Who is responsible
This policy covers RawBoard’s public website and account service. Websites you visit have their own policies. RawBoard’s operator is responsible for the account and browser data described below.
Information we handle
- Your account: username, salted password hash, session records, creation date, friend-code redemption and subscription status.
- Your server browser: saved tab addresses and titles, website cookies, local storage, IndexedDB, saved website usernames and passwords, and recent page-assistant conversations.
- AI and billing usage: token counts, estimated provider cost, allowances, plan periods, Stripe customer/subscription identifiers and payment status.
- Technical information: connection and request information, errors and security or abuse-prevention events. Websites receive the information needed to handle browsing requests.
Account registration currently asks for a username and password, not an email address. Stripe may collect your email and billing details during its own checkout. RawBoard does not receive your full card number or security code from hosted checkout.
Why we use it
- Providing the service: accounts, browser sessions, saved tabs and requested AI assistance are used to perform the service contract.
- Subscriptions: usage and payment records support allowances, renewals and payment reconciliation, under the contract and applicable legal obligations.
- Security: access checks, limited diagnostic records and spam controls protect accounts and service availability. Where GDPR applies, the basis is the operator’s legitimate interest in a secure service.
- Requests and disputes: necessary information is used to respond to support, privacy and consumer requests and establish or defend legal claims.
Optional processing that legally requires consent must be explained separately. RawBoard currently has no marketing mailing list, advertising trackers or public-site analytics.
When you press AI
Opening the page assistant or asking a follow-up can send relevant page text, exercise fields and choices, diagrams or images, your question and recent conversation to DeepSeek’s API. This can include names, messages or other personal information visible on the page. Only use the assistant on content you are entitled to share. Avoid private messages, medical, financial and other sensitive pages.
The API key stays on RawBoard’s server. Answers and recent chat can be saved with your encrypted browser profile. Cached answers reduce repeat requests, but a follow-up or changed page can send fresh context and use tokens.
DeepSeek processes AI requests outside the EEA, including in China. Its public privacy notice expressly distinguishes downstream developer applications; it does not establish RawBoard’s API-specific retention or training terms. RawBoard does not promise zero retention, no training or an EU-only AI service. API contractual terms and a lawful transfer mechanism must be confirmed before an EU paid launch. See AI provider and transfer information.
Storage, security and access
The physical country of the main server has not yet been confirmed for publication. Browser profiles and saved website credentials are separated by account and encrypted at rest. Account passwords use salted hashes. Public connections use HTTPS. This is not end-to-end encryption: the server operator controls the system and encryption keys.
The administrator’s account screen shows usernames, subscriptions, token usage and estimated cost; it does not display other users’ browsing history or website passwords. Authorized operational access may still be necessary for maintenance, security or a verified support request. No system can guarantee that a security incident is impossible.
Detected games may run on your device or open separately, connecting directly to the game’s website. Third-party sites and payment/AI providers have their own roles and practices; see Service providers & data sharing.
How long information stays
Saved tabs, website storage, saved credentials and assistant conversations can remain while your account exists. A tab’s two-minute offload or midnight focus expiry closes its renderer; it does not delete saved account data. Login sessions expire after 7 days unless you sign out earlier. Expired session records are periodically purged.
Removing a saved password deletes that credential from the active profile. Account deletion removes active account records and its browser profile through the administrator’s deletion process. Deleting your RawBoard account does not delete accounts held with visited websites, or payment records that Stripe retains independently.
Database backups currently have no automatic expiry schedule. Copies may remain after active records are removed. The operator must set and publish a backup/deletion schedule and any required financial-record retention before paid launch; no fixed deletion deadline or automatic inactive-account deletion is currently promised.
Your choices and rights
You can remove individual saved website passwords in RawBoard’s browser menu, manage website choices on the visited site, sign out, or cancel paid renewal in Subscription & tokens. To request access, correction, deletion, portability, restriction, or to object to processing based on legitimate interests, contact the account administrator, joels through the channel where you received access. The privacy request template tells you what to include.
Where GDPR applies, requests normally receive a response within one month; a permitted extension or refusal must be explained. Rights have legal exceptions. We may need proportionate information to verify account ownership, but you should never send a password or full card number. You can withdraw consent for processing based on consent without affecting earlier lawful processing.
You may complain to the data-protection authority where you live, work or believe an infringement occurred. European Commission: your data-protection rights.
Spam and allowance checks can automatically pause AI requests. They do not decide school results or credit eligibility. Contact the operator to ask for human review of an incorrect restriction.
Young users and changes
The operator has not yet confirmed the minimum account age. If you are under 18, involve a parent or guardian before registering, sharing personal information or purchasing a plan.
The date above identifies this version. Material changes to data use need an updated notice before the new processing begins and, where required, a separate consent request. Accepting service terms is not blanket consent for unrelated data use.