This Privacy Policy explains what Raven Labs ("we", "us") does with personal data when you use Raven (the "Service"). It's written to comply with India's Digital Personal Data Protection Act, 2023 (DPDP Act) and, where applicable, the EU GDPR. If you're an organisation using Raven on behalf of your business, you're the data fiduciary for the accounting data; we act as your data processor on your instructions.
What we collect
Account data. Your email address, used for one-time-code sign-in. We don't ask for a password — there isn't one.
Accounting data. When you connect your Zoho Books org, we read invoices, bills, payments, chart of accounts, customers, vendors, and related entities. Imported into a per-org schema in our database. We never write to your Zoho org.
Operational metadata. Audit findings, report definitions you create, reconciliation decisions, membership changes. Tied to your organisation and visible to your colleagues with the appropriate role.
No tracking of personal activity. We don't run analytics in the dashboard; we don't share usage data with advertisers. The marketing site uses PostHog for anonymous page-view analytics — that's it.
Why we have it
- Run reports and audit findings you ask for.
- Authenticate you and prove you have access to a given organisation.
- Keep an audit log of who-changed-what for security and compliance.
- Respond to support requests you send us.
Where it lives
Your data is stored in Supabase Postgres in the ap-south-1 (Mumbai) region. Compute runs on Fly.io machines in the bom (Mumbai) region. Data does not leave India for storage in the normal course of operation. (Anthropic, when invoked by the audit AI pass, may process metadata in the US — see the sub-processors list below.)
Sub-processors
We use the following providers to run the Service:
- Supabase — Postgres database + authentication (ap-south-1, Mumbai)
- Fly.io — Application hosting (bom region, Mumbai)
- Vercel — Dashboard frontend + marketing site hosting
- Resend — Transactional email (sign-in codes)
- Anthropic — LLM provider for the audit AI pass (only the substrate metadata sent for inspection)
- Zoho — Source of accounting data, via OAuth from your own Zoho org
How long we keep it
Accounting data is kept for as long as your Zoho org is connected to Raven. If you disconnect the org or delete your account, we retain the data for up to 30 days in case you reconnect, then it's removed from active systems. Backups taken before deletion may persist for up to a further 30 days before they roll out of rotation.
Membership audit-log entries (who joined/left an organisation, when) are retained indefinitely for security and compliance — they reference user IDs and emails but not any user-identifying personal data beyond that.
Your rights
Under the DPDP Act (and where applicable, the GDPR), you have the right to:
- Access the personal data we hold about you.
- Correct it if it's inaccurate (your email is editable on Supabase's side; reach out for anything else).
- Delete your account — do this yourself from Settings → Danger zone.
- Withdraw consent for processing (which means deleting your account in our case).
- Lodge a complaint with the Data Protection Board of India (DPDP Act, section 27).
Security
Data in transit uses TLS (HTTPS only; HSTS enforced on dashboard.ravenlabs.app). Data at rest is encrypted by Supabase's storage layer. Authentication uses Supabase Auth with email one-time codes (no passwords stored). Sign-in tokens are short-lived (1 hour) and rotated automatically; you can sign out of every device at once from Settings.
Inside Raven, every API call is scoped to organisations you're a member of — backend authorization checks against the membership table on every request, not just at the UI layer.
Children
Raven is not directed at children under 18. We don't knowingly collect personal data from minors. If you believe a minor has provided us data, contact us and we'll remove it.
Changes
We'll post material updates to this policy here with an updated "Last updated" date. For changes that materially expand how we use personal data, we'll also notify you in-app or by email and, where required, request fresh consent.
Contact
Privacy questions or rights requests: hello@ravenlabs.app.