Privacy Policy
Last updated: April 13, 2026
1. Who We Are
Rightify ("we", "us", "our") operates the legal rights information platform at rightify.app. We are committed to protecting your personal data and respecting your privacy in accordance with applicable data protection laws, including the General Data Protection Regulation (GDPR) and equivalent privacy frameworks worldwide.
For privacy questions, contact us at: legalandprivacy@rightify.app
2. Data We Collect
We collect the following categories of personal data:
- Account data: Email address, name, and password (hashed) when you register.
- Usage data: Questions you ask, countries selected, language preferences, your subscription plan, and question count.
- Documents: Files you upload for scanning or analysis (processed in memory, not permanently stored).
- Payment data: Handled entirely by our payment processor. We store only your customer ID and subscription status — never card details.
- Communications: If you contact support, we store the content of your messages.
- Technical data: IP address (for country detection), browser type, and general usage analytics.
3. How We Use Your Data
We use your data to:
- Provide and improve the Service
- Authenticate your account and manage your subscription
- Personalise your experience (preferred country, language)
- Send deadline reminders and important account notifications
- Prevent fraud and abuse
- Comply with legal obligations
Legal basis: We process your data on the basis of contract performance (to deliver the Service), legitimate interests (to improve the Service and prevent fraud), and consent (for marketing emails, which you may withdraw at any time). Where required by applicable law, we will seek your explicit consent before processing your data.
4. AI Processing
Questions and documents you submit are processed by third-party AI service providers acting under our instructions as data processors. These providers are contractually bound to handle your data securely and only for the purpose of generating responses on our behalf. We do not use your data to train AI models, and we select providers that maintain strong data protection standards. Please avoid including sensitive personal information (such as identity document numbers or financial credentials) in your questions.
5. Data Sharing
We share your data only with trusted third-party service providers necessary to operate the Service, including:
- Authentication and database providers — to securely store your account and usage data
- Payment processors — to handle subscription billing securely
- Email delivery providers — to send transactional and account emails
- AI service providers — to generate legal information responses
- Hosting and analytics providers — to deliver and monitor the Service
All third-party providers are contractually required to protect your data and may not use it for their own purposes. We do not sell your personal data to any third party.
6. Data Retention
We retain your account data and conversation history for as long as your account is active, or for 2 years after your last activity, whichever is sooner. You may request deletion of your data at any time (see Your Rights below). Financial and transaction records are retained for as long as required by applicable accounting, tax, and regulatory obligations in the jurisdictions where we operate.
7. Cookies
We use only essential cookies required for authentication and session management. We do not use advertising or tracking cookies. Analytics are collected in an aggregated, anonymised form and do not identify individual users.
8. Your Rights
Depending on your location, you may have rights under applicable data protection laws (including GDPR, CCPA, and equivalent regulations), such as:
- Access — request a copy of your personal data
- Rectification — correct inaccurate or incomplete data
- Erasure — request deletion of your data ("right to be forgotten")
- Restriction — limit how we process your data
- Portability — receive your data in a machine-readable format
- Objection — object to processing based on legitimate interests
- Withdraw consent — for any consent-based processing, at any time
To exercise any of these rights, email privacy@rightify.app. We will respond within 30 days. You also have the right to lodge a complaint with the data protection authority in your country of residence.
9. International Transfers
Rightify operates globally and your data may be processed in countries outside your own. Where data is transferred internationally, we ensure appropriate safeguards are in place — such as standard contractual clauses or equivalent mechanisms — to protect your data in accordance with applicable law.
10. Security
We implement appropriate technical and organisational measures to protect your data, including encrypted connections (HTTPS), hashed passwords, and access controls on our database. However, no internet transmission is 100% secure, and we encourage you to use a strong, unique password for your account.
11. Children
Rightify is not directed at children under 18. We do not knowingly collect personal data from minors. If you believe a child has provided us with personal data, please contact us and we will delete it promptly.
12. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by email or by posting a notice on the Service. Your continued use of the Service after changes are posted constitutes acceptance of the updated policy.
13. Contact
For any privacy questions or requests: legalandprivacy@rightify.app