Privacy notice
Last updated: 1 October 2026
This notice explains what personal data RALPH collects, why, where it is kept, how long for, and what you can do about it. It covers RALPH’s app, the connections that let an AI assistant act for you, and RALPH’s website at ralphops.ai.
Who we are
RALPH is run by Agnelli Ltd (“RALPH”, “we”, “us”), a company registered in England and Wales under number 08128078, whose registered office is at 51 Keeling House, Claredale Street, London, E2 6PG.
You can reach us about anything in this notice at hey@ralphops.ai.
Two kinds of data, two controllers
RALPH is used by flight schools, flying clubs and other aviation organisations. What RALPH holds falls into two parts, and a different organisation is responsible for each.
- Your organisation’s records. Bookings, people, aircraft, flights, calendar feeds and the other records your organisation keeps in RALPH belong to that organisation. The organisation is the controller of the personal data in them, and RALPH processes it on the organisation’s instructions, as its processor, under the terms agreed with that organisation. If you have a question about those records, or want to use your rights over them, contact your organisation. We will help them answer you.
- Your sign-in. To let you sign in, and to know which organisations you belong to, RALPH keeps a record of you that sits outside any one organisation, because one person can belong to several. For this data, and for the data our website collects, RALPH is the controller. The rest of this notice is about that data.
Signing in with Google
You sign in to RALPH with your Google account, directly with Google; RALPH uses what Google sends only as described below. Google sends RALPH your Google account’s id, its email address and whether Google has verified it, your basic Google profile (such as your name, profile picture and language), and, for a Google Workspace account, its domain. RALPH keeps only:
- the id Google gives your account, which never changes;
- your email address, when Google confirms it belongs to you;
- your name.
RALPH doesn’t keep your profile picture, stores no password, and keeps no Google token once you are signed in.
We use this to sign you in, to recognise you each time you return, to show your name in RALPH, and to link you to the organisations that have given you access, including an invitation addressed to your email address. We use it for nothing else. We don’t sell it, use it for advertising, or use it to train AI models.
RALPH’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Some people signed in to RALPH before it had its own Google sign-in, through Neon Auth, a sign-in service run by Neon. Neon Auth holds its own record of those sign-ins until RALPH finishes moving off it.
Invitations. When an organisation invites you before you have signed in, RALPH keeps the email address it invited, and the organisation it invited you to; the organisation gave us that address. When we set up an organisation for you, we keep the name and email address of the person it is for in the same way. When you first sign in with that address, the invitation becomes your access. When an admin adds you through RALPH’s API with a retry key, RALPH keeps a copy of its reply (your email address and, if you have one, your account id) with the admin’s account, so a retried request isn’t recorded twice. That copy isn’t yet deleted automatically; it goes when the admin’s sign-in record is deleted.
You can’t use RALPH without signing in, so without this data we can’t give you access.
Lawful basis: our legitimate interest in giving you secure access to the organisations that use RALPH, and, where you have a contract with us yourself, performing that contract.
Your session
When you sign in to the app, your browser gets a session cookie for RALPH’s app host. It holds a random value that means nothing on its own, RALPH keeps only a hash of it, and your browser sends it only to RALPH’s own host.
With each session RALPH keeps:
- a label for the device, worked out from your browser’s user agent when you sign in, such as “Safari on iPhone” (the user agent itself is not kept);
- when the session started, and when it was last used.
A session ends after 7 days without use, or 30 days after you signed in, whichever comes first. You can see your sessions and end any of them, and signing out ends the session and tells your browser to clear what it holds for RALPH. RALPH deletes a session’s record as soon as it is ended early, and an expired one within a day.
While you sign in, RALPH also sets a short-lived cookie and keeps a matching record, so that Google’s answer can be matched to the request that started it. Both expire after 10 minutes, and the record is deleted within a day.
RALPH doesn’t store your IP address. The app uses no analytics and no third-party scripts.
Lawful basis: our legitimate interest in keeping your account secure, and these cookies are strictly necessary for the service you asked for.
Your preferences. The app keeps a few preferences on your device, in your browser’s local storage, and signing out tells your browser to clear them:
- your theme, whether the sidebar is open and whether single-key shortcuts are on, once you change them;
- the organisation you last opened, so it can take you back there;
- for each organisation, the corner style you picked if you are one of its admins;
- for each organisation, on a phone-sized screen, the resource you last viewed on its Schedule, so it opens there again.
Lawful basis: our legitimate interest in remembering your choices.
Unsent drafts. If your session ends while you are part-way through some forms, such as a booking decision, an aircraft or your organisation’s settings, the app keeps what you had typed on your device, in your browser’s IndexedDB storage, so you can pick up where you left off after signing in again. Each draft records your account, the page and a one-line summary of it, and holds the organisation’s records you were editing. A draft is deleted once you send or discard it, when it is 24 hours old (the next time the app is open), or when you sign out, which tells your browser to clear it.
Lawful basis: our legitimate interest in not losing your work; for your organisation’s records in a draft, RALPH acts for your organisation.
Connecting an AI assistant or an agent
You can let an AI assistant, such as Claude or ChatGPT, or a script, act for you in RALPH.
- Connected apps. When you approve a connection, RALPH records the grant: which app, for which of your organisations, with which permissions, and when. A grant ends after 90 days at most, or sooner: after 30 days without use, when your access to that organisation ends, or if RALPH detects that its credentials were copied. RALPH doesn’t yet let you end a connection yourself. On RALPH’s side, the tokens behind it are stored only as hashes, or not at all.
- RALPH’s command-line tool. If you sign in with “ralph login”, the tool keeps its tokens on your computer, in a file in your ralph configuration folder, private to your user account (the tool locks the file down on macOS and Linux; on Windows it relies on your profile folder’s permissions). They stay there until you run “ralph logout” for that RALPH address, and stop working when the connection ends. Logging out removes them from your computer, but doesn’t end the connection.
- Access keys. An access key for an agent or script is stored only as a hash, with its name, its permissions, who created it, whom it acts for, when it expires (a year ahead unless set otherwise) and when it was last used. A staff member or admin of your organisation can also create a key that acts for you, within your permissions; its actions are recorded as done for you by that key, and the key records who created it.
While you approve a connection, RALPH’s API sets two short-lived cookies and keeps a record of the request: which app, for which organisation if the app names one, with which permissions, and, once you have signed in, your account. The cookies and the record expire after 10 minutes at most, whether or not you approve, and the record is deleted within a day. When you approve, RALPH gives the app a one-time code, valid for a minute and deleted within a day, which it exchanges for the grant.
RALPH’s own servers call no AI model. The assistant you connect works under your own account with its provider, whose terms and privacy notice cover what it does.
Lawful basis: our legitimate interest in providing the connections you, or your organisation’s staff or admins, ask for, and keeping them secure.
If you set up an organisation
When an organisation is set up for you, RALPH keeps a billing account for it and records:
- that you can manage the organisation’s subscription, and delete or restore the organisation;
- the subscription’s plan, status and renewal date;
- the setup itself: the organisation’s name, its short name in RALPH’s addresses, its home region, and who set it up, or who it was set up for;
- once RALPH takes payments, the payment provider’s references for the billing account, the subscription and the checkout.
We use these to know who may manage the organisation and its subscription, and to keep a history of it. We keep them while the organisation’s billing account exists, and afterwards for as long as we need them to meet our legal, accounting and tax obligations or to settle a dispute.
Lawful basis: our legitimate interest in knowing who manages each organisation and its subscription, and, where you contract with us yourself, performing that contract.
A record of changes to access
RALPH keeps a security record of changes to its shared data, such as an access key being created or revoked, or a person’s access to an organisation being removed. It records who did what, and when, by internal id, and not the details that changed. RALPH’s service can only add to it, never edit or delete it, so it is kept for as long as RALPH runs. Once your sign-in record is deleted, the ids that belonged to it no longer link to you. The record can also hold ids that lead to you through an organisation’s records: your person record there, your access to that organisation, or an access key that acts for you. Those ids link to you for as long as that organisation’s records still identify you.
Lawful basis: our legitimate interest in keeping RALPH secure and being able to show who did what.
RALPH’s logs
RALPH’s servers write operational logs, which Fly holds for us. They can include the internal ids of your sign-in record and your organisation, and your organisation’s short name, but not your IP address. They are kept only for as long as Fly keeps its logs; we don’t copy them anywhere else.
When RALPH’s staff act on an organisation or an account, such as setting one up, re-sending a founder’s invitation, deleting or restoring an organisation, linking or disabling a sign-in, or ending sessions, the command they run records who acted and the reason they gave, which may mention you, and, where the command names you, your email address. The command that lists sign-ins not yet moved to RALPH’s own Google sign-in also shows each one’s internal id, status, number of memberships, email address, name and Neon Auth account id. That record stays in the session of the staff member who ran the command, and we don’t copy it anywhere else.
Lawful basis: our legitimate interest in running RALPH securely and being able to account for what our staff do.
Our website
Our website at ralphops.ai collects very little.
- Analytics, only if you accept them. The site uses PostHog’s EU Cloud to count visits. Nothing loads unless you choose Accept on the site’s banner; Reject, or no answer, loads nothing. If you accept, PostHog sets a cookie and a matching entry in your browser’s local storage holding a random id for your browser, and receives the pages you visit and whether you click a link to request early access (including our email address on the Contact page) or to sign in, along with details your browser sends, such as its type and your IP address. It records no session replays, heatmaps or other clicks. We keep this data only for as long as we need it to understand how the site is used. Lawful basis: your consent.
- Your choice. The site remembers whether you accepted or rejected in your browser’s local storage, not in a cookie, so it doesn’t ask you again. You can change your mind at any time with “Cookie settings” at the foot of any page. Choosing Reject later stops PostHog, but doesn’t delete what it already stored in your browser; clearing your cookies and site data for the site removes it.
- Early access. “Request early access” opens your own email app with a message to us. The site itself keeps nothing. We use what you send to reply, and, if you ask us to, to keep you updated about early access. We keep it while we’re in touch with you about early access, and delete it when you ask us to. Lawful basis: our legitimate interest in answering you, and your consent for updates.
- Server logs. The server that hosts the site logs each request it answers: your IP address, the page, the time, the page you came from and your browser’s user agent. They are kept only for as long as Fly keeps its logs; we don’t copy them anywhere else. Lawful basis: our legitimate interest in running the site securely.
The site loads its fonts and everything else from itself. Without your consent, it makes no request to anyone else.
Where your data is kept, and who helps us
Each organisation’s records are kept in the home region chosen when it is set up, and can’t be moved from within RALPH. Today every organisation’s records, RALPH’s servers and RALPH’s shared data are in London, UK.
We use these services to run RALPH:
- Fly.io runs RALPH’s servers and the website, in London, UK.
- Neon hosts RALPH’s databases, in London, UK, including Neon Auth for the sign-ins described above.
- Google provides sign-in. You sign in with Google directly, and Google is the controller of your Google account, under Google’s privacy policy.
- Google Workspace holds the email you send to hey@ralphops.ai, such as early-access requests and requests about your rights. We’ve set Google Workspace to store that mail in the EU: each message’s subject, body, attachments, senders and recipients. Google may still process that mail, and store other data about it such as logs, outside the EU, under Google’s data processing terms and the transfer safeguards in them.
- PostHog provides the website’s analytics, in its EU Cloud, only if you accept them.
- Lemon Squeezy will be the merchant of record when RALPH starts taking payments, which it doesn’t yet. It will then handle checkout, payment and tax for an organisation’s subscription as its own controller, and receive the payer’s email address, the organisation’s name, short name and home region, and an internal reference that links the payment to the payer’s RALPH account. RALPH keeps Lemon Squeezy’s references for the customer and the subscription. We’ll update this notice before any other payment provider receives your data.
Fly.io, Neon and Lemon Squeezy are US companies. Where they handle your data outside the UK, they do so under the transfer safeguards UK and EU data protection law require, set out in our agreements with them.
Copies and backups
Before each release, RALPH tries to take a snapshot of its shared database so a failed release can be undone; each snapshot expires after 7 days. To test a change before it goes live, RALPH also runs it against a short-lived copy of its databases, deleted when the change is finished or after 7 days without use. These copies run only in RALPH’s own test environments, on the same Fly and Neon services, and only RALPH’s staff can sign in to them.
How long we keep it
- Your sign-in record: until you ask us to delete it. When an organisation is deleted, the sign-in record of anyone whose only access was to it is deleted too, unless they still have access elsewhere or a billing relationship with us.
- Details of the person an organisation is set up for: until the organisation is set up for them.
- Invitations, and access keys: until the organisation is deleted, including, once withdrawn or revoked, the record of when that happened.
- Sessions: up to 30 days, as described above, then deleted within a day.
- Preferences on your device: until you sign out or clear your browser’s data for RALPH.
- Unsent drafts on your device: 24 hours, deleted the next time the app is open after that, or when you sign out.
- Copies of replies to adding you: until the sign-in record of the person who added you is deleted.
- Connected apps: deleted within a day of the grant expiring, going unused or being ended. When a connection stops working because your access to the organisation ended, its record is kept until the app’s last credential expires, at most 30 days, then deleted within a day.
- Billing and setup records: while the billing account exists, then as long as our legal, accounting and tax obligations or a dispute require.
- Security record of changes: for as long as RALPH runs, as described above.
- RALPH’s logs: as long as Fly keeps its logs; records of staff commands stay only in the staff member’s session.
- Website data: as stated in “Our website”.
Your rights
Under UK and EU data protection law you have the right to:
- ask for a copy of the personal data we hold about you;
- have it corrected if it’s wrong;
- have it deleted;
- restrict or object to how we use it, including anything we do on the basis of our legitimate interests;
- receive it in a portable format;
- withdraw your consent at any time, where we rely on it, without affecting what we did before.
To use any of these rights, email hey@ralphops.ai. We will reply within one month. For your organisation’s records, contact your organisation, and we will help them.
You can also complain to the UK Information Commissioner’s Office at ico.org.uk, or to the data protection authority where you live or work in the EU. We’d appreciate the chance to put things right first.
Changes to this notice
When we change this notice, we’ll update the date at the top. If a change affects how we use data we already hold, we’ll tell you before it takes effect.