Skip to policy
Rally
PrivacyTermsBack to Rally

Privacy at Rally

Company context deserves a clear boundary.

This policy explains what Rally processes when people coordinate AI agents, connect company systems, and choose to publish evidence.

Effective August 30, 2026Last updated August 31, 2026Early access service

On this page

Scope and rolesData we processHow we use dataWhen data movesRetention and deletionSecurityYour choices and rightsInternational useChanges and contact
1No advertising business

Rally does not sell personal information or use company content for targeted advertising.

2Credentials stay outside model context

Hosted credentials are encrypted per connection and never returned through the customer API.

3Public proof is deliberate

A run appears publicly only through Rally’s explicit, double-opt-in publication path.

01

Scope and processing roles

This Privacy Policy applies to the Rally website, hosted administration surface, authenticated control plane, commission and run workflow, support communications, and any public run evidence at rally.agent9.dev (together, the “Service”). Rally is an independent Agent9 AI project.

When an organization uses Rally for its own workforce or business data, that organization generally decides why the data is processed and Rally processes it to provide the Service. For website visitors, account administration, security, and direct support, Agent9 AI determines the processing described here. A separate data-processing agreement may be required before production use involving regulated or sensitive data.

This policy does not replace the privacy terms of Google, Anthropic, OpenAI, Cloudflare, Resend, or a company system that an administrator chooses to connect.

02

Data Rally processes

CategoryExamples and source
Account identityFor Google sign-in: the Google account subject identifier, verified email, name, profile image, and Workspace domain supplied through Google Identity Services. For allowlisted company-email sign-in: the normalized email address and workspace binding needed to deliver and validate a one-time link. In the pilot these are distinct operator identities; Rally does not silently merge a company-email vault with a Google-subject vault. Google’s full-page fallback uses a two-minute exchange code and 30-minute session; the company-email path enters that same session exchange. Firestore stores SHA-256 hashes of one-time links, exchange codes, and sessions with associated identity, expiry, consumption, and rate-limit records—not the raw link, code, or session token.
Organization and authorityCompany name, team, commissioner identities, approved systems, connector scopes, policy presets, spending or turn limits, approval rules, and administrator choices.
Teammate and email setupTeammate name and business role, accountable human owner, requested email local part and domain, selected email provider and connection method, reachability, approved sender addresses or domains, activation status, workspace identifier, creator’s Google subject, and setup timestamps. These records describe the requested identity; Rally does not label an address live until the applicable provider, DNS, and mail checks pass.
Jobs and company contentGoals, instructions, messages, files, source material, tool inputs and outputs, model responses, artifacts, corrections, and human steering submitted during a run.
Credentials and connectionsProvider tokens or keys an administrator deliberately imports, credential type, connector identity, status, and timestamps. Hosted credential values are encrypted before storage; local/self-hosted credentials may remain in provider tooling or the operating-system keychain.
Evidence and operationsChecklist state, owner and verifier identities, tool receipts, hashes, timestamps, retry and recovery events, residual risk, errors, and content-free tracing or logging metadata. The authenticated Work dashboard reads a sanitized private run projection scoped to the administrator’s configured workspace.
Website and security dataIP address, browser and device information, request time, referrer, request URL, abuse signals, and similar records ordinarily processed by Cloudflare, Google Cloud, and security infrastructure. Rally disables Workers Logs and automatic tracing for its callback-bearing Worker and instructs the edge not to inject a client-side analytics beacon, so Rally does not add browser analytics or persist callback URLs in those Cloudflare observability products. The browser, Cloudflare edge, and other necessary infrastructure still process request metadata under their respective controls and policies.
CommunicationsEmail address, subject, message content, attachments, delivery events, and support correspondence when a person commissions work or contacts Rally.
Browser boundary. Rally’s hosted admin keeps the Google ID token or short-lived Rally session and a pasted credential in page memory; it does not save those values in local storage, session storage, or cookies. A company-email link carries a ten-minute one-time value in the URL fragment; the admin removes it immediately and exchanges it for the same short-lived Rally session used by Google’s full-page fallback. Connector consent uses a separate ten-minute, per-flow, HttpOnly browser-binding cookie containing no identity or provider credential; page scripts cannot read it and Rally clears it on return. Standard OAuth sends a one-time authorization code to Rally’s registered production callback, which the Cloudflare Worker handles server-side. The admin page receives neither that code nor a provider token, and there is no less-secure static callback fallback. Google Sign-In and infrastructure providers may use their own browser or security state under their policies.
03

How Rally uses data

Rally processes data to:

  • authenticate users, isolate each administrator’s connection vault, and enforce account or domain allowlists;
  • persist a workspace’s teammate roles, accountable owners, requested email identities, and commissioning boundaries;
  • receive a goal, coordinate approved AI agents and tools, preserve state, recover bounded work, and return an independently checked result;
  • apply budgets, permissions, ownership, verification, human-approval, and other deterministic governance rules;
  • encrypt and manage connection credentials, discover provider capabilities, and prevent models from receiving raw credentials;
  • maintain evidence, prevent duplicate work, investigate failures or abuse, secure the Service, and support users;
  • improve reliability and product design using operational signals, feedback, and de-identified or aggregated information; and
  • comply with law, enforce the Terms, and protect Rally, users, providers, and the public.

Where law requires a legal basis, Rally relies on performance of a contract, legitimate interests in operating and securing the Service, consent where requested, and compliance with legal obligations. Rally does not use customer content to train a Rally-owned foundation model.

04

When data moves

Rally shares or transmits data only as needed for the Service, at an administrator’s direction, or as required by law:

  • Google Cloud and Google Identity Services provide authentication, Cloud Run, Firestore, Cloud KMS, Pub/Sub delivery queues, Vertex AI, logging, and trace infrastructure. A requested company-email delivery may briefly place the normalized destination, workspace binding, expiry, and opaque delivery identifier in Pub/Sub; no usable sign-in token is placed there.
  • Cloudflare provides website delivery, Workers, D1, security, and related edge infrastructure.
  • AI providers such as Google, Anthropic, OpenAI, and an administrator-enabled xAI worker receive the portions of a job dispatched to their selected model or agent under the organization’s configuration and the provider’s terms.
  • Connected company systems receive tool requests and return data only when an administrator has enabled the connection and the run has matching authority.
  • Communications providers such as Resend process commission, notification, reply, and requested company-email sign-in delivery. Resend receives the destination address and the one-time sign-in message needed for delivery.
  • Professional advisers, authorities, or a successor operator may receive limited information when reasonably necessary for legal compliance, security, a transaction, or protection of rights, with appropriate safeguards.

Rally does not sell personal information, rent customer lists, or share personal information for cross-context behavioral advertising. Providers process data under their own contracts and privacy terms; administrators should select providers and configure retention appropriate to their organization.

Private workspace and public run evidence

The authenticated Work dashboard reads a separately allowlisted run projection from Cloudflare D1. Before storage, Rally replaces the configured workspace identifier with a keyed hash; the browser must present a valid Google identity or short-lived Rally session, and the edge returns only rows whose workspace hash matches that verified account’s workspace.

Runs are private by default. The public console reads only an explicitly public, sanitized projection produced through a separate opt-in. An operator must enable public publication and select the run; a normal run is not made public automatically. Public evidence may include a goal title, agent roles, checklist status, proof receipts, and residual risk, but should not include credentials, private paths, raw model reasoning, or unapproved company content.

05

Retention and deletion

Rally retains information for as long as reasonably needed to provide the Service, preserve an organization’s requested audit trail, meet security or legal obligations, resolve disputes, and enforce agreements. Retention can differ by deployment and by a connected provider’s settings.

  • Teammate and email setup records remain until the teammate or account is deleted, or an early-access administrator requests deletion. Removing a Rally setup record does not cancel a mailbox, DNS record, API credential, or provider account controlled outside Rally.
  • Connector credentials remain until replaced, disconnected, or the account is deleted. Disconnect first disables Rally use. If an OAuth provider publishes an automatic revocation endpoint, Rally revokes there before deleting its encrypted copy; a failed revocation leaves the copy sealed for retry. If automatic revocation is unavailable, Rally deletes its copy and tells the administrator to revoke the grant, key, or token in provider settings.
  • Authentication state expires after two minutes for a one-time exchange code, ten minutes for a company-email sign-in link or unfinished connector authorization flow and its browser-binding cookie, and 30 minutes for a Rally browser session. Company-email link records are consumed atomically on first use; hashed rate-limit records expire after their enforcement window. Signing out requests deletion of the session hash and clears page memory; if that request cannot complete, expiry remains the backstop. Firestore TTL removes expired records asynchronously and may do so after the logical expiry.
  • Run state and evidence, including the sanitized private workspace projection, remain according to the customer’s deployment and retention configuration. Content-free hosted connector execution receipts expire after 90 days. Early-access users may request deletion where an in-product control is not yet available.
  • Public evidence remains available until withdrawn or removed. Removing the Rally projection cannot erase copies independently cached or recorded by others.
  • Security records and backups may persist for a limited period according to infrastructure-provider schedules, fraud prevention, and legal requirements.

To request access, correction, export, unpublication, or deletion, email terry@agent9.dev. Rally may verify identity and organizational authority before acting.

06

Security and credential custody

Rally uses administrative, technical, and organizational safeguards designed for the sensitivity of coordinated agent work. The hosted control plane is separate from the private coordinator. Customer routes verify audience-bound Google identity tokens or hashed, short-lived Rally sessions. Exact callbacks, one-use state, same-browser binding, PKCE where supported, and atomic code consumption protect browser returns. Each hosted connection receives a unique AES-256-GCM data-encryption key; Google Cloud KMS wraps that key, and Firestore stores ciphertext, a wrapped key, and non-secret metadata. The customer API never returns a stored credential. A Certified connection permits only tenant-authenticated, preset-bounded calls whose live tool schema still matches the certified manifest, with content-free receipts; agent runs additionally require a separate immutable authority snapshot.

Other controls include least-privilege service identities, bounded connector adapters, content-disabled telemetry, duplicate suppression, deterministic authority checks, independent verification, and hard execution limits. No security system is infallible. Users must protect their accounts, choose narrow provider credentials, review requested authority, revoke suspected credentials, and notify Rally promptly of an incident.

07

Your choices and privacy rights

Depending on location, a person may have rights to access, correct, delete, restrict, object to, or receive a copy of personal information, and to withdraw consent without affecting prior lawful processing. A person may also complain to a local data-protection authority. Rally will not discriminate for exercising applicable privacy rights.

Administrators can limit collection by choosing narrower connectors and scopes, keeping publication off, deleting connector records, revoking access at the provider, or discontinuing the Service. Organization-managed users should ordinarily direct requests to their employer first because the organization controls the work data.

08

International use and children

Rally and its providers may process information in the United States and other countries where they operate. Those locations may have different data-protection laws. Where required, the responsible organization should put appropriate transfer safeguards and provider agreements in place before production use.

Rally is a business service and is not directed to children under 18. Do not submit children’s personal information. Contact Rally if you believe such information was provided.

09

Changes and contact

Rally may update this policy as the Service, providers, or law changes. The effective date will be revised, and material changes may also be communicated through the Service or an account contact. Continued use after an update is governed by the updated policy to the extent permitted by law.

Questions, privacy requests, or security concerns may be sent to:

Agent9 AI · Rally Privacy
terry@agent9.dev
https://rally.agent9.dev/

RallyIndependent Agent9 AI project
PrivacyTermsContact