Privacy Policy

Last Updated: July 10, 2026  |  Resh Consultancy LLC, Dallas, Texas

Table of Contents

  1. What Information Do We Collect?
  2. How Do We Process Your Information?
  3. Legal Bases (EU/UK GDPR)
  4. When and With Whom Do We Share Your Information?
  5. Artificial Intelligence Products
  6. International Transfers
  7. How Long Do We Keep Your Information?
  8. Security
  9. Minors
  10. Your Privacy Rights
  11. US State Privacy Rights
  12. Do Not Sell or Share
  13. Breach Notification
  14. AI Governance and Biometric Data
  15. Data Processing Agreement (Enterprise)
  16. Updates to This Notice
  17. Contact and Data Protection Officer

This Privacy Notice for Resh Consultancy LLC (doing business as R.ai) describes how and why we collect, store, use, and share your personal information when you use our services at https://resh-ai.com.

Questions or concerns? Contact us at privacy@resh-ai.com

1. What Information Do We Collect?

Information You Provide Directly

Automatically Collected Information

What we do not collect: Raw phone numbers (hashed immediately and discarded), payment card numbers (handled by Stripe), government ID numbers, Social Security numbers, or biometric templates. We do not build behavioral profiles for advertising.

2. How Do We Process Your Information?

We process your information to:

We do not use your conversation content to train AI models. Your prompts and responses are yours. They are processed to deliver your requested service and stored for your session history only.

3. Legal Bases (EU/UK GDPR)

Processing ActivityLegal Basis
Delivering AI services, authentication, billingPerformance of a Contract (Art. 6(1)(b))
Face photo processing for image generationExplicit Consent (Art. 6(1)(a) + Art. 9(2)(a))
Forensic audit logging, security, fraud preventionLegitimate Interests (Art. 6(1)(f))
Compliance with legal obligationsLegal Obligation (Art. 6(1)(c))
Marketing communications (if any)Consent (Art. 6(1)(a)) — you may withdraw at any time

4. When and With Whom Do We Share Your Information?

We share personal information only with service providers who perform services on our behalf under data processing agreements. We do not sell your personal information.

ProviderPurposeData SharedPrivacy Policy
Novita AI / DeepSeekLLM inferenceConversation prompts (no PII)novita.ai/privacy
Google (Gemini)Vision analysis, independent accuracy reviewConversation prompts, uploaded images (no PII)policies.google.com/privacy
OpenAI (GPT-4o-mini)Independent accuracy reviewConversation prompts (no PII)openai.com/privacy
Together AI (Llama 3.3)Independent accuracy reviewConversation prompts (no PII)together.ai/privacy
fal.aiImage generation, face photo processingUploaded images onlyfal.ai/privacy
TavilyWeb searchSearch queries (no PII)tavily.com/privacy
DigitalOceanCloud infrastructure hostingEncrypted data at restdigitalocean.com/legal/privacy-policy
TwilioPhone OTP authenticationPhone number (hashed on our end)twilio.com/legal/privacy
SupabaseDatabase and storageAccount data, hashed credentialssupabase.com/privacy
StripePayment processingBilling datastripe.com/privacy
CloudflareCDN, WAF, DDoS protectionIP addresses, request metadatacloudflare.com/privacypolicy

We may also disclose your information: (a) to comply with applicable law, regulation, or legal process; (b) to protect the rights, property, or safety of Resh Consultancy LLC, our users, or the public; (c) in connection with a merger, acquisition, or sale of all or a portion of our assets, with advance notice to affected users.

5. Artificial Intelligence Products

R.ai provides AI-powered services including conversational AI, image generation, document analysis, image analysis, AI-powered search, and natural language processing.

All AI inference is routed through a 15-tribe governance architecture. Prompts are processed by third-party AI providers (Novita AI/DeepSeek, Google Gemini, OpenAI, Together AI, fal.ai, Tavily) solely to deliver requested services and, for select responses, to independently verify accuracy through automated cross-checking before you see them. Third-party AI providers do not receive your account identity, phone hash, or billing information.

To opt out of AI processing, contact privacy@resh-ai.com or delete your account. Note that opting out of AI processing means you cannot use the core R.ai service.

6. International Transfers

Our servers are located in the United States (DigitalOcean). All listed third-party processors are US-based. If you access R.ai from the European Union or United Kingdom, your data is transferred to the United States.

Transfers from the EU/UK to the US are governed by European Commission Standard Contractual Clauses (SCCs) incorporated into our data processing agreements with service providers. For questions about international data transfers, contact privacy@resh-ai.com.

7. How Long Do We Keep Your Information?

Data TypeRetention PeriodDeletion Trigger
Account data (hashed phone, tier, settings)Duration of accountAccount deletion request
Conversation historyDuration of accountAccount deletion request or manual deletion
Face photos (biometric)Not stored by Resh Consultancy LLC. fal.ai CDN: minimum 7 days then may be deleted. fal.ai request payloads: up to 30 days.Automatic CDN expiry
Uploaded session filesActive session onlySession end
Forensic audit logs (D.A.V.I.D. Spine)Up to 12 months for security and complianceAutomated purge after retention period
Billing records7 years (tax and legal compliance)Legal retention period
Log data (IP, usage)90 daysAutomated deletion
Upon account deletion request, we delete your personal data from active systems within 30 days, except where retention is required by law (billing records) or where data is part of an anonymized aggregate dataset.

8. Security

We implement the following technical and organizational security measures:

No transmission over the internet is 100% secure. While we implement industry-leading security measures, we cannot guarantee absolute security. In the event of a security incident affecting your data, we will notify you as described in Section 13.

9. Minors

R.ai is intended for users 18 years of age and older. We do not knowingly collect personal information from users under 18. By using R.ai, you confirm you are at least 18 years of age.

If we learn that we have collected personal information from a user under 18, we will delete that information promptly. If you believe we have collected data from a minor, contact us at privacy@resh-ai.com.

10. Your Privacy Rights

Access

Request a copy of your personal data we hold.

Correction

Request correction of inaccurate personal data.

Deletion

Request deletion of your personal data.

Portability

Request your data in a machine-readable format.

Withdraw Consent

Withdraw consent at any time where processing is based on consent.

Restrict Processing

Request restriction of processing in certain circumstances.

Object

Object to processing based on legitimate interests.

Opt Out of Automated Processing

Request human review of automated decisions affecting you.

To exercise any right, contact privacy@resh-ai.com. We will respond within 30 days. EU/UK users may lodge complaints with their Member State data protection authority.

11. US State Privacy Rights

StateLawKey Rights
CaliforniaCCPA / CPRAKnow, access, correct, delete, opt out of sale/sharing, limit sensitive data use
TexasTDPSAAccess, correct, delete, portability, opt out of targeted advertising and profiling
ColoradoCPAAccess, correction, deletion, portability, opt out
ConnecticutCTDPAAccess, correction, deletion, portability, opt out
VirginiaVCDPAAccess, correction, deletion, portability, opt out

Submit rights requests to privacy@resh-ai.com. We will respond within 45 days (extendable by 45 days with notice). Appeals may be submitted to your state attorney general.

Do Not Sell or Share My Personal Information: We do not sell or share your personal information for cross-context behavioral advertising. To confirm or submit an opt-out request, contact privacy@resh-ai.com.

12. California "Shine the Light"

California Civil Code Section 1798.83 permits California residents to request information about personal data disclosed to third parties for direct marketing purposes. We do not disclose personal data to third parties for their direct marketing purposes. Submit any requests to privacy@resh-ai.com.

13. Breach Notification NEW

In the event of a data security breach that affects your personal information, Resh Consultancy LLC will:

For security-related concerns or to report a vulnerability, contact privacy@resh-ai.com.

14. AI Governance and Biometric Data

R.ai operates under a governed AI architecture covered by USPTO provisional patent applications (7 filed). All user interactions are processed through a 15-tribe intelligence routing system that enforces domain-specific governance mandates at the inference layer.

Biometric Data (Face Photos)

Forensic Audit Logging

The D.A.V.I.D. Forensic Spine maintains an immutable, HMAC-signed audit record of governed inference calls. This log records governance decisions, gate routing, and response classifications — not the full content of your conversations. Audit logs are retained for up to 12 months for security, compliance, and platform integrity purposes.

Phone Number Handling

Phone numbers collected for OTP authentication are immediately converted to a one-way cryptographic hash (PBKDF2-SHA256). The original phone number is discarded immediately after hashing. The hash is used solely for account identity verification. Phone numbers are never transmitted to AI inference providers.

15. Data Processing Agreement (Enterprise) NEW

Enterprise customers who require a formal Data Processing Agreement (DPA) in accordance with GDPR Article 28, CCPA, or other applicable data protection laws may request one by contacting privacy@resh-ai.com.

The DPA will cover:

Current Sub-Processor List: Novita AI, Google, OpenAI, Together AI, fal.ai, Tavily, DigitalOcean, Twilio, Supabase, Stripe, Cloudflare. We will notify enterprise customers at least 30 days before adding or replacing sub-processors.

16. Updates to This Notice

We may update this Privacy Notice from time to time. The updated version will be indicated by the updated date at the top of this page. For material changes, we will notify active users by email at least 14 days before the changes take effect. We encourage you to review this notice periodically.

17. Contact and Data Protection Officer

Contact TypeDetails
Privacy Inquiries / Rights Requestsprivacy@resh-ai.com
Data Protection OfficerVijay Anand Raj Kanaparthy, Resh Consultancy LLC
Mailing AddressResh Consultancy LLC, Dallas, TX 75252, United States
General Supportsupport@resh-ai.com
Websitehttps://resh-ai.com

How to Review, Update, or Delete Your Data

To request access, correction, or deletion of your personal data, email privacy@resh-ai.com with the subject line "Data Request — [Access / Correction / Deletion]". We will respond within 30 days.