Privacy Policy
Last updated: 10 October 2026
Hey Rass is a service of RassIntel (“we”, “us”). It lets a business create an AI Employee that answers its customers on its website. This policy explains what personal data we handle, why, and the choices you have. It is written to meet India's Digital Personal Data Protection Act, 2023 (DPDP Act).
1. Who is responsible for your data
- If you chat with an AI Employee on a business's website or link: that business decides why and how your data is used (it is the “Data Fiduciary”). We process the conversation on its behalf, as its service provider (“Data Processor”). For questions about your conversation, contact that business first; you can also write to us.
- If you have a Hey Rass account (you are a business owner or team member): RassIntel is the Data Fiduciary for your account data.
2. What we collect
| Who | Data | Why |
|---|---|---|
| Account holders | Name, email address, password (stored only as a one-way hash), workspace name, sign-in sessions | To create and secure your account and send service emails (verification, password reset, alerts) |
| Businesses | AI Employee settings, business details, knowledge documents and web pages you add | So your AI Employee can answer from them |
| Visitors who chat | The messages you send and the AI's replies, the language detected, a random browser identifier, and the website the chat is on | To answer you, keep the conversation going if you return, and let the business review its conversations |
| Visitors who share contact details | Name, phone number and/or email, and a short note of what you asked for | Only when you agree, so the business can contact you |
| Everyone | Your IP address, stored only as an irreversible hash; request counts. For account holders, also the browser type of each signed-in session | To prevent abuse and keep the service secure |
We do not sell personal data, show advertising, or build advertising profiles. Please do not share sensitive information (health, financial account numbers, government IDs, passwords) in a chat.
3. Artificial intelligence
- You are always told when you are talking to an AI. An AI Employee never claims to be a person.
- Replies are generated by an AI model from the business's information. They can be wrong; confirm anything important with the business.
- Conversations are sent to our AI provider only to produce the reply. We use a paid service tier under which the provider does not use your content to train its models.
4. Cookies and similar storage
- Sign-in cookie: keeps account holders signed in. Essential.
- Browser storage in the chat: a random identifier and a token so you can continue your conversation after a refresh. Essential; cleared when you start a new conversation or clear your browser data.
- Bot protection: Cloudflare Turnstile checks that a chat is started by a person and may use device signals for that purpose.
We use no advertising or cross-site tracking cookies.
5. Who we share data with
Only the service providers needed to run Hey Rass, under contracts that restrict their use of the data:
| Provider | Purpose | Location |
|---|---|---|
| Supabase | Database (accounts, conversations, leads, knowledge) | Mumbai, India |
| Hostinger | Application server | Mumbai, India |
| Google (Gemini API) | Generating AI replies and searching knowledge | Processed outside India |
| Resend | Sending service emails | Processed outside India |
| Cloudflare | Domain services and bot protection | Global network |
The business whose AI Employee you chat with can read that conversation and any contact details you chose to share. We may disclose data when the law requires it.
6. How long we keep data
- Account data: while the account is open.
- Conversations, leads and knowledge: until the business asks us to delete them or closes its account. Knowledge documents can be deleted by the business at any time.
- After an account is closed, or on a valid deletion request: our team deletes the data within 30 days, unless the law requires us to keep something longer. Records of usage and of security-relevant actions are kept for accounting and security.
- Abuse-prevention counters: about one day.
7. Your rights
Under the DPDP Act you can ask to:
- know what personal data about you is processed, and get a summary of it;
- correct or update it, or have it erased;
- withdraw consent you gave (for example, to be contacted);
- nominate someone to exercise your rights if you are unable to;
- raise a grievance and receive a response.
Write to privacy@heyrass.com. If your request is about a chat with a business's AI Employee, tell us which website it was on; we will act on it together with that business. We respond within 30 days.
8. Security
- All connections are encrypted (HTTPS).
- Each business's data is isolated from every other business's at the database level.
- Passwords and API keys are stored only as hashes; access is limited to what each part of the system needs.
- If a personal data breach occurs, we will notify affected businesses and the Data Protection Board of India as the law requires.
9. Children
Hey Rass accounts are for businesses and are not offered to anyone under 18. Businesses must not use an AI Employee to knowingly collect personal data from children without the verifiable consent the law requires.
10. Grievance Officer and contact
Grievance Officer, RassIntel: privacy@heyrass.com. General questions: support@heyrass.com. If you are not satisfied with our response, you may complain to the Data Protection Board of India.
11. Changes
We will post any change here and update the date above. For significant changes we will notify account holders by email.