What we hold, and what we don't.
AskRITZ works by understanding your business. That only works if you know exactly what we keep, why, who can reach it, and what we have not built yet.
01Who we are
AskRITZ is an AI operating layer for businesses, built and operated from Dubai, United Arab Emirates. This page describes what happens to information you give us and information the product generates on your behalf. It is written to be read, not to be survived.
02What we hold
Four kinds of information, and nothing beyond what the product needs.
- Your account. Email address, name if you give one, and the workspace you belong to. Authentication is handled by Supabase Auth; we never store your password ourselves.
- Your business context. What you tell Ritz about your business during onboarding and in conversation — your idea, industry, audience, goals, and the documents and decisions that accumulate from there. This is the point of the product: you should not have to repeat yourself to each specialist.
- A record of work. When a specialist runs, we record which one, when it started, when it finished, and whether it succeeded. This is what lets the interface tell you the truth about what is happening rather than an animation.
- Launch-update signups. If you ask for launch updates on the public site, we hold the email address you gave us, and the business name and industry only if you chose to add them. This is separate from an account — most people who sign up have not created one.
We do not collect location data, contacts, browsing history outside AskRITZ, or advertising identifiers.
03Why we hold it
To operate the product you asked for: to understand your business well enough that specialists produce work grounded in it, to show you accurate progress, to keep a record of decisions you approved, and to support you when something goes wrong. If you asked for launch updates, we use your email for exactly that — to tell you when there is something real to show you — and any business details you added help us understand who is interested.
We do not sell your information, share it with advertisers, or use one customer's business context to serve another.
04Launch updates and email preferences
Signing up is consent to receive AskRITZ launch and product updates. The newsletter is a separate preference and is not automatically enabled. Private links let you manage launch updates, newsletter preferences, or stop all AskRITZ email updates without an AskRITZ account.
Resend is our email delivery processor and may process recipient addresses, message content, delivery status, bounce, complaint and suppression events. We retain bounce, complaint and provider suppression state to prevent unwanted future delivery. Open and click tracking is disabled for this email lifecycle.
Cloudflare Turnstile processes browser, network and request signals for abuse prevention. We also use short-lived HMAC-derived rate-limit identifiers; rate buckets do not store raw IP addresses or raw email addresses. Expired buckets are removed in bounded batches during signup traffic.
We may store bounded source, UTM campaign and referral attribution with a signup. We retain consent purpose, version, time and source as operational and compliance evidence, alongside preference and delivery records. These records do not have an automated deletion schedule; you can contact us about retention or deletion using the address below.
05AI processing
Generating brand, website and SEO work requires sending relevant parts of your business context to Anthropic, our AI model provider. Only the context needed for that specific piece of work is sent, not your entire history.
Search-performance checks send the public web address you ask us to analyse to the Google PageSpeed Insights API. That address is already public.
Your business context is not used to train third-party models.
06Separation between customers
Every table holding customer information enforces row-level security in the database itself, keyed to your workspace. Separation does not depend on application code remembering to filter correctly — the database refuses the query.
We verify this with an automated suite that signs in as one workspace and attempts to read and write another's records. Those attempts must fail for the suite to pass. See Security for detail.
08How long we keep things
Your workspace content is kept while your account is open, because removing it would remove the accumulated understanding the product is built on. When an account is closed we delete its business context and generated work. Records we are required to keep for legal or accounting reasons are retained for the period the law requires and nothing longer.
09What is not built yet
AskRITZ is pre-launch. The following are designed and intended but not yet implemented, and we would rather say so here than describe them as though they work:
- self-service data export;
- self-service account deletion — email us and we will do it manually;
- multi-factor authentication and session management;
- automated retention and deletion schedules;
This section will shrink as these ship. Until each one does, it stays listed here.
10Your rights
You can ask what we hold about you, ask for a copy, ask us to correct it, or ask us to delete it. Until the self-service tools above exist, write to hello@askritz.ai and a person will handle it. We aim to respond within 30 days.
11Changes
When this document changes materially we update the date at the top. If a change affects how we handle information you have already given us, we will tell account holders directly rather than relying on you to re-read this page.