This Privacy Notice for Resh Consultancy LLC (doing business as R.ai) describes how and why we collect, store, use, and share your personal information when you use our services at https://resh-ai.com.
Questions or concerns? Contact us at privacy@resh-ai.com
We process your information to:
| Processing Activity | Legal Basis |
|---|---|
| Delivering AI services, authentication, billing | Performance of a Contract (Art. 6(1)(b)) |
| Face photo processing for image generation | Explicit Consent (Art. 6(1)(a) + Art. 9(2)(a)) |
| Forensic audit logging, security, fraud prevention | Legitimate Interests (Art. 6(1)(f)) |
| Compliance with legal obligations | Legal Obligation (Art. 6(1)(c)) |
| Marketing communications (if any) | Consent (Art. 6(1)(a)) — you may withdraw at any time |
We share personal information only with service providers who perform services on our behalf under data processing agreements. We do not sell your personal information.
| Provider | Purpose | Data Shared | Privacy Policy |
|---|---|---|---|
| Novita AI / DeepSeek | LLM inference | Conversation prompts (no PII) | novita.ai/privacy |
| Google (Gemini) | Vision analysis, independent accuracy review | Conversation prompts, uploaded images (no PII) | policies.google.com/privacy |
| OpenAI (GPT-4o-mini) | Independent accuracy review | Conversation prompts (no PII) | openai.com/privacy |
| Together AI (Llama 3.3) | Independent accuracy review | Conversation prompts (no PII) | together.ai/privacy |
| fal.ai | Image generation, face photo processing | Uploaded images only | fal.ai/privacy |
| Tavily | Web search | Search queries (no PII) | tavily.com/privacy |
| DigitalOcean | Cloud infrastructure hosting | Encrypted data at rest | digitalocean.com/legal/privacy-policy |
| Twilio | Phone OTP authentication | Phone number (hashed on our end) | twilio.com/legal/privacy |
| Supabase | Database and storage | Account data, hashed credentials | supabase.com/privacy |
| Stripe | Payment processing | Billing data | stripe.com/privacy |
| Cloudflare | CDN, WAF, DDoS protection | IP addresses, request metadata | cloudflare.com/privacypolicy |
We may also disclose your information: (a) to comply with applicable law, regulation, or legal process; (b) to protect the rights, property, or safety of Resh Consultancy LLC, our users, or the public; (c) in connection with a merger, acquisition, or sale of all or a portion of our assets, with advance notice to affected users.
R.ai provides AI-powered services including conversational AI, image generation, document analysis, image analysis, AI-powered search, and natural language processing.
All AI inference is routed through a 15-tribe governance architecture. Prompts are processed by third-party AI providers (Novita AI/DeepSeek, Google Gemini, OpenAI, Together AI, fal.ai, Tavily) solely to deliver requested services and, for select responses, to independently verify accuracy through automated cross-checking before you see them. Third-party AI providers do not receive your account identity, phone hash, or billing information.
To opt out of AI processing, contact privacy@resh-ai.com or delete your account. Note that opting out of AI processing means you cannot use the core R.ai service.
Our servers are located in the United States (DigitalOcean). All listed third-party processors are US-based. If you access R.ai from the European Union or United Kingdom, your data is transferred to the United States.
Transfers from the EU/UK to the US are governed by European Commission Standard Contractual Clauses (SCCs) incorporated into our data processing agreements with service providers. For questions about international data transfers, contact privacy@resh-ai.com.
| Data Type | Retention Period | Deletion Trigger |
|---|---|---|
| Account data (hashed phone, tier, settings) | Duration of account | Account deletion request |
| Conversation history | Duration of account | Account deletion request or manual deletion |
| Face photos (biometric) | Not stored by Resh Consultancy LLC. fal.ai CDN: minimum 7 days then may be deleted. fal.ai request payloads: up to 30 days. | Automatic CDN expiry |
| Uploaded session files | Active session only | Session end |
| Forensic audit logs (D.A.V.I.D. Spine) | Up to 12 months for security and compliance | Automated purge after retention period |
| Billing records | 7 years (tax and legal compliance) | Legal retention period |
| Log data (IP, usage) | 90 days | Automated deletion |
We implement the following technical and organizational security measures:
R.ai is intended for users 18 years of age and older. We do not knowingly collect personal information from users under 18. By using R.ai, you confirm you are at least 18 years of age.
If we learn that we have collected personal information from a user under 18, we will delete that information promptly. If you believe we have collected data from a minor, contact us at privacy@resh-ai.com.
Request a copy of your personal data we hold.
Request correction of inaccurate personal data.
Request deletion of your personal data.
Request your data in a machine-readable format.
Withdraw consent at any time where processing is based on consent.
Request restriction of processing in certain circumstances.
Object to processing based on legitimate interests.
Request human review of automated decisions affecting you.
To exercise any right, contact privacy@resh-ai.com. We will respond within 30 days. EU/UK users may lodge complaints with their Member State data protection authority.
| State | Law | Key Rights |
|---|---|---|
| California | CCPA / CPRA | Know, access, correct, delete, opt out of sale/sharing, limit sensitive data use |
| Texas | TDPSA | Access, correct, delete, portability, opt out of targeted advertising and profiling |
| Colorado | CPA | Access, correction, deletion, portability, opt out |
| Connecticut | CTDPA | Access, correction, deletion, portability, opt out |
| Virginia | VCDPA | Access, correction, deletion, portability, opt out |
Submit rights requests to privacy@resh-ai.com. We will respond within 45 days (extendable by 45 days with notice). Appeals may be submitted to your state attorney general.
California Civil Code Section 1798.83 permits California residents to request information about personal data disclosed to third parties for direct marketing purposes. We do not disclose personal data to third parties for their direct marketing purposes. Submit any requests to privacy@resh-ai.com.
In the event of a data security breach that affects your personal information, Resh Consultancy LLC will:
For security-related concerns or to report a vulnerability, contact privacy@resh-ai.com.
R.ai operates under a governed AI architecture covered by USPTO provisional patent applications (7 filed). All user interactions are processed through a 15-tribe intelligence routing system that enforces domain-specific governance mandates at the inference layer.
The D.A.V.I.D. Forensic Spine maintains an immutable, HMAC-signed audit record of governed inference calls. This log records governance decisions, gate routing, and response classifications — not the full content of your conversations. Audit logs are retained for up to 12 months for security, compliance, and platform integrity purposes.
Phone numbers collected for OTP authentication are immediately converted to a one-way cryptographic hash (PBKDF2-SHA256). The original phone number is discarded immediately after hashing. The hash is used solely for account identity verification. Phone numbers are never transmitted to AI inference providers.
Enterprise customers who require a formal Data Processing Agreement (DPA) in accordance with GDPR Article 28, CCPA, or other applicable data protection laws may request one by contacting privacy@resh-ai.com.
The DPA will cover:
Current Sub-Processor List: Novita AI, Google, OpenAI, Together AI, fal.ai, Tavily, DigitalOcean, Twilio, Supabase, Stripe, Cloudflare. We will notify enterprise customers at least 30 days before adding or replacing sub-processors.
We may update this Privacy Notice from time to time. The updated version will be indicated by the updated date at the top of this page. For material changes, we will notify active users by email at least 14 days before the changes take effect. We encourage you to review this notice periodically.
| Contact Type | Details |
|---|---|
| Privacy Inquiries / Rights Requests | privacy@resh-ai.com |
| Data Protection Officer | Vijay Anand Raj Kanaparthy, Resh Consultancy LLC |
| Mailing Address | Resh Consultancy LLC, Dallas, TX 75252, United States |
| General Support | support@resh-ai.com |
| Website | https://resh-ai.com |
To request access, correction, or deletion of your personal data, email privacy@resh-ai.com with the subject line "Data Request — [Access / Correction / Deletion]". We will respond within 30 days.