Skip to content

Privacy Policy

Last updated: September 11, 2026 (status notice only; policy text last revised August 15, 2026)

Status, September 11, 2026: the Rindler web-automation product described below stopped operating on August 20, 2026. The chat app at chat.rindler.ai, the dashboard at app.rindler.ai and the MCP server at mcp.rindler.ai are shut down, and those host names no longer resolve. The present-tense descriptions in this policy therefore describe how the service handled data while it ran. Your rights below are unchanged. The in-product controls that used to exercise some of them are gone with the apps, so every request now goes to founders@rindler.ai.

Rindler operates infrastructure that lets AI agents interact with third-party websites on behalf of a user. This page describes what we collect, why, who we share it with, and the rights you have over it. We try to keep it short and specific rather than long and hedged.

Who this applies to

This policy covers:

  • End users of chat.rindler.ai ("the chat app"), where you can sign in and ask an AI agent to perform tasks on your behalf.
  • Merchants and operators using app.rindler.ai ("the dashboard"), where you manage your site's Rindler integration and see traffic from AI agents.
  • Visitors to rindler.ai ("the marketing site").

The Rindler Custody mobile app for iOS and Android has its own, more specific policy, because it handles data this one does not (site logins held on your own device, and sign-in codes). See the Custody app privacy policy.

What we collect

Account data. When you sign in via Clerk (our authentication provider), we receive your email address, name, profile image (if set on your identity provider), and Clerk user ID. We never see your Rindler password.

Chat content. Messages you send to the chat app, files you upload, and the model's responses. We persist these so you can revisit past conversations and so the agent can carry context across turns. Tool calls the agent makes and the live page content it observes are persisted alongside the conversation.

Browser session data. When you grant the chat app permission to act on a third-party site (a retailer, a job board, a supplier portal) by completing a login flow inside a Rindler-managed browser, we extract the resulting session cookies, encrypt them with AES-256-GCM, and store the encrypted state in our database. Cookies are decrypted only when the chat app reuses the authenticated session on your behalf.

Stored site sign-ins. On a limited set of sites you can choose, per site, to let Rindler store the sign-in details for that site instead of only the session. This is opt-in and off by default, the details are encrypted with AES-256-GCM under a key scoped to your account, and they are never shown to the models. You can revoke a stored sign-in at any time, which deletes the encrypted record. On every other site Rindler holds only the session described above and never receives the password.

Telemetry. Operational logs (request paths, timings, error fingerprints), aggregate counters (number of sessions per site per day), crash reports with sensitive fields redacted server-side before they are sent to Sentry, and anonymous engagement events on rindler.ai, keyed by a random first-party visitor id (the rin_vid cookie): page views, clicks on links and buttons (we store the element's visible label, never the values of input fields), scroll depth, the terms you type into our docs search, and demo-call requests. These are stored in our own database and also processed by PostHog, our product-analytics provider, under that same visitor id. We collect these to understand what is useful.

Payment and form data. We do not collect payment-card numbers. Stripe processes card details, payer name, billing address, and email for Rindler subscriptions. Stripe sends us signed billing events that can include payer name, billing address, email, and billing metadata, but not card numbers. We deliberately do not persist payer name or billing address from those events. We receive and store only the payer email, Stripe payment, subscription, and event identifiers, the amount and currency, and the billing event and its reconciliation status. For carts an agent builds on a third-party site, checkout stays with that site. We do not use third-party ad-network trackers, fingerprinting, or session-replay tools. Our analytics events do not record the values of input fields or forms you fill in, aside from the anonymous docs-search terms noted above; the subscription billing data listed here follows a separate Stripe path.

How AI providers receive your messages

Rindler sends content to a large-language-model provider in two places. The chat app routes your messages, the system prompt, and the agent's tool-call results. Separately, when Rindler runs a site automation for you, it sends the rendered text of each page the agent visits to the same provider on every step, so the model can choose the next action. Today we use:

  • Anthropic (Claude models): operating under their standard API terms. Anthropic's default API tier does not use customer inputs to train their models.
  • OpenAI (GPT models): operating under their standard API terms. Rindler sends the OpenAI request with store: false set, which opts the request out of OpenAI's default 30-day input/output retention.

Both providers process messages strictly to generate a response and may briefly retain content for abuse-detection purposes per their policies. We do not send your name, email, or Clerk user ID to either provider as request metadata.

Sub-processors

The following service providers process data on Rindler's behalf. We update this list when we add or remove a vendor.

  • Clerk: authentication, session management, and merchant-invite metadata. Data: email, name, profile image, Clerk user ID.
  • Anthropic: LLM inference for the chat agent and for site automations. Data: chat messages, system prompt, tool results, and the rendered text of pages an automation visits.
  • OpenAI: LLM inference for the chat agent and for site automations when an OpenAI model is selected. Data: chat messages, system prompt, tool results, and the rendered text of pages an automation visits. We send store: false to suppress default retention.
  • Amazon Web Services (AWS): application hosting (Go MCP server, Next.js apps), managed Postgres (RDS), managed Redis (ElastiCache), and secret storage. Data: everything Rindler stores at rest.
  • Porter: deployment and cluster orchestration running on top of our own AWS account. Data: same scope as AWS.
  • Sentry: error monitoring. Data: stack traces, request metadata. Cookies, auth headers, and chat content are stripped before submission by a server-side scrubber.
  • PostHog: product analytics for our marketing site, chat app, dashboard, and benchmark tool. Data: engagement events (page views, clicks on links and buttons, feature usage) keyed by the rin_vid visitor id when you are signed out, or by your account id when you are signed in, plus coarse device and locale metadata. Chat message content, credentials, session cookies, the addresses of the third-party pages we act on, and the values of input fields are never sent. Session replay is not enabled.
  • Cloudflare: CDN and edge functions for the marketing site (rindler.ai). Data: standard CDN access logs (IP, user agent, request path).
  • Google: only when a workspace connects Google Drive on the Integrations tab, and only for that workspace. The account is your own, and you authorise it on Google's consent screen; we never see your Google password. Data: the files the integration reads or writes, and the email address of the account that granted access. The default grant is limited to files Rindler itself creates or that you explicitly pick for it; full access to your Drive is a separate choice you make when connecting. You can disconnect at any time, which revokes the grant at Google.
  • Kernel: managed cloud browser used to run authenticated and high-stealth-tier sessions. Data: the third-party URL being visited and, for authenticated sessions, the session cookies for that site.
  • Browserbase: fallback managed cloud browser used when Kernel is unavailable. Same data scope as Kernel.
  • BrightData: residential and ISP proxy network, plus a managed Scraping Browser, used to reach third-party sites that block datacenter traffic. Data: the third-party URL being visited and, for authenticated sessions, the request traffic for that site, which includes its session cookies. Selected per site, not used for every session.
  • Capsolver: captcha solving for third-party sites that challenge our sessions. Data: the captcha challenge itself, which may include a screenshot region of the page presenting it.
  • Anti-Captcha: captcha solving for third-party sites that challenge our sessions. Data: the third-party page URL, reCAPTCHA site key, requested action, minimum score, and generated captcha token.
  • Resend: transactional email delivery for notifications. Data: recipient email address and the message body.
  • Stripe - subscription billing. Stripe processes payment-card details, payer name, billing address, and payer email. It sends Rindler signed billing events that can include payer name, billing address, email, and billing metadata, but not card numbers. Rindler deliberately persists only payer email, payment, subscription, and event identifiers, amount, currency, and billing and reconciliation status. Rindler does not persist payer name or billing address from those events.
  • Slack: internal notifications for our team. Data: when you send feedback from the chat app, your email address (if you ask for a reply), your message, your account id, and a link to that conversation; when you request a new site, your account id and the domain you asked for; and operational alerts about agent runs that can include the third-party domain, the action attempted, and a short agent-written status note. Payment details and stored third-party credentials are never sent.
  • Infisical: secrets management. Stores service credentials (API keys, encryption keys); does not receive end-user data.

Your rights

Regardless of where you live, you can:

  • Request a copy of the data we hold about you.
  • Request correction of inaccurate data.
  • Request deletion of your account and the chat history associated with it. We honor these within 30 days.
  • Revoke any authenticated browser session you set up. This deletes the encrypted cookie record so we can no longer act on your behalf at that site.

Residents of the EU/UK (GDPR) and California (CCPA/CPRA) have additional rights including data portability and, for California residents, the right to opt out of any "sale" or "share" of personal information. There is nothing to opt out of: we have never sold your data, and we never will.

We do not sell, rent, or share consumer personal information, including phone numbers, with any third party or affiliate for marketing, advertising, or lead-generation purposes. Not for a fee, not as part of a partnership, and not in exchange for services. Your phone number is used only to operate the product you asked us to operate: to verify it belongs to you, to deliver service messages you have opted into, and to complete sign-in steps you have explicitly authorized. The only outside companies that ever handle your information are the operational sub-processors listed above, each of which processes it solely on our instructions to deliver the service and none of which is permitted to use it for their own marketing. We run no third-party advertising or ad-network trackers, and we participate in no data-broker or lead-generation exchange.

To exercise any of these rights, email founders@rindler.ai from the address on your account. We verify identity through Clerk before fulfilling deletion or export requests.

Retention

Chat history was retained for the lifetime of your account, and the chat app exposed a per-user "auto-delete" preference (7, 30, or 90 days, or off). The chat app is shut down, so neither of those controls is reachable any more. Deletion is now a request to the address above, which we honor within 30 days.

Encrypted browser sessions are retained until the underlying third-party cookie expires or you revoke the session. We do not refresh expired sessions silently.

Operational telemetry (error fingerprints, aggregate counters, and anonymous engagement events) is retained for up to 12 months for reliability work, with PII-bearing fields redacted server-side before persistence.

Security

Browser session cookies are encrypted at rest with AES-256-GCM and a per-user derived key. The encryption key is held in our secrets manager and is never logged or returned in API responses. Production database access is limited to the engineering team; the credentials live in our secrets manager rather than in our codebase, and every connection requires TLS. The administrator credential that can change the schema is separate, reaches production only through our deploy pipeline, and that pipeline refuses any statement that would destroy data.

We are not SOC 2, HIPAA, or PCI certified. We do not claim certifications we have not earned. Send us your questionnaire and we will fill it in, and we will get your security team on a call with us.

Children

Rindler is not directed at children under 13 and we do not knowingly collect data from them. If you believe a child has created an account, email founders@rindler.ai and we will delete it.

Changes to this policy

We will update the "Last updated" date and the sub-processor list when material changes occur. For changes that meaningfully expand how we use data, we will email signed-in users at least 14 days before the change takes effect.

September 11, 2026: added the status notice above and corrected the retention note that told you to delete conversations from the chat app, which is shut down. No right, retention period or sub-processor entry was changed.

Contact

Privacy questions: founders@rindler.ai. Security reports: founders@rindler.ai. Mailing address available on request.

Plain-English notice: this page is intentionally specific. If a claim here turns out to be inaccurate, that is a bug. Please report it to founders@rindler.ai and we will correct it promptly.