Privacy

Effective 2026-09-26.

Alex Neyman, doing business as Agent Rails operates Rails and is responsible for the personal information covered by this policy (the data controller where that term applies).

This privacy policy covers Rails, this site, and each app at <app>.rails.so. Rails runs apps, stores their records, and serves tools that you can use from an agent host. A host such as Muse, claude.ai, Hermes or Grok is a separate service. Its privacy policy covers the conversation it holds. Connecting an app does not give Rails your whole chat history.

What we collect and why

Information comes from you, the host you connect, the app's work, Clerk, Whop if you buy paid access, and Google if you connect Google Calendar. Records can contain information about other people, such as contacts you supply. Only send information you have the right to use. Avoid sensitive personal information unless it is needed for the task and you have the right to provide it.

What each app stores

The following inventory describes the record types declared by the existing apps. A record type does not mean every person has a record of that type. Optional capabilities create records only when available and used.

Assistant

Poker Trainer (existing app)

Language Tutor (existing app)

Poker Trainer connector

Language Tutor connector

Job Bot

Recruiter

Rolodex

Unblock

Google Calendar data

If you connect Google Calendar, Rails stores Google tokens for your account and receives limited calendar data from Google. Only you can connect it, from a browser where you are signed in to Rails. A connected agent host cannot connect or revoke it, or confirm an event. Google asks you to allow two permissions: to see the list of your calendars (calendar.calendarlist.readonly) and to see and edit events (calendar.events). Rails requests no other Google permission. It uses the second one to read the event details listed below and to create events you confirm; it never edits or deletes an event.

Who receives information

Rails does not sell personal information or share it for cross-context behavioral advertising. These legal pages have no analytics, advertising, third-party requests or tracking scripts. Service delivery to the providers above is not advertising.

Providers can process information in countries other than yours. Those countries can have different privacy laws. Where transfer safeguards are legally required, they must cover the transfer. Ask us which locations and safeguards apply to your app. This policy does not assert a particular data region, adequacy decision or contractual safeguard that has not been verified.

Purposes and legal grounds

We use account details, app records and payment information to provide the service you request and perform our agreement with you. We use necessary operational and security information for our legitimate interests in running a reliable service, preventing abuse and resolving disputes. We keep legally required accounting records to meet legal obligations. When a feature needs consent, we ask for it; you can withdraw it without changing the lawfulness of earlier processing.

A phone number and verification are required to sign in. Without the content needed for a task, an app cannot do that task. App-generated feedback and estimates are assistance for you, not decisions about your legal rights. We do not use them to make solely automated decisions with legal or similarly significant effects.

Retention, export and deletion

Saved app records have no automatic age-based expiry unless the feature says otherwise. They remain until deleted. Account and installation metadata remain while needed to provide access and resolve account issues. Purchase records and receipts remain for accounting, security and disputes, including after an app is removed. The current software does not automatically expire those ledgers.

We assess a deletion request against the purpose of each retained category and any legal duty to keep it. If something must remain, we explain the category, reason and applicable period. This policy does not claim a fixed log, support-mail or backup deletion schedule: those operational schedules have not yet been verified.

Revoking a token stops future access with that token; it does not delete saved data. Signing out clears that session, not every connection. Exports do not include provider copies or backups. Deletion at Rails does not erase material you or a host already copied elsewhere. We handle requests concerning our service providers as required by applicable law.

Your choices and rights

Contact us to ask what we hold, obtain a copy or a portable export, correct a mistake, delete information, or stop a connection. You can ask about data another person entered about you even if you have no Rails account. Tell us the app and what you need; do not send a sign-in code, password or full card number. We verify identity and authority using information proportionate to the request. An authorized agent can act for you with proof of authority. We explain any refusal and any lawful exception. You do not have to buy an app to exercise your privacy rights.

In the EEA, where the GDPR applies, your rights include access, correction, erasure, restriction, portability, objection to legitimate-interest processing, and withdrawal of consent. You can complain to your local data protection authority. We respond within one month, subject to lawful extensions that we explain within that month.

California residents have the rights that apply under the CCPA: know and access, correct, delete, opt out of sale or advertising sharing, and limit qualifying uses of sensitive personal information. We do not sell or share data for that advertising purpose, including data about minors, and use sensitive information only as needed for the requested service and permitted operational purposes. There is no sale or advertising sharing to opt out of, including when your browser sends Global Privacy Control. We do not penalize you for exercising rights. Where the CCPA applies, we respond to access, correction and deletion requests within 45 days, with notice of any lawful extension.

The categories described above include identifiers, commercial information, internet activity, content you provide, audio where used, and inferences such as learning estimates. They describe current collection and operational disclosure, not a claim that every feature ran throughout the preceding 12 months. You can ask for the categories, sources, recipients and specific information applicable to you.

Security and cookies

Rails scopes app records to a person and installation. PostgreSQL row-level security adds tenant separation behind the service's access checks. This is not end-to-end encryption: authorized service code and operators can process the data. Tokens grant access and must be kept private. Handoff tokens can expire or be revoked.

The Rails session cookie is strictly necessary for sign-in. It is host-only, HttpOnly and SameSite=Lax, with Secure on HTTPS. It is not an advertising cookie. The planned per-app sign-in flow exchanges an authorization code for a separate, host-only session bound to that app. That flow is not yet available in this release; we do not share the apex session cookie across app subdomains. Reading this privacy policy or the terms sets no cookie and needs no sign-in.

No service can guarantee perfect security. Contact us promptly about a suspected exposure. Keep control of your phone and disconnect hosts you no longer trust.

Children

Rails is not for children under 13, or under 16 in the EEA. These are our minimum ages, not a claim that every country's consent age is the same. Do not create an account below the applicable age. If you believe a child below that age has supplied personal information, contact us so we can investigate, close the account and arrange deletion subject to legal obligations.

Changes to this policy

We publish changes here and update the effective date when adopted. We give notice of material changes through the service before they take effect. If a new use needs consent, we ask before starting it. A policy update does not remove your legal rights.

Contact and privacy requests

Use the address below for privacy requests, support, refunds and security reports.

Write to support@rails.so.