Privacy policy.
What happens to your information when you use RaLHF and this website.
Last updated 5 August 2026
The short version
How we handle your privacy depends on which parts of RaLHF you use.
The RaLHF desktop app, free plan
- Your context library is stored on your own device and is never sent to our servers
- We do not collect your context, your files, or what you ask your AI
- You do not need an account, so we do not know who you are
- The app connects to the internet to check for updates, and to reach any web apps you choose to connect
- It reports crashes and basic usage events so we can fix bugs and see which features get used. This never includes your context
- When you authorize an AI to read your library, your context goes to that AI, not to us
Premium, sync, sharing and access from any device
- To reach your context from any device we store your library on our servers, encrypted in transit and at rest
- It is not end to end encrypted, because the cloud has to read your context to serve it to your AI. See the note below
- Your context is only ever served to an AI that has authenticated as you
- If you cancel, the cloud copy is deleted. Your local library on each device is untouched
A Bot Food account
- Buying Premium requires an email address
- Payment details go to our payment processor, never to us
- We email you receipts and important product notices, nothing else unless you ask
- You can delete your account at any time
This website
- Analytics only run if you accept them in the consent banner
- Declining changes nothing about what you can read or download
Who we are
RaLHF is made by Bot Food Corporation, a company based in Toronto, Canada. We are responsible for the personal information under our control. Our practices are designed to comply with the Personal Information Protection and Electronic Documents Act (PIPEDA) in Canada and corresponding provincial privacy legislation.
For anything in this policy, write to info@botfood.ai.
What we do not collect
Your context library. On the free plan it is a set of files on your own device. It is not transmitted to us, we hold no copy, and we could not produce it if we were asked to. This is a consequence of how the product is built rather than a policy we could quietly change.
We also do not collect the contents of your conversations with any AI, the queries you run against your own library, or the files you point RaLHF at.
What we do collect
If you create an account. Your email address, and the billing information you give our payment processor. We receive confirmation of payment and a subscription status, not your card details.
If you use Premium. The library you choose to put in the cloud, so we can serve it to your devices and to the AI you authorize. Encrypted in transit and at rest, but readable by our systems, which is explained in full below.
If you contact us. Whatever you put in the message, so we can answer it.
On this website, with your consent. Standard analytics including IP address, browser and device type, pages visited and referring URL. Nothing loads until you accept.
Crash reports and usage analytics
RaLHF reports errors and basic product analytics so we can find crashes and understand which features people actually use. We use Sentry for error reporting and Amplitude for product analytics.
What this covers: which screens and features are opened, whether an action succeeded or failed, app version, operating system and device type, and the technical detail of any crash.
What it never covers: the contents of your context library, the files or apps you connect, what you ask your AI, or what your AI sends back. Those never reach us on the free plan and are not part of any diagnostic report.
Why we use it
- To run your account and deliver the features you paid for
- To answer your questions and fix problems you report
- To understand which pages of the website are useful, if you consented to analytics
- To meet legal and tax obligations
We do not use your information to build advertising profiles, and we do not sell it. Your context is never used to train an AI model, ours or anyone else's.
Who we share it with
We share the minimum needed with service providers who work on our behalf, under contracts that require them to protect it: our payment processor for billing, our cloud infrastructure provider for hosting Premium sync, and our email provider for receipts and product notices.
Some of these providers operate outside Canada, which means your information may be processed in other countries and may be subject to the laws of those countries.
We will disclose information if required by law. Because we do not hold your context library on the free plan, there is nothing of that kind for us to disclose.
Premium, and what it honestly means
Sync, sharing and access from any device need a server, so Premium is the point where your context leaves your device. We would rather be plain about what that means than hide behind a word.
Your library is stored on our infrastructure and encrypted in transit and at rest. It is not end to end encrypted. It cannot be, because the cloud MCP server has to be able to read your context in order to hand it to your AI. Anything your AI can read could in principle be read by someone with production access at Bot Food.
What we do about that: production access is limited to the few people who need it to run the service and is logged, your context is only ever served in response to a request from an AI that has authenticated as you, and it is never used to train a model, never sold, and never shared with anyone you have not chosen.
If you would rather nothing ever left your device, stay on the free plan. The local app is complete on its own.
When you connect an AI
RaLHF hands context to the AI services you authorize. Once it reaches them, what happens to it is governed by their privacy policies, not ours. You choose which AI gets access and you can revoke it at any time. We recommend reading the policy of any AI you connect.
How long we keep it
Account information is kept while your account is open. If you cancel a Premium subscription, the synced copy of your library is deleted within 30 days, and the local library on each of your devices is unaffected. If you delete your account, we delete your account data and any synced content, other than records we are required to keep for tax and accounting purposes.
Your rights
You can export or delete your entire local library at any time from within the app, without asking us and without an account.
For any information we do hold, you can ask us to show you what it is, correct it, or delete it. Write to info@botfood.ai. If you are in the European Economic Area or the United Kingdom you have rights under the GDPR including access, rectification, erasure, restriction, portability and objection. If you are a California resident you have rights under the CCPA including the right to know, delete, and opt out of sale. We do not sell personal information.
Security
Premium storage uses encryption in transit and at rest on AWS infrastructure. Access to production systems is restricted to staff who need it, authenticated, and logged. Requests for your context are authenticated per user, so one account cannot reach another's library. No system is perfectly secure, and we will notify affected users and the relevant regulator if a breach occurs that presents a real risk of significant harm.
Children
RaLHF is not intended for children. You must have reached the age of majority where you live, and be able to form a binding contract, to use the service. We do not knowingly collect personal information from children, and if we learn that we have, we delete it.
Changes
We will post any changes here with a new date at the top. If a change materially reduces the protection of information we already hold, we will ask before applying it to that information.