Privacy
What we hold, and what we refuse to.
Last updated 8 August 2026
RAUHA is operated by GYMFLOOR AI LTD. Contact privacy@rauha.ai about anything on this page, including deletion.
The short version
RAUHA stores conclusions, not conversations. When an assistant sends us something, a language model reads it once, keeps what was decided or learned, and the rest is discarded rather than filed. We do not keep transcripts and we do not train anything on your memory.
What we store
Your memory. Each entry holds the conclusion in our words, your own words where they carried the reasoning, the reasoning itself, a category, its type — decided, learned, remember or remind — the date it happened, any due date, and whether it is current or has been superseded.
Your account. Email address, a scrypt hash of your password, your name if you gave one, and which plan you chose. Sessions are rows in our database rather than tokens, so signing out genuinely revokes.
Credentials. API keys and connector tokens are stored only as SHA-256 hashes. We cannot show you a key again after it is created, because we do not have it. We record when each was last used.
Delivery records. When a device sends a conversation, we log the shape of what arrived — field names, counts, whether the signature verified, what we did with it — so a lost conversation can be told apart from one that never came. The content is not kept.
If you joined the waitlist. Your email address, and the referring page, browser and country of that request.
What we refuse
The model that reads your submissions is instructed to discard, and not to record: how you were feeling, your health, tiredness or stress; where you were and who you were with; and another person’s private circumstances — their health, money, family, or a judgement of them as a person.
Professional facts about people are kept, because they are the substance of someone’s working life — that a contact runs a particular company, or told you something about their market. Those keep their attribution, so a claim never becomes a bare fact.
This is instruction to a model, not a guarantee about every possible input. If something is in there that should not be, tell us and we will remove it.
Who else sees it
Anthropic.We use AI to flatten conversations into decisions and things learned, and commit them like a searchable git, so decisions survive across different assistants. That means the text you send to be remembered is passed to Anthropic’s API and read by a Claude model, which decides what is worth keeping. Separating the conclusion from the conversation cannot be done without something reading it. It is not used to train their models.
Your existing memory is not sent with it. Only the new text goes, along with the list of categories it might be filed under. Nothing you have already stored leaves our database to be read by anyone else.
Supabase hosts the database. Vercel hosts and runs the site. Resend sends what little email we send. ElevenLabs handles speech, if you use a RAUHA device.
Cloudflare Web Analytics counts visits. It records the page, where the visit came from, the country and the kind of device — and nothing else. No cookies, no identifiers, no profile, and no way to follow anybody between sites or link a visit to an account. There is no consent banner because there is nothing to consent to.
Nobody else. We do not sell anything and there is no advertising in the site.
What an assistant can reach
A connected assistant can read your memory and add to it. It cannot edit or delete anything — there is no tool for either, deliberately, so nothing it does can quietly rewrite what you remember. A change supersedes what came before and the earlier version is kept.
Each assistant holds its own credential. Revoking one leaves the others working. Your memory is scoped to your account and is never mixed with anyone else’s.
Security, honestly
Everything travels over TLS, and the database is encrypted at rest by the provider. Passwords and credentials are hashed and never stored in a usable form.
There is no application-level encryption of entries yet. That means anyone holding the database credentials could read memory in plain text, so those credentials are the real boundary rather than the encryption. We would rather tell you that than let “encrypted at rest” do work it cannot do.
Keeping and deleting
Memory is kept until you ask us to delete it — the point of it is that it outlasts the conversation. Sessions expire after thirty days. Connector tokens expire in an hour and renew until you disconnect.
Email privacy@rauha.ai and we will delete your account and everything in it. There is no self-service delete button yet, and building one is on the list.
Your rights
Under UK and EU data protection law you can ask for a copy of what we hold, ask us to correct or delete it, or object to how we use it. Ask at privacy@rauha.ai and we will answer within a month.
If someone else’s name appears in a RAUHA account because our customer wrote about their work, the same rights apply to them. Write to us and we will deal with it.
Our lawful basis is performing the contract you asked for — a memory only works if it remembers — and our legitimate interest in keeping the service running and secure.
Children
RAUHA is not for under-16s.
Changes
If we change what we collect or who sees it, we will change the date at the top and email you. Not a banner you can dismiss.