# Privacy Policy · Rationale

> How Rationale handles personal data: what we collect, why, who processes it, how long we keep it and your rights.

Source: https://rationalehq.com/privacy
Language: en

# Privacy Policy

This version effective 6 October 2026 · First published 3 October 2026

In short

-   Rationale is a tool for teams. The organization that uses it decides what goes into its workspace, and we process that content on its behalf.
-   For running Rationale itself we collect what we need: your email address to sign you in, security records, your devices and AI connections, and what you choose to connect. Connected tools such as Jira and GitHub also bring in the names and photos of the people who appear in them.
-   We do not sell personal information or use it for advertising, we use no third-party analytics or tracking cookies, and we do not use your content to train AI models.
-   Our servers are in the United States (DigitalOcean). Emails are sent through Resend.
-   You can access, correct or delete your data and object to how we use it ([section 9](#rights)). Anything about your data: [privacy@rationalehq.com](mailto:privacy@rationalehq.com).

## 1\. Who we are

Rationale (rationalehq.com) is a service of **Inside My Tranquility, Lda.**, a private limited company (sociedade por quotas) with registered office at Estrada Comandante Camacho de Freitas, n.º 779, São Roque, 9020-154 Funchal, Madeira, Portugal, registered with the Conservatória do Registo Comercial do Funchal under the single registration and tax number (NIPC) 519 295 145, with a share capital of €5,000.00 ("we", "us").

Write to us at [privacy@rationalehq.com](mailto:privacy@rationalehq.com) about personal data, or at [support@rationalehq.com](mailto:support@rationalehq.com) for anything else, or by post to the address above. We are not required to appoint a data protection officer and have not appointed one. The person responsible for personal information at Inside My Tranquility, Lda., including for the purposes of Canada's PIPEDA and Quebec's Act respecting the protection of personal information in the private sector, is the company's manager (gerente), reachable at [privacy@rationalehq.com](mailto:privacy@rationalehq.com).

## 2\. Two roles: your organization's content, and our own records

-   **Workspace content.** The organization that uses Rationale (the "customer") controls the content of its workspace: decisions and their reasons, tasks, handoffs, notes members share with the team, summaries, the titles of the work sessions captured, and what it brings in through connectors such as Jira. We process this content only to provide the service to the customer, following its instructions, our [Data Processing Terms](https://rationalehq.com/terms#data-processing) and, for US state privacy laws, our [US State Privacy Terms](https://rationalehq.com/terms#us-privacy). If you want to see, correct or delete content in a workspace, ask that workspace's owners; we help them answer you.
-   **Account and service data.** For the data we need to run Rationale itself (accounts, sign-in, security, emails and support) we decide how it is used, as controller. This policy explains that data in detail, and also what we do with workspace content.

## 3\. What we collect, why, and for how long

Data

Why we use it

Legal basis (EU/UK)

How long we keep it

**Account:** your email address, when you last signed in, your workspaces and role. You give it to us, or the person who invited you does, or we open it when we approve your access request.

To sign you in with a link sent by email and to run your membership in workspaces.

Our legitimate interest in providing the service your organization uses (Art. 6(1)(f) GDPR); if you use Rationale for yourself, our contract with you (Art. 6(1)(b)).

While you have an account. On request, within 30 days, we delete your account or, where a workspace's records still refer to you, replace your email address with a placeholder; audit log entries that name you are kept for the periods below, for accountability. Sign-in links work once, for 15 minutes.

**Access requests:** your email address, your team's size, which AI agents, task tracker and code host your team uses, and whether it uses GitHub Projects. You give them to us on the request form, or type your address on our website, which sends it to the app to fill in the form.

To decide whether to open an account for you and to email you the link that signs you in when it is open. Without your address, to count which tools teams use and decide what to support next.

Steps you ask for before using the service (Art. 6(1)(b) GDPR); the counts, our legitimate interest in building what teams use (Art. 6(1)(f)).

Until we decide, at most 90 days. If we open your account, it is kept as above, and is deleted if nobody signs in to it within 90 days; the link in that email works once, for 7 days. 30 days after we decide, the request keeps only your answers, with no address and no link to your account, as counts. The request stores no IP address, but its record in our audit log keeps the IP address it came from for 12 months (see Audit log). Our staff get an email with your address and answers, which we delete within the same periods. We email you nothing about the request unless we open your account.

**Your private notes:** the rules you, or your AI assistant from your own words, write for your assistants to follow (for example "answer me in Spanish"), where they apply, and the words that set them. Only your own assistants receive them.

To give them to your AI assistants when a session starts and when they ask Rationale for context.

Our legitimate interest in providing the service your organization uses (Art. 6(1)(f) GDPR); if you use Rationale for yourself, our contract with you (Art. 6(1)(b)).

While you keep them. An archived note stays, hidden, as part of its history; deleting your account deletes all your private notes. A note that applied only to a workspace is deleted with that workspace. Notes you share with the team are workspace content (section 2).

**Invitations:** the invited email address, who invited and the role. Given by a workspace owner.

To send the invitation email and let the person join.

Legitimate interest of the organization and ours in adding people to its workspace (Art. 6(1)(f)).

The link works for 7 days. Invitations nobody accepted are deleted 30 days after they expire or are canceled; accepted ones stay as the record of how you joined, while the workspace exists. The audit log keeps a record that the invitation was sent (see below).

**Sign-in sessions:** your IP address, your browser's user agent and when you signed in. Collected automatically.

To keep you signed in and to protect your account.

Legitimate interest in securing the service (Art. 6(1)(f)).

Deleted 30 days after you sign in.

**Devices and AI connections:** your computer's name, which the Rationale client sends when you sign it in, the client's version, when and from which IP address a device or a connected AI assistant (MCP) was last used, and the name and return address of AI apps that register to connect. Signing in a device uses a short code that works for 10 minutes.

To let the Rationale client and the AI assistants you connect act for you, and to let you see and revoke them.

Our legitimate interest in letting the tools you approve act for you, and in letting you see and revoke them (Art. 6(1)(f)).

A device or connection unused for 90 days stops working; revoked and expired ones keep their name and dates as history while the workspace exists. Device sign-in codes are deleted a day after they expire. IP addresses are removed 12 months after they were last recorded.

**Client activity:** for each capture of a work session and each file check, which member, which AI tool and model, token counts and timings, turn numbers, the repository, branch and file paths involved, and the client's version. Sent by the Rationale client on your computer.

To attach decisions to the right task, show the team what was captured, and measure whether capture works.

Processed for the customer (workspace content). To measure whether capture works we also use counts and timings from it, never content, as controller, based on our legitimate interest in making the service work (Art. 6(1)(f)).

As long as the workspace exists.

**Audit log:** who did what and when, including the email addresses involved, decision numbers, task handles, file paths shown to agents and IP addresses; and account events such as sign-ins and requests for sign-in links. Every time our staff look at a workspace's data in our admin, it is recorded in that workspace's log.

So the workspace's owners can see who did what (including our staff's views), and to secure the service.

Legitimate interest in accountability and security (Art. 6(1)(f)).

A workspace's events: as long as the workspace exists. Account events with no workspace: 24 months. IP addresses are removed after 12 months.

**Jira connector:** your Atlassian account ID and display name, the access and refresh tokens Atlassian issues to Rationale, and which Jira projects your account can browse (their IDs, keys and names). Received from Atlassian when an owner connects Jira or you link your Atlassian account.

To show you and your AI agents only what your own Jira account can see. See [section 4](#jira).

Processed for the customer (workspace content); reporting account IDs to Atlassian is our legitimate interest and an obligation under Atlassian's developer terms (Art. 6(1)(f)).

Until you unlink your account, you are removed from the workspace, the workspace turns the connector off, or Atlassian tells us the account was closed; everything is deleted then. If Atlassian stops accepting the link, the tokens are deleted at once and the rest is deleted 90 days later unless you link again.

**GitHub connector:** your GitHub user ID and username (and, for pull requests in the repositories a workspace follows, the GitHub user ID and username of the person who opened each), the access and refresh tokens GitHub issues to Rationale for you, and which repositories of the workspace's installation your account can access (their IDs and names). Received from GitHub when an owner installs Rationale's GitHub App or you link your GitHub account.

To show you and your AI agents only what your own GitHub account can see. See [section 4](#github).

Processed for the customer (workspace content).

Until you unlink your account, you are removed from the workspace, or the workspace turns the connector off or uninstalls the app on GitHub; everything is deleted then. If GitHub stops accepting the link, the tokens are deleted at once and the rest is deleted 90 days later unless you link again.

**People in a workspace's sources:** for each person a Jira ticket brought into Rationale is assigned to or was reported by, their Atlassian account ID, display name, profile photo and, when their Jira profile shows it, email address; for each person on a pull request Rationale keeps (who opened it, reviewed it, was asked to review it or wrote in its threads and conversation), for the first assignee and the author of each brought GitHub issue, and for the person who opened each open pull request, their GitHub user ID, username, public profile name, profile photo and, when they made it public, profile email address; the Jira projects and repositories they were seen in; and which of these accounts are the same person, with the suggestions that they may be (why, and who confirmed or refused them). Received from Atlassian and GitHub with the tickets and pull requests, or looked up by account ID.

To show who is working on what: a member by their email address and photo, anyone else by the name and photo the source gives, marked as not in Rationale, and only to members whose own linked account can see where that person appears. Email addresses from Jira or GitHub are used only to suggest that accounts are one person and to let workspace owners invite that person. See [section 4](#people).

Processed for the customer (workspace content); reporting Atlassian account IDs to Atlassian as above (Art. 6(1)(f)).

While a source keeps showing them: deleted 90 days after a ticket or pull request last showed them (unless they are a member who linked that account), at once when the workspace turns the connector off or Atlassian tells us the account was closed, and with an erasure request. Tickets, issues and pull requests keep the account IDs of the people on them while they are kept, and a kept pull request keeps the usernames in its review threads and comments (encrypted).

**Emails you send us** (support@, privacy@): your address and your message.

To answer you, and to handle requests about your rights.

Our legitimate interest in answering people who write to us (Art. 6(1)(f)); for requests about your rights, our legal obligation to answer them and show we did (Art. 6(1)(c)).

As long as needed to answer you. Requests about your rights and our replies are kept for 3 years to show we handled them, without the data we sent.

**Terms acceptance:** who accepted which version of our Terms of Service, for which workspace, when, and whether for the organization (an owner) or as a member joining by invitation; its record in our audit log keeps the IP address it came from.

To show that the organization accepted the Terms, and that each person who joined agreed to use Rationale under them.

Performance of the contract (Art. 6(1)(b)); our legitimate interest in being able to prove it (Art. 6(1)(f)).

While the workspace exists; deleted with it. IP addresses in the audit log are removed after 12 months.

**Monday summary email:** once a week, an email to each member who has signed in at least once with what moved in their workspace, as counts and links only (new decisions by area, decisions superseded, revisits waiting for a person, pull requests merged with decisions, the inbox); never the text of a decision. Nothing is sent when nothing moved. Each email leaves an audit event with those counts.

To keep members informed of what their team decided without reading the whole workspace.

Legitimate interest in making the service useful to the team (Art. 6(1)(f)). You turn it off in one click in Settings → Members, and the link to do so is in every email.

While your account exists and the summary is on; the audit event while the workspace exists.

**Server logs:** when you visit our website or use the app: IP address, browser user agent, time, the address requested (with its query) and the response; the website's log also records the page that linked to it (the referrer). The text of decisions and tasks you send is filtered out of our application's log. Search terms and the secret part of sign-in and invitation links never travel in web addresses, so no log records them (invitation links sent before 3 October 2026, which expire by 10 October, still do). Two short-lived codes can appear in a logged address: a device sign-in code (it works for 10 minutes, and only for a signed-in member) and the code Atlassian or GitHub returns when a workspace connects Jira or GitHub or a member links an account (used at once, and only with our app's own secret), with the GitHub installation's number. Counters by IP address limit abuse.

To run the service, find faults and stop abuse.

Legitimate interest in operating and securing the service (Art. 6(1)(f)).

Logs are capped at 10 MB per container and overwritten as they fill; the logs of the last five releases are kept until newer releases replace them. Rate-limit counters are removed within about a day. Failed background tasks, whose details can name a person, are deleted after 30 days.

You need to give an email address to have an account; everything else is optional or collected as you use the service. We do not ask for sensitive data (such as health, beliefs or ethnic origin) and ask you not to record it. Items moved to a trash or retired stay until the workspace is deleted. Data we delete leaves our database backups within 7 days; logs and emails follow the periods above.

### Workspace content

Decisions (the question, the choice, the reasons, the options ruled out, short quotes from the conversation where they were decided, and the words a person used to confirm one), notes, tasks, handoffs, summaries and session titles are stored encrypted. Workspace and project names and descriptions, repository and branch names, file paths and Jira keys are stored as they are, unencrypted. Decisions are captured by the Rationale client on members' own computers, using each member's own AI tool (for example Claude Code). The conversation itself never reaches our servers: the client sends only what it extracts (decisions, short quotes, summaries, topics and session titles) and the client activity listed above. Workspace content also goes to members' own AI tools. The Rationale client gives a member's AI agent the decisions that apply to the work it is doing. About once a day per project, the client has a member's own AI tool (Claude Code or Codex) write the project's summary from the workspace's shared decisions and handoffs, including the email address of who made each decision. An AI assistant a member connects to Rationale (MCP) reads workspace content for the member. Each AI provider (for example Anthropic or OpenAI) receives that content under the member's or the customer's own agreement with it, not ours, and that agreement decides whether the provider may keep it or train on it. Workspace content is kept as long as the workspace exists, and deleted when the customer asks (see our [Terms](https://rationalehq.com/terms#termination)).

### Automation controls

Workspace owners choose automatic context, decision capture and Rationale task creation separately for each project. Automatic context starts on. For new projects, automatic capture and task creation start off; existing projects that already listed repositories keep their capture setting. A member can pause automatic capture for themselves in a project. These settings and pauses do not grant access to another project or source, and explicit requests to read or record remain available.

Turning capture off or pausing it stops new automatic decision recording and background handoffs. With Rationale client 0.11.0 or later, background capture after activation or resumption uses only new turns, including in its earlier-turn context; it does not import turns from the time capture was off or paused. Existing records stay under the retention periods above. With automatic context on, a prompt hook may send up to three ticket or pull-request references from a listed repository, never the prompt itself; missing work from a connected source is brought in by a background job under the member's existing permissions. Automatic tasks record concrete work already agreed or assigned; they do not assign people or authorize new work, tracker writes or deployments.

We keep the project settings, each member's pause and resumption dates, and who changed them and when, to apply these choices and account for them. Settings are not encrypted and stay while the workspace exists; a person's pause preferences are included in their export and removed when the member leaves or on account erasure. Local capture receipts hold only decision numbers and counts, expire after 24 hours and are shown to that member's agent separately from MCP calls. Automatic records are inferred unless a recorded human action confirms them.

## 4\. Jira and other connectors

When a workspace owner connects Jira and when you link your own Atlassian account, Rationale receives from Atlassian, through Atlassian's OAuth, your Jira profile, of which it keeps your Atlassian account ID and display name (and, if you also appear on tickets it keeps, what [People](#people) describes), and tokens that let Rationale read Jira for you within the permissions you approved (view Jira issues and user profiles, manage the webhooks Rationale registers, and stay connected while you are away). With your own token, Rationale asks Atlassian which Jira projects your account can browse when you link and about every 6 hours, and keeps their IDs, keys and names. Names, display names and tokens are encrypted.

Rationale never receives your Atlassian password and does not create or edit issues, projects or settings in Jira; the only thing it may create there are webhooks that tell it about changes. A workspace owner chooses which Jira projects a Rationale project follows; nothing is copied until a member asks for a ticket by its key, and then Rationale keeps that ticket's epic and the epic's tickets and sub-tasks, and keeps them up to date. For each it keeps, unencrypted, the issue key, ID, link, status, issue type, when Jira last changed it and the Atlassian account IDs of its assignee and its reporter (whose display names and photos are kept with [People](#people)); and, if the owner chose content, its title and description, encrypted. A member sees a ticket's title and description only if their own Jira account can see its Jira project. Assignee and reporter account IDs are cleared when the workspace turns the connector off or Atlassian tells us the account was closed; the rest is workspace content. Other workspace members see which Jira projects each member's account can see, and a project's name only if their own account can see it.

Once a week (or as often as Atlassian asks) Rationale sends Atlassian the Atlassian account IDs it stores for every connected Jira site, linked members' and ticket assignees' alike, as Atlassian requires, so that Atlassian can tell us which accounts were closed (we delete them) or changed (we fetch the name again). You can revoke Rationale at any time from your Atlassian account (Profile → Connected apps) or unlink it in Rationale (Settings → Connectors → Jira).

**Rationale, not Atlassian, is responsible for the personal data that Rationale collects and processes through its Jira connector.** Atlassian's own handling of your data is described in Atlassian's privacy policy.

**GitHub.** A workspace owner installs Rationale's GitHub App on their organization or account and chooses, on GitHub, which repositories it may read. The app reads repository metadata, pull requests, checks, commit statuses and, once an organization approves it, issues. It writes one thing on GitHub, and only once the organization grants it permission to write pull requests: a comment on a pull request naming the decisions recorded in the workspace that govern the files it changes (each one's question and what was chosen, with a link; never a decision kept private), edited in place as that set changes. Without that permission it writes nothing. It stores no code: to find which lines an open pull request changes, it reads the pull request's changes and keeps only the line numbers. It acts as itself, with short-lived tokens Rationale does not store; the names of the repositories it may read are kept, unencrypted, like the repository names sessions report. When you link your GitHub account, Rationale receives your GitHub user ID and username (the username is encrypted) and tokens that expire after 8 hours and can be renewed for 6 months; with your own token it asks GitHub which of the installation's repositories you can access, when you link and about every 6 hours. Other workspace members see which repositories each member's account can access.

For the repositories a workspace's projects list, Rationale reads pull requests: number, state, branches, last commit, the GitHub user ID of the person who opened it, whether reviews approved it or asked for changes and how many review threads are unresolved, whether its checks pass, and the paths of the files it changes (never the changes themselves), plus the Jira keys and task handles it mentions. Its title, description and its author's username, and while it is open its unresolved review threads (the file and line, the first comment and the newest reply, up to 10 threads), each reviewer's latest verdict, the people asked to review it who have not yet (teams asked to review are not kept), and its last 10 conversation comments by people (bots left out), with the GitHub user IDs and usernames of who wrote them, are kept, encrypted, only while it is linked to a task or decisions were captured on its branch, and are shown only to members whose own GitHub account can see the repository. For open pull requests Rationale also keeps the line numbers each one changes, per file (not the changes), to tell two people when their open pull requests change the same lines or files; that warning, and the answer a member gives to it (in the web, or through their agent with their own words, which are encrypted), is kept while both pull requests are open. A pull request linked to nothing is forgotten 30 days after it closes; everything is deleted when the workspace turns the connector off or the app loses the repository. You can revoke Rationale at any time on GitHub (Settings → Applications → Authorized GitHub Apps) or unlink it in Rationale (Settings → Connectors → GitHub); an organization owner uninstalls the app in the organization's settings, and Rationale then deletes every link to that installation.

For issues, once the organization approves Rationale's permission to read them, Rationale reads an issue only when work starts on it: a member or their agent asks for it, in a repository a workspace's project lists. It then reads the issue with its parent and sub-issues in the repositories that project lists, and follows them: node ID, number, state and why it was closed, issue type, parent, when it last changed, and the GitHub user IDs of its first assignee and of its author. Its title and description (up to 4,000 characters) are kept, encrypted, and shown only to members whose own GitHub account can see the repository. Issues nobody asked for are never imported. An issue leaves Rationale's lists when GitHub no longer returns it or it leaves the brought work (its history stays), and everything is deleted when the workspace turns the connector off.

**People.** So the work has names, Rationale keeps the people its connectors meet: the person each brought Jira ticket is assigned to and the person who reported it (Atlassian account ID, display name and profile photo), the first assignee and the author of each brought GitHub issue, the people on the pull requests it keeps (who opened, reviewed or was asked to review it, and who wrote in it) and the person who opened each open pull request while it is open (GitHub user ID, username, public profile name and profile photo), each with the Jira projects and repositories they were seen in. When Jira or GitHub shows a person's email address (only if their profile shows it there), Rationale keeps it, encrypted, to suggest that their accounts are one person (the same address in Jira and GitHub, or a member's sign-in address) and so a workspace owner can invite them; it is shown only to owners, in the invitation they confirm, never to other members. Accounts in different sources become one person when a member links them as their own, or when the person concerned or a workspace owner confirms a suggestion. Suggestions come from rules on data Rationale already holds (someone who keeps opening pull requests for one person's tickets, names that match, the same email address) or from a member's AI agent, with that member's words when they gave them; each says why, and a refused one is never suggested again. Account IDs are kept unencrypted; names, usernames, email addresses and photos are encrypted. Profile photos are copied from where Atlassian or GitHub serves them into our database and shown from app.rationalehq.com, never loaded from Atlassian or GitHub in your browser, so those companies do not see who views them; a photo is fetched again when the source gives a new one and at most weekly while the source keeps showing the person. A member's own linked accounts are shown as that member. Anyone else is named only to members whose own Jira or GitHub account can see a ticket, issue or pull request where they appear; to everyone else they are "someone not in Rationale". Who someone is never changes what a member can see. Names, email addresses and photos are deleted 90 days after a source last showed the person, when the workspace turns the connector off, when Atlassian tells us the account was closed, or with an erasure request (a photo the source no longer has is deleted at the next fetch); Atlassian account IDs are reported to Atlassian as described above, and a changed name or photo is fetched again. Members see the people list in Settings → People. If you are not a member and appear in a workspace's Jira or GitHub, the workspace's organization decides this processing: write to us and we pass your request to its owners and help them answer it.

**Private records.** You can keep a decision, a handoff, a task you created in Rationale (with its subtasks) or one of your agent sessions (with what was captured from it) to yourself, with a click on its page, or by asking your AI assistant in your own words (it records them with the change). Tasks that mirror Jira follow who can see them in Jira. A private record reaches only you and your own assistants: other members of the workspace, its owners included, and the summaries and topics everyone reads do not see it or that it exists; the workspace's audit log keeps the event that it was made private (ids and dates, not its content), and shows it to nobody but you. A copy of a workspace's content made for its customer leaves private records out, as it leaves out private notes; a copy of your own data includes yours. They are deleted with the workspace, like everything else in it.

## 5\. What we do not do

-   We do not sell personal information, and we do not "share" it for cross-context behavioral advertising.
-   We do not show ads, and we use no third-party analytics, tracking pixels or third-party cookies.
-   We do not use your content to train AI models, and Rationale's servers run no AI models on it. Whether an AI provider that members use may train on what it receives depends on that provider's terms and the member's account settings.
-   We do not make decisions about you based solely on automated processing that have legal or similarly significant effects.

## 6\. Who receives personal data

We use these service providers (sub-processors), each under a written data processing agreement:

Provider

What for

Where

DigitalOcean, LLC

Servers, database and backups

United States (New York area)

Resend (Plus Five Five, Inc.)

Sending sign-in, invitation, access and Monday summary emails; receiving email sent to our addresses

United States and the European Union

Others who receive data:

-   **Atlassian**, when a workspace uses the Jira connector, as described in [section 4](#jira).
-   **GitHub**, when a workspace uses the GitHub connector, as described in [section 4](#github).
-   **Your workspace.** The owners of a workspace see its members' email addresses, roles, activity and IP addresses in its audit log; members see each other's email addresses and which Jira projects and GitHub repositories each member's account can see.
-   **GitHub, Inc.** hosts the downloadable Rationale client. Downloads and the client's automatic updates are fetched from GitHub, which receives those requests under GitHub's privacy statement; we count downloads per day and store no IP address with them.
-   **AI providers members use**: the AI tools members run or connect (such as Claude Code, Codex or an MCP assistant) receive the workspace content described in [Workspace content](#workspace-content), under the member's or the customer's agreement with their provider.
-   **Authorities**, only when the law requires it and after checking the request is valid; we tell the customer unless the law forbids it.
-   **A buyer or successor**, if the company or the service is sold or merged; this policy would continue to protect the data, and we would tell you first.

## 7\. International transfers

Our servers and database are in the United States. We are established in Portugal, so these transfers are made under the GDPR, wherever you are. For DigitalOcean, LLC they rely on its certification under the EU-U.S. Data Privacy Framework, its UK Extension and the Swiss-U.S. Data Privacy Framework (an adequacy decision, Art. 45 GDPR) and, if that stops applying, on the European Commission's Standard Contractual Clauses in its data processing agreement (Art. 46(2)(c)). For Resend (Plus Five Five, Inc.) they rely on the Standard Contractual Clauses in its data processing agreement, which always apply (Art. 46(2)(c)), and on its certification under the EU-U.S. Data Privacy Framework and its UK Extension. Write to us for a copy of the clauses. If you are in Canada, including Quebec: your personal information is processed and stored in the United States and may be accessible to the courts, law enforcement and national security authorities of that country.

## 8\. How we protect data

-   Connections to Rationale use HTTPS, and the emails we send leave over an encrypted connection to our email provider.
-   The text of decisions, notes, tasks, handoffs, summaries and session titles, connector tokens, the names, email addresses and photos Jira and GitHub give for people and GitHub usernames are encrypted in our database with keys kept apart from it. Identifiers such as workspace and project names and descriptions, repository, branch and file names are not.
-   Only our staff operate the service. Our admin is built never to read or decrypt content, and every staff view of a workspace's data in it is written to that workspace's audit log. Opening a production console, which can, is recorded in our own audit log and done only for support you ask for or to handle an incident.
-   If a security incident affects personal data, we tell the affected customers without undue delay (within 48 hours, as our Data Processing Terms say), and notify the authorities and the people affected as the law requires.

## 9\. Your rights

**Right to object: you can object at any time, on grounds relating to your situation, to processing based on our legitimate interests.** We then stop, unless we have compelling legitimate grounds or need the data for legal claims.

Wherever you live, you can ask us for a copy of your personal data, to correct it or to delete it, by writing to [privacy@rationalehq.com](mailto:privacy@rationalehq.com). It is free. We answer within 30 days (if the law allows us more time for a complex request, we tell you why within those 30 days). To protect you, we may ask you to confirm the request from the email address of your account. Someone may make a request on your behalf if they show you authorized them. For content inside a workspace, we pass your request to the workspace's owners and help them answer it. To complain about how we handle your data, write to the same address: we acknowledge complaints within 30 days and tell you what we found and did.

-   **European Economic Area and United Kingdom.** We do not offer Rationale to organizations established in the United Kingdom (see our [Terms](https://rationalehq.com/terms#eligibility)), but people there may use it as members of a customer's workspace. You also have the right to restrict processing and to receive your data in a portable format. You can complain to the Portuguese data protection authority, the Comissão Nacional de Proteção de Dados ([cnpd.pt](https://www.cnpd.pt)), to the authority where you live or work, or in the United Kingdom to the Information Commissioner's Office ([ico.org.uk](https://ico.org.uk)). We would appreciate the chance to fix the problem first.
-   **United States.** For workspace content we are the organization's service provider (processor) under our [US State Privacy Terms](https://rationalehq.com/terms#us-privacy): we pass your request to the workspace's owners and act on it as they instruct. We do not sell or share personal information, do not use it for targeted advertising, and use sensitive personal information (such as the tokens that connect your accounts) only to provide the service. Depending on your state, the law may give you rights to know, access, correct and delete your personal information; we honor these requests from anyone, and we will not treat you differently for making one. If we decline a request, you can appeal by replying to our answer; we decide on the appeal within 45 days.
-   **Canada.** We do not offer Rationale to organizations established in Quebec, but people in Canada, including Quebec, may use it as members of a customer's workspace. You can access and correct your personal information and withdraw consent where we rely on it, subject to legal limits. If you are not satisfied with our answer, you can complain to the Office of the Privacy Commissioner of Canada ([priv.gc.ca](https://www.priv.gc.ca)) or, in Quebec, to the Commission d'accès à l'information ([cai.gouv.qc.ca](https://www.cai.gouv.qc.ca)).

## 10\. Cookies and similar technologies

Our website, rationalehq.com, sets no cookies and stores nothing in your browser. The app, app.rationalehq.com, uses only what it needs to work, so it does not ask for cookie consent:

Name

What it does

How long

session\_id

Keeps you signed in (signed, not readable by scripts)

30 days

\_rationale\_session

Protects forms against forged requests, remembers where to return after signing in or connecting Jira or GitHub, and remembers the email address you typed to sign in or request access so it never goes in a web address (encrypted, not readable by scripts)

Until you close the browser

staff\_session\_id

Signs our staff in to the admin, on admin.rationalehq.com (staff only)

8 hours

rationale-theme

Remembers light or dark mode if you pick one (stored in your browser only, never sent to us)

Until you change it or clear your browser

Fonts and scripts are served by Rationale itself; no third party learns that you visited our website. Because we do not track you across sites, browser signals such as Do Not Track and Global Privacy Control do not change anything: we already do what they ask.

## 11\. Children

Rationale is for work and for people aged 18 or over. It is not directed to children, and we do not knowingly collect personal data from anyone under 18. If you believe a child has given us personal data, write to us and we will delete it.

## 12\. Changes to this policy

We publish every new version here with its date. If a change materially reduces your rights or lets us use data we already hold in a materially different way, we email the members of every workspace at least 30 days before it takes effect, unless the law or a security need requires it sooner. A change that describes a new feature or a new legal requirement applies when it is published, and new service providers are announced as our Data Processing Terms say. Earlier versions are available on request.

## 13\. Contact

Privacy: [privacy@rationalehq.com](mailto:privacy@rationalehq.com) · Support: [support@rationalehq.com](mailto:support@rationalehq.com) · Post: Inside My Tranquility, Lda., Estrada Comandante Camacho de Freitas, n.º 779, São Roque, 9020-154 Funchal, Madeira, Portugal.
