Privacy Policy
Last updated: September 8, 2026 · Draft for beta review — final version pending legal review.
1. Who we are
Outrayo ("we", "us") is operated by Ravinaro LLC-FZ. This policy covers the Outrayo platform at app.outrayo.ravinaro.com and the marketing site at outrayo.ravinaro.com.
2. What we process
- Account data: your name, email, password (hashed), workspace details.
- Connected mailboxes: OAuth tokens for Gmail/Microsoft accounts you explicitly connect, used only to send messages you approve and read replies to those messages.
- Lead data: publicly available business information (company name, website content, published business contact emails) discovered from the open web at your direction, plus your communications with those leads.
3. Roles: controller vs processor
For your own account data, we are the controller. For lead data you discover and process through Outrayo, you are the controller and we act as processor: you choose who to contact, determine the lawful basis (our campaign tools require a jurisdiction attestation), and we process on your documented instructions.
4. How we use data
- Operating the service (discovery, drafting, sending, tracking, attribution).
- Protecting the platform and email ecosystem from abuse (rate limits, content screening, suppression lists).
- Billing and service communication. We do not sell data, and we do not email your leads for our own marketing.
5. Subprocessors
We use third parties to operate the platform: Cloudflare (hosting, databases), Stripe (payments), the LLM/search/scraping/verification providers you or we configure (OpenAI/Anthropic or equivalent, Serper, Exa, Firecrawl, email verifiers), and Google/Microsoft APIs for mailbox access. The current list is available on request.
6. Your rights (and your leads' rights)
EU/UK users have GDPR rights including access, rectification, erasure, and portability. Outrayo provides built-in data-subject-request tooling so you (as controller) can fulfil requests relating to lead data — erasure requests propagate to suppression lists instantly. Contact privacy@ravinaro.com for anything about your own data.
7. Security & retention
OAuth tokens and secrets are encrypted at rest (AES-GCM). Data is stored in Cloudflare D1 with daily backups (30-day point-in-time recovery). EU-tenant data can be pinned to EU-resident storage. We delete account data within 30 days of verified account deletion.
8. Contact
Privacy questions: privacy@ravinaro.com · Ravinaro LLC-FZ.