Privacy and data use
Last updated September 7, 2026
Use staging for evaluation
The hosted Rationexa site is an experimental staging preview with no uptime or data-durability guarantee. Do not submit confidential customer data, production secrets, regulated information, or decision material you cannot safely lose.
What is stored
Rationexa stores the decision material you submit, extracted candidate premises, human review choices, finalized records, revisit evidence, model provenance, usage metadata, and account information needed to provide the workspace.
Guest workspaces are isolated through a browser cookie and are scheduled for deletion after 24 hours. Registered workspace data remains until you delete the account or the staging environment is reset during development.
Models and BYOK
Deterministic rules run without a model key. If you connect a hosted provider and select one of its models, the relevant source or evidence is sent to that provider under its own terms. Provider keys are encrypted at rest per workspace and are not returned by the API or included in shared records.
Use a restricted, revocable provider key with a spending limit. Do not reuse a privileged personal or production key in the public preview.
Infrastructure and analytics
The preview uses Vercel for web and API hosting, PostgreSQL for workspace storage, an SMTP provider for password-recovery email when configured, and the model provider you explicitly connect. Privacy-filtered web analytics may record page and device-level usage; share-token paths are excluded.
Operational logs record request metadata such as route, status, duration, and request ID. The application is designed not to log request bodies, cookies, provider keys, reset tokens, or evidence content.
Sharing and deletion
Shared links expose only the finalized record fields selected by the product. They expire and can be revoked. They do not include provider credentials, private source artifacts, session metadata, or internal workspace identifiers.
You can remove a provider connection, revoke a share, delete an individual decision, or permanently delete your registered account and workspace from Account & AI connections.
Questions and security reports
For ordinary questions or private security reports, contact the maintainer. Once the repository is public, its support and security guides provide the community reporting paths.