Legal

Raf Privacy Policy

Effective policy

Version 2.0 — effective July 25, 2026. Counsel approved.

Raf (rafads.com) operates a market that sponsors integration defaults inside the use() flow of coding agents. This policy describes what we collect from developers (people who run the Raf runtime, in either lane), advertisers (people who fund campaigns), and visitors to rafads.com and registry.rafads.com — and what we deliberately do not collect.

Raf is operated from the United States by Raf Together, Inc., 2261 Market Street #4000, San Francisco, CA 94114 (“Raf”, “we”). We are the controller — the “business” under US state privacy laws — for the personal data this policy describes: we decide what is collected and why. Stripe is an independent controller for the identity and payment data it collects during checkout and payout onboarding; our hosting provider and our product-analytics provider process data only on our instructions; Google and GitHub act under their own policies for the sign-in provider you choose. The service is operated and targeted from the United States. We and our hosting infrastructure process data in the United States, but our providers and their subprocessors may also process it in other countries under their published privacy and transfer safeguards. Using the service from elsewhere therefore transfers your data to the United States and potentially other jurisdictions where those providers operate.

The two lanes, first

The runtime has two modes, and what we collect depends entirely on which one you chose:

Separately from the lanes, runtime telemetry is its own opt-in, offered only by the interactive installer; the plugin install path ships with telemetry off and no consent prompt ever appears in an agent conversation.

What we collect

From developers.

From advertisers.

From site visitors. rafads.com and registry.rafads.com run no third-party analytics or advertising scripts and set no advertising cookies. On-device preferences (such as the theme toggle) stay in your browser and are not sent to us. Signing in stores session credentials in your browser solely to keep you signed in. The opt-in runtime telemetry described above is the only analytics processing anywhere in the service, and it never applies to website visits. No analytics or error-reporting vendor will be added before this policy is updated to describe it. Our hosting provider keeps standard operational logs (IP address, request path, timestamp) for security and abuse prevention across rafads.com, ads.rafads.com, and registry.rafads.com; they are retained briefly and never used for profiling.

What we do not collect

Providers we share data with

We share personal data only with the providers needed to run the service, and when law requires:

A current list of our processors is available on request at privacy@rafads.com. Our hosting and analytics providers act as processors or service providers for the data they handle on our instructions; Stripe and the sign-in providers may act as independent controllers for data they collect under their own terms. They and their subprocessors may process data in the United States and other jurisdictions using the transfer mechanisms described in their published privacy notices and data-processing terms. We do not sell personal data, and no advertising vendors receive it. For transfers involving the EEA, UK, or Switzerland, we rely on the applicable safeguards published by each provider, which may include adequacy decisions, the EU-US Data Privacy Framework and its UK or Swiss extensions, or standard contractual clauses. Contact privacy@rafads.com for information relevant to your data. Advertisers must not send us their end customers’ personal data; we do not process that customer data on advertisers’ behalf and do not offer advertisers a data-processing agreement at launch.

How we use it

Operating the market: serving the signed campaign feed, vesting and billing adoptions, paying the developer pool, preventing fraud (the receipt/artifact cross-check, importance-sampled audits), keeping the public trust guarantees (disclosure enforcement, the written-reason ledger), and communicating with you about your account. Where a law like the GDPR applies, our legal bases are: performing our contract with you (accounts, serving, attribution, billing, and payouts); our legitimate interests (fraud prevention, security, and the audit ledger); our legal obligations (tax, accounting, and sanctions compliance); and consent where required — runtime telemetry is our only consent-based processing, and withdrawing it is one command.

Retention

Receipts, vesting evidence, and ledger records are the audit trail the market promises; the schedule:

Security

Credentials are stored as hashes, never in the clear — link codes, device secrets, and access tokens included. The campaign feed the runtime serves from is signed (Ed25519) and verified against pinned keys before a single byte of it is trusted. Money and audit records live in an append-only ledger that is corrected by new entries, never rewritten. Payment details stay with Stripe; we hold references, never card or bank numbers. Access to production data is limited to the operator. No safeguard is perfect, and we do not promise ours are — but the design assumes hostile input everywhere and fails closed.

Your choices and rights

Switch lanes at any time (raf ads on opts a machine into the earning lane; raf ads off returns it to organic-only serving; the free lane is the default). Turn telemetry off at any time. Unlink a machine at any time. Override any default with not:, and block any category or advertiser — blocklists are enforced before serving, so blocked advertisers never reach your machine.

You can request access to, correction of, deletion of, or a portable copy of your personal data — we honor these rights for everyone, whatever your location, even though Raf does not currently meet the applicability thresholds of laws like the CCPA. Email privacy@rafads.com from your account email; that match is how we verify you (an authorized agent may write with your signed permission). We respond within 45 days and may extend once by 45 days with notice. If we refuse a request, reply to appeal and a different reviewer will decide. We never discriminate for exercising these rights. We delete identity data and sever machine links on request; append-only ledger history is retained in de-identified form for audit.

We do not sell or share personal data, so a Global Privacy Control signal has nothing to switch off; we honor the rights above with or without it.

Eligibility and children

The service is not directed to children. You must be at least 18 to hold an account, and we do not knowingly collect personal data from children under 13; if you believe a child has used the service, write privacy@rafads.com and we will delete the data.

Changes

We will post changes here with a new version and effective date. Material changes are announced at least 14 days in advance — by email to account holders and a notice on rafads.com — and never apply retroactively to previously collected data without your consent where consent is required.

Contact

Raf Together, Inc. · rafads.com · privacy@rafads.com. Postal notices: 2261 Market Street #4000, San Francisco, CA 94114.