Legal

Privacy Policy

How Rect collects, uses, shares, and protects information when you use our websites, applications, APIs, and hosted Agent.

Last updated: August 27, 2026

This Privacy Policy explains Rect's data practices and the choices and rights available to you.

1. Controller and scope

Rect is provided by Suri, Inc., a United States corporation. Suri, Inc. is the controller of personal information covered by this policy unless another notice says otherwise. This policy applies to Rect websites, hosted applications, APIs, CLI and MCP access, hosted Agent features, and related support and billing services.

A workspace customer may separately control personal information it places in Rect. In that case, the customer is responsible for its instructions and notices, and Rect processes the information to provide the service.

2. Information we collect

Depending on how you use Rect, we collect:

  • Account and workspace information: name, email address, authentication identifiers, profile details, teams, memberships, roles, and account settings.
  • Customer content: Rect templates, source and built assets, view state, App runs, prompts, Agent conversations, tool inputs and outputs, annotations, attachments, and file metadata.
  • Sharing and access information: capability links, permissions, invitations, and records of who created, accessed, or changed content where the product records that activity.
  • Usage, device, and network information: IP address, browser and device characteristics, requested URLs, timestamps, referring pages, security events, and server logs. Optional browser analytics and diagnostics are collected only according to your cookie choices.
  • Billing and communications: plan, payment status, transaction metadata, support messages, and other communications. Stripe processes payment card details; Rect does not store full card numbers.

Rect may receive content from people without accounts when an App or Rect permits anonymous use. An essential, pseudonymous visitor cookie helps preserve the anonymous Agent session and limit abuse.

3. How and why we use information

We use information to:

  • provide the service, authenticate users, operate workspaces, store and synchronize content, run user-requested actions and Agents, and deliver support;
  • secure Rect, prevent abuse, debug failures, maintain reliability, and enforce our Terms of Service;
  • administer subscriptions, process payments, and maintain required business and tax records;
  • understand and improve Rect using optional analytics and browser diagnostics when you permit them; and
  • comply with law and protect users, Rect, and others.

Where the GDPR or similar law applies, our legal bases are performance of our contract, our legitimate interests in securing and improving the service, compliance with legal obligations, and consent for optional technologies where required. You may withdraw consent at any time without affecting earlier processing.

4. Hosted Agent and AI processing

When you use Rect's hosted Agent, Rect sends the information needed to complete your request to AI and execution providers. This can include your prompt, relevant Agent history and memory, Rect or App state, selected attachment descriptors or contents, tool inputs and outputs, and system instructions. The primary hosted Agent uses OpenAI models; an observational-memory process uses Google Gemini; and selected file and command tasks may run in an E2B sandbox. Artifacts may be stored in Supabase-backed storage.

The Agent may also call tools you select, such as web or connected services, and those providers receive the tool input needed to answer the request. AI output can be inaccurate. Rect does not use customer content to train its own general-purpose model or intentionally opt customer content into third-party general-purpose model training. Providers may retain limited data for security and abuse prevention under their commercial or API terms.

An AI agent that you connect to Rect through MCP, the CLI, or an API may independently read or write content according to the permissions you grant. That agent and its provider are also governed by their own privacy terms.

5. How we disclose information

We disclose information only as needed to:

  • other users, workspace members, link recipients, and agents according to the permissions and sharing choices you set;
  • service providers that operate Rect, including Supabase for database, authentication, and storage; Vercel for hosting and optional analytics; Stripe for billing; OpenAI and Google for hosted AI; E2B for sandbox execution; our configured email provider; and Sentry for server-side reliability and security monitoring when configured, and for browser diagnostics when you permit them;
  • authorities or other parties when required by law, to protect rights and safety, or to investigate abuse; and
  • a successor or participant in a merger, financing, reorganization, or sale, subject to appropriate confidentiality protections.

We do not sell personal information or share it for cross-context behavioral advertising.

7. International processing and transfers

Rect is operated from the United States. Information is transmitted over encrypted network connections to the United States and other locations where our providers operate when you use the relevant feature. The principal recipients and purposes are:

  • Supabase and Vercel — account, content, request, and hosting data to operate Rect;
  • OpenAI and Google — Agent prompts, relevant context, and outputs for AI inference and memory processing;
  • E2B — selected files, commands, and results for sandboxed execution;
  • Stripe — billing identifiers and transaction data when you purchase a plan; and
  • Sentry — server error and request context for reliability and security monitoring when configured; browser error, trace, and sampled replay data only when diagnostics are configured and you consent.

Transfers occur when you use the service or relevant feature and the recipient retains data under its contract with us and the retention periods described below. Where required, we rely on contractual safeguards such as standard contractual clauses or another lawful transfer mechanism. Contact us for more information about applicable safeguards or overseas processing.

8. Retention

We keep account information while the account is active and for the additional period needed for security, dispute resolution, tax, accounting, or legal obligations. Customer content, Agent conversations, and memory remain until the authorized user deletes them, the account is deleted, or a product-specific retention rule applies. Deleting an account initiates deletion from Rect's active systems, subject to legal holds, fraud-prevention records, and backup rotation. Versioned records showing acceptance of our Terms may be retained after account deletion for contract administration and the establishment, exercise, or defense of legal claims.

Free Rect instances are archived 30 days after creation, which stops public availability but does not automatically delete the instance or attachment. Essential anonymous-Agent and cookie-preference cookies last up to one year. Security and diagnostic logs are kept only as long as reasonably needed for their purpose. Providers retain data according to their contracts and security schedules.

9. Security

We use technical and organizational measures designed to protect information, including database-layer access control, private attachment storage, encrypted transport, scoped capability tokens, sandboxed views, and restricted execution environments. No storage or transmission method is completely secure, and you are responsible for protecting credentials and capability links.

10. Your privacy rights

Depending on your location, you may have rights to access, correct, delete, restrict, object to, or receive a portable copy of personal information, and to withdraw consent. You may also have the right to appeal a decision or complain to your local data-protection authority. We do not discriminate against you for exercising applicable rights.

You can change optional cookie choices at any time through Cookie settings, edit account information in Rect, delete content you control, or send a request to support@suri.team. We may verify your identity and authority before completing a request. Authorized agents may submit requests where applicable.

11. Children

Rect is not directed to children under 13, and we do not knowingly collect personal information from a child under 13. If you believe a child has provided information, contact us so we can take appropriate action. A higher minimum age may apply where local law requires it.

12. Changes to this policy

We may update this policy as Rect or applicable law changes. We will post the updated date and take reasonable steps to provide additional notice of material changes when required.

13. Contact

Contact Suri, Inc. at support@suri.team or by mail at 1111b South Governors Av #88996, Dover, DE 19904, US.