Legal
Privacy Policy
Last updated: August 11, 2026
Thank you for your interest in Reframe AI, Inc. ("Rye", "we", "our", or "us"). Rye provides an LLM security platform that supervises AI coding agents, enforces workspace policy on model traffic, and records audit events for security and compliance teams.
This Privacy Policy explains how we collect, use, disclose, and protect personal information when you use our websites, dashboards, CLI tools, APIs, documentation, support channels, and related services (collectively, the "Service"). This policy does not apply to employee or contractor data, or to customer data that we process only as a service provider under a separate customer agreement.
Region-specific disclosures
- California. California residents may have rights to know, access, correct, delete, and limit certain uses of personal information. We do not sell personal information as that term is commonly used in privacy laws.
- Nevada. Nevada residents may submit opt-out requests for covered information. Rye does not sell covered information under Nevada law.
- European Economic Area, United Kingdom, and Switzerland. Additional disclosures for these regions are included below, including legal bases for processing and rights available under applicable privacy laws.
1. Information we collect
We collect information that you provide directly, information generated through use of the Service, information from third parties, and information collected automatically through logs, telemetry, and similar technologies.
Information you provide
- Account and registration information. Name, business name, email address, password or SSO profile, workspace details, role, and authentication metadata.
- AI request and policy information. Model traffic metadata, policy decision records, blocked or redacted request summaries, secret detection events, audit trail entries, protected path configurations, device identity records, and workspace policy settings.
- Developer and integration information. API keys, proxy configuration, environment settings, request IDs, CLI version and invocation metadata, install scripts, test payloads, logs, and documentation feedback.
- Communications. Messages sent to sales, support, security, trust and safety, or legal teams, including contact details and the contents of the communication.
- Payment information. We may receive billing metadata from payment processors. We do not intentionally store full payment card numbers on our systems.
Information from third-party sources
- Single sign-on. If you sign in with a provider such as Google, we receive information made available by that provider, such as your name, email address, profile picture, and account identifier.
- AI model providers and identity providers. We may receive request routing, authentication, and error metadata from upstream model API providers or identity systems used to authenticate devices and users.
- Service providers and partners. We may receive fraud, compliance, analytics, marketing, and support information from vendors that help us provide the Service.
Automatically collected information
- Log data, including IP address, operating system, referring pages, timestamps, request IDs, API paths, status codes, proxy events, and diagnostic details.
- Device and usage data, including workstation identity metadata, CLI invocations, dashboard actions, documentation activity, feature usage, and session events.
- Approximate location derived from IP address, which may be used for security, anomaly detection, localization, and compliance.
- Cookie and similar technology data used for authentication, security, analytics, preferences, and service reliability.
2. How we use information
- To create accounts, authenticate users and devices, provide dashboards, issue API keys, and maintain access controls.
- To operate the local proxy, evaluate model traffic against workspace policy, enforce secret controls, and record policy decisions in the audit trail.
- To detect abuse, security incidents, credential compromise, policy bypass attempts, and violations of our agreements or policies.
- To monitor reliability, debug proxy and API errors, improve documentation, analyze product usage, and develop new security features.
- To communicate with you about the Service, support requests, billing, security notices, product updates, and legal changes.
- To comply with legal obligations, enforce agreements, resolve disputes, and protect Rye, our customers, and the public.
4. Your choices and controls
- You may update account information through the Service or by contacting support.
- You may unsubscribe from marketing emails by using the instructions in those emails. We may still send transactional or service messages.
- You may manage cookies through browser settings, though blocking some cookies may affect authentication or core functionality.
- Depending on your location, you may request access, correction, deletion, portability, restriction, objection, or withdrawal of consent.
5. Cookies and tracking technologies
We use cookies and similar technologies for authentication, security, session management, preferences, analytics, and performance. Some cookies are necessary for the Service to work, while others help us understand usage and improve the product.
| Category | Purpose | Examples |
|---|---|---|
| Strictly necessary | Authenticate users, maintain sessions, protect accounts, and route requests. | Session, CSRF, SSO state, and security cookies. |
| Analytics and performance | Understand page usage, proxy behavior, reliability, and product adoption. | Event, device, and usage analytics. |
| Preference | Remember workspace, language, region, and display settings. | Dashboard and documentation preferences. |
6. Retention and security
We retain personal information for as long as needed to provide the Service, comply with legal obligations, resolve disputes, enforce agreements, maintain security, and preserve legitimate business records.
We use administrative, technical, and organizational safeguards designed to protect personal information. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
7. International transfers
The Service is operated primarily from the United States. Personal information may be transferred to, stored in, or processed in countries other than the country where it was collected. Where required, we use appropriate transfer safeguards.
8. Children's privacy
The Service is not directed to children under 13, and we do not knowingly collect personal information from children under 13. If you believe a child provided personal information to us, contact privacy@rye.com.
9. EEA, UK, and Switzerland disclosures
Where applicable, our legal bases for processing include performance of a contract, legitimate interests, compliance with legal obligations, and consent. Legitimate interests include operating and improving the Service, securing our systems, preventing abuse, communicating with customers, and developing our business.
| Information | Use | Legal basis | Recipients |
|---|---|---|---|
| Account and contact information | Create accounts, authenticate users and devices, provide support, and send service notices. | Contract, legitimate interests, legal obligations. | Infrastructure, authentication, support, and communications providers. |
| AI request, policy, and audit information | Operate the proxy, enforce workspace policy, detect secrets, record audit events, and support security investigations. | Contract, legitimate interests, legal obligations. | Hosting, observability, analytics, security, and data processing providers. |
| Usage, log, and device information | Secure the Service, debug proxy issues, monitor performance, and improve security features. | Legitimate interests, legal obligations. | Hosting, observability, analytics, security, and data processing providers. |
| Marketing and preference information | Send updates, manage preferences, and measure engagement. | Consent where required, legitimate interests. | Communications, CRM, and analytics providers. |
10. Changes and contact
We may update this Privacy Policy from time to time. If changes are material, we will provide notice through the Service or another reasonable method.
Questions or requests may be sent to privacy@rye.com.