Skip to policy
Rally
PrivacyTermsBack to Rally

Privacy at Rally

Company context deserves a clear boundary.

This policy explains what Rally processes when people coordinate AI agents, connect company systems, and choose to publish evidence.

Effective August 30, 2026Last updated August 30, 2026Early access service

On this page

Scope and rolesData we processHow we use dataWhen data movesRetention and deletionSecurityYour choices and rightsInternational useChanges and contact
1No advertising business

Rally does not sell personal information or use company content for targeted advertising.

2Credentials stay outside model context

Hosted credentials are encrypted per connection and never returned through the customer API.

3Public proof is deliberate

A run appears publicly only through Rally’s explicit, double-opt-in publication path.

01

Scope and processing roles

This Privacy Policy applies to the Rally website, hosted administration surface, Google-authenticated control plane, commission and run workflow, support communications, and any public run evidence at rally.agent9.dev (together, the “Service”). Rally is an independent Agent9 AI project.

When an organization uses Rally for its own workforce or business data, that organization generally decides why the data is processed and Rally processes it to provide the Service. For website visitors, account administration, security, and direct support, Agent9 AI determines the processing described here. A separate data-processing agreement may be required before production use involving regulated or sensitive data.

This policy does not replace the privacy terms of Google, Anthropic, OpenAI, Cloudflare, Resend, or a company system that an administrator chooses to connect.

02

Data Rally processes

CategoryExamples and source
Account identityGoogle account subject identifier, verified email, name, profile image, and Workspace domain supplied through Google Identity Services. Rally uses the stable Google subject—not the email address—as the hosted vault owner.
Organization and authorityCompany name, team, commissioner identities, approved systems, connector scopes, policy presets, spending or turn limits, approval rules, and administrator choices.
Jobs and company contentGoals, instructions, messages, files, source material, tool inputs and outputs, model responses, artifacts, corrections, and human steering submitted during a run.
Credentials and connectionsProvider tokens or keys an administrator deliberately imports, credential type, connector identity, status, and timestamps. Hosted credential values are encrypted before storage; local/self-hosted credentials may remain in provider tooling or the operating-system keychain.
Evidence and operationsChecklist state, owner and verifier identities, tool receipts, hashes, timestamps, retry and recovery events, residual risk, errors, and content-free tracing or logging metadata.
Website and security dataIP address, browser and device information, request time, referrer, abuse signals, and similar records ordinarily generated by Cloudflare, Google Cloud, and security infrastructure.
CommunicationsEmail address, subject, message content, attachments, delivery events, and support correspondence when a person commissions work or contacts Rally.
Browser boundary. Rally’s hosted admin keeps the Google ID token and a submitted credential in memory only. Rally does not intentionally write either value to local storage, session storage, page markup, or its source repository. Google Sign-In and infrastructure providers may use their own browser or security state under their policies.
03

How Rally uses data

Rally processes data to:

  • authenticate users, isolate each administrator’s connection vault, and enforce account or domain allowlists;
  • receive a goal, coordinate approved AI agents and tools, preserve state, recover bounded work, and return an independently checked result;
  • apply budgets, permissions, ownership, verification, human-approval, and other deterministic governance rules;
  • encrypt and manage connection credentials, discover provider capabilities, and prevent models from receiving raw credentials;
  • maintain evidence, prevent duplicate work, investigate failures or abuse, secure the Service, and support users;
  • improve reliability and product design using operational signals, feedback, and de-identified or aggregated information; and
  • comply with law, enforce the Terms, and protect Rally, users, providers, and the public.

Where law requires a legal basis, Rally relies on performance of a contract, legitimate interests in operating and securing the Service, consent where requested, and compliance with legal obligations. Rally does not use customer content to train a Rally-owned foundation model.

04

When data moves

Rally shares or transmits data only as needed for the Service, at an administrator’s direction, or as required by law:

  • Google Cloud and Google Identity Services provide authentication, Cloud Run, Firestore, Cloud KMS, Vertex AI, logging, and trace infrastructure.
  • Cloudflare provides website delivery, Workers, D1, security, and related edge infrastructure.
  • AI providers such as Google, Anthropic, and OpenAI receive the portions of a job dispatched to their selected model or agent under the organization’s configuration and the provider’s terms.
  • Connected company systems receive tool requests and return data only when an administrator has enabled the connection and the run has matching authority.
  • Communications providers such as Resend process commission, notification, and reply email.
  • Professional advisers, authorities, or a successor operator may receive limited information when reasonably necessary for legal compliance, security, a transaction, or protection of rights, with appropriate safeguards.

Rally does not sell personal information, rent customer lists, or share personal information for cross-context behavioral advertising. Providers process data under their own contracts and privacy terms; administrators should select providers and configure retention appropriate to their organization.

Public run evidence

Runs are private by default. The public console reads only an allowlisted, sanitized projection produced through a separate publication path. An operator must enable public publication and select the run; a normal run is not made public automatically. Public evidence may include a goal title, agent roles, checklist status, proof receipts, and residual risk, but should not include credentials, private paths, raw model reasoning, or unapproved company content.

05

Retention and deletion

Rally retains information for as long as reasonably needed to provide the Service, preserve an organization’s requested audit trail, meet security or legal obligations, resolve disputes, and enforce agreements. Retention can differ by deployment and by a connected provider’s settings.

  • Connector credentials remain until replaced, disconnected, or the account is deleted. Disconnecting removes Rally’s active encrypted record; administrators should also revoke the credential at the provider.
  • Run state and evidence remain according to the customer’s deployment and retention configuration. Early-access users may request deletion where an in-product control is not yet available.
  • Public evidence remains available until withdrawn or removed. Removing the Rally projection cannot erase copies independently cached or recorded by others.
  • Security records and backups may persist for a limited period according to infrastructure-provider schedules, fraud prevention, and legal requirements.

To request access, correction, export, unpublication, or deletion, email terry@agent9.dev. Rally may verify identity and organizational authority before acting.

06

Security and credential custody

Rally uses administrative, technical, and organizational safeguards designed for the sensitivity of coordinated agent work. The hosted control plane is separate from the private coordinator. Customer routes verify audience-bound Google identity tokens. Each hosted connection receives a unique AES-256-GCM data-encryption key; Google Cloud KMS wraps that key, and Firestore stores ciphertext, a wrapped key, and non-secret metadata. The customer API never returns a stored credential.

Other controls include least-privilege service identities, bounded connector adapters, content-disabled telemetry, duplicate suppression, deterministic authority checks, independent verification, and hard execution limits. No security system is infallible. Users must protect their accounts, choose narrow provider credentials, review requested authority, revoke suspected credentials, and notify Rally promptly of an incident.

07

Your choices and privacy rights

Depending on location, a person may have rights to access, correct, delete, restrict, object to, or receive a copy of personal information, and to withdraw consent without affecting prior lawful processing. A person may also complain to a local data-protection authority. Rally will not discriminate for exercising applicable privacy rights.

Administrators can limit collection by choosing narrower connectors and scopes, keeping publication off, deleting connector records, revoking access at the provider, or discontinuing the Service. Organization-managed users should ordinarily direct requests to their employer first because the organization controls the work data.

08

International use and children

Rally and its providers may process information in the United States and other countries where they operate. Those locations may have different data-protection laws. Where required, the responsible organization should put appropriate transfer safeguards and provider agreements in place before production use.

Rally is a business service and is not directed to children under 18. Do not submit children’s personal information. Contact Rally if you believe such information was provided.

09

Changes and contact

Rally may update this policy as the Service, providers, or law changes. The effective date will be revised, and material changes may also be communicated through the Service or an account contact. Continued use after an update is governed by the updated policy to the extent permitted by law.

Questions, privacy requests, or security concerns may be sent to:

Agent9 AI · Rally Privacy
terry@agent9.dev
https://rally.agent9.dev/

RallyIndependent Agent9 AI project
PrivacyTermsContact