This Privacy Policy explains how Rhycon, Corp., a Delaware corporation ("Rhycon", "we", "our", or "us"), collects, uses, discloses, and retains personal information through app.rhycon.ai, our websites, and the related sales-outreach, appointment-setting, and account services (collectively, the "Service").
1. Scope and our role
Rhycon is responsible for personal information used to administer customer accounts, billing, our websites, support, security, and our own business operations. When a customer uses the Service to upload, source, enrich, sync, or communicate with prospects and other business contacts, the customer ordinarily decides why and how that information is used. For that customer-controlled information, Rhycon acts as a processor or service provider on the customer's instructions, as described in our Data Processing Addendum.
If you received a message sent through Rhycon for one of our customers, the sender identified in the message is the primary contact for questions about that outreach. Rhycon also processes limited recipient information for delivery, security, abuse prevention, and suppression of future messages.
2. Information we collect
Customer, account, and billing information
- name, business email, phone number, company, role, workspace membership, login and authentication records;
- billing identifiers, subscription, plan, invoice, and payment status from Stripe; Rhycon does not store full payment-card numbers;
- business profile, offer, product, target-market, brand-voice, signature, scheduling, campaign, and notification settings;
- support requests, feedback, consent records, and communications with us; and
- device, browser, IP address, session, feature-use, diagnostic, security, and audit information.
Signature details may be retained as sender-identity settings, but under the current generated-text-only policy, stored signatures are not appended to cold-email bodies.
Customer Content and business-contact information
Customers may provide or direct us to collect business-contact information, including names, professional profiles, employers, roles, business contact details, locations, company information, public professional activity, campaign history, suppression status, and notes. Sources may include customer uploads and CRM systems, connected accounts, public websites and professional profiles, search and business-data providers, email verification providers, recipients themselves, and inferences produced from those sources.
Customer Content may also include campaign instructions, prospect lists, emails and LinkedIn messages, replies, meeting and RSVP information, CRM records, documents, presentations, images, and other materials submitted for research, personalization, analysis, or account configuration. Please do not submit sensitive personal information unless it is necessary, lawful, and expressly supported by the Service.
Uploaded sales materials remain inactive unless the customer completes the separate sharing confirmation. After activation, we store the selected file privately, perform safety checks, and may retrieve and transmit it through the customer's connected email account when a recipient asks for more information and the reply system determines, from the conversation and the customer's description of the file, that it is relevant. We do not use the file in cold outreach. We record activation, scan, and delivery metadata for security, support, and accountability.
Connected accounts
- Email: authorized sender accounts, addresses, connection state, sent-message metadata, delivery events, message content, and replies needed to run and monitor configured outreach.
- Google or Microsoft calendar: connected account identity, availability, relevant event details, and meeting data needed to avoid conflicts and create, update, or cancel meetings.
- LinkedIn: connected-account identity and status, professional profile and connection information, invitations, Rhycon-initiated message history, and related replies needed for the mode the customer enables. Credential and challenge entry is handled by our hosted connection provider; Rhycon does not request or store the customer's LinkedIn password.
- HubSpot: authorized CRM account identifiers, contacts, companies, deals, lists, communication preferences, and timeline activity needed for the sync or action the customer requests.
Google sign-in uses basic OpenID Connect account scopes to identify the user and does not by itself grant access to Google Calendar. Customers separately authorize each connected-account integration and can disconnect it.
3. How and why we use information
Depending on the context, we use information to:
- authenticate users, administer workspaces, provide support, process subscriptions, and communicate about the Service;
- discover, verify, enrich, rank, and segment professionally relevant business contacts at a customer's direction;
- generate and operate configured email and LinkedIn outreach, classify and draft replies, apply suppression choices, and measure campaign performance;
- sync customer-selected CRM records and preferences;
- check calendar availability, schedule meetings, manage invitations and reminders, and send opted-in operational notifications;
- provision and administer customer-requested domains, DNS settings, mailboxes, sender profiles, warm-up, and deliverability monitoring;
- analyze customer-provided documents and business context to personalize the Service;
- secure the Service, prevent fraud and abuse, investigate incidents, enforce our agreements, and comply with law; and
- understand aggregate usage and improve the reliability and functionality of the Service.
Where European or UK data-protection law applies and Rhycon determines the purpose of processing, our legal bases may include performance of a contract, compliance with law, consent where requested, and our legitimate interests in operating, securing, supporting, and improving a business service. A customer is responsible for identifying and documenting the lawful basis for its own prospecting and outreach. Individuals may object to direct marketing at any time.
4. AI-assisted and automated processing
The Service uses AI and rules-based systems to research professional context, rank potential business fit, generate or personalize content, classify replies, propose or send follow-ups in an enabled autonomous mode, and assist with scheduling. These systems can be wrong. Customers control their campaign criteria, connected accounts, approval or autonomy mode, and may stop future activity. Rhycon does not permit the Service to be used for employment, credit, housing, insurance, health, or other high-impact eligibility decisions.
We send limited prompts and relevant Customer Content to configured AI and research providers to return the requested result. Rhycon does not use Customer Content to train a general-purpose Rhycon model. Provider handling is governed by the applicable business and API terms in place for the Service.
5. Google API data
Rhycon's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. We use Google Calendar data only to provide or improve the customer-facing calendar and scheduling features the user authorizes. We do not use Google user data for advertising, sell it, use it to determine creditworthiness, or permit humans to read it except with the user's affirmative agreement for support or security, when required by law, or where the data has been aggregated and anonymized for internal operations. Access may be revoked by disconnecting Google Calendar or through the user's Google account controls.
6. SMS communications
A workspace owner or invited notification recipient may separately opt in to operational text alerts, including alerts about positive prospect replies. Consent is specific to the phone number entered and is not a condition of purchasing the Service. Message frequency varies; message and data rates may apply. Reply STOP to unsubscribe or HELP for help. We provide phone and messaging information to Twilio to verify the number and deliver these alerts, but do not share mobile opt-in information for third-party marketing.
7. When we disclose information
We may disclose information:
- to vendors and subprocessors that host, secure, support, analyze, or provide a requested part of the Service;
- to connected services and recipients at the customer's direction;
- to a customer that controls the relevant workspace or campaign;
- to professional advisers, auditors, insurers, and financing or transaction counterparties subject to appropriate protections;
- when reasonably necessary to comply with law, legal process, or a valid government request, or to protect rights, safety, security, and the integrity of the Service; and
- with consent or as otherwise disclosed when information is collected.
We do not sell personal information for money, and we do not share personal information for cross-context behavioral advertising as those terms are defined by California law. We have not done so in the preceding 12 months. We also do not use third-party advertising cookies on the Service.
8. Service providers and subprocessors
The providers used for a particular customer depend on the features enabled. Current provider categories and examples include:
- Hosting, database, authentication, and storage: Vercel and Supabase;
- Payments: Stripe;
- Connected email and professional-network accounts: Unipile, Google, Microsoft, and LinkedIn;
- CRM: HubSpot;
- AI, search, research, and enrichment: Anthropic, DeepSeek, Perplexity, Z.AI where configured, Serper, Hunter, and Reoon;
- Transactional email and messaging: Resend, Twilio, and Telegram for limited operational alerts;
- Domain, mailbox, DNS, warm-up, and deliverability operations: PrimeForge, WarmForge, Infraforge, and Entri; and
- Customer-selected mailbox, calendar, domain, and DNS providers where needed to perform the customer's instructions.
These providers receive only the information reasonably needed for their function. Provider availability may change as the Service evolves; material changes will be reflected in this notice or communicated as required.
9. Retention
We retain personal information for the period reasonably necessary to provide the Service, maintain security and suppression records, resolve disputes, enforce agreements, and satisfy legal, tax, and accounting duties. Retention depends on the data and feature: connected-account credentials and tokens are generally retained while the integration remains connected; account and campaign data is generally retained while the workspace is active and for a limited period after closure; billing and compliance records may be kept longer where required; and backups are deleted on their ordinary lifecycle. A customer may request account deletion, subject to these limited exceptions. The customer controls retention of information it exports to its own systems.
10. Security
We use technical and organizational safeguards designed to protect personal information, including encrypted network transport, authentication and workspace permissions, database access controls, operational logging, and service-provider controls. No Internet service is completely secure, and we cannot guarantee absolute security. Customers are responsible for protecting their credentials, limiting workspace access, and using the Service in accordance with our security instructions.
11. International processing
Rhycon is based in the United States. Our primary database is hosted in the European Union, and providers may process information in the United States and other countries where they operate. Those countries may have different data-protection laws. Where a legally recognized transfer safeguard is required, the applicable customer agreement, provider terms, or transfer mechanism governs that transfer.
12. Privacy rights and choices
Depending on location and subject to legal exceptions, an individual may have rights to know or access, correct, delete, restrict or object to processing, obtain portability, withdraw consent, opt out of direct marketing, or appeal a decision about a request. California residents may also have the right to know the categories and specific pieces collected, correct or delete information, and receive equal service without unlawful discrimination for exercising a privacy right. Because we do not sell personal information or share it for cross-context behavioral advertising, we do not offer an opt-out for those practices.
Account holders may update certain information or disconnect integrations in the Service. To make another request, email sales@rhycon.ai. We may need to verify identity and authority. If Rhycon processes information solely for a customer, we may direct the request to that customer or assist it in responding. Authorized agents may submit requests where permitted by law.
Individuals in the EEA or United Kingdom may complain to their local data-protection supervisory authority. They may also contact us first so we can try to resolve the concern.
Additional US state disclosures
During the preceding 12 months, the categories of personal information described in this policy may include identifiers and contact information; customer and commercial records; Internet, device, and Service activity; professional and employment-related information; message, calendar, image, and document content; approximate location derived from an IP address; and inferences about professional relevance or campaign activity. We use these categories for the purposes in Section 3 and may disclose them to the provider categories in Section 8, connected services and recipients at Customer direction, and the other parties described in Section 7. We do not intentionally collect sensitive personal information for the purpose of inferring characteristics about an individual.
13. Notice to business contacts and outreach recipients
This section is for a person whose professional information is processed through the Service but who is not a Rhycon account holder. Rhycon may process the categories described under "Customer Content and business-contact information," such as name, work email, business phone, job title, employer, professional profile URL, public professional context, communication history, meeting information, and campaign or suppression status. That information may come from the Rhycon customer, the person or their employer, public websites and professional profiles, connected CRM or communication accounts, and business-data, search, enrichment, or verification providers.
We process this information on the customer's instructions to research professional relevance, prepare or send business communications, manage replies and meetings, synchronize CRM records, measure campaign activity, prevent duplicate or unwanted contact, and protect the Service. The customer that selected the person or sent the message is ordinarily the Controller and is responsible for its legal basis, required notice, and response to privacy requests. Rhycon is ordinarily its Processor. The providers, international processing, retention approach, and available rights are described in Sections 8 through 12.
A recipient may opt out using the method in the message or by contacting the identified sender. If the sender cannot be identified or reached, email sales@rhycon.ai and include the receiving address and sender information so we can route the request and apply technical suppression where appropriate. Publishing this section does not replace a customer's obligation to provide a direct notice at the time required by applicable law.
14. Cookies and local storage
We use cookies and similar local technologies that are necessary for authentication, security, session continuity, onboarding progress, workspace selection, and preferences. We do not use third-party advertising cookies on the Service. Our Cookie & Local Storage Notice identifies the technologies currently used and their ordinary duration.
15. Children
The Service is for business users aged 18 or older and is not directed to children. If we learn that we collected a child's personal information through the Service contrary to this policy, we will take appropriate steps to delete it.
16. Changes to this policy
We may update this policy as the Service or law changes. We will post the revised policy and update the date above. We will provide additional notice of a material change where required.
17. Contact
Privacy questions and requests may be sent to:
Rhycon, Corp.1111B Governors Ave #87247
Dover, DE 19904, United States
sales@rhycon.ai