Rally does not sell personal information or use company content for targeted advertising.
Hosted credentials are encrypted per connection and never returned through the customer API.
A run appears publicly only through Rally’s explicit, double-opt-in publication path.
Scope and processing roles
This Privacy Policy applies to the Rally website, hosted administration surface, authenticated control plane, commission and run workflow, support communications, and any public run evidence at rally.agent9.dev (together, the “Service”). Rally is an independent Agent9 AI project.
When an organization uses Rally for its own workforce or business data, that organization generally decides why the data is processed and Rally processes it to provide the Service. For website visitors, account administration, security, and direct support, Agent9 AI determines the processing described here. A separate data-processing agreement may be required before production use involving regulated or sensitive data.
This policy does not replace the privacy terms of Google, Anthropic, OpenAI, Cloudflare, Resend, or a company system that an administrator chooses to connect.
Data Rally processes
| Category | Examples and source |
|---|---|
| Account identity | For Google sign-in: the Google account subject identifier, verified email, name, profile image, and Workspace domain supplied through Google Identity Services. For allowlisted company-email sign-in: the normalized email address and workspace binding needed to deliver and validate a one-time link. In the pilot these are distinct operator identities; Rally does not silently merge a company-email vault with a Google-subject vault. Google’s full-page fallback uses a two-minute exchange code and 30-minute session; the company-email path enters that same session exchange. Firestore stores SHA-256 hashes of one-time links, exchange codes, and sessions with associated identity, expiry, consumption, and rate-limit records—not the raw link, code, or session token. |
| Organization and authority | Company name, team, commissioner identities, approved systems, connector scopes, policy presets, spending or turn limits, approval rules, and administrator choices. |
| Teammate and email setup | Teammate name and business role, accountable human owner, requested email local part and domain, selected email provider and connection method, reachability, approved sender addresses or domains, activation status, workspace identifier, creator’s Google subject, and setup timestamps. These records describe the requested identity; Rally does not label an address live until the applicable provider, DNS, and mail checks pass. |
| Jobs and company content | Goals, instructions, messages, files, source material, tool inputs and outputs, model responses, artifacts, corrections, and human steering submitted during a run. |
| Credentials and connections | Provider tokens or keys an administrator deliberately imports, credential type, connector identity, status, and timestamps. Hosted credential values are encrypted before storage; local/self-hosted credentials may remain in provider tooling or the operating-system keychain. |
| Evidence and operations | Checklist state, owner and verifier identities, tool receipts, hashes, timestamps, retry and recovery events, residual risk, errors, and content-free tracing or logging metadata. The authenticated Work dashboard reads a sanitized private run projection scoped to the administrator’s configured workspace. |
| Website and security data | IP address, browser and device information, request time, referrer, request URL, abuse signals, and similar records ordinarily processed by Cloudflare, Google Cloud, and security infrastructure. Rally disables Workers Logs and automatic tracing for its callback-bearing Worker and instructs the edge not to inject a client-side analytics beacon, so Rally does not add browser analytics or persist callback URLs in those Cloudflare observability products. The browser, Cloudflare edge, and other necessary infrastructure still process request metadata under their respective controls and policies. |
| Communications | Email address, subject, message content, attachments, delivery events, and support correspondence when a person commissions work or contacts Rally. |
How Rally uses data
Rally processes data to:
- authenticate users, isolate each administrator’s connection vault, and enforce account or domain allowlists;
- persist a workspace’s teammate roles, accountable owners, requested email identities, and commissioning boundaries;
- receive a goal, coordinate approved AI agents and tools, preserve state, recover bounded work, and return an independently checked result;
- apply budgets, permissions, ownership, verification, human-approval, and other deterministic governance rules;
- encrypt and manage connection credentials, discover provider capabilities, and prevent models from receiving raw credentials;
- maintain evidence, prevent duplicate work, investigate failures or abuse, secure the Service, and support users;
- improve reliability and product design using operational signals, feedback, and de-identified or aggregated information; and
- comply with law, enforce the Terms, and protect Rally, users, providers, and the public.
Where law requires a legal basis, Rally relies on performance of a contract, legitimate interests in operating and securing the Service, consent where requested, and compliance with legal obligations. Rally does not use customer content to train a Rally-owned foundation model.
When data moves
Rally shares or transmits data only as needed for the Service, at an administrator’s direction, or as required by law:
- Google Cloud and Google Identity Services provide authentication, Cloud Run, Firestore, Cloud KMS, Pub/Sub delivery queues, Vertex AI, logging, and trace infrastructure. A requested company-email delivery may briefly place the normalized destination, workspace binding, expiry, and opaque delivery identifier in Pub/Sub; no usable sign-in token is placed there.
- Cloudflare provides website delivery, Workers, D1, security, and related edge infrastructure.
- AI providers such as Google, Anthropic, OpenAI, and an administrator-enabled xAI worker receive the portions of a job dispatched to their selected model or agent under the organization’s configuration and the provider’s terms.
- Connected company systems receive tool requests and return data only when an administrator has enabled the connection and the run has matching authority.
- Communications providers such as Resend process commission, notification, reply, and requested company-email sign-in delivery. Resend receives the destination address and the one-time sign-in message needed for delivery.
- Professional advisers, authorities, or a successor operator may receive limited information when reasonably necessary for legal compliance, security, a transaction, or protection of rights, with appropriate safeguards.
Rally does not sell personal information, rent customer lists, or share personal information for cross-context behavioral advertising. Providers process data under their own contracts and privacy terms; administrators should select providers and configure retention appropriate to their organization.
Private workspace and public run evidence
The authenticated Work dashboard reads a separately allowlisted run projection from Cloudflare D1. Before storage, Rally replaces the configured workspace identifier with a keyed hash; the browser must present a valid Google identity or short-lived Rally session, and the edge returns only rows whose workspace hash matches that verified account’s workspace.
Runs are private by default. The public console reads only an explicitly public, sanitized projection produced through a separate opt-in. An operator must enable public publication and select the run; a normal run is not made public automatically. Public evidence may include a goal title, agent roles, checklist status, proof receipts, and residual risk, but should not include credentials, private paths, raw model reasoning, or unapproved company content.
Retention and deletion
Rally retains information for as long as reasonably needed to provide the Service, preserve an organization’s requested audit trail, meet security or legal obligations, resolve disputes, and enforce agreements. Retention can differ by deployment and by a connected provider’s settings.
- Teammate and email setup records remain until the teammate or account is deleted, or an early-access administrator requests deletion. Removing a Rally setup record does not cancel a mailbox, DNS record, API credential, or provider account controlled outside Rally.
- Connector credentials remain until replaced, disconnected, or the account is deleted. Disconnect first disables Rally use. If an OAuth provider publishes an automatic revocation endpoint, Rally revokes there before deleting its encrypted copy; a failed revocation leaves the copy sealed for retry. If automatic revocation is unavailable, Rally deletes its copy and tells the administrator to revoke the grant, key, or token in provider settings.
- Authentication state expires after two minutes for a one-time exchange code, ten minutes for a company-email sign-in link or unfinished connector authorization flow and its browser-binding cookie, and 30 minutes for a Rally browser session. Company-email link records are consumed atomically on first use; hashed rate-limit records expire after their enforcement window. Signing out requests deletion of the session hash and clears page memory; if that request cannot complete, expiry remains the backstop. Firestore TTL removes expired records asynchronously and may do so after the logical expiry.
- Run state and evidence, including the sanitized private workspace projection, remain according to the customer’s deployment and retention configuration. Content-free hosted connector execution receipts expire after 90 days. Early-access users may request deletion where an in-product control is not yet available.
- Public evidence remains available until withdrawn or removed. Removing the Rally projection cannot erase copies independently cached or recorded by others.
- Security records and backups may persist for a limited period according to infrastructure-provider schedules, fraud prevention, and legal requirements.
To request access, correction, export, unpublication, or deletion, email terry@agent9.dev. Rally may verify identity and organizational authority before acting.
Security and credential custody
Rally uses administrative, technical, and organizational safeguards designed for the sensitivity of coordinated agent work. The hosted control plane is separate from the private coordinator. Customer routes verify audience-bound Google identity tokens or hashed, short-lived Rally sessions. Exact callbacks, one-use state, same-browser binding, PKCE where supported, and atomic code consumption protect browser returns. Each hosted connection receives a unique AES-256-GCM data-encryption key; Google Cloud KMS wraps that key, and Firestore stores ciphertext, a wrapped key, and non-secret metadata. The customer API never returns a stored credential. A Certified connection permits only tenant-authenticated, preset-bounded calls whose live tool schema still matches the certified manifest, with content-free receipts; agent runs additionally require a separate immutable authority snapshot.
Other controls include least-privilege service identities, bounded connector adapters, content-disabled telemetry, duplicate suppression, deterministic authority checks, independent verification, and hard execution limits. No security system is infallible. Users must protect their accounts, choose narrow provider credentials, review requested authority, revoke suspected credentials, and notify Rally promptly of an incident.
Your choices and privacy rights
Depending on location, a person may have rights to access, correct, delete, restrict, object to, or receive a copy of personal information, and to withdraw consent without affecting prior lawful processing. A person may also complain to a local data-protection authority. Rally will not discriminate for exercising applicable privacy rights.
Administrators can limit collection by choosing narrower connectors and scopes, keeping publication off, deleting connector records, revoking access at the provider, or discontinuing the Service. Organization-managed users should ordinarily direct requests to their employer first because the organization controls the work data.
International use and children
Rally and its providers may process information in the United States and other countries where they operate. Those locations may have different data-protection laws. Where required, the responsible organization should put appropriate transfer safeguards and provider agreements in place before production use.
Rally is a business service and is not directed to children under 18. Do not submit children’s personal information. Contact Rally if you believe such information was provided.
Changes and contact
Rally may update this policy as the Service, providers, or law changes. The effective date will be revised, and material changes may also be communicated through the Service or an account contact. Continued use after an update is governed by the updated policy to the extent permitted by law.
Questions, privacy requests, or security concerns may be sent to:
Agent9 AI · Rally Privacy
terry@agent9.dev
https://rally.agent9.dev/
