Legal

Privacy Policy

Last updated: 2026-04-25

Data controller

Rada OÜ (registrikood 111111111), a private limited company registered in the Republic of Estonia, registered office [REGISTERED OFFICE ADDRESS], Tallinn, Estonia, is the controller for personal data processed via the Service. Data-protection contact: privacy@userada.dev.

1. What We Collect

The Service collects only the following categories of personal data:

  • Account email — provided when you create an account, stored in Supabase auth, used to identify your account and to send transactional emails (sign-in links, billing receipts, security notifications).
  • Beta invite code — the redeemed invite code is recorded against your profile so we can attribute beta cohorts and revoke access if necessary.
  • Local diagnostics — when you opt in at first launch, the desktop app writes structured event logs to ~/.rada/diagnostics/rada-events.jsonl. These logs stay on your device and are never uploaded by Rada unless you explicitly attach them to a support ticket.
  • cloud_request_completed events — for authenticated users who have opted into cloud telemetry, metadata about completed cloud LLM requests (model id, token counts, timestamp, latency, opaque request id) is synced to Supabase to support quota accounting and billing reconciliation. Prompt and response content are not included.
  • Sentry crash and error events — application stack traces, breadcrumbs, OS and app version metadata, and an anonymous installation id, transmitted to Sentry (EU region) for defect diagnosis.
  • Billing data — handled by Creem; we receive only a customer reference, subscription tier, and invoice metadata.

2. What We Do NOT Collect

We have designed the Service so that the following categories of information do not leave your device through any Rada-operated channel:

  • The text of your prompts.
  • The contents of your source code or repositories.
  • The contents of any file Rada reads from your filesystem.
  • The text of any model output (cloud or local) generated for you.

Cloud requests forwarded through OpenRouter are subject to OpenRouter's own terms, but Rada does not retain a copy of the prompt or output content after the request completes.

3. Third-Party Processors

We rely on the following sub-processors. Each processes personal data only on documented instructions from Rada and is bound by a data-processing agreement.

Supabase
United States and European Union (dual-region; account data is replicated across both regions for redundancy).

Account authentication and Postgres storage for account email, beta invite code, and opted-in cloud_request_completed telemetry events.

Creem.io
Determined by Creem's own data-processing terms; payment card data is never stored by Rada.

Merchant of record for all paid subscriptions. Handles payment processing, card storage, VAT and sales-tax collection, invoicing, and refunds.

Sentry
European Union (Sentry EU region).

Crash reports and unhandled-error events from the Rada desktop application, used solely to diagnose product defects.

OpenRouter
Routing is handled by OpenRouter; specific upstream model regions vary per request and are governed by OpenRouter's terms.

LLM inference proxy for opt-in cloud requests. Forwards prompts and returns model output. Rada does not log or persist the prompt or output content beyond the duration of the request.

Formspree
United States. Form submissions are transmitted to and stored by Formspree under its own data-processing terms.

Processes the waitlist and enterprise-sales forms on the marketing site (the email address, company, team size, and any message you submit) and forwards them to Rada.

PostHog
European Union (PostHog EU region).

Product analytics for opt-in, anonymous in-app usage events. Only collected after you grant telemetry consent; no prompts, code, or API keys are sent.

4. Data Retention

  • Account records are retained for the lifetime of your account and for up to ninety (90) days after closure to handle billing reversals and legal obligations.
  • cloud_request_completed events are retained for thirteen (13) months from the date of the event, then aggregated and deleted.
  • Sentry events are retained for ninety (90) days under our Sentry plan and then automatically purged.
  • Local diagnostics remain on your device and are rotated according to your local disk policy; you can delete them at any time.
  • Billing records retained by Creem are kept according to applicable tax and accounting law (typically seven years in Estonia).

5. Your Rights Under the GDPR

Because Rada is operated by an Estonian entity and offers its Service to individuals in the European Economic Area, the General Data Protection Regulation applies. You have the right to:

  • Access the personal data we hold about you and obtain a copy.
  • Rectify inaccurate or incomplete personal data.
  • Erasure ("right to be forgotten") of personal data, subject to legal retention obligations.
  • Data portability — receive your data in a structured, commonly used, machine-readable format.
  • Object to processing based on our legitimate interests, including telemetry processing.
  • Withdraw consent for any processing that relies on consent (e.g. opted-in cloud telemetry), at any time and without affecting the lawfulness of processing carried out before withdrawal.

To exercise any of these rights, contact privacy@userada.dev. We will respond within thirty (30) days.

6. Complaints

If you believe we have not handled your personal data in accordance with applicable law, you have the right to lodge a complaint with your local supervisory authority. Rada's lead supervisory authority is the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon), aki.ee/en.

7. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be communicated by email to active accounts at least thirty (30) days before they take effect. The "Last updated" date at the top of this page indicates when the policy was most recently revised.

8. Contact

The data controller for personal data processed via the Service is Rada OÜ, Estonia. Privacy questions, GDPR rights requests, and data-processing agreement requests can be sent to privacy@userada.dev.