LEGAL

Privacy policy

Last updated: 2026-08-20 (draft, pending legal review)

This policy explains how ReadyForAI (“we”) collect, use, store, and delete personal information on readyforai.com. We collect only what a given feature needs, and encrypt data in transit and at rest.

1. What we collect

1.1 Browsing (automatic)

  • IP hash — SHA-256 truncated to 16 hex characters. We do not store the raw IP. Used for daily rate limits and abuse detection.
  • Session id — an HttpOnly cookie named rfai_sid, issued by us, to tie requests in one session for follow-up caps. Functional only: no cross-site tracking, no ads.
  • Access logs — intent-box query text, matched intent, confidence, latency. Stored in our database for debugging, content ops, and model evaluation.

1.2 Data you submit (contact forms)

  • Name, email, company
  • Topic (demo / pricing / deep dive / other)
  • Optional notes
  • Source page (for example /en/products/aulo)
  • IP hash, User-Agent, and Referer at submit time (anti-spam)

We do not collect phone numbers, national IDs, geolocation, or biometrics. New fields will be labeled on the form and reflected here.

2. Why we collect it

  • Service — IP hash / session cookie enforce the daily free allowance; intent logs improve how we read governance questions.
  • Your request — form data goes to sales or the matching engineer. If you did not ask for anything else, we will not use the email for other purposes.
  • Safety — abuse detection (flooding, prompt injection) keeps a small audit trail.

3. Storage and sharing

  • Production data lives in our domestic-cloud database, consistent with PRC data-residency rules.
  • We do not sell personal data or share it with ad networks.
  • Third parties only when:
    • an LLM provider required to answer your intent (query text only, no contact fields);
    • email delivery to our own sales inbox;
    • required by law or a lawful judicial request.

4. Retention

  • Intent logs: up to 180 days, then deleted.
  • Form data: up to 24 months; deletion within 30 days of a request.
  • IP hash and rate-limit counters: 24 hours in Redis.

5. Your rights

Under the PIPL you may access, copy, correct, delete, or withdraw consent. Email [email protected]. We reply within 15 business days.

6. Cookies

One HttpOnly functional cookie (rfai_sid) for follow-up caps. No third-party analytics or ad cookies, and no Google Analytics / Facebook Pixel.

7. Updates

Material changes update the date at the top of this page and are emailed to people who left a lead. Continued use means you accept the updated policy.

8. Contact

Privacy: [email protected]
Other: [email protected]

SYSTEM READYlegal/privacy