Privacy at RLSOK
Last updated 11 September 2026. This notice explains data handled by the public site, authenticated Cloud, evaluation intake, and commerce when enabled.
RLSOK is operated by Qi Zheng, an Individual / Sole Proprietor in China. Qi Zheng determines the purposes and means of RLSOK product-data processing. Contact privacy@rlsok.com for privacy questions.
What we collect
Cloud stores account email and identity, password hashes or OAuth provider identifiers, session-token hashes and timestamps, organization membership, and audit records. Evaluation and support flows may process contact details, organization, use case, referral/landing facts, request status, and correspondence. Product records include Runtime pairing and registered robot/controller/binding metadata; release, approval, revocation, Permit and Evidence records; and minimal Paddle customer/subscription/event identifiers from payment testing or any earlier billing activity. Managed artifact flows may store uploaded content; metadata-only Zero-to-Shadow stores digest and size without policy bytes.
Why we use it and our legal bases
We use data to authenticate users, isolate organizations, provide execution authorization and Evidence, operate support, prevent repeated trial claims using one-way account and normalized-email fingerprints, process billing state, and improve onboarding. Personal data is not currently sold.
Depending on the context and applicable law, processing is necessary to provide the requested service or take pre-contract steps, comply with law, protect the service and users, or pursue legitimate operational and security interests. Optional analytics relies on consent and may be withdrawn without losing core service access.
Storage and retention
Product records are stored in self-hosted PostgreSQL on the same RackNerd VPS as the API in Buffalo, New York, USA; there is no separate managed-database provider in the prepared deployment. RLSOK does not market unsupported per-plan Evidence retention periods. Downgrade does not delete robot bindings or historical Evidence. Records are kept only while needed for the stated purpose, an active account or contract, security and abuse prevention, dispute handling, backup recovery, or a legal obligation. The exact period therefore depends on record type.
A verified deletion request removes eligible live records. Compressed local rolling database backups remain on the same VPS and are retained for approximately seven days. A verified full-database recovery snapshot is separately stored in a private Vercel Blob store in theiad1 (Washington, D.C., USA) region. It is encrypted on the VPS with an RSA-3072 recipient key and AES-256-CBC before upload, while Vercel also applies AES-256 encryption at rest. The recovery private key is held separately and is not uploaded with the snapshot. Because this is a full database dump, it can contain account and organization data, robot execution-binding metadata, Permit/Evidence history, audit facts, and commerce identifiers. Backups expire under their schedules rather than being edited in place, so deletion and backup expiry may complete at different times.
Operational logs and activation analytics
Service and security logs may contain timestamps, request paths, organization-scoped identifiers, and outcome codes needed to operate and protect the service. The access-request abuse control uses a normalized network address in memory and does not store it in the application database. Vercel, Cloudflare, and the production host may independently process network metadata under their operational terms. First-party activation analytics record named onboarding milestones. Commercial analytics do not store robot command payloads, Evidence payloads, credentials, configuration files, or payment-card data.
Payments and service providers
New paid subscriptions are temporarily unavailable. The payment and billing pages do not load Paddle Checkout. Paddle was used for Sandbox payment testing; identifiers and lifecycle records from testing or any earlier billing activity may remain subject to the retention purposes above. Disabling new checkout does not erase those records. RLSOK does not store payment-card details. For any earlier order processed by Paddle, its privacy terms continue to apply to its processing. See the service-provider inventory.
Google OAuth and GitHub OAuth are active sign-in options on the current public service. Cloudflare routes the published support addresses to a mailbox monitored by Qi Zheng; the mailbox provider therefore processes inbound correspondence. Google Analytics provides optional statistics about public-page visits and evaluation-entry interactions after the visitor accepts Analytics.
Providers may process data outside your country, including through international transfers. The production database is in the United States, and the verified offsite recovery snapshot is also stored in a United States region. RLSOK limits transfers to the service purposes above and uses the provider and contractual arrangements applicable to the deployed service. Any China-specific cross-border mechanism that applies to actual China-origin personal data must be resolved before the affected Live data flow.
Cookies and optional analytics
Necessary cookies support sign-in, security, and session continuity. Google Analytics loads only after Analytics consent and only on the Production site. Consented page views can include a high-level traffic channel such as AI search, organic search, direct, or referral. Access-request form values, email addresses, organization names, use cases, passwords, API keys, and authentication cookies are not sent to Google Analytics. Declining analytics does not block the site or form.
Consented analytics uses its own browser identifiers and cookies. Page paths and approved campaign parameters, referring origins, browser/device information, and named interactions may be processed. Clicking an evaluation link is measured separately from submitting an access request. Private setup and authenticated product pages are excluded. Use Cookie settings in the footer of a public page to withdraw consent. Learn how Google uses information from sites that use its services.
Your choices
Subject to applicable law, you may request access, a copy, correction, deletion, restriction or objection, or withdrawal of consent. You may also complain to the competent privacy regulator. RLSOK may need to verify identity and may retain records where law or a documented security, dispute, or contractual need permits.
Children
RLSOK accounts and paid services are intended for adults and organizations, not children under 18. Do not submit a child's personal information.
Changes
Material changes will be posted here with an updated effective date and any notice required by applicable law.
Contact: privacy@rlsok.com