Privacy Policy

Effective April 12, 2026 · Version 1.0

Ryze Labs, LLC ("we", "us", "our") operates Ryze, an AI-powered LinkedIn personal brand platform. This policy explains what personal data we collect, why we process it, how long we keep it, and your rights.

1. Data Controller

Ryze Labs, LLC is the data controller for personal data processed through Ryze. For questions, contact privacy@ryze.so.

2. What We Collect

Account information

Name, email address, and hashed password provided during registration.

LinkedIn engagement data

Post content you interact with, comment text generated and selected, post author names, headlines, and company information visible on public LinkedIn posts.

Voice and brand calibration data

Questionnaire responses, writing samples, and AI-generated voice/brand profiles used to personalize comment generation.

Contact and CRM data

Professional contact information (names, LinkedIn URLs, headlines, companies) for people you engage with through the platform.

Usage and engagement analytics

Interaction records, sentiment classifications, topic categories, and engagement metrics derived from your commenting activity.

Technical data

Session tokens and IP addresses for authentication. We do not use analytics cookies, advertising trackers, or third-party tracking scripts.

3. Why We Process Your Data

PurposeLawful Basis
Provide the Ryze serviceContract (Art. 6(1)(b))
Personalize AI comment generationContract (Art. 6(1)(b))
Per-user engagement analytics and CRM intelligenceContract (Art. 6(1)(b))
Improve voice models from engagement patternsLegitimate Interest (Art. 6(1)(f))
Platform analytics and AI model trainingLegitimate Interest (Art. 6(1)(f))
Aggregate insights and benchmarking (de-identified)Legitimate Interest (Art. 6(1)(f))
Account security and authenticationContract (Art. 6(1)(b))

Data Used for AI Training and Aggregate Intelligence

We use conversation data (comment threads, reply exchanges, engagement classifications) to train and improve our AI models and to generate aggregate, de-identified market intelligence such as topic trends, sentiment benchmarks, and buyer intent patterns.

Before data enters the aggregate intelligence layer, it is irreversibly anonymized: all user identifiers, contact names, company names, and personally identifiable details are stripped. The resulting aggregates cannot be traced back to any individual user, conversation, or contact (GDPR Recital 26).

You may opt out of contributing to cross-user aggregate analytics at any time from Settings → Privacy & Data. Opting out does not affect your access to the service or your personal engagement analytics.

4. How Long We Keep Your Data

We apply a tiered retention model:

Data categoryRetention period
Conversation threads (visible)7 days to 1 year (user-configured), then hidden from your feed
Conversation threads (platform archive)Up to 3 years for analytics and AI model improvement, then permanently deleted
Engagement & contact records3 years from creation, then deleted
Anonymized aggregate analyticsIndefinite (contains no personal data)
Account informationUntil account deletion

When conversation threads expire from your feed, they are archived for platform analytics and AI model improvement. After the archive retention period, engagement statistics are aggregated into anonymized records that cannot be traced back to any individual (GDPR Recital 26), and the original thread data is permanently deleted.

5. Third-Party Processors

We share personal data with the following processors, all under appropriate data processing agreements:

ProcessorPurposeLocation
AnthropicAI comment and voice generationUS
OpenAIAI classification and analysisUS
ResendTransactional email deliveryUS
RailwayApplication and database hostingUS
AWS (S3)File and image storageUS
ReplicateImage generation modelsUS

6. International Data Transfers

Our processors are based in the United States. For transfers of EU personal data, we rely on Standard Contractual Clauses (SCCs) and the EU-US Data Privacy Framework where applicable.

7. Your Rights

Under GDPR, CCPA/CPRA, and applicable privacy laws you have the right to:

  • Access — request a copy of your personal data
  • Rectification — correct inaccurate data
  • Erasure — request deletion of your data
  • Data portability — export your data in a machine-readable format
  • Restriction — limit how we process your data
  • Object — object to processing based on legitimate interest
  • Withdraw consent — where processing is consent-based

You can exercise your access, export, and deletion rights directly from Settings → Privacy & Data in the app. For other requests, contact privacy@ryze.so. We respond within 30 days.

8. Cookies

Ryze uses only strictly necessary cookies: a session authentication token and a UI preference cookie. We do not use analytics, advertising, or third-party tracking cookies. Strictly necessary cookies are exempt from consent requirements under the ePrivacy Directive.

9. Data Security

We protect your data with TLS encryption in transit, encrypted database connections, bcrypt-hashed passwords, and role-based access controls. Our infrastructure runs on managed cloud platforms with industry-standard security certifications.

10. Complaints

You have the right to lodge a complaint with your local data protection supervisory authority. For EU residents, a list of authorities is available at edpb.europa.eu.

11. Changes to This Policy

We may update this policy periodically. Material changes will be communicated via email or an in-app notification. The version number and effective date at the top of this page indicate the current version.

Terms of Service · Sign in