Legal

Privacy policy

Last updated 16 July 2026

This policy describes the actual data flows of the Ravelon website, account portal and optional cloud service.

Controller

The controller for the processing described here is Ravelon · Austria · hello@ravelon.app. Full company details are available in the legal notice.

Strictly necessary browser storage

The site stores your language, privacy choice and, when you sign in, a secure session. The refresh session uses an HttpOnly, Secure and SameSite-Strict cookie and is required for the sign-in you requested. This storage is not used for advertising. The legal bases are performance of a contract or pre-contractual steps (Article 6(1)(b) GDPR) and provision of the requested service.

Account and cloud synchronisation

For an account, we process in particular your email address, sign-in provider, display name, device names, subscription status and security-relevant audit events. Ravelon vault contents are end-to-end encrypted before upload. The sync service stores ciphertext only and has no decryption key. Terminal contents and transferred files are not collected for analytics.

If you deliberately use the Ravelon Agent, the desktop app sends your question and the selected, locally redacted terminal evidence directly to the AI provider profile you chose. Ravelon's hosted service does not proxy that request. Provider credentials and internal endpoint addresses remain device-local and are excluded from vault sync. The selected provider's own privacy and retention terms apply to the request. Redacted incident capsules and runbooks may be stored in and synchronized with the vault you selected.

Google, GitHub or Discord sign-in

If you voluntarily use an external sign-in provider, we receive the confirmed email address and a provider identifier. We never receive your provider password. The provider's own privacy information also applies.

Payments

Stripe may process payments for paid offers. Card and payment details are handled directly by Stripe and are not stored on Ravelon servers. Billing data required by tax and accounting law is retained for the applicable statutory periods.

Newsletter

If you subscribe to a newsletter, we process your email address, the chosen language and the time and version of your consent in order to send it. The legal basis is your consent (Article 6(1)(a) GDPR). We send nothing until you confirm the subscription through the link in a confirmation email. You can withdraw consent at any time with the unsubscribe link in every issue or in your account settings. Unconfirmed requests and the data of unsubscribed addresses are deleted after a short period. An email service provider sends the messages as our processor.

Server logs and security

Operating the service produces necessary connection and security data, such as time, shortened or full IP address depending on the infrastructure, requested path, status code and user agent. It is used for secure and stable operation, abuse prevention and troubleshooting, and retained only as long as those purposes or legal duties require. The legal basis is Article 6(1)(f) GDPR; our legitimate interest is operating the service securely.

Audience measurement with Umami

Umami loads only after you explicitly consent to the “Analytics” category. Before then, no Umami script is loaded and no request is sent. Analytics covers public marketing, documentation and legal pages only; account, sign-in, OAuth, live-share and admin pages are excluded. Umami runs on umami.michaelortner.at.

Umami sets no cookies. It records the page you open (without query parameters), the page title, the referring page, screen size, language, browser, operating system, device type and the country derived from your IP address. From these it forms an anonymous session identifier; the IP address itself is not stored.

**Session recordings and heatmaps:** For a share of visits, Umami also records how the page is used: page layout, clicks, scrolling and mouse movement. This produces session recordings and heatmaps that help us find usability problems. Anything typed into form fields is masked before sending and never transmitted.

You can withdraw your choice at any time through “Privacy” at the bottom left of the page. The legal basis is consent under Article 6(1)(a) GDPR together with section 165(3) TKG 2021.

Location

The location feature is currently disabled. The site does not request your location when a page opens.

Recipients and international transfers

Only hosting, authentication, support and payment providers required for the relevant purpose receive data. Where a recipient processes data outside the EEA, the safeguards required by Chapter V GDPR are used. Processors are bound under Article 28 GDPR.

Retention and deletion

Account data and encrypted vault data are retained until account deletion. Security audit events are routinely deleted after 365 days. Evidence of registration, legal acceptance and account deletion may be retained for up to 1,095 days; on account deletion these records are separated from the user identifier and their IP address and details are removed. Invoices, credit notes and the related purchase data (including the declarations made at checkout) are kept after account deletion for seven years from the end of the calendar year of issue, as Austrian law requires (BAO section 132, UGB section 212; Article 17(3)(b) GDPR), and deleted automatically afterwards; they are detached from the deleted account. Production backups must be overwritten by the operator according to a documented rotation schedule and kept accessible solely for disaster recovery. Local vaults and settings on your devices are not removed by deleting the cloud account and can be deleted in the respective installation.

Your rights

Subject to the statutory conditions, you have rights of access, rectification, erasure, restriction, portability and objection. In the privacy centre you can obtain your stored account data as a readable PDF report or machine-readable JSON file and delete your account. You may withdraw consent at any time for the future. Send requests to hello@ravelon.app. You may also complain to the competent supervisory authority; in Austria this is the Austrian Data Protection Authority, Barichgasse 40,42, 1030 Vienna.

Changes

If purposes or services change materially, we update this policy and request a new choice where consent is required.