Privacy
What Ravn reads, and where it stays.
Ravn reads your working material so it can answer questions about it. That material stays on your own machine, in a database you control. It is never sold, never used for advertising, and never used to train anyone's models.
What it accesses
Connecting an account grants read-only permission. Ravn cannot send mail, edit documents, change calendars or modify contacts, because it never asks for the permission that would allow it.
- Mail. Headers, bodies and attachments, excluding spam and trash.
- Files and documents. Names, folder structure, sharing permissions, comments and contents.
- Calendars. Events, attendees and recurrence, for the past year and everything upcoming.
- Contacts. Names, addresses and organizations, used to recognize the same person across different systems.
- Code hosts. Repositories, commits, issues, pull requests, reviews and releases, where you connect one.
You choose which accounts to connect, and can narrow each one further by excluding particular labels, folders, shared drives, calendars or repositories.
Where it is stored
On your machine. Ravn runs locally against a database you host. There is no Ravn server holding a copy, and no account on our side that could be compromised to reach it.
Access tokens are encrypted before storage, under a key held in your operating system's keychain and never written to the database. A copy of the database alone cannot yield a usable token.
What leaves your machine
Ravn uses a language model to interpret material and judge what is relevant to a question. The relevant portions are sent to the model provider at the moment they are needed. This is the one case where your content leaves your machine, and it happens only to answer you.
Providers are used under API terms that exclude submitted content from training. You can point Ravn at a different provider, including one running locally, in which case nothing leaves at all.
Optional features reach the public internet when used. Web search sends your query to a search provider, and the browser fetches pages you ask for. Neither receives your connected material.
Limited use of Google user data
Ravn's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
- Google user data is used only to provide and improve the features you are using Ravn for.
- It is not transferred to others except as necessary to provide those features, to comply with applicable law, or as part of a merger or acquisition.
- It is never used for advertising of any kind.
- No human reads it, except with your explicit permission for a specific issue, to comply with applicable law, or where it has been aggregated and made anonymous.
- It is not used to develop, improve or train generalized artificial intelligence models.
How long it is kept
Ravn keeps what it has read so it can answer questions about the past. When something is deleted at its source, Ravn records the removal and stops treating it as current rather than erasing its own record. Otherwise a question about last month would quietly return a different answer than it did last month.
Deleting your local database removes everything Ravn has ever read.
Revoking access
Disconnect an account at any time from your Google account permissions page, which invalidates Ravn's tokens immediately. To remove what has already been stored, delete its database and object store. Both live on your machine.
Children
Ravn is not directed at, or intended for, anyone under 16.
Changes
If this policy changes in a way that affects how your data is handled, the date above will change and the substance will be described here rather than quietly folded in.