Privacy Policy
Last updated July 2026
This policy explains what Paneotech collects when you use Rafiki AI, why, who else sees it, and how long it is kept. It describes the system as it actually runs, including the places where a protection you might expect is not yet in place.
What we collect
Account data: your name, email address, whether that address is verified, your approval status, and, if you enable two-factor authentication, a shared secret and your unused backup codes.
Content you create: your conversations and the model replies in them, saved prompts, skills, and the memories you ask the assistant to keep. This is stored so the product can show it back to you.
Usage and billing records: which model handled each request, the token counts, the cost, your credit ledger, and the payment attempts behind it. We store a payment processor's reference for a transaction; we never see or store card numbers.
API keys: only an internal alias and the last four characters. The key itself is shown to you once, at creation, and is never stored here in a form we could return to you or to anyone else.
Security and operational records: sign-in attempts, an audit log of significant account actions, and the IP address those actions came from.
Why we hold it
To run the service: routing your requests, showing your history and usage, applying budgets, and taking payment.
To secure accounts: rate-limiting sign-ins, detecting abuse, and giving you an audit log of what happened on your workspace.
To meet legal obligations, in particular keeping billing records for tax and accounting purposes.
We do not sell your data, we do not use your content to train models, and we do not use it for advertising.
Who else sees it
Model providers. Running a request means sending its content to whichever provider serves the model you chose, currently Alibaba, Anthropic, DeepSeek, Google, Groq, Meta, MiniMax, Mistral, Moonshot, OpenAI, Zhipu and xAI. What they do with it is governed by their own policies and their own contracts with us, not by this one. If a request contains something you would not want leaving this service, do not send it.
Payment processors, which receive the amount, a reference and whatever they need to take the payment. They handle your card or mobile-money details directly; those details never reach us.
Our email provider, which delivers verification, password-reset and notification messages.
Infrastructure providers that host the servers and the database.
Nobody else. We disclose data to law enforcement only where legally compelled, and will tell you unless we are prohibited from doing so.
How long we keep it
Plainly, before the list: there is no expiry we apply across the platform. Each workspace decides whether the conversations its agents hold are erased on a clock, and a workspace that has made no such choice, which is what every new one starts as, has nothing expiring on its own. Anything below that is not deleted by you, by the workspace's period or by us stays until it is.
Conversations, prompts and memories: for as long as the workspace that owns the agent chooses. A workspace can set a retention period of between 1 and 36 months, and where it has, we erase them on that clock. Where it has not, which is what a new workspace starts as, they are kept until somebody deletes them.
Usage and billing records: at least 7 years, since they support invoices and tax records. We do not delete them after that today.
Audit and security events: for as long as the workspace exists. An audit trail that can be tidied away is not one, so nothing in the product deletes these.
If you ask us to delete your account, it is done by you, from inside the product, under Settings, Your data. Two separate things live there. Close a workspace and the workspace goes with everything keyed to it: your knowledge documents, the SMS, USSD and voice records holding your customers' numbers, and that workspace's own audit trail. Your account stays open. Delete your account and, seven days later, the account itself goes: your chats and the files in them, your saved facts, your phone number, your sign-in and your gateway keys, plus any workspace you are the only person in, closed the same way. Seven days is a cooling-off period and you can stop it in one press at any point inside it. Three things deliberately survive with your name taken out of them, because a business is required to keep them: what was spent, what was paid, and the record of who changed what. A workspace can only be closed once its agents have been deleted, and deleting an agent removes the records of the work it did with it. Billing records survive deletion, because we are required to keep them.
Where a workspace has set a period, it erases conversations, including every message; SMS and USSD messages, including the customer's phone number; voice calls, including the caller's number; runs of a conversation, and the step by step trace of each one; run events; handovers to a person, including any contact detail the customer gave; orders the agent took, including the customer's delivery address; receipts the agent issued, including the customer's phone number; and appointments in the diary, including the attendee's contact details. It does not reach every copy of the same words. After the period has passed we still hold conversations behind an agent no workspace can be shown to own; runs that never belonged to a conversation; documents an agent wrote, which may name a customer in the text; the tab book, where a customer's name and number sit against what they owe; m-Pesa payments the shop received, and the name the payer's account is in; and flagged answers, including the question the customer asked. Those keep the message and the reply verbatim, and no retention period reaches any of them. Some can still be erased by hand. Deleting a conversation removes the SMS and USSD copies of it, empties the records of the work behind it and their step by step traces, empties any handover raised from one, and removes the flagged answers marked on the conversation itself or on one of those SMS and USSD turns. It does not reach a flag marked on a single run of a WhatsApp, Telegram or web conversation, and it does not reach a voice call record. So a period is not on its own an assurance that what a customer said has gone. Where you need something erased that a period and a delete cannot reach, write to [email protected] and we will say what we can and cannot do about it.
Deleting a conversation with one of your agents erases what was said in it. The messages go, and the record of the work behind each one is emptied in the same operation: what the customer wrote and what the agent answered are replaced by a count of the characters. What stays is the bookkeeping, the reference, the timings and the cost, because erasing a conversation must not be a way to erase a bill. Deleting the agent goes further and removes those records altogether.
Data residency, honestly
Region-specific routing, including EU-only, is not guaranteed on this installation and the option is disabled rather than shown as if it worked. Model providers operate globally and a request may be processed outside your country.
We would rather say this plainly than claim a residency control we cannot substantiate. When endpoint regions are confirmed, this section will change and the date at the top of the page will change with it.
Your rights
Your own chats with Rafiki AI, your saved prompts and your memories are yours to see, export and delete at any time, and deleting one of those removes it outright. A single chat exports from the chat screen itself. Your customers' conversations with your agents are a separate thing and are covered in "How long we keep it" above: deleting one is not the same as erasing everything we hold about that customer.
You can take everything with you. Settings, Your data lists what is held, in numbers, and the workspace owner can download the lot: knowledge sources, test suites, usage, invoices, the audit trail, and the agents, conversations and runs that can be shown to belong to the workspace. It comes in two shapes, built from the same read a moment apart. A page you can read opens in any browser and prints, and carries the agents and their instructions, the conversations word for word, the messages and calls on your numbers, and the text of every document. A data file in JSON carries everything the page leaves out, for another system to read. Both begin with a section saying what is in them and what is not.
You can delete your account yourself, from inside the product: Settings, Your data, Delete your account. It is not a deactivation and it is not a request that reaches a person. You type your email address to confirm, the date it will happen is printed on the screen, and seven days later the account and everything listed there is deleted. You can stop it in one press at any point in those seven days. Deleting your account does not reach every copy of every word: what a period and a delete cannot reach is listed above, and the same list is on the screen before you press anything.
You can also ask us for a copy of the personal data we hold about you, ask us to correct it, or object to how we are using it.
Requests go to [email protected]. We answer within 30 days. If you are not satisfied with our response you can complain to your local data protection authority.
Security
Passwords are hashed, never stored in a recoverable form. Traffic is encrypted in transit. Payment credentials and provider API keys are encrypted at rest, and Rafiki AI never returns a stored secret to a browser, only a four-character hint.
Two-factor authentication is available in Settings and we recommend enabling it. Sign-in attempts are rate-limited.
No system is perfectly secure. If we discover a breach affecting your personal data, we will notify you and the relevant authority as the law requires.
Children
The service is not directed at children and accounts are not knowingly created for anyone under 18. If you believe a child has an account here, contact us and we will remove it.
Changes to this policy
We may update this policy. Material changes go to the email address on your account, and the date at the top of this page changes with them.
Who is responsible, and contact
Paneotech operates Rafiki AI. The registered entity acting as data controller is stated in the binding version of this policy on the marketing site. For anything about your data, write to [email protected].
Questions, or a request about your data? Contact info@paneo.tech.
Rafiki AI