Legal

Privacy Policy

Last updated: 4 June 2026

This Privacy Policy explains what Raven Labs ("we", "us") does with personal data when you use Raven (the "Service"). It's written to comply with India's Digital Personal Data Protection Act, 2023 (DPDP Act) and, where applicable, the EU GDPR. If you're an organisation using Raven on behalf of your business, you're the data fiduciary for the accounting data; we act as your data processor on your instructions.

What we collect

Account data. Your email address, used for one-time-code sign-in. We don't ask for a password — there isn't one.

Accounting data. When you connect your Zoho Books org, we read invoices, bills, payments, chart of accounts, customers, vendors, and related entities. Imported into a per-org schema in our database. We never write to your Zoho org.

Operational metadata. Audit findings, report definitions you create, reconciliation decisions, membership changes. Tied to your organisation and visible to your colleagues with the appropriate role.

No tracking of personal activity. We don't run analytics in the dashboard; we don't share usage data with advertisers. The marketing site uses PostHog for anonymous page-view analytics — that's it.

Why we have it

  • Run reports and audit findings you ask for.
  • Authenticate you and prove you have access to a given organisation.
  • Keep an audit log of who-changed-what for security and compliance.
  • Respond to support requests you send us.

Where it lives

Your data is stored in Supabase Postgres in the ap-south-1 (Mumbai) region. Compute runs on Fly.io machines in the bom (Mumbai) region. Data does not leave India for storage in the normal course of operation. (Anthropic, when invoked by the audit AI pass, may process metadata in the US — see the sub-processors list below.)

Sub-processors

We use the following providers to run the Service:

  • Supabase Postgres database + authentication (ap-south-1, Mumbai)
  • Fly.io Application hosting (bom region, Mumbai)
  • Vercel Dashboard frontend + marketing site hosting
  • Resend Transactional email (sign-in codes)
  • Anthropic LLM provider for the audit AI pass (only the substrate metadata sent for inspection)
  • Zoho Source of accounting data, via OAuth from your own Zoho org

How long we keep it

Accounting data is kept for as long as your Zoho org is connected to Raven. If you disconnect the org or delete your account, we retain the data for up to 30 days in case you reconnect, then it's removed from active systems. Backups taken before deletion may persist for up to a further 30 days before they roll out of rotation.

Membership audit-log entries (who joined/left an organisation, when) are retained indefinitely for security and compliance — they reference user IDs and emails but not any user-identifying personal data beyond that.

Your rights

Under the DPDP Act (and where applicable, the GDPR), you have the right to:

  • Access the personal data we hold about you.
  • Correct it if it's inaccurate (your email is editable on Supabase's side; reach out for anything else).
  • Delete your account — do this yourself from Settings → Danger zone.
  • Withdraw consent for processing (which means deleting your account in our case).
  • Lodge a complaint with the Data Protection Board of India (DPDP Act, section 27).

Security

Data in transit uses TLS (HTTPS only; HSTS enforced on dashboard.ravenlabs.app). Data at rest is encrypted by Supabase's storage layer. Authentication uses Supabase Auth with email one-time codes (no passwords stored). Sign-in tokens are short-lived (1 hour) and rotated automatically; you can sign out of every device at once from Settings.

Inside Raven, every API call is scoped to organisations you're a member of — backend authorization checks against the membership table on every request, not just at the UI layer.

Children

Raven is not directed at children under 18. We don't knowingly collect personal data from minors. If you believe a minor has provided us data, contact us and we'll remove it.

Changes

We'll post material updates to this policy here with an updated "Last updated" date. For changes that materially expand how we use personal data, we'll also notify you in-app or by email and, where required, request fresh consent.

Contact

Privacy questions or rights requests: hello@ravenlabs.app.