Privacy Policy

Last updated: July 27, 2026

This policy explains what data Raylight ("Raylight", "we", "us") collects when you use raylight.app and related services, how we use it, and the choices you have. The short version: we collect what we need to run the product, we run our own analytics instead of ad trackers, and we never sell your data.

Information we collect

Account information

When you sign up we collect your email address and, if you sign in with Google, the name and email associated with your Google account. Authentication is handled by Supabase. We do not receive or store your Google password.

Your content

Projects, uploaded images, video, and audio, exported videos, templates you publish, and messages you send to the built-in assistant are stored so we can provide the service. If you publish a share link, embed, or community template, that content becomes publicly accessible to anyone with the link.

Payment information

Payments are processed by Stripe. We never see or store your full card number. We store your subscription status and Stripe customer reference. If you enroll in the creator payout program, Stripe collects your payout and identity details through Stripe Connect onboarding, and we store your payout account status, legal name, country, and tax form status to comply with tax reporting obligations.

Usage data

We run our own first-party analytics. When you use the app we record product events (for example: project created, export completed) along with the page path, referrer, a randomly generated device identifier, your IP address, and browser user agent. Raw event records, including IP address and user agent, are deleted after 30 days; only aggregate counts are kept beyond that. On the marketing site we use Plausible, a cookieless, privacy-focused analytics tool, and Vercel Speed Insights for performance measurement.

Share page viewing

When someone watches a shared video or embed, we record watch time, a random viewer identifier, the referring page, and a derived country and device type (desktop, mobile, or tablet) so creators can see how their work performs. We do not store viewers' IP addresses or raw browser details with these records.

Fraud prevention

To protect the referral and payout program from abuse, we keep an append-only record of referral signups that includes IP address and browser user agent. These records are retained even after account deletion because they exist to detect and dispute fraud.

Support and feedback

If you contact us or submit in-app feedback, we keep your message and any screenshot you attach.

How we use your data

  • Providing, maintaining, and improving the service
  • Rendering your exports, which may run on cloud GPU infrastructure
  • Processing payments, subscriptions, and creator payouts
  • Understanding how features are used so we can improve them
  • Detecting and preventing fraud and abuse
  • Sending transactional email and occasional product emails from the founder, each of which includes a one-click opt-out link
  • Monitoring errors and performance

AI features

When you use the built-in assistant, your messages and relevant project context are sent to Anthropic to generate responses. We store your conversations so you can continue them later. We do not use your content to train AI models.

Who we share data with

We share data only with service providers that help us run Raylight, and only what they need to do their job:

  • Supabase — database, authentication, and file storage
  • Stripe — payments, subscriptions, and creator payouts
  • Vercel, Railway, and Cloudflare — hosting and content delivery
  • RunPod and Google Cloud — cloud video rendering
  • Resend — sending email
  • Sentry — error monitoring
  • Anthropic — powering the AI assistant
  • Plausible — cookieless marketing site analytics

We do not sell your personal data, and we do not share it with advertisers or data brokers. We may disclose data if required by law or to protect our rights, users, or the public.

Cookies and local storage

We do not use advertising or cross-site tracking cookies. We use browser local storage for things like your session, editor preferences, theme, and the random analytics identifiers described above. Signing out or clearing your browser storage removes them.

Data retention and deletion

We keep your data for as long as your account is active. Raw analytics events are deleted after 30 days. To delete your account and associated content, email us at cyrus@raylight.app. Some records survive deletion where we have a legitimate need: aggregate statistics that no longer identify you, fraud-prevention records, and financial records we are legally required to keep.

Your rights

Depending on where you live, you may have the right to access, correct, export, or delete your personal data, and to object to or restrict certain processing. To exercise any of these rights, email cyrus@raylight.app and we will respond within a reasonable timeframe.

Children

Raylight is not directed at children under 13, and we do not knowingly collect data from them. If you believe a child has created an account, contact us and we will delete it.

Changes to this policy

We may update this policy as the product evolves. If we make material changes, we will update the date at the top of this page and, for significant changes, notify you by email or in the app.

Contact

Questions about privacy? Email cyrus@raylight.app.