale of Personal Data
RightAsk does not sell, rent, or trade your personal information to third parties for their independent marketing purposes.
5. Cookies & Tracking Technologies
We use cookies and similar technologies to operate the platform, remember your preferences, analyze usage, and support security. Categories include:
Essential cookies: Required for the platform to function (e.g., session management, authentication).
Analytics cookies: Used to understand how users interact with the platform.
Preference cookies: Used to remember your settings and personalization choices.
Marketing cookies: Used to deliver relevant promotional content, where permitted.
You may manage cookie preferences through your browser settings or through the cookie consent banner displayed on your first visit. Where required by law, we obtain your explicit consent before placing non-essential cookies.
5.1 Global Privacy Control (GPC)
We honor the Global Privacy Control (GPC) signal. If your browser transmits a GPC signal indicating a preference to opt out of the sale or sharing of personal information, we will treat this as a valid opt-out request consistent with applicable law, including the CCPA/CPRA. Note that RightAsk does not sell or share personal information as those terms are defined under the CCPA/CPRA.
6. Data Retention
We retain personal data for as long as necessary to fulfill the purposes outlined in this policy, including to comply with legal obligations, resolve disputes, and enforce our agreements.
Account data: Retained for the duration of your account and for up to 3 years following termination.
Transaction records: Retained for 7 years to meet tax and financial compliance requirements.
AI session logs: Retained for up to 12 months for platform analytics and improvement.
Security and audit logs: Retained for up to 24 months.
Following the applicable retention period, we securely delete or anonymize your data.
7. Your Privacy Rights
7.1 All Users
Regardless of location, you have the right to: access the personal data we hold about you; correct inaccurate or incomplete data; request deletion of your personal data, subject to legal obligations; and opt out of marketing communications at any time.
7.2 California Residents (CCPA/CPRA)
California residents have additional rights, including the right to know, delete, correct, and opt out of the sale or sharing of personal information. We do not sell personal information. To submit a CCPA request, contact us at support@rightask.ai. We will respond within 45 days.
7.3 EEA & UK Residents (GDPR / UK GDPR)
In addition to the rights above, EEA and UK residents have the right to data portability; the right to restrict processing; the right to object to processing based on legitimate interests; and the right not to be subject to solely automated decision-making with legal or similarly significant effects. You also have the right to lodge a complaint with your local supervisory authority.
7.4 Canadian Residents (PIPEDA)
Canadian residents have the right to access and correct personal information we hold, and to withdraw consent subject to legal or contractual restrictions. Contact us at support@rightask.ai.
8. International Data Transfers
RightAsk is headquartered in the United States. If you access the platform from outside the United States, your information will be transferred to and processed in the United States.
For transfers from the EEA, UK, or Switzerland, we rely on Standard Contractual Clauses (SCCs) approved by the European Commission and, where applicable, the UK International Data Transfer Agreement. A copy of our applicable transfer mechanisms can be requested at support@rightask.ai.
9. Data Security
We implement industry-standard technical and organizational measures to protect your personal data, including encryption in transit (TLS), access controls, and regular security assessments. No method of transmission or electronic storage is 100% secure. In the event of a data breach, we will notify affected users and relevant authorities in accordance with applicable law.
10. Children's Privacy
The platform is not directed to individuals under the age of 18. We do not knowingly collect personal information from minors. If we become aware that we have collected personal data from a person under 18 without verifiable parental consent, we will promptly delete that information. Contact us at support@rightask.ai if you believe a minor has provided personal data.
11. Third-Party Links & Services
The platform may contain links to third-party websites or integrate with third-party services. This Privacy Policy does not apply to those third parties. We encourage you to review the privacy policies of any third-party services you access through the platform.
12. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. When we do, we will revise the effective date at the top of this page and, where changes are material, provide additional notice via email or in-platform notification. Your continued use of the platform after any update constitutes your acceptance of the revised policy.
13. Contact Us
Company | RightAsk AI, Inc., a Delaware corporation |
Address | 244 Madison Avenue #3870, New York, NY 10016 |
Website |