Terms, privacy & usage policy
Last updated 2026-08-14 · Early access: see §6 before you assume anything here is permanent.
The short version
- Your data is yours. We store what you put in KV and mailbox tools so we can serve it back to you; we don't read it for any other purpose, and we never sell it.
- An owner key is a password. Anyone holding it can act as your account. Treat it that way.
- You can delete your data or your account at any time; nothing is kept "just in case" once you ask for it gone.
- This is early access. Features, limits, and this policy can change; we won't do it quietly (§6).
- Don't put anything through raccha.ai you wouldn't be comfortable storing on a server you don't personally control.
1. Terms of service
The agreement between you and raccha.ai for using the service.
raccha.ai is an MCP-first toolbox: key-value storage, mailbox ingestion, and utility tools reachable over the Model Context Protocol or plain HTTP. By requesting an owner key or calling any endpoint, you agree to these terms.
The service is provided as-is, in active early-access development. We aim for reliability but make no uptime guarantee at this stage: see §6 for what "early access" means in practice.
You're responsible for what you store and for what any key you generate or share is used to do. We're responsible for keeping the boundaries between accounts real: one account's key should never reach another account's data, and if it ever does, that's a bug we treat as urgent, not a feature.
2. Accounts & keys
How sign-in and access actually work.
Sign-in uses a magic link tied to your email: no password to leak, no password database to breach. Whoever clicks a valid, unexpired link is treated as that email's owner.
An owner key is full access to your account, generated once you verify. A shared key is anything you deliberately hand to someone else, scoped down on purpose, never a copy of the owner key. Both are bearer credentials: whoever holds one can use it. Store them like you'd store any other credential, and revoke a shared key the moment it's no longer needed.
We deliberately return identical rejection responses for "wrong key" and "no key": this is a security property (no enumeration of valid accounts), not a bug if you notice it in the API.
3. Privacy
What we collect, why, and who can see it.
We collect: your email (for sign-in), the data you explicitly store via KV or mailbox tools, and basic usage stats (call counts, timestamps) needed to run rate limiting and show you your own dashboard.
We do not sell your data, share it with advertisers, or use it to train anything, and we don't read the content of what you store except when directly debugging an issue you've reported, or when required to respond to a valid legal request.
Staff access to account data is limited to what's needed for support and abuse investigation, not a standing ability to browse accounts.
4. Acceptable use
What you agree not to do with the service.
- No storing or transmitting content that's illegal, or that infringes someone else's rights.
- No attempting to access another account's data, enumerate valid emails/keys, or otherwise probe around the account boundary.
- No using the service to send unsolicited bulk mail or abuse the mailbox-ingestion tooling as a spam relay.
- No load-testing or intentionally degrading the service for other users.
We reserve the right to suspend a key or account that's actively causing harm to the service or to other users, and we'll tell you why if we do.
5. Data retention & deletion
What happens to your data, and how to make it go away.
Data you store stays until you delete it or close your account. Deleting a KV entry or a mailbox item removes it immediately, not on a delayed schedule. Closing your account removes everything tied to it, including issued keys, within a short operational window.
Backups exist for disaster recovery and roll off on a routine schedule; deleted data isn't reachable through the product after deletion, even if a backup briefly still contains it.
6. Changes & early access
What "early access" actually commits us to.
raccha.ai is under active, visible development. Features marked coming soon in the product aren't live yet and nothing is charged or promised around them. Rate limits, storage limits, and pricing (currently: free) can change as the product matures.
If we make a material change to this policy (anything that affects what we do with your data, not just wording cleanup), we'll surface it in the product, not just quietly edit this page. The "last updated" date above is the source of truth for what's currently in effect.
7. Contact
Questions, a deletion request, or something that looks like a security issue: [email protected].