Privacy Policy
Last updated: 12 August 2026
The short version. Rabt reads your recent email read-only to build a brief of what needs your attention. Your email is never written to — we do not send, change, or delete any message. In the business tools you connect, Rabt can also carry out actions you ask for, such as issuing a refund, raising an invoice, or updating an order. Nothing happens on its own: you approve each action, anything involving money or deletion asks you to confirm the exact figure first, and every action is recorded in your history. Your email contents are processed to create the brief and are not stored. We only keep your account ID and encrypted access tokens, and you can disconnect and delete them at any time.
Who we are
Rabt (“Rabt”, “we”, “us”) is a business assistant operated by [LEGAL ENTITY NAME]. This policy explains what data we handle when you use Rabt and why. For any privacy question, contact us at [privacy@yourdomain].
What we access, and why
When you connect an account, you approve the access that account needs. Some connections are read-only; others also let Rabt act on your instruction. We use them to build your brief and to carry out the actions you choose:
- Google or Microsoft sign-in (your name, email address, and profile basics) — to identify your account and sign you in.
- Email, read-only (Gmail or Outlook) — we read your recent messages (sender, subject, date, and snippet) to work out what may need a reply or follow-up. We do not send, modify, label, or delete any message.
- Google Calendar (read and write) — we read your upcoming events for your brief. When you ask, Rabt can also create, reschedule, or cancel an event and notify its guests.
- Messaging you connect (Slack, WhatsApp via your business provider) — we read who is waiting on a reply (unread counts, sender names, and message timing; for WhatsApp, message direction and timing only, never message text). When you ask, Rabt can send a reply you have written and approved.
- Business tools you choose to connect (Zoho Books, QuickBooks, Salla, Shopify, Tap Payments, Tabby, Moyasar, MyFatoorah, Tamara) — we read figures like overdue invoices, bills, orders, and payments for your brief. When you ask, Rabt can also act in them: raise or update an invoice, record a payment, issue a refund, update an order or its stock, or cancel something. Each tool is optional and connected only when you add it.
Actions are never automatic. Rabt acts only when you tell it to, and asks you to confirm the exact amount before anything involving money or deletion. The one exception is a standing instruction you set up yourself, which you can see and switch off at any time. Every action — yours or a standing one — is written to a history you can review.
What we store — and what we don't
We store, in an encrypted database:
- Your account identifier and basic profile (e.g. email address).
- Access and refresh tokens for the accounts you connect — encrypted at rest. These let Rabt rebuild your brief without asking you to sign in every time.
We do not store:
- The contents of your emails. They are fetched, processed in memory to generate your brief, shown to you, and not written to our database.
- The generated brief itself is returned to your browser; it is not retained on our servers.
AI brief generation
To write your brief, a digest of your recent email (and any connected-tool figures) is sent to our AI provider, Anthropic (the Claude API). This content is used only to generate your brief. It is not used to train AI models. Rabt does not train any public AI model on your inbox or workspace data.
Google API Services — Limited Use
Rabt’s use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
In plain terms: information obtained through Google sign-in, Gmail (read-only), and Google Calendar (read, and write only when you ask Rabt to create, reschedule, or cancel an event) is used only to provide and improve the Rabt morning brief shown to you and to carry out actions you request. We do not use it for advertising, we do not sell it, and no human reads it except with your explicit consent, to resolve a problem you have reported to us, where the law requires it, or as necessary for security. The digest sent to our AI provider (Anthropic) is used solely to generate your brief and is not used to train any AI model.
Who else processes your data (sub-processors)
We rely on a small set of providers strictly to run the service:
- Google / Microsoft — sign-in, read-only mail access, and Google Calendar (the accounts you connect).
- The business and messaging tools you connect (Slack, your WhatsApp business provider, and any accounting, store, or payment tools you add) — we exchange data with them only to build your brief and to carry out actions you request.
- Anthropic — generates your brief from the digest described above.
- MongoDB Atlas — encrypted storage of your account ID and tokens.
- Vercel — application hosting.
- Zoho, Intuit (QuickBooks), Salla, Shopify, Tap Payments, Tabby, Moyasar, MyFatoorah, Tamara — only if you connect them.
Usage analytics
During this beta, basic usage events (for example, when a brief is generated) are kept locally in your browser to help us measure whether Rabt is working. We do not currently send this to a third-party analytics service. If that changes, we will update this policy first.
How long we keep things
We keep your account ID and encrypted tokens until you disconnect the account or delete your data, after which they are removed. Email contents are not retained beyond generating your brief.
Your choices
- Disconnect any account at any time from Settings — this removes its stored tokens.
- Request deletion of your data by contacting us at the email above.
- Revoke Rabt's access directly from your Google or Microsoft account security settings.
Security
Access and refresh tokens are encrypted at rest, and your session is protected with a signed, httpOnly cookie. No system is perfectly secure, but we limit what we collect specifically to reduce risk — we keep tokens, not your mail. If something breaks, we record the technical error (the message, where it happened, and a stack trace) in our own server logs to fix it — never your email contents, and never shared with a third party.
Children
Rabt is a tool for businesses and is not directed to anyone under 18.
Changes & contact
We may update this policy as Rabt evolves; the “last updated” date above will change. Questions or requests: [privacy@yourdomain]. Governing law: [JURISDICTION].
This document reflects how Rabt currently handles data and is provided for the beta. It is not legal advice. Replace the bracketed placeholders and have it reviewed before a public launch.