Last updated: September 5, 2026

RAG Studio Privacy Notice

RAG Studio is a browser-based workspace for retrieval-augmented generation at https://rag.masihmoafi.com.

01Information used for sign-in

RAG Studio uses Google sign-in through Supabase Auth. Google and Supabase process the account information needed to authenticate you, including your email address and a provider-specific account identifier. RAG Studio's profile table stores your Supabase user ID, a randomly generated public handle that is not derived from your email address, and the profile creation time.

02Documents, questions, and model requests

Documents you load, their local index, and retrieval settings remain in your browser. When you ask a selected model provider to generate an answer, RAG Studio sends that provider the question, selected model ID, and retrieved passages needed for the request. The provider processes that request under its own privacy terms. RAG Studio does not sell personal data or use it for advertising. Signed-in browser workspaces are separated by account. Guest workspaces use a separate tab-session identity, which changes after sign-out. Older browser data without an account owner is retained but is not automatically opened or assigned to an account. This separation does not protect against someone with direct access to your browser profile, developer tools, malicious extensions, or compromised site code. Use separate operating-system or browser profiles on shared devices.

03Provider API keys

An API key used only for the current session remains in the active browser session. If you choose Remember on this device, the key is encrypted in IndexedDB with a non-exportable browser key. If you choose Save to account, the key is sent over HTTPS to the RAG Studio server, encrypted there with AES-256-GCM, and stored as ciphertext in Supabase. The full account key is not returned to the browser after it is saved. You can remove either saved copy from Settings. Remembered device keys use the same account or guest-session separation as the workspace, with a separate encryption key for each identity. Signing out clears the active workspace and credentials from the Studio interface, but does not erase stored account records or local encrypted copies.

04Other browser and account data

RAG Studio stores non-secret provider and model preferences in local browser storage. Supabase session cookies are used to keep you signed in. Account records and encrypted account keys remain until you remove the key or request account deletion; signing out alone does not delete them.

05Service providers

RAG Studio relies on Google for sign-in, Supabase for authentication and account storage, Vercel for hosting, and the model provider you select for generation. Each service may process network metadata such as IP address and request timing under its own terms.

06Your choices

You can use the local workspace without saving a provider key to an account, remove saved keys in Settings, clear local browser storage, and sign out at any time. For privacy questions or an account-deletion request, use the user-support contact shown on RAG Studio's Google authorization screen.

07Security and changes

RAG Studio uses transport encryption, owner-scoped database access controls, and encryption for saved provider keys. No system can guarantee absolute security. This notice may be updated when the product or its data handling changes; the date above will be revised when that happens.

Back to RAG Studio