inkata

Privacy Policy

Effective 19 August 2026. Last updated 18 August 2026.

This policy explains what rinkata collects, where it goes, and what you can ask us to do about it. rinkata is operated by Quirence, Inc. ("Quirence", "we", "us"), which is the controller of the personal data described here.

We wrote this policy against what the product actually does. Where a practice is narrower than you might expect, we say so.

1. What we collect

Account data. When you sign in with Google, we store your email address, Google's stable subject identifier for you, your name, a link to your profile picture, and the hosted-domain claim if your account belongs to a Google Workspace. If you sign in with an email link instead, we store the email address you used. We derive a handle from the local part of your email address, and we record when your account was created and when it was last seen.

We do not store a password. rinkata has none.

Workspace content. Everything your workspace creates: Goals, specs, tickets, decisions, ideas, inbox notes, handoffs, comments, and completion evidence, plus the documents you upload to a knowledge base and the screenshots you attach as evidence.

Billing data. If you buy a Team plan, Stripe collects and stores your payment details. Card numbers never reach rinkata's systems. We store the identifiers that let us match your workspace to your Stripe customer and subscription, and we mirror your invoices so you can see them in the product.

Operational logs. Ordinary server logs, and a record of tool calls made against your workspace, so we can run the service and investigate problems.

2. What we do not collect

3. How we use it

We use your data to run rinkata: to authenticate you, to show your workspace to the people in it, to provide the AI features you use, to bill you, to send you transactional email, and to keep the service secure and working.

We do not sell your personal data, and we do not share it for advertising.

4. What we send to AI models, precisely

This is the most important disclosure in this policy, so it is exact.

Your content IS sent to Google Gemini for:

Your content is NOT sent for contextual help. That feature sends a fixed, private catalog of interface descriptions and the identity of the element you pointed at. No artifacts, no project data.

Google does not use this content to train its models. rinkata uses a paid Gemini API tier. Under Google's Gemini API Additional Terms of Service, Google does not use prompts or responses from paid services to improve its products, and it retains them only for a limited period to detect and prevent abuse. The different, training-permissive terms that apply to Google's free tier do not apply to rinkata's use.

That statement covers Google only. Other providers set their own terms, and we do not restate them here.

Where a Pressure debate goes

A debate is argued by two AI models on opposite sides. rinkata sends the topic and context to Pressure, our own debate service, which runs both sides and sends them on to the model providers, currently xAI (Grok) and Google Gemini.

So a debate transfers your content to xAI as well as to Google. Nothing else in rinkata does. If you would rather your content never reached xAI, do not run a debate.

5. Sub-processors

These are the companies that process data on our behalf so rinkata can work.

PartyWhat it doesWhat it receives
Google CloudHosting, database, file storageEverything, at rest
Google GeminiAI featuresThe content described in section 4
StripePaymentsBilling identity, payment details, invoices
ResendTransactional emailEmail addresses, for sign-in links and invites
GitHubRepository integrationAccess to the repositories you connect, including file content read during an import
xAI (Grok)One side of a Pressure debateThe debate topic and context only, and only when you run a debate

We will update this list before we add a sub-processor.

6. Services you connect yourself

rinkata lets you connect AI agents such as Claude, ChatGPT, Grok, and others to your workspace over MCP.

When you connect one, your project data goes to that provider under your agreement with them. They are not our sub-processors. We do not control what they do with what they read, and this policy does not cover it. Read their privacy terms before you connect them.

You can end any connection immediately from Settings → Connected apps.

7. Cookies and sessions

rinkata sets one cookie: your session. It is httpOnly, it is sameSite: lax, it is marked secure in production, and it lasts 14 days. The session itself is stored on our servers, in our database. The cookie holds a reference to it, not your data.

There are no advertising cookies, no tracking pixels, and no third-party analytics cookies.

Web fonts are self-hosted. rinkata serves its public web fonts from the same origin as the site, so loading a page does not send your IP address to a font provider.

8. Where your data lives

Google Cloud, in the us-central1 region of the United States. Compute runs on Cloud Run, the database is Cloud SQL, and uploaded documents and screenshots are in Google Cloud Storage.

There is one region and no EU data residency option. If you are outside the United States, using rinkata means your data is transferred to and stored in the United States.

9. How long we keep it

We keep your workspace content for as long as your workspace exists. Dropping from Team to Free deletes nothing. Plan limits bound what you can add, not what you already have.

Sessions expire after 14 days. Stripe keeps billing records for as long as its own obligations require.

10. Your rights, and how to exercise them

Depending on where you live, you may have the right to access your personal data, to correct it, to receive a copy of it, to have it deleted, or to object to how we use it.

Be aware of how this works today, because we would rather tell you than imply something automatic. rinkata has no self-service export and no self-service account deletion. Every request is handled by a person.

To make a request, email support@quirence.ai from the address on your account. We will confirm your identity, and we will respond within 30 days. If a request is complex and we need longer, we will tell you inside those 30 days and explain why.

What you can do yourself, in the product, today:

Deactivation is not deletion. It removes your access and stops you counting toward a seat, and your authored work stays in the workspace. If you want deletion, email us.

If you are in the EEA or the UK and you think we have handled your data wrongly, you can complain to your local supervisory authority.

11. Security

Sessions are server-side. Card data never touches our systems. Access to production data is limited to people who need it to run the service.

No service is perfectly secure, and we do not claim to be.

12. Children

rinkata is not for children. Do not use it if you are under 18, and do not create an account for somebody under 18.

13. Changes to this policy

We can change this policy. When a change is material, we will tell you before it takes effect. The date at the top of this page is the date of the current version.

14. Contact

Quirence, Inc., 700 El Camino Real, Suite 120 #1438, Menlo Park, CA 94025