← Home

Draft Document

Privacy Policy

Last updated: July 12, 2026

1. Overview

This Privacy Policy describes how Invicta Systems LLC ("Invicta," "we," "us"), operator of RallyForge, collects, uses, retains, and deletes information when you use rallyforge.ai and related services. This is a draft policy pending counsel review and may change before general availability.

This policy should be read together with our Terms of Service and Acceptable Use Policy.

2. Information we collect

We may collect:

  • Account data: name, email, authentication identifiers, role, and subscription tier
  • Workspace data: projects, drafts, scheduled posts, assets, and connected account metadata you provide
  • Usage data: feature usage, AI generation counts, and admin audit events
  • Technical data: IP address, browser type, device information, and logs needed for security and debugging
  • Support data: bug reports and messages you send us

3. How we use information

We use information to:

  • Provide, secure, and improve the Service
  • Authenticate users and enforce access controls
  • Process subscriptions and usage limits
  • Send transactional email (e.g. sign-in links) and optional product notices
  • Generate AI-assisted drafts when you request them
  • Detect abuse, fraud, and technical issues
  • Review, remove, or restrict content that may violate our Acceptable Use Policy

4. AI processing

When you use AI features, prompts and relevant context may be sent to our AI provider(s) (e.g. Anthropic) to generate responses. Do not submit sensitive personal data you are not permitted to share. Provider terms and retention policies also apply.

5. Service providers

We use trusted processors to run the Service, such as:

  • Hosting and deployment (e.g. Vercel)
  • Database and authentication (e.g. Supabase)
  • Email delivery (e.g. Resend)
  • SMS delivery when configured (e.g. Twilio)
  • Payments when enabled (e.g. Stripe)
  • AI inference (e.g. Anthropic)

These providers process data on our behalf under contractual safeguards. We do not sell your personal information.

6. Cookies and local storage

We use cookies and similar technologies for session management, security, and preferences (e.g. workspace UI state). You can control cookies through your browser; some features may not work if cookies are disabled.

7. Data retention

The periods below are draft defaults for a SaaS product and may be adjusted as the Service matures or as law requires. We retain different categories of data for different lengths of time.

  • Account and profile data (name, email, authentication identifiers, role, subscription tier): retained while your account is active. After account closure or deletion, we may keep limited records for a reasonable wind-down period (typically up to 90 days) to complete pending operations, resolve disputes, and honor legal obligations.
  • Workspace content (campaigns, posts, drafts, assets, connected account metadata, and AI-generated outputs stored in your workspace): retained while your account is active. When you delete content or close your account, we delete or anonymize it from production systems within the timelines described in Section 8, subject to backup lag.
  • Policy acceptances and consent records (Terms, Privacy, AUP acceptance, age confirmation, marketing opt-in/out): retained for compliance and audit purposes — typically up to seven (7) years, or longer if required by applicable law — even after your account is deleted.
  • Billing and subscription records (invoices, payment metadata, plan history): retained for tax, accounting, and fraud-prevention purposes — typically up to seven (7) years — even after account deletion.
  • Logs, security, and error data (access logs, rate-limit events, error traces, security alerts): retained for a short operational period — typically 30 to 90 days — unless a longer period is needed for an active investigation, abuse response, or legal hold.
  • Support and bug-report data: retained while your issue is open and for a limited period afterward to improve the Service — typically up to one (1) year for resolved reports unless you request earlier deletion and we are not required to retain them.
  • Marketing opt-in records: retained until you opt out, plus a reasonable compliance period afterward to demonstrate consent and honor unsubscribe requests.

8. Data deletion

You may request deletion of your account and associated personal data. We will process verified requests within a reasonable period — our target is within thirty (30) days — unless a longer period is permitted or required by law.

How to request deletion:

  • In the product: if available, use Settings → Data & privacy → "Request account deletion" while signed in. This logs your request for our team to review and confirm before permanent removal.
  • By email: contact support@rallyforge.ai from the email address associated with your account. Include enough information for us to verify your identity.

What we delete, anonymize, or retain:

  • Deleted from production systems: account credentials, profile fields, workspace content you control, and other personal data we no longer need to operate the Service or meet legal obligations.
  • Anonymized where practical: aggregated usage metrics and audit entries that no longer identify you, when deletion would break operational reporting.
  • Retained as required: policy acceptance records, billing and tax records, fraud-prevention data, and information subject to legal hold, dispute, or regulatory retention requirements — even after account deletion.

Third-party processors: RallyForge relies on service providers such as Supabase (database and authentication), Stripe (when billing is enabled), email and SMS providers, hosting platforms, and AI inference providers. We delete or instruct deletion of data we control in those systems where we can. Each provider also maintains its own retention and deletion practices; we cannot guarantee immediate removal from their independent systems or from connected social platforms you authorized.

Backups: deleted data may persist in encrypted backups for a limited period (typically up to 90 days) before those backups expire or are overwritten. Backup copies are not used to restore deleted accounts except where required for disaster recovery or legal compliance.

9. Security

We use industry-standard measures including encryption in transit, access controls, and monitoring. No method of transmission or storage is 100% secure.

10. Your choices and rights

This section describes rights in plain language. It is a draft summary — not legal advice — and does not create obligations beyond what applicable law requires once this policy is finalized.

Depending on where you live, you may have rights to:

  • Access a copy of personal data we hold about you
  • Correct inaccurate account or profile information
  • Request deletion of personal data, subject to the retention limits in Sections 7 and 8
  • Request a portable export of certain personal data
  • Object to or restrict certain processing, where applicable
  • Withdraw marketing consent where processing is based on consent

RallyForge is operated from the United States. If you are in the European Economic Area, United Kingdom, or another jurisdiction with similar privacy laws, you may have additional rights (such as lodging a complaint with a supervisory authority). We will describe applicable mechanisms and contacts in the final policy where required.

To exercise these rights, use the in-product Data & privacy controls where available, or email support@rallyforge.ai or privacy@rallyforge.ai. We may verify your identity before fulfilling a request. We aim to respond within thirty (30) days unless law allows or requires a different timeline.

11. Children

The Service is not directed to children under 13 (or 16 in the EEA). We do not knowingly collect personal information from children.

12. International users

If you access the Service from outside the United States, your information may be processed in the US and other countries where our providers operate. We will describe transfer mechanisms in the final policy where required.

13. Changes

We may update this Privacy Policy. We will post changes on this page and update the "Last updated" date. Material changes may be communicated by email or in-product notice where required.

14. Contact

Privacy questions or data requests: privacy@rallyforge.ai or support@rallyforge.ai. Replace these addresses with counsel-approved contacts before launch.