Raya Privacy Policy

Effective September 21, 2026

This policy covers Raya, Ikan Media Inc.'s private AI assistant and connected business tools, including their Google account connections. It explains application data practices separately from the company's public advertising and publishing websites. For information received through Raya's Google connections, this policy takes precedence over the general website privacy policy.

Information accessed

Depending on the connection and permissions you authorize, Raya may access:

Raya also processes the instructions, messages, files, and feedback you provide directly, along with operational records needed to run and troubleshoot the application. Different connections may have different permissions; this list is not a request for all permissions from every user.

How the information is used

Raya uses information to answer requests, find and summarize relevant messages and documents, prepare briefings, identify appointments, retain useful context, and perform supported actions you authorize. Depending on granted permissions, actions include sending email, creating or changing calendar events, deleting events, creating or updating documents, and operating connected business reporting tools.

Authorized background workflows may use connected information to provide reminders, briefings, and reporting without a separate prompt for each run. Access to Gmail, Calendar, and Drive content is for the assistant's productivity features, not for selling that content or using it to serve personalized advertisements.

AI processing and service providers

Relevant information, including excerpts from connected messages, events, documents, conversation history, and saved context, may be transmitted to AI service providers such as Anthropic, Google, and OpenAI. These services support response generation, summaries, information extraction, and embeddings used to retrieve saved context. The provider used depends on the configured feature and processing route.

Assistant responses, notifications, and requested information may be delivered through Telegram. Conversation records, saved facts, contacts, tasks, and derived information may be stored in configured Supabase databases and local application records. Hosting, infrastructure, and service providers process information to support these functions under their applicable service terms and privacy practices. Raya is not a local-only application, and this policy does not promise zero provider retention.

When you authorize an action such as sending an email or creating a document, information is also sent to the service and recipients needed to perform that action. Information may be disclosed when necessary to comply with law or address security and abuse.

Google API data

Information received from Google APIs is subject to the Google API Services User Data Policy, including its Limited Use requirements where applicable. Google mailbox, calendar, and document content is not a data product offered to advertising partners or data brokers. Access and transfers must support the authorized features described here or another use permitted by Google's policy.

Storage, retention, and security

Conversation history and saved context can include information obtained from Google services, including content returned in assistant responses. These records may persist across sessions. Authorization credentials and operational records are maintained in application storage. Retention depends on the record, operational purpose, applicable obligations, and service-provider practices; Raya does not currently apply one automatic deletion period to all records.

Application access is limited to authorized users, and Google API connections use authenticated requests. No system can guarantee complete security. Do not give Raya access to an account or information you are not authorized to use.

Your choices and deletion requests

You can review and remove Raya's connection through your Google Account connections settings. Removing a connection stops future access through that authorization. It does not automatically delete conversation history, saved memories, local records, reports, or messages already delivered through Telegram or other services.

To request access to, correction of, or deletion of retained application information, email [email protected] and identify the connected account and records involved. We may need to verify that you control the account. Requests are reviewed by the operator; records subject to legal obligations or provider-controlled retention may require separate handling. Do not send passwords or authorization tokens with your request.

Changes and contact

Updates to this policy will appear here with a revised effective date. A new use of Google data beyond the authorization and disclosures already provided requires appropriate notice and consent before that use begins.

Operator: Ikan Media Inc. Business correspondence: 390 NE 191st St, STE 62202, Miami, FL 33179. Privacy: [email protected]. Application support: [email protected].