Privacy Policy
Last updated: July 8, 2026
Rationale LLC (“Rationale,” “we,” “us”) builds an organizational-memory platform that captures and connects the reasoning behind your decisions. We take that responsibility seriously, and we built Rationale so your knowledge stays yours. This policy explains what personal information we handle and why.
1. Who this policy covers
This policy applies to our website, the Rationale application, and related services. It describes how we handle personal information for which we are responsible.
Important distinction for our customers: the documents, decisions, and other artifacts your organization uploads or connects, together with the outputs Rationale generates from them (“Customer Content”), may contain personal information about your people or third parties. For Customer Content, your organization is the data controller and Rationale acts as a processor on its behalf under our agreement with your organization. If you are an employee of a Rationale customer, please direct privacy requests to your organization first.
2. Information we collect
We collect the following categories of information:
- Information you provide: your name and email when you create an account, the contents of messages you send us (for example, through the contact form), and information in support requests.
- Customer Content you upload: the artifacts you or your organization upload to the platform, which may include personal information. We process this only to provide the service.
- Data from services you connect: if you or your organization connect a third-party service such as Google Docs, Jira, Confluence, or Notion, we collect the content and metadata you authorize us to access from that service, along with the encrypted tokens needed to keep the connection working. This is Customer Content too - see section 3.
- Information collected automatically: log and usage data such as IP address, browser and device information, pages and features used, and timestamps, along with information from cookies and similar technologies.
3. Data from services you connect
Connectors are the main way most teams bring content into Rationale. When you connect a service, we access it read-only, under the permission (OAuth) grant you approve on that service’s consent screen, and we sync only what that grant covers:
- Google Docs: Google Drive file metadata and the content of Google Docs the connected account can read, or only a specific folder where the connector has been scoped to one (available on request).
- Jira and Confluence: issues, comments, and pages, including the names and Atlassian account IDs of people who appear in them (such as reporters, assignees, and commenters).
- Notion: the pages and databases shared with the connection, along with the workspace name and ID.
We use connected content solely to provide the service - extracting decisions and the reasoning behind them into your organization’s memory graph. It is stored on our infrastructure in the United States, and the OAuth access and refresh tokens are stored encrypted. Connected content may include personal information about your colleagues and other people who never use Rationale; your organization is responsible for that data as its controller (see section 1).
We store source account identifiers for Atlassian connectors (Atlassian account IDs) so we can honor erasure obligations: when we learn that an Atlassian account has been closed (we check nightly), or your organization asks us to erase a specific person, we run a targeted redaction of that person’s personal data in Rationale. For other connected services, we handle erasure requests manually. Automated redaction may miss indirect references (for example, a paraphrased mention); we handle those through manual review on request.
You can disconnect a service at any time; no further syncs will run, and you can delete already-synced artifacts in the app or ask us to delete them.
Rationale’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. In particular, we use Google user data only to provide the features described here, we do not use it for advertising, we do not sell it, and we do not allow humans to read it except with your permission, for security purposes, to comply with law, or when it has been aggregated and anonymized.
4. Cookies and tracking technologies
We use strictly necessary cookies to sign you in, keep your session secure, and operate the site. These are always on. With your consent, we may also use a limited amount of first-party analytics to understand how the product is used so we can improve it. We do not run any analytics today; if we introduce them, they will run only with your consent.
You can accept or reject non-essential cookies when you first visit, and change your choice at any time through the “Cookies” link in the footer. You can also manage cookies through your browser settings.
We do not use third-party advertising cookies and we do not track you across other companies’ websites. We honor recognized opt-out signals such as Global Privacy Control: if your browser sends one, we turn off non-essential cookies automatically, even if you previously accepted them (you can expressly re-enable analytics afterwards in the cookie preferences if you choose). Our site does not respond to older “Do Not Track” browser signals, which lack a settled standard; use the cookie controls described above instead.
5. How we use information
We use personal information to provide, secure, and operate the service; to authenticate you; to respond to your messages; to monitor, debug, and improve the product; to send you service and administrative communications; and to comply with our legal obligations. Customer Content is an exception: as sections 2, 3, and 6 describe, we process it only to provide the service.
Where the GDPR or similar laws apply, we rely on the following lawful bases:
- Performance of a contract: creating and operating your account and providing the service.
- Legitimate interests: securing, monitoring, debugging, and improving the service, and responding to your messages.
- Consent: optional analytics cookies, and anything else we expressly ask you for. You can withdraw consent at any time.
- Legal obligation: complying with applicable law and lawful requests.
6. AI processing and your content
Rationale processes Customer Content to extract decisions and the reasoning behind them and to connect that knowledge into your organization’s memory graph.
We do not use Customer Content to train our own or any third party’s AI models, and we do not sell it. Processing relies on vetted infrastructure and model providers - currently Anthropic (language models) and OpenAI (language models and text embeddings) - under commercial terms that prohibit them from training their models on your content and limit their use of it to providing their services to us (with limited retention for trust-and-safety review and legal compliance).
Bring your own key: workspace administrators can supply their organization’s own API key for a supported model provider. When you do, calls Rationale makes to that provider for your workspace are made with your key and are governed by your organization’s own agreement with that provider, not by our commercial terms with them; the no-training commitments described above then depend on that agreement. This applies per provider: providers you have not supplied a key for continue to run under our agreements, and document embeddings always run through Rationale’s OpenAI account under our terms. Your keys are stored encrypted, are never displayed back after entry, and are sent only to that provider’s official API.
7. How we share information
We share personal information only in these limited circumstances:
- Service providers and subprocessors who help us operate the platform, acting on our instructions. Currently: Clerk (authentication), Amazon Web Services (cloud hosting and email delivery, United States), Vercel (website hosting), Anthropic (AI language models), and OpenAI (text embeddings). We update this list when our subprocessors change.
- Legal and safety reasons, when required by law or to protect the rights, property, or safety of Rationale, our users, or the public.
- Business transfers, such as a merger, acquisition, financing, or sale of assets, in which case this policy will continue to govern the information transferred.
8. We do not sell or “share” your personal information
We do not sell personal information for money, and we do not “share” it for cross-context behavioral advertising, as those terms are defined under the California Consumer Privacy Act (as amended by the CPRA) and similar laws. We have not done so in the preceding twelve months.
Because we do not sell or share personal information, there is no need to opt out of a sale. If this ever changes, we will update this policy and provide a clear opt-out before doing so.
9. Your privacy rights
Depending on where you live, you may have the right to access, correct, delete, or port your personal information, to restrict or object to certain processing, and to withdraw consent. California residents also have the rights to know what we collect, to delete and correct it, to opt out of sale or sharing (which we do not do), and not to receive discriminatory treatment for exercising these rights.
To exercise a right, email us at privacy@therationale.ai or contact@therationale.ai. We will verify your request before acting on it and respond within the time required by applicable law. If we deny your request, you can appeal by replying to our response, and we will answer the appeal within 45 days. Where we process Customer Content on behalf of an organization, we will forward your request to that organization. If you are in the EEA or UK, you may also lodge a complaint with your local supervisory authority.
10. Data retention
We keep personal information only as long as we need it for the purposes described in this policy:
- Account information: while your account remains open, and afterwards until we complete the deletion described below.
- Customer Content (including connected-service content): while your account remains open, until you delete it or ask us to delete it. Disconnecting a source stops new syncing; already-synced content remains until you delete it or request deletion.
- Contact-form messages and support correspondence: for as long as needed to handle your inquiry and for a reasonable period afterward.
- Log and usage data: up to 12 months.
If you stop using Rationale or your organization’s agreement with us ends, we will delete your Customer Content and associated personal information within 30 days of a verified written request and confirm when deletion is complete. Copies may persist in backups for a short period until those backups expire on our rotation schedule, and we may retain specific records where the law requires it.
11. Security
We use administrative, technical, and organizational safeguards designed to protect personal information, including access controls, encryption in transit, and access scoped to each project. No method of transmission or storage is completely secure, so we cannot guarantee absolute security.
12. International data transfers
We are based in the United States and process information on servers located in the United States. If you use Rationale from another country, your information will be transferred to, stored, and processed in the United States.
Where the GDPR, UK GDPR, or similar laws require safeguards for such transfers, we will put appropriate safeguards in place, such as the European Commission’s Standard Contractual Clauses (with the UK Addendum or International Data Transfer Agreement for transfers from the UK). You can request a copy of the safeguards that apply to your data by contacting us.
13. Children’s privacy
Rationale is a workplace product and is not directed to children under 16. We do not knowingly collect personal information from children. If you believe a child has provided us information, contact us and we will delete it.
14. Changes to this policy
We may update this policy from time to time. When we do, we will revise the date at the top of this page and, for material changes, notify you in advance - for example by email or an in-product notice. If a change materially affects how we use personal information we have already collected, we will ask for your consent before applying the change to that information.
15. Contact us
Questions or privacy requests: privacy@therationale.ai. For anything else, reach us at contact@therationale.ai.