Rapidly privacy

What we store and why

Last updated 12 July 2026

Data Rapidly stores

We store account details such as your name, email, sign-in method and profile image so you can authenticate and manage your account. We store the teams you belong to, ideas, experiments, tasks, files and team knowledge so Rapidly works for you and your colleagues.

When you use the Idea Validator or AI and MCP tools, we may store the prompt or idea you submit, the generated result, your account or verified email, IP address, tool and project identifiers, and security or delivery logs. API keys are stored as one-way hashes; OAuth codes, refresh tokens and MCP sessions are stored only for authentication and connection lifecycle.

How we use it

We use this data to provide the product, generate requested analysis, secure and rate-limit the service, preserve team work, send requested account and product emails, support billing, and diagnose failures. We do not use one customer's private team data to give another customer access to it.

Retention

Direct identity and raw AI input and output in the MCP capability engine are scrubbed after 90 days. Pseudonymous audit metadata is retained for up to 365 days. Security events are retained for 180 days. Terminal jobs and sessions are generally retained for 30 days; expired short-lived authorization data is removed sooner. Active account, team, billing and configuration data remains while it is needed to provide the service.

Account deletion and erasure

You can permanently delete your account from Edit profile. You must type your current email to confirm. If you are the only admin of a team, promote another member first so the team is not left without an admin.

Deletion removes your local login, profile and profile avatar, memberships, API and OAuth credentials, agent sessions, personal validator leads, direct activity rows, and directly attributable raw AI content. Shared team ideas, tasks, files, audit events and operational configuration remain for the team, but your creator, owner or assignee identity is removed. Deletion cannot be undone.

Service providers

Rapidly sends the minimum data needed for a requested function to service providers used by the live code: OpenAI for AI generation, Stripe for billing, Postmark for transactional email, Google or Microsoft for optional sign-in, and Pipedrive and Attio for customer and product communications. Google Analytics measures website and product usage.

Self-service deletion completes the local Rapidly cascade. Records already held by an external provider may follow that provider's legal or operational retention rules. To request a provider-side erasure or ask a privacy question, email [email protected].