Rakita Book Demo
Legal

Privacy Policy

How we collect, use, store and protect your personal data across the Rakita platform and products.

Last updated: August 14, 2026

1. Who we are

Rakita (the “Platform”, “we”, “us”) is operated by NOMRA L.LC-FZ, a free-zone company registered at Meydan — Free Zone, The Meydan Hotel, Dubai, United Arab Emirates. NOMRA L.LC-FZ is the data controller for the personal data described in this policy.

This policy covers the Rakita marketing site at rakita.io, the Rakita platform at platform.rakita.io, and every Rakita product built on it: Agents, Kurt, Navar, Atlas, Marketplace Moderator and Social Moderator.

For any privacy question, or to exercise the rights in section 8, write to hello@rakita.io.

2. Information we collect

We collect information in four buckets.

  • Account data — email address, display name, password hash (we never store your password in plain text), and any passkeys you register on your device.
  • Usage data — the messages you exchange with AI virtuals, documents you upload, and metadata such as timestamps, IP address, browser, and the channel a conversation arrived on (web embed, Slack, WhatsApp, Telegram).
  • Connector data — when you link a third-party service, we receive identifiers and tokens from that service and use them only to perform the action you asked for. Which service depends on the product you use; see section 3.
  • Social sign-in data — if you sign in with Google, Facebook or Apple, we receive your email address and basic profile (display name) from that provider and use it only to identify your account. Google sign-in is described in detail in section 5.

On the marketing site we also collect what you submit through the demo-request form (name, work email, company, and anything you write in the message field) and, with your consent, analytics data as described in our Cookie Policy.

3. Data each product handles

Rakita is a suite. Each product processes a different category of data on your behalf, and your organization decides which products to enable.

ProductWhat it processesTypical connectors
Agents Customer support conversations, tickets and the knowledge documents you ground them on. Slack, WhatsApp, Telegram, web embed, email
Kurt Source code, issues and pull requests in the repositories you connect. Kurt reads and writes code on your instruction. Git hosting and issue trackers
Navar Candidate applications, CVs, interview notes and hiring-pipeline status. This includes personal data about people who are not Rakita users. Job boards, email, calendars
Atlas Employee records, org structure, positions, leave requests and review cycles. This includes personal data about your employees. HR systems, email, calendars
Marketplace Moderator Marketplace listings, buyer questions and your replies. Trendyol and other marketplaces
Social Moderator Social and live-chat messages, author display names, and the moderation action taken. YouTube, and other social networks you connect

Where you are the controller. For Navar, Atlas, Agents, Marketplace Moderator and Social Moderator, the personal data you load about your candidates, employees, customers or viewers belongs to you. Your organization decides why and how it is processed; Rakita processes it on your instructions as your processor. You are responsible for having a lawful basis to load it and for telling those people that you use Rakita.

4. How we use it, and who processes it

  • To authenticate you and keep your account secure.
  • To answer questions through AI virtuals, including retrieval over documents you upload.
  • To send transactional email (password resets, invitations, billing notices).
  • To debug, monitor reliability and improve product quality.
  • To bill you and to meet our accounting and tax obligations.

We do not train AI models on your data, and we do not permit our model providers to do so. We do not sell personal data, and we do not share it with advertising networks or data brokers.

Hosting and data residency

Rakita stores data in two places, and which one applies depends on the kind of data:

  • Türkiye — your account record, conversation history, connector configuration and the search index built from your documents. Database backups are held in the same region.
  • European Union — the document files themselves. When you upload a file it is stored as an object in Amazon S3 in an EU region; the text extracted from it is indexed in Türkiye.

That means uploading a document involves an international transfer of that file out of Türkiye to the EU. Several sub-processors below also operate outside Türkiye, so using Rakita involves transferring the specific data listed against each one. We make every such transfer under contract with the recipient, on our instructions only, limited to what the service needs, and with the safeguards the applicable law requires.

Sub-processors

ProviderPurposeData it receives
Anthropic (via OpenRouter) Large language model inference The prompt and context of the request being answered
Voyage AI Embeddings for document similarity search Text extracted from documents you upload
OpenAI / Ollama Optional alternative model providers, only if your operator enables them As above, when selected
Amazon Web Services (S3, EU region) File storage for documents you upload The document files themselves
Resend Transactional email delivery Recipient email address and message content
Sentry Error and performance monitoring Diagnostic reports, which can include your email address and account identifier
Google, Facebook, Apple Optional sign-in providers Your email address and basic profile only
Cloudflare Content delivery and protection for rakita.io Request metadata, including IP address
Google Analytics Marketing-site analytics, only with your consent Pseudonymous usage events — see the Cookie Policy

5. Google user data

Rakita asks for access to your Google account in two separate, independent places, each with its own consent screen. This section describes exactly what Google user data each one accesses, how we use it, with whom we share, transfer, or disclose it, how we protect it, and how long we keep it.

5a. Signing in with Google

What we access. Only the standard OpenID Connect sign-in scopes — openid, profile, email. From those we receive your Google account email address, whether Google has verified it, and your basic profile (display name and profile picture URL). Signing in requests no other scopes: it does not let us read your Gmail, Google Drive, Calendar, Contacts, or Photos, and we call no other Google API for it.

How we use it. Solely to provide the sign-in feature you asked for: to verify who you are, to match you to your existing Rakita account (we match by email address), to create your account if you are registering with a valid invitation, and to display your name in the interface. We use it for nothing else.

What we store. Your email address and display name, in our own database. We do not store the Google access token, refresh token, or ID token from sign-in: we never request offline access, so Google issues no refresh token, and the sign-in tokens are discarded as soon as the sign-in completes. We do not store your Google profile picture.

5b. Connecting a YouTube channel (Social Moderator)

Social Moderator, our social-media moderation product, can moderate the live chat of your own YouTube live streams alongside your other social channels. This is optional: it happens only if you, as the owner of the channel, choose to connect it, and it has its own Google consent screen.

What we access. One scope — https://www.googleapis.com/auth/youtube.force-ssl. Live-chat moderation is a write operation, and the YouTube Data API authorizes deleting a live chat message or banning a viewer only with this scope; youtube.readonly cannot do either. It is the narrowest scope that supports the feature, and the only scope we request for it. With it we call: channels.list (your own channel id and title), liveBroadcasts.list (your currently active broadcast and its live chat id), videos.list (the broadcast title and concurrent-viewer count), liveChatMessages.list (read the live chat), liveChatMessages.delete (remove an abusive message), and liveChatBans.insert / liveChatBans.delete (time out or ban a viewer, and lift the ban). We never upload, edit, or delete your videos, ratings, or captions, and we act only on broadcasts of the channel you connected.

How we use it. To show your live chat in the moderation console and to carry out the moderation actions you or your configured policy decide on. Message text and author display name are classified (spam, harassment, hate speech, question, complaint) so the console can flag what needs attention.

What we store. The channel id and title, the OAuth refresh token (needed to keep moderating without re-consenting), and the live chat messages shown in the console — message text, author display name, author channel id, and what action was taken — scoped to the organization that connected the channel. Tokens are held server-side and are never sent to the browser.

With whom we share, transfer, or disclose it

We disclose the Google user data described above only to the following recipients, and only for the purposes stated:

  • Your organization — Rakita is a workspace product, so administrators and members of the organization you belong to can see your email address and display name in the member list.
  • Resend (transactional email delivery) — your email address is passed on so we can send you the messages the service requires, such as invitations and password resets.
  • Sentry (error and performance monitoring) — diagnostic reports for failed requests can include your email address and account identifier, so we can trace and fix the failure.
  • Anthropic, via OpenRouter (large language model inference) — only for the YouTube live-chat moderation feature in 5b: a viewer’s chat message text and display name are sent for a single classification call so the console can flag spam, harassment, and hate speech. Your Google account email address and profile are never sent to it, and no data from this call is used to train or improve any model.
  • NOMRA L.LC-FZ infrastructure and hosting providers — the servers and managed database that store your account record, under contract and on our instructions only.
  • Authorities or legal counsel — where we are legally required to disclose, or to establish or defend a legal claim.
  • A successor entity — if the business or a part of it is merged, acquired, or transferred, under this same policy.

We share, transfer, and disclose Google user data to no one else. In particular, we do not sell it, do not disclose it to data brokers, do not use it for advertising or ad targeting, and do not use it to develop, improve, or train any AI or machine-learning model, including non-personalized models. Your Google sign-in data (5a) is never sent to any AI or large-language-model provider at all.

Limited Use

Rakita’s use and transfer of information received from Google APIs to any other app adheres to the Google API Services User Data Policy, including the Limited Use requirements. Google’s own handling of your data is described in the Google Privacy Policy.

YouTube API Services

The YouTube feature in 5b uses YouTube API Services. By connecting a YouTube channel you also agree to the YouTube Terms of Service. We do not use YouTube API data to create derived data or metrics, and we do not use it to train machine-learning models. You can disconnect the channel in Social Moderator at any time, or revoke our access from your Google account, which stops any further data flow.

How we protect it, how long we keep it

It travels over HTTPS and is held under the access controls described in our Security page. Sign-in data (5a) is kept for as long as your account is active, then deleted on the schedule in section 7. YouTube API data (5b) is deleted or refreshed within 30 calendar days, as the YouTube API Services Developer Policies require, and the stored tokens are deleted as soon as you disconnect the channel. You can revoke Rakita’s access at any time at Google Account → Third-party apps with account access, and you can ask us to delete the data we already hold by following our Data Deletion Instructions.

6. Cookies

The Rakita platform at platform.rakita.io sets strictly necessary cookies only — the authentication session cookie and a short-lived passkey challenge cookie. It runs no analytics, advertising or cross-site tracking.

The marketing site at rakita.io additionally uses Google Analytics, which is off until you consent to it in the cookie banner. Full detail, including how to change your choice at any time, is in the Cookie Policy.

7. Data retention

We retain account data while your account is active. Chat messages and uploaded documents are kept until you (or an organization admin) delete them, or for 6 months after account closure, whichever is sooner. Backup snapshots may persist for up to 30 days after the live data is deleted. Invoices and records we must keep for tax and accounting purposes are retained for as long as the applicable law requires.

To delete your data sooner, follow the Data Deletion Instructions.

8. Your rights

Under the UAE Personal Data Protection Law (Federal Decree-Law No. 45 of 2021), and under the EU General Data Protection Regulation and Türkiye’s KVKK where those apply to you, you have rights to access, correct, delete, restrict and port your personal data, and to object to certain uses. To exercise any of these, write to hello@rakita.io. We respond within 30 days.

How each of those rights works in practice, and what to expect when you exercise one, is set out on Your Data Rights.

9. Security

We use HTTPS in transit, hashed passwords (bcrypt), HMAC-signed tokens for password reset and passkey challenges, tenant isolation on every data access, and least-privilege access to production systems. Our full security posture is described on the Security page. No system is perfect — if you suspect a security issue, please email hello@rakita.io.

10. Children

Rakita is a business product and is not directed at children. We do not knowingly collect personal data from anyone under 18. If you believe a child has provided us personal data, email us and we will delete it.

11. Changes

We will revise this policy when our practices change. The “Last updated” date above reflects the current version. If a change materially affects how we handle your personal data, we will notify account administrators by email before it takes effect.

Other documents
Terms of ServiceCookie PolicySecurityYour Data RightsData Deletion