Data boundary
Privacy
The public selection run is a read-only synthetic scenario. Private programme processing is a separately provisioned pilot capability and remains disabled until authentication, retention, storage, deletion, audit, and backup controls have passed review.
Published
The public run uses synthetic mission data
The public mission has no upload, account, or approval mutation workflow. Its DEMO-iPSC identifiers, sources, reviewer, activity timeline, candidate dispositions, and final artifact are fictional. Supporting catalogue surfaces may include illustrative public-source records and clearly marked placeholders; they are not customer data.
Ordinary hosting and network systems may receive request information such as IP address, time, path, browser or device information, and error details. This notice does not state a fixed retention period for infrastructure logs that is not yet contractually established.
Private pilots are organization and programme scoped
A provisioned pilot uses passwordless Supabase authentication. Server-side authorization verifies the access token, organization membership, programme scope, and one of four roles: programme administrator, reviewer, contributor, or viewer. Browser clients do not receive direct access to domain tables.
Product services scope each private query by organization and programme. Public read endpoints are isolated to records explicitly seeded as the synthetic demo. The administrative API key is reserved for operator maintenance, not ordinary product workflows.
Private documents are quarantined and isolated
Private uploads are designed for PDF, DOCX, XLSX, and CSV. A new object remains quarantined until detected MIME type matches the declared type and malware scanning reports a clean result. Objects use programme-scoped keys in a private Supabase Storage bucket; access is through short-lived signed URLs.
Deleting a document removes its storage object. The database retains an audited tombstone, deletion time, and content hash so the mission record can explain that evidence was removed without retaining the document body. Backups and restore procedures must be approved before a private pilot is enabled.
Private-document model processing is off by default
Riyaan does not enable model processing for private documents until the pilot has approved the provider, model, and retention controls. The initial adapter sends structured extraction requests with storage disabled (store:false), does not request background processing, and does not use hosted files or vector stores.
Those request settings do not by themselves eliminate provider abuse monitoring. OpenAI states that API abuse-monitoring logs may retain customer content for up to 30 days by default, with different controls available to eligible customers. See the provider data-controls documentation. Riyaan therefore requires an explicit retention-control approval in addition to technical request settings.
Audit records exclude document and credential content
Audit events may record organization, authenticated actor, mission, action, target, input hash, approval kind, and approval identifier. They are designed not to log document bodies, prompts, access tokens, model credentials, or provider API keys.
Operational monitoring covers worker heartbeat, queue age, failures and retries, the oldest pending approval, ingestion failures, mission outcomes, and artifact approval latency. Access to these operational aggregates is restricted to operator maintenance.
Email choices and contact
If you apply for a founding pilot by email, the message may include your email address, name, organization, and the programme context you choose to provide. It may be used to respond to your inquiry and continue the requested conversation. Keep the first message free of sensitive data.
Questions or deletion requests concerning email correspondence can be sent to [email protected]. Whether a particular legal right applies depends on applicable law and the relevant pilot agreement.