1. Scope
This Privacy Policy explains how Ripent may collect, use, disclose, and protect information when you visit ripent.io, create an account, or use the Ripent platform. It applies to information handled by Ripent as the service provider for the account or workspace using the platform.
If you use Ripent through an organization, that organization may control the information it sends to Ripent. In those cases, the organization's agreement with Ripent and its own privacy practices may also apply.
2. Information we collect
Account and profile information. We may collect your name, business email address, company, role, login credentials, and other information you provide when you register, request a working session, or contact us.
Connected-service information. If you connect a CRM, email, calendar, collaboration, or other supported service, Ripent may receive the records and metadata that you authorize that service to share. The available data depends on your permissions and the connected provider.
Usage and device information. We may collect information about how you use the website and platform, including pages or features viewed, browser and device details, security events, and diagnostic logs.
Communications. We may retain messages, support requests, feedback, and other communications you send to us.
3. How we use information
We use information to provide, maintain, secure, and improve the website and platform; authenticate users; respond to requests; operate connected integrations; personalize the service; detect abuse; communicate about the service; and comply with legal obligations.
We may also use aggregated or de-identified information for analytics, service improvement, and planning when it cannot reasonably be used to identify you or your organization.
4. Connected services and customer content
Ripent accesses connected services only through the permissions granted by you or your organization. You can manage or revoke those permissions through the connected provider or your Ripent workspace, subject to the provider's functionality and any applicable agreement.
You are responsible for ensuring that you have the rights and permissions needed to provide customer content to Ripent and to allow Ripent to process it for the purposes described in your agreement.
5. Google user data and Limited Use
If you choose to connect a Google account, Ripent requests only the scopes needed for the features you use. Your basic identity (openid, userinfo.email, userinfo.profile) identifies your account and populates your profile. Gmail read access (gmail.readonly) lets Ripent surface the email context and reply activity shown against your accounts and outreach. Gmail send access (gmail.send) sends only the outreach messages you approve in Ripent. Calendar access (calendar.events) reads and creates the meetings you schedule through Ripent. Google Sheets access (spreadsheets) and per-file Google Drive access (drive.file) read and write only the specific files you select or that Ripent creates for you.
Ripent uses this Google user data solely to provide and improve those user-facing features. Ripent's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Google user data is never used for advertising and is never sold. It is not transferred to others except as needed to provide or improve these features, to comply with applicable law, or as part of a merger or acquisition. No human reads your Google user data except with your explicit permission, where required for security purposes such as investigating abuse, to comply with applicable law, or where the data has been aggregated and de-identified.
Ripent does not use Google user data to train generalized artificial-intelligence or machine-learning models. Where a feature summarizes or drafts content, the request is processed to produce that result for you and is not used to improve a third-party foundation model.
You can disconnect a Google account at any time from Ripent's connector settings. Disconnecting marks the connection inactive and clears the access and refresh tokens Ripent stored for it, so Ripent can no longer call Google on your behalf. You can also review or withdraw Ripent's access directly in your Google Account under Third-party apps with account access, which revokes the grant at Google.
Who we share Google user data with. Ripent does not sell Google user data and does not share it with advertising networks or data brokers. It is disclosed only to the infrastructure providers that run the service on Ripent's behalf: Amazon Web Services, which provides Ripent's compute, PostgreSQL database, object storage, and content delivery; and Amazon Bedrock, the AWS service that performs the model inference behind Ripent's summarization and drafting features. These providers process the data only to deliver those functions to Ripent under their agreements with us. Beyond them, Google user data is disclosed only when you direct Ripent to send it somewhere (for example, sending an email you approved, or exporting to a Google Sheet you selected), when required by law or legal process, or in connection with a merger, acquisition, or sale of assets.
How we protect Google user data. All traffic between your browser, Ripent, and Google's APIs is encrypted in transit using HTTPS/TLS. OAuth access and refresh tokens are encrypted at rest in Ripent's database using Fernet authenticated symmetric encryption applied at the storage layer, so the tokens are never held in the database as readable text. Access to production systems and stored credentials is limited to personnel who need it to operate and support the service. No method of transmission or storage is completely secure, so we cannot guarantee absolute security.
Retention and deletion of Google user data. Ripent retains Google user data only while your connection is active and while it is needed for the features described above. Disconnecting a Google account clears the stored OAuth tokens for that connection immediately. To request deletion of the Google user data associated with your account, email founder@ripent.io; we will delete it except where we are required or permitted by law to retain it, and we will confirm when the deletion is complete. If you use Ripent through an organization, your administrator may also request deletion on your behalf.
6. When we share information
We may share information with service providers that help us host, secure, support, and operate Ripent; with connected providers when you ask Ripent to use an integration; with your organization's administrators; when required by law or legal process; or as part of a corporate transaction such as a merger, acquisition, financing, or sale of assets.
We do not sell personal information for behavioral advertising. We limit access to information to people and providers who need it for the purposes described in this Policy or in the applicable customer agreement.
7. Retention and security
We retain information for as long as reasonably necessary to provide the service, meet the purposes described in this Policy, resolve disputes, enforce agreements, and comply with legal obligations. The applicable customer agreement may define additional retention or deletion requirements.
We use administrative, technical, and organizational safeguards designed to protect information. These include encryption in transit over HTTPS/TLS for all traffic to the website, the platform, and connected provider APIs; encryption at rest for credentials and sensitive profile fields, applied at the database layer so they are not stored as readable text; and restricting access to production systems and stored credentials to personnel who need it to operate and support the service. No method of transmission or storage is completely secure, so we cannot guarantee absolute security.
Deleting your information. You can disconnect any connected service at any time, which clears the stored credentials for that connection. To request deletion of your account or the data associated with it, email founder@ripent.io. We will delete the data except where we are required or permitted by law to retain it, and we will confirm when the deletion is complete. If you use Ripent through an organization, that organization's administrator may also make this request on your behalf.
8. Cookies and similar technologies
Ripent may use cookies and similar technologies to keep you signed in, protect the service, remember preferences, understand usage, and improve the website. You can control cookies through your browser settings, although disabling required cookies may affect sign-in or platform functionality.
9. Your choices and rights
Depending on where you live and how you use Ripent, you may have rights to request access to, correction of, deletion of, or a copy of your personal information, or to object to or restrict certain processing. You may also withdraw consent where processing is based on consent.
To make a request, contact us at founder@ripent.io. If you use Ripent through an organization, you may need to contact that organization first. We may verify your identity and may retain information where required or permitted by law.
10. Children and policy changes
Ripent is intended for business users and is not directed to children. We may update this Policy from time to time. When we make material changes, we will update the date above and provide any notice required by applicable law.
11. Contact us
Questions about this Privacy Policy or Ripent's handling of information can be sent to founder@ripent.io.
Questions? founder@ripent.io