Rha privacy policy
Effective September 22, 2026
This policy explains what Rha ("we", "us") collects when you use Rha, why, and what you can do about it. The short version: we keep what's needed to run your account and your maps, we don't sell personal data, and we don't use your location to advertise to you.
What we collect
Account. Email address, name, password hash, and sign-in provider if you use Google or GitHub. If you subscribe, our payment provider (Stripe) holds your card details; we see the subscription status, not the card.
What you make. Saved maps, drawings, uploaded data, place lists, and your conversations with the assistant, including which external sites you allowed it to reach. Conversations are stored so you can return to them; you can delete them.
Location. Only if you grant it in the browser, and only to centre the map and answer "near me". Your location is sent with your requests to the assistant while you use it; we don't keep a location history.
Usage. Server logs (IP address, browser, pages and API endpoints requested, timing, errors), kept for up to 30 days for security and debugging. We count assistant messages per account to apply plan limits.
Cookies. A session cookie to keep you signed in and browser storage for preferences (chosen model, panel layout). No advertising cookies, no third-party trackers.
How we use it
To run the service and your account; to answer your requests to the assistant; to enforce plan limits and prevent abuse; to fix problems; to tell you about changes to the service or these terms. We use aggregated, non-identifying usage statistics to understand what people use.
Who sees it
- AI models. Your assistant messages, the current map summary and, when you grant location, your location go to the model provider selected for your conversation: Anthropic Claude through Amazon Bedrock, or other providers listed in the model picker. Providers process the request to produce the answer under their business terms and don't use your data to train their models.
- Web search and external sites. When you allow the assistant to search the web (Tavily) or read a site, the query or URL goes to that service. Only what's needed for that request is sent.
- Infrastructure. Amazon Web Services (hosting, storage, email delivery) in the United States.
- Payments. Stripe, if you subscribe.
- Shared maps. Anyone with a share link can see that map, including its layers and drawings, until you unshare it.
- Legal. We disclose data if required by law or to protect the service and its users.
We don't sell personal data and we don't share it with advertisers.
Where it lives and how long
Data is stored on servers in the United States. Account data and your content stay while your account exists; when you delete your account, they're deleted within 30 days, except what we must keep for legal or accounting reasons. Logs are kept up to 30 days. Backups roll off within 30 days.
Your choices
- Change or delete your maps, place lists and conversations in the app at any time.
- Revoke a site the assistant may reach from the conversation's allowed-sites list.
- Withdraw location access in your browser settings.
- Export your maps and data with the export tools.
- Delete your account from the account page, or email us to do it.
- Residents of California, the EU/UK and other places with data-protection laws have rights to access, correct, delete and port their data and to object to some processing; email us to exercise them and we'll respond within the time the law requires.
Children
Rha isn't for children under 13 (or the age of digital consent where you live), and we don't knowingly collect their data.
Changes
We'll post updates here and change the date above. For material changes we'll tell you in the app or by email before they take effect.
Contact
legal@rhaspatial.com — Rha, San Francisco, California.