Privacy notice
What stays on your Mac, what reaches a provider, and the choices you have.
Effective date: October 9, 2026
Who operates the service
SaaSpero, LLC operates Rayito and is responsible for the account, subscription and support data described here. Contact support@rayito.app for privacy questions or requests. 1111B S Governors Ave STE 26326, Dover, DE 19904, United States
On your Mac
Conversation history, saved screen context and annotation replays are stored locally. Default dictation and speech synthesis run on your Mac; voice packages may need an initial download. Rayito captures screen context when you ask for help or run an active task, rather than continuously monitoring in the background. An app-control session inspects the selected window as it works.
Your selected AI and voice services
Your questions and selected screen context go through the AI connection you choose, such as Codex or Claude Code. The provider processes them under its own policies and your account settings. Conversation context may accompany a follow-up question. If you enable external voice synthesis with your own ElevenLabs key, the text to be spoken also goes to that service. Do not include information you do not want those providers to process. Changing or deleting local history does not delete data held by your provider.
Accounts and subscriptions
The account service uses your email address, verified account identifier, authentication and session information, and trial start and expiry records. SaaSpero uses shared Supabase sign-in infrastructure for Rayito and other products, including ScreenVeil. A shared sign-in identity does not by itself grant Rayito access: Rayito registers and checks its own product membership and sessions.
Access checks include a random installation identifier and a one-use request challenge. The installation identifier is not a hardware fingerprint. The billing service handles account and access state; it does not receive screen captures, conversation text or microphone recordings.
Sign-in email and security
Rayito sends an eight-digit email code through Postmark as Rayito <support@rayito.app>, with replies directed to the same address. The Rayito verification challenge expires after 10 minutes. Its receipt is stored as a hash, not in its original form. Rayito does not log codes, original receipts, credentials or account tokens.
Requesting a new code can replace another pending code for the same email address in a product using the shared sign-in infrastructure. This does not sign you out of existing sessions or change your password. Finish one sign-in at a time; if a code no longer works, request a new one in the product you want to use.
Abuse prevention uses keyed HMAC values derived from email and network addresses for request limits, rather than storing those raw values in Rayito’s quota records. Postmark still receives the email address and message needed for delivery, and infrastructure providers process network metadata under their own policies.
Service providers
Supabase supplies shared authentication and Rayito’s billing-service infrastructure. Postmark delivers sign-in email. RevenueCat tracks purchases and subscription access. Stripe processes payments. Hosted checkout collects information needed for payment, invoices and applicable taxes. Card details are entered in hosted checkout, not stored by the native app. Service providers also process ordinary network and request metadata needed to deliver and secure their services.
Purelymail hosts the support@rayito.app mailbox. If you contact us, it receives your address, message and any attachments you choose to send. Support messages are separate from the app’s conversation history; avoid sending screen captures containing sensitive material unless they are needed for your request.
Why we use this information
We use account and purchase information to provide your account, trial, subscription and support. We use authentication, session and request-limit information to protect accounts, prevent abuse and verify access. Payment records also support accounting, tax and dispute handling. We do not send screens, conversations or voice recordings to our account or billing service for these purposes.
Where a legal basis is required, providing the service relies on performing our agreement with you; necessary security and abuse prevention rely on our legitimate interests; and required financial recordkeeping relies on legal obligations. When consent is required for an optional use, that use depends on your consent.
The website and updates
Vercel hosts the public website. The website does not use a sign-up form, analytics SDK, tracking cookies or third-party font/script embeds. Hosting may process the network metadata needed to deliver the page. Checking for app updates and downloading releases contacts GitHub, which hosts Rayito’s update feed and release files. Update requests expose ordinary connection and request metadata to that host; Sparkle system profiling is disabled. Checkout may return to this website with a provider identifier in the URL; the return page does not use it to identify an account or grant access and removes URL parameters in supported browsers. The initial request still reaches the hosting service.
Your controls
You can stop tasks, change macOS permissions, change providers and delete saved conversations on your Mac. Rayito sign-out revokes the selected Rayito session, or all Rayito sessions if you choose that scope, and clears this app’s stored credentials and access cache. It does not sign you out of other SaaSpero products or delete the shared sign-in identity. An access authorization already held by another offline installation may remain usable until its expiry, for at most 72 hours and no longer than the underlying paid or trial period.
Before deleting your Rayito account, cancel any recurring subscription and close any open checkout. Confirm deletion with a fresh email code for the same account. Deletion marks your Rayito membership as deleted, revokes its sessions and removes pending verification challenges and operational quota records. It retains the stable account identifier (UUID), membership and revocation timestamps, and original trial record to preserve purchase and trial continuity. The shared sign-in identity, other products’ accounts, sessions and data, and RevenueCat customer and receipt records are not deleted.
You must explicitly choose to rejoin and verify a new code to reactivate Rayito. Rejoining with the same original account identifier retains the original trial dates, gives no new trial and can restore any paid time that is still valid. If another product or an administrator deletes the shared identity and a new identity is created, continuity is not automatic and may require support review.
Deleting your Rayito account does not delete conversations saved on your Mac, refund payments or cancel charges. Local History is a separate choice. Cancelling renewal and deleting account data are separate operations. To ask about account data or request review, contact support@rayito.app. We may need to verify your identity before acting.
Retention
Rayito verification receipts expire after 10 minutes. Expired receipts and request-limit records are cleaned up on each request and by a scheduled job every 15 minutes. During normal scheduled operation, receipt retention is bounded by expiry plus 15 minutes, and quota-record retention is about 25 hours plus 15 minutes. Service interruptions can delay scheduled cleanup. The job’s own run history older than seven days is also pruned; this does not define retention for other infrastructure logs or backups.
Postmark’s default retention for message content, delivery events and metadata is 45 days. Rayito’s sending account currently uses this 45-day setting. Code expiry and deletion of Rayito’s verification receipt do not remove the delivered email or immediately erase Postmark’s records. Aggregated statistics and suppression records follow Postmark’s policies.
Account and session records are kept to operate and protect your account. Deleting Rayito membership retains its stable UUID, membership and revocation timestamps and original trial ledger to prevent an old session from regaining access, preserve purchases and avoid repeatedly granting a first-account trial. These continuity records currently have no automatic deletion date. A request to remove them needs review of those purposes and any records that must be retained; product deletion is not complete erasure of every record.
Rayito account deletion does not delete the shared Supabase sign-in identity or other SaaSpero products’ records. Requests about that identity can be sent to support. Infrastructure logs and backup copies are retained separately under the relevant providers’ policies and service settings. Removing a live account record does not immediately erase those copies. Their retention is not defined by Rayito’s verification-receipt cleanup schedule.
Support correspondence and attachments remain in the support mailbox until manually removed. We keep them to respond to requests, retain relevant support history and handle disputes; there is currently no fixed automatic deletion period. You can ask us to review or remove a support record by emailing support@rayito.app. Any remaining need to retain it is considered as part of that request.
RevenueCat and Stripe retain purchase and financial records under their own policies and applicable obligations. Local conversations remain on your Mac until you remove them; provider-held AI and voice data follows the relevant provider’s policies and your account settings.
Your legal rights and changes
Depending on where you live, you may have rights to access, correct, delete or obtain a copy of your personal data, restrict or object to processing, and complain to a data-protection authority. Where we rely on consent, you may withdraw it without changing the lawfulness of earlier processing. To make a request, email support@rayito.app. We verify identity as needed and respond under the rules that apply to the request. You can also ask us to review an account-access decision.
Our providers may process data outside your country, where data-protection rules can differ. Processing locations and retention depend on the service and its configuration. Contact us for information about the providers handling your account data and the safeguards relevant to that processing. The AI and voice providers you choose separately handle their processing under your agreement with them.
Material changes to this notice will be reflected in its effective date and communicated where applicable law requires.