1. Who we are and what this policy covers
Riplics AI (“Riplics AI”, “we”, “us”) provides an agentic automation platform that lets you build workflows in which AI agents browse the web, extract information, call connected services, and take actions on your behalf. This Privacy Policy explains what data we collect through the Riplics AI website (riplics.ai) and the Riplics AI application (app.riplics.ai), why we collect it, who we share it with, and the choices you have.
This policy applies to people who visit our website, create a Riplics AI account, or are invited into a Riplics AI team. If you use Riplics AI through an employer or another organisation, that organisation administers your account and its own privacy notice may also apply.
Questions about this policy can be sent to hello@riplics.ai.
2. Data we collect
We collect the following categories of data:
- Account data. Your name, email address, password hash, team membership, roles, and account preferences.
- Workflow content. The workflows, prompts, instructions, parameters, schedules, and knowledge you create, together with the run history, logs, screenshots, extracted data, business records, and files those runs produce.
- Connected-service data. When you connect a third-party account (for example Gmail, Google Calendar, Google Drive, Google Sheets, Outlook, Slack, Notion, HubSpot, or Salesforce), we store the access credentials issued to us and process the data your workflows read from or write to that service.
- Billing data. Plan, credit balance, and usage counts. Card details are handled by our payment processor and are never stored on our systems.
- Technical data. IP address, browser and device information, timestamps, and diagnostic or error reports generated when you use the service.
We do not sell personal data, and we do not use behavioural advertising trackers on the Riplics AI website.
3. How we use data
We use the data above to:
- provide, operate, and secure the Riplics AI platform and your account;
- execute the workflows you configure, including the actions you explicitly authorise;
- maintain run history, audit trails, and approval records so your automations remain traceable;
- meter usage, apply budgets, and bill you correctly;
- detect, investigate, and prevent abuse, fraud, and security incidents;
- provide support and respond to your requests;
- comply with legal obligations.
Where the GDPR applies, our legal bases are performance of our contract with you, our legitimate interest in operating and securing the service, your consent (for example when you connect a third-party account), and compliance with legal obligations.
4. Google API Services — Limited Use disclosure
Riplics AI’ use and transfer of information received from Google APIs to any other app adheres to the Google API Services User Data Policy, including the Limited Use requirements.
If you connect a Google account, Riplics AI requests only the scopes needed for the workflows you build — for example reading incoming messages and attachments to trigger a workflow, sending a message you have approved, reading or writing a spreadsheet, or creating a calendar event. You can review the exact scopes on Google’s consent screen before you approve the connection.
Google user data obtained through these scopes is:
- used only to provide and improve the user-facing features you have configured;
- never sold, and never transferred to third parties except as needed to provide those features, for security purposes, or to comply with applicable law;
- never used for advertising, ad targeting, or the training of generalised artificial-intelligence models;
- read by humans only with your explicit consent, to resolve a support issue you have raised, for security purposes, or where required by law.
You can disconnect a Google account at any time from the Integrations page in Riplics AI, or revoke Riplics AI’ access directly at myaccount.google.com/permissions. Revoking access stops future processing; workflow results already stored in your account remain until you delete them.
5. AI models and automated processing
Riplics AI uses third-party large-language-model providers to interpret your instructions and drive agent behaviour. The content you supply to a workflow — instructions, page content an agent reads, and documents it processes — may be sent to these providers as part of executing your run.
We use providers under agreements that prohibit training their general models on our customers’ data. Riplics AI does not use your workflow content to train models of its own.
6. Sharing and sub-processors
We share data only with:
- Service providers that host our infrastructure, deliver email, process payments, provide model inference, and collect error diagnostics — each bound by contract to process data only on our instructions;
- Services you connect, when your workflow reads from or writes to them;
- Members of your team, according to the permissions your team administrator sets;
- Authorities or acquirers, where required by law or in connection with a merger, acquisition, or asset sale, subject to this policy.
7. Security
Data is encrypted in transit with TLS and at rest. Third-party credentials are stored encrypted and are used only to execute your workflows. Access to production systems is restricted to personnel who need it, and agent sessions run in isolated, sandboxed browser environments.
No system is perfectly secure. If a breach affects your personal data, we will notify you and any competent supervisory authority as required by law.
8. Retention
We retain account data for as long as your account is active. Workflow content, run history, and stored records are retained until you delete them or delete your account. After account deletion we remove or anonymise your data within 30 days, except where we must keep records longer to meet legal, accounting, or security obligations. Backups are purged on a rolling schedule.
9. International transfers
Riplics AI is operated from the European Union and our primary infrastructure is hosted there. Some sub-processors may process data outside the European Economic Area. Where that happens, we rely on the European Commission’s Standard Contractual Clauses or an adequacy decision to protect the transfer.
10. Your rights
Depending on where you live, you may have the right to access, correct, delete, or export your personal data; to restrict or object to certain processing; and to withdraw a consent you previously gave. Much of this is available directly in the application — you can edit your profile, export records to CSV, disconnect integrations, and delete workflows, records, and your account.
For anything else, contact hello@riplics.ai. We respond within 30 days. If you are in the EEA or the UK, you also have the right to lodge a complaint with your local data-protection authority.
11. Cookies
We use strictly necessary cookies to keep you signed in and to protect against cross-site request forgery, and we store your interface preferences locally in your browser. We do not use advertising or cross-site tracking cookies.
12. Children
Riplics AI is a business tool and is not directed at children. We do not knowingly collect personal data from anyone under 16. If you believe a child has provided us with personal data, contact hello@riplics.ai and we will delete it.
13. Changes to this policy
We may update this policy as the service evolves. When we make a material change we will update the date at the top of this page and, where the change significantly affects you, notify you by email or in the application before it takes effect.
14. Contact
For privacy questions, data-subject requests, or security reports, write to hello@riplics.ai.