Legal
Raf Privacy Policy
Effective policy
Version 2.0 — effective July 25, 2026. Counsel approved.
Raf (rafads.com) operates a market that sponsors integration defaults inside the use() flow of coding agents. This policy describes what we collect from developers (people who run the Raf runtime, in either lane), advertisers (people who fund campaigns), and visitors to rafads.com and registry.rafads.com — and what we deliberately do not collect.
Raf is operated from the United States by Raf Together, Inc., 2261 Market Street #4000, San Francisco, CA 94114 (“Raf”, “we”). We are the controller — the “business” under US state privacy laws — for the personal data this policy describes: we decide what is collected and why. Stripe is an independent controller for the identity and payment data it collects during checkout and payout onboarding; our hosting provider and our product-analytics provider process data only on our instructions; Google and GitHub act under their own policies for the sign-in provider you choose. The service is operated and targeted from the United States. We and our hosting infrastructure process data in the United States, but our providers and their subprocessors may also process it in other countries under their published privacy and transfer safeguards. Using the service from elsewhere therefore transfers your data to the United States and potentially other jurisdictions where those providers operate.
The two lanes, first
The runtime has two modes, and what we collect depends entirely on which one you chose:
- Free lane (the default). Serving is organic-only. The runtime sends us nothing: no telemetry, no receipts, no identifiers. Catalog and campaign-feed fetches are anonymous reads.
- Earning lane (opt-in). You opted into sponsored defaults and the developer pool. Sponsored, attributed connections produce the call receipts described below — and that evidence stream is the deal: receipts are what make your payouts payable and the market auditable. No receipts, nothing vests, nothing pays. Turning the stream off is always one command, and it returns you to the free lane — no ads, no data, no payouts. Nobody sees an ad they aren’t being paid to see.
Separately from the lanes, runtime telemetry is its own opt-in, offered only by the interactive installer; the plugin install path ships with telemetry off and no consent prompt ever appears in an agent conversation.
What we collect
From developers.
- Web account: dashboard sign-in is email and password, or OAuth via Google or GitHub — your choice. Where you choose a password, it is stored as a salted hash, never in the clear. OAuth sign-ins share the basic profile the provider supplies (name, email address, avatar where present). We record which terms version you accepted and when.
- Linked machines: linking a machine creates a device record holding a client identifier, an optional machine name, and hashed credentials. Link codes and device secrets are stored as hashes only.
- Call receipts (earning lane, sponsored connections only): when you accept a sponsored default and the integration is used, the runtime sends receipts carrying the campaign, provider, and category identifiers, a coarse segment label, a salted project hash, a timestamp, and a success flag — nothing else. Never payloads, never source, never secrets, never paths or filenames. Organic connections and everything in the free lane produce no receipts at all.
- Segments: the runtime computes a coarse segment label (framework family × project-scale bucket; roughly 10–20 possible values) on your machine, from your project directory. The raw signals never leave your machine — only the coarse label is stamped on receipts and funnel events.
- Attribution: accepting a sponsored default records the attribution locally on your machine (a file in your Raf data directory) with a 14-day expiry — the same window as billing disputes and payout holdback. We receive its campaign linkage only through the receipts above.
- Local receipt spool: the runtime queues call receipts on your machine (a file in your Raf data directory) before sending them, bounded at 7 days — see Retention. Same fields as the receipts described above; nothing additional is stored.
- Runtime telemetry (separate opt-in, installer only): funnel events about the
use()flow — a need was stated, a default was shown, accepted, wired, connected — with the coarse segment. Processed for us by a product-analytics provider acting on our instructions. Never prompts, never code, never file contents. - Settings: your lane state, category and advertiser blocklists, and payout preference.
- Ledger: every pool accrual, rejection, and clawback on your account, each with its written reason. Ledger rows are append-only and retained for audit.
- Payouts: cashouts run through Stripe Connect. Stripe collects the identity and banking details it needs for onboarding and compliance (KYC) directly; we store a reference to your Stripe account and your payout history, never your banking details.
From advertisers.
- Account and claim identity: the email address Stripe Checkout collected (used with the paid Checkout success return or Stripe receipt-number fallback to claim your campaigns), your dashboard sign-in identity once you claim, business name, and website URL. Receipt numbers are verified against Stripe and are not stored.
- Campaign configuration: category, bid (CPA), the deposit that caps your budget, and the pitch and URL your campaign serves.
- Billing: deposits run through Stripe Checkout. We store references to your Stripe customer and the campaign ledger of deposits, draw-downs on vested adoptions, and refunds — never card numbers. There is no auto-recharge and no off-session charging.
- Verification artifacts: the automated verification pipeline’s results for your product (pass/fail and the failure report we send you) — your product’s behavior, not personal data.
From site visitors. rafads.com and registry.rafads.com run no third-party analytics or advertising scripts and set no advertising cookies. On-device preferences (such as the theme toggle) stay in your browser and are not sent to us. Signing in stores session credentials in your browser solely to keep you signed in. The opt-in runtime telemetry described above is the only analytics processing anywhere in the service, and it never applies to website visits. No analytics or error-reporting vendor will be added before this policy is updated to describe it. Our hosting provider keeps standard operational logs (IP address, request path, timestamp) for security and abuse prevention across rafads.com, ads.rafads.com, and registry.rafads.com; they are retained briefly and never used for profiling.
What we do not collect
- Code, prompts, file paths, or repository contents from your machines. Receipts and telemetry carry identifiers, coarse labels, salted hashes, timestamps, and flags — not your project.
- Behavioral profiles. Segment computation runs on your machine and exports only the coarse label; advertiser dashboards are aggregate-only behind a k-anonymity floor, so no advertiser ever sees an individual developer.
- Anything in the free lane, and anything while telemetry is off: both are the defaults, and
raf ads offreturns an earning-lane machine to organic serving at any time.
Providers we share data with
We share personal data only with the providers needed to run the service, and when law requires:
- Stripe — advertiser checkout and billing, and developer payouts (Stripe Connect). Stripe acts under its own terms and privacy policy (stripe.com/privacy) for the identity and payment data it collects.
- Google / GitHub — OAuth sign-in, only for the provider you choose; password sign-in involves no identity provider at all.
- A hosting and edge provider — hosting for every service surface (the website, the ad server, the registry), acting only on our instructions.
- A product-analytics provider — processing of the opt-in runtime telemetry described above, acting only on our instructions. No website analytics.
A current list of our processors is available on request at privacy@rafads.com. Our hosting and analytics providers act as processors or service providers for the data they handle on our instructions; Stripe and the sign-in providers may act as independent controllers for data they collect under their own terms. They and their subprocessors may process data in the United States and other jurisdictions using the transfer mechanisms described in their published privacy notices and data-processing terms. We do not sell personal data, and no advertising vendors receive it. For transfers involving the EEA, UK, or Switzerland, we rely on the applicable safeguards published by each provider, which may include adequacy decisions, the EU-US Data Privacy Framework and its UK or Swiss extensions, or standard contractual clauses. Contact privacy@rafads.com for information relevant to your data. Advertisers must not send us their end customers’ personal data; we do not process that customer data on advertisers’ behalf and do not offer advertisers a data-processing agreement at launch.
How we use it
Operating the market: serving the signed campaign feed, vesting and billing adoptions, paying the developer pool, preventing fraud (the receipt/artifact cross-check, importance-sampled audits), keeping the public trust guarantees (disclosure enforcement, the written-reason ledger), and communicating with you about your account. Where a law like the GDPR applies, our legal bases are: performing our contract with you (accounts, serving, attribution, billing, and payouts); our legitimate interests (fraud prevention, security, and the audit ledger); our legal obligations (tax, accounting, and sanctions compliance); and consent where required — runtime telemetry is our only consent-based processing, and withdrawing it is one command.
Retention
Receipts, vesting evidence, and ledger records are the audit trail the market promises; the schedule:
- Pending device link codes: 15-minute expiry, purged within 24 hours.
- Stripe-receipt fallback attempts: checkout email stored only as a hash; attempt rows expire after 24 hours. Receipt numbers are not stored.
- Local attribution records (on your machine): 14-day expiry.
- The runtime’s local receipt spool (on your machine): bounded at 7 days; drops rather than grows.
- Receipt rows and vesting evidence on our servers: kept for the life of the campaign ledger they support; deleted or de-identified within 90 days after account deletion, unless an open dispute or a legal obligation requires longer.
- Runtime telemetry events (opt-in only): deleted or reduced to aggregates after 12 months, and sooner if you opt out or ask.
- Ledger, billing, and payout records: kept 7 years from the transaction for tax and audit purposes, de-identified after account deletion.
Security
Credentials are stored as hashes, never in the clear — link codes, device secrets, and access tokens included. The campaign feed the runtime serves from is signed (Ed25519) and verified against pinned keys before a single byte of it is trusted. Money and audit records live in an append-only ledger that is corrected by new entries, never rewritten. Payment details stay with Stripe; we hold references, never card or bank numbers. Access to production data is limited to the operator. No safeguard is perfect, and we do not promise ours are — but the design assumes hostile input everywhere and fails closed.
Your choices and rights
Switch lanes at any time (raf ads on opts a machine into the earning lane; raf ads off returns it to organic-only serving; the free lane is the default). Turn telemetry off at any time. Unlink a machine at any time. Override any default with not:, and block any category or advertiser — blocklists are enforced before serving, so blocked advertisers never reach your machine.
You can request access to, correction of, deletion of, or a portable copy of your personal data — we honor these rights for everyone, whatever your location, even though Raf does not currently meet the applicability thresholds of laws like the CCPA. Email privacy@rafads.com from your account email; that match is how we verify you (an authorized agent may write with your signed permission). We respond within 45 days and may extend once by 45 days with notice. If we refuse a request, reply to appeal and a different reviewer will decide. We never discriminate for exercising these rights. We delete identity data and sever machine links on request; append-only ledger history is retained in de-identified form for audit.
We do not sell or share personal data, so a Global Privacy Control signal has nothing to switch off; we honor the rights above with or without it.
Eligibility and children
The service is not directed to children. You must be at least 18 to hold an account, and we do not knowingly collect personal data from children under 13; if you believe a child has used the service, write privacy@rafads.com and we will delete the data.
Changes
We will post changes here with a new version and effective date. Material changes are announced at least 14 days in advance — by email to account holders and a notice on rafads.com — and never apply retroactively to previously collected data without your consent where consent is required.
Contact
Raf Together, Inc. · rafads.com · privacy@rafads.com. Postal notices: 2261 Market Street #4000, San Francisco, CA 94114.