[go: up one dir, main page]

rabbit

privacy policy

Last Updated: September 22, 2026

1. Introduction

rabbit inc. ("rabbit," "we," "us," or "our") respects your privacy and is committed to protecting it through our compliance with this Privacy Policy (this "Policy").

This Policy describes the types of information we may collect from you or that you may provide when you use rabbit OS3 ("OS3"), the rabbit agent application, the rabbit r1 and other rabbit-branded devices, our websites, and the related software and services we provide (collectively, the "Services"). It also explains how we use, share, retain, transfer, and protect that information, and the rights and choices available to you.

Data Controller. rabbit inc., a corporation organized under the laws of the State of California, United States, with its principal place of business at 1626 Montana Avenue, Suite 162, Santa Monica, California 90403, USA, is the data controller responsible for the processing of your personal information under this Policy. Our contact details, including our Data Protection Officer and EU/UK representative, are set out in Section 14.

This Policy applies to information we collect:

  • On or through the OS3/rabbit.tech website, the rabbit agent application installed on your computer, and any other software or interface we provide;
  • Through paired Channels, including Telegram, SMS/text messaging, and other channels we may add;
  • Through rabbit-branded hardware, including the r1 handheld device and future devices, when paired with your account;
  • In email, text, and other electronic messages between you and us; and
  • When you register for an account, pair a Node or Channel, configure a model, or otherwise use the Services.

It does not apply to information collected by:

  1. third-party models, applications, websites, tools, or services that you configure or invoke yourself (including Custom Models and third-party Skills), which are governed by their own privacy policies;
  2. any website or service not operated by rabbit, even if linked from the Services; or
  3. information collected by your employer or organization where you use the Services through an enterprise account administered by that organization.

2. Notice and Children's Privacy

Please read this Policy carefully to understand our policies and practices regarding your information and how we will treat it. If you do not agree with our policies and practices, your choice is not to use the Services. By creating an account, installing the rabbit agent, pairing a device or Channel, clicking "I agree," or otherwise accessing or using the Services, you acknowledge that you have read, understood, and agree to this Policy.

Notice to California Residents. If you are a California resident, this Policy provides the notices required under the California Consumer Privacy Act ("CCPA"), as amended by the California Privacy Rights Act ("CPRA"), including the categories of personal information we collect, the sources and purposes of collection, the categories of recipients, your rights to know, delete, correct, limit the use of sensitive personal information, and opt out of sale or sharing, and the right to non-discrimination. See Section 9 (California Privacy Rights) for details.

Not for Use by Children. The Services are not directed to children. In the United States, we do not knowingly collect personal information from children under 13 years of age, as defined by the Children's Online Privacy Protection Act ("COPPA"). In the European Economic Area ("EEA"), the United Kingdom, and Switzerland, we do not knowingly collect personal information from children under the age of 16 (or the lower digital age of consent specified in the law of your EEA Member State, if applicable). No one under the applicable minimum age may provide information to or through the Services. If we learn we have collected personal information from a child below the applicable age without verifiable parental consent, we will delete that information promptly. If you believe we might have information from or about a child, please contact us using the details in Section 14.

3. Information We Collect About You

"Personal data" or "personal information" means any information relating to an identified or identifiable individual, as defined under the General Data Protection Regulation ("GDPR"), the UK GDPR, and applicable U.S. federal and state privacy laws. It does not include data where the identity has been removed (anonymous data).

We may collect, use, store, and transfer different kinds of personal data about you, which we have grouped together as follows. Where a field is listed, the purpose for which it is collected is stated alongside it.

3.1 Account and Registration Information

When you register and log in to your rabbit account, we collect the following information, which you provide directly to us:

  • Email address: used for account registration, login authentication, password recovery, transactional notifications, and service communications;
  • Account identifier (user ID / subject ID): used to identify your account across the Services, pair Nodes and Channels, and associate your conversation history and Memory with your account;
  • Account password: managed by our identity provider (Auth0/Okta); passwords are not stored by rabbit in plain text and are used only for authentication;
  • Onboarding and profile information: where you provide it, your display name, reported city or region, and timezone, used to personalize your experience and configure regional settings;
  • Device display names and labels: names you choose for paired Nodes and Channels, used to help you identify and manage your devices.

3.2 Node Pairing and Device Environment Information

When you install the rabbit agent on a computer and pair it with your account (thereby making that computer a "Node"), we collect the following information:

  • Node identifier and public key: a unique identifier and a locally generated public key for the Node, used to authenticate, route instructions to, and verify the identity of the paired device; the private key is generated and retained on your device and is not sent to us;
  • Connection and heartbeat status: used to determine whether the Node is online and available to receive instructions;
  • Operating system and distribution, architecture, shell, hostname, OS username, runtimes, executable path, CPU cores, memory, locale, and virtual-machine status: reported by the rabbit agent, used to select compatible tools and commands, route tasks to the correct device, and diagnose environment-specific issues;
  • Rabbit agent version: used to determine whether updates are needed and to manage feature availability;
  • Working directory and default file paths: where you configure them, used to locate files you ask OS3 to access.
  • Learned device notes (os3Note): in addition to labels you choose, OS3 may maintain notes about each paired Node learned from task context, used to select the correct computer and reuse device-specific knowledge;

3.3 Conversation, Input and Task Data

When you interact with OS3 through a Channel, we collect the content of your communications and the tasks you request:

  • Chat input and instructions: the contents of your conversations and instructions sent through the website, Telegram, SMS, or a paired r1, including text, pasted content, and messages,used to understand your intent, carry out your tasks, and maintain conversation history; unrestricted text input may contain personal information you choose to include;
  • Uploaded files and attachments: files you select, drag, paste, or send from a Channel or r1, including file bytes and filenames, used for processing in connection with a task you request;
  • Task records and context: records of the tasks you initiate, the prompts and context assembled for the model, tool definitions and tool-call results, and the Output returned to you. used to execute tasks, provide continuity, and for debugging and improvement.

3.4 Device-Control and Desktop Operation Data (DLAM)

When a task requires OS3 to operate your computer through the device-control capability ("DLAM"), the following information may be generated or collected:

  • Tool arguments and results: the arguments passed to local tools or commands and the results returned, used to execute and verify the task;
  • Command output (stdout/stderr): output from terminal commands or scripts executed on your Node at your direction, used to complete the task and diagnose errors;
  • Screenshots and dynamic on-screen content: when a task uses the visual fallback (i.e., it needs information displayed on screen that is not otherwise available), the rabbit agent may capture screen content.this is processed transiently and is not permanently retained by default;
  • Input simulation records: records of mouse movements, clicks, and keyboard input simulated by the rabbit agent, used to execute the requested operation and for audit and debugging.

3.5 File and Content Data Accessed for Tasks

When a task requires access to files on your computer, the rabbit agent locates and accesses only the specific files and data the LLM determines are needed for that task within your instructions and authorized scope. The content of those files is processed through rabbit's servers together with the prompts needed for the task and is sent to the LLM provider you connected, where it is handled under that provider's terms. rabbit keeps no copy of the file itself, and the original file remains on your computer. See our Terms of Use for the principles governing device control and file access.

3.6 Memory and Inferred Profile Data

OS3 may build Memory from your conversations to provide continuity and personalization across tasks and Channels. We collect:

  • Memory entries: facts, persons, entities, keywords, locations, topics, and other information of reference value extracted from your conversations, used to maintain continuity across sessions;
  • Embedding vectors: vector representations used to recall relevant Memory entries when you start a new task;
  • Source conversation references: references to the conversations from which Memory entries were derived, used for transparency and to allow you to review or delete Memory.
  • SOUL / persona document: in addition to Memory entries, we store a SOUL document containing profile and personality text that you provide (such as a preferred user name or butler name) and information derived by AI from your conversations and onboarding, used to personalize replies and retain stable user preferences;

3.7 BYOK Model Credentials and Channel Pairing Information

When you configure a Custom ("Bring Your Own Key" or "BYOK") Model or pair a Channel, we collect:

  • Custom Model provider name, endpoint, and API key: used to route your Input to the model provider you designate. API keys are encrypted using envelope encryption with AWS Key Management Service, and only a masked version is displayed in the interface;
  • Telegram pairing information: if you pair Telegram, your Telegram user/bot identifiers, bot ID and bot token needed to link that Channel, plus messages and files you send through that Channel.The bot token is stored with your account (protected by our database-level encryption) and remains on our servers until you unpair,unpairing removes the OS3 pairing but does not delete messages you have exchanged with the bot on Telegram itself;
  • SMS/text messaging information: if you use SMS as a Channel, your phone number and the messages you send and receive through that Channel, used to deliver the Service.

3.8 Log, Usage and Diagnostic Data

We automatically collect the following information when you use the Services:

  • IP address, browser type and version, operating system, and device identifiers: used for security, fraud prevention, rate limiting, and to ensure compatibility;
  • Access times and usage/token-consumption counters: used for rate limiting, service planning, and billing where applicable;
  • Operational and diagnostic logs: correlation/trace identifiers, request and error metadata, timing, and, during the technical preview, debug log content that may include chat, tool, and prompt text (retained for a limited period for troubleshooting);
  • Node lifecycle audit logs: records of Node registration, pairing, unregistration, and permission changes, used for security audit and traceability.
  • Normalized email-derived bucket hash: a hash derived from your email address, used together with your IP address for rate limiting and abuse prevention (for example, to deter verification-email abuse, brute-force and password-guessing attempts), retained for approximately 15 minutes;
  • Onboarding progress and diagnostic data: the onboarding step you have reached, attempt counts and timestamps, and error codes, associated with your user ID, used to track and recover the onboarding flow and diagnose drop-off points;
  • HTTP tunnel and local application proxy: where you use the browser-based Node preview or a local model endpoint, proxied HTTP/WebSocket traffic to your Node is relayed through our edge,this traffic is streamed transparently and is not persistently stored, and access is authorized by sealed short-lived tokens;
  • Coding-agent and Skill import: where you opt in through an import card, OS3 detects installed coding agents and reads selected reusable instructions, commands, project instructions, fixed preferences and source paths (excluding credential files and transcript contents), converting them into OS3 Skills or profile facts;

3.9 rabbit Hardware (r1) Data

When you pair an r1 or other rabbit-branded hardware with OS3, we may receive:

  • Device identifiers: serial number, hardware model, firmware version, and connection status, used for device identification, pairing, and management;
  • Content you upload from the device: photos, voice, messages, or other content you choose to transmit from the r1 to OS3 for processing;
  • Device usage and diagnostic data: usage statistics, error logs, and performance information, used to diagnose faults and improve the device.
  • Legacy Journal / Rabbit Hole data export: where you request it, we may export historical data held by a prior rabbit product (such as Journal entries, Hoover or Intern tasks, and referenced audio, images, documents or artifact files) as a ZIP to a temporary AWS S3 bucket for download, the download link is available for approximately 7 days and the signed URL expires after approximately 1 hour. This is an export of pre-existing data, not new OS3 collection.

3.10 Information from Third Parties

We receive information from third parties in the following circumstances:

  • Identity provider: we receive authentication information, account identifiers, and email verification status from our identity provider (currently Auth0/Okta);
  • LLM and embedding providers: where you use a Model or the embedding service, the provider may return usage metadata.For Custom Models, the provider processes your Input under its own terms;
  • Telegram: when you pair Telegram as a Channel, we receive the messages and files you send through that Channel;
  • SMS/text providers: we receive delivery status and message content for SMS-based interactions;
  • Where applicable, payment processors and hardware fulfillment providers: we receive order and shipping information necessary to process purchases of rabbit hardware or paid services.

3.11 Aggregated Data

We also collect, use, and share Aggregated Data such as statistical or demographic data for any purpose. Aggregated Data could be derived from your personal data but is not considered personal data in law as this data will not directly or indirectly reveal your identity. However, if we combine or connect Aggregated Data with your personal data so that it can directly or indirectly identify you, we treat the combined data as personal data and will use it in accordance with this Policy.

Optional first-run workspace scan: where you opt in during setup, the rabbit agent may inspect recent file names, paths and modification metadata, the list of installed applications, and infer work context, in order to initialize a work-area profile. This scan is limited to metadata and installed-app names,it does not open file contents, and it requires your affirmative selection.

3.12 Sensitive and Special-Category Information

You may choose to Input, or OS3 may need to access, sensitive personal information (for example, health, financial, precise location, biometric data, or government identifiers) or GDPR Article 9 special categories of personal data in the course of a task. We do not seek to collect such information, but because you may include it in unrestricted text input or it may appear in files or on screen during a task, it may be processed incidentally. Where we process special categories of data, we rely on your explicit consent or another applicable legal basis. You are responsible for not including sensitive information you do not wish to be processed, and for closing or hiding sensitive windows or documents before initiating a task that uses the visual fallback.

3.13 Cookies and Similar Technologies

We use first-party cookies, browser/local storage, and (only where you opt in) third-party analytics or advertising technologies. Strictly necessary cookies are used to authenticate and secure your session, maintain login state, and enable core functionality. The principal cookies and similar technologies are summarized below.

Technology / keyCategoryPurposeLifetime / control
os3_sessionFirst-party strictly necessarySealed session/access token for authenticated use7-day seal; cleared on logout / browser data
os3_auth_stateFirst-party strictly necessaryOAuth redirect/PKCE state during login5 minutes; cleared after callback
os3_email_challengeFirst-party strictly necessaryLinks browser to email verification10 minutes; cleared on completion/logout
os3_pending_loginFirst-party strictly necessaryPending login / invite completion5 minutes; cleared on login/logout
Local storage (browser)First-party strictly necessaryUI preferences, recent Node/Channel selectionUntil cleared in browser
Analytics / advertising pixelsThird-party (opt-in only)Product usage analytics and advertising where you opt inControlled via consent settings; opt out at any time
Host-os3_proxyFirst-party strictly necessary (per-Node proxy origin)Sealed userId/nodeId/port for browser Node preview and HTTP tunnel; browser session cookieSession cookie; HttpOnly, Secure, SameSite=Lax; cleared on browser data
rabbit-hole-session-idBrowser localStorage, functionalOS3 session identifier used to reconnect conversations; no server-side deletionNo TTL; cleared via app setting or browser site-data
Auth0 hosted-domain cookiesThird-party identity cookies (when hosted login is used)Auth0 session/transaction/security cookies during login/logoutGoverned by Auth0’s own cookie policy; cleared on Auth0 logout
Tunneled application cookiesConditional target-side technologyWhen you access a local web app through the proxy, that app sets its own cookies which OS3 does not controlCleared by the target application or via browser site-data for that origin
Cookie consent preferenceFirst-party functional cookie/localStorageRecords your consent choices (accept/reject categories); no advertising identifiersNo TTL; changed via consent banner or cleared via browser site-data

You can refuse non-essential cookies through our consent settings or your browser controls. Blocking strictly necessary cookies may prevent login or core functionality. We honor browser-level Global Privacy Control ("GPC") signals as a request to opt out of the sale or sharing of personal information for cross-context behavioral advertising.

4. How We Use Your Information

We use information that we collect about you or that you provide to us, including any personal information, in the following circumstances:

  • To provide the Services, including receiving your instructions through Channels, coordinating agents, Skills, models and devices, operating your Nodes, accessing the specific files and tools needed to complete your tasks, and returning results to you;
  • To enable account registration, login authentication, Node and Channel pairing, and management of your account;
  • To maintain conversation history and Memory so that OS3 provides continuity across Channels and devices;
  • To operate the device-control (DLAM) capability, including simulating input, accessing files and applications, and executing commands at your direction;
  • To route your Input and necessary context to the Custom Model you configure, and to return Output to you;
  • To provide customer and technical support, verify and deliver hardware orders, and respond to your inquiries;
  • To maintain security, prevent fraud and abuse, enforce rate limits, and audit Node lifecycle actions;
  • To diagnose problems, maintain reliability, and analyze performance and usage;
  • To fulfill any other purpose for which you provide the information;
  • To carry out our obligations and enforce our rights arising from any contracts entered into between you and us, including for billing and collection;
  • To notify you about changes to the Services or any products or services we offer;
  • To review, improve, and develop the Services, including improving and training our models where you have not opted out (see Section 6.4);
  • To comply with legal obligations, respond to lawful requests, and protect rights, property, and safety; and
  • For any other purpose with your consent.

5. Our Legal Basis for Processing Your Information

Where the GDPR or UK GDPR applies, we may only use your information when we have a "legal basis" to do so under Article 6 (and, where relevant, Article 9). We use different legal bases depending on the purpose of the processing. These legal bases are described below. For more information on how to exercise your rights, please see Section 8 (Your Rights and Choices).

5.1 Contractual Necessity

We use your Account Information, Node pairing information, conversation and task data, and file content accessed for tasks where it is necessary to perform the contract you enter into (our Terms of Use) when you register for, access, or use the Services. This includes processing to:

  • Provide you with the Services, including logging in, pairing and controlling Nodes, sending instructions, receiving Output, and using OS3 across Channels;
  • Enforce our Terms, including suspending or restricting access if we determine that you are violating our Terms;
  • Administer the Services, including communicating with you on service-related matters and responding to your queries.

Your rights: Whenever we use your information on the basis that it is necessary for the contract we have with you, you have the right to port information you have provided to us (see Section 8.4).

5.2 Legitimate Interests

We use your information where this is necessary to achieve legitimate interests ,whether belonging to us, you, or a third party, provided these interests are not outweighed by your interests or fundamental rights and freedoms. Where we rely on legitimate interests, we conduct a balancing assessment. The legitimate interests we rely on include:

  • Ensuring the security and stability of the Services, including identifying and combating technical or security issues, detecting abuse, fraud, and illegal activity, and enforcing rate limits;
  • Improving and developing the Services, including analyzing usage patterns, diagnosing faults, and improving navigation and task-execution algorithms;
  • Administering and protecting our business, including enforcing our Terms, managing corporate transactions, and protecting our rights, property, and safety;
  • Providing effective customer support and troubleshooting.

Your rights: Whenever we use your information on the basis of legitimate interests, you can object to, and request restriction of, such usage (see Sections 8.5 and 8.6).

5.3 Your Consent

We use your information based on your consent where we are not relying on another legal basis, including:

  • Optional analytics and advertising cookies (you may withdraw at any time through consent settings);
  • Processing of special categories of personal data (GDPR Article 9) where you include such information in your Input or it is accessed during a task;
  • Marketing communications, where you have opted in;
  • Optional first-run workspace scan or coding-agent import features, where you authorize them.

Your rights: Whenever we use your information based on your consent, you can withdraw your consent at any time. However, your withdrawal of consent will not affect the lawfulness of processing your information based on your consent before its withdrawal (see Section 8.7).

5.4 Compliance with a Legal Obligation

We may use your information where it is necessary to comply with a legal obligation. This includes:

  • Complying with applicable laws, regulations, court orders, and lawful government or regulatory requests;
  • Maintaining records required by law, including tax, accounting, and audit records;
  • Complying with valid legal requests such as orders from law enforcement agencies or courts.

We generally use account records, logs, and transaction information for these purposes, although it depends on the specific situation.

5.5 Protection of Vital Interests

We may use your information where it is necessary to protect your or someone else's life, physical integrity, or safety. This includes providing law enforcement agencies or emergency services with information in urgent situations.

6. AI Models, Memory and Automated Processing

6.1 Custom (BYOK) Models

Custom Model (BYOK).When you configure a Custom Model with your own API key, we store your API key encrypted on our servers (see Section 3.7) and use it solely to authenticate and route your Input to the model provider you designate. Your Input is transmitted to that model provider, and the Output is returned by that provider. rabbit acts as a technical intermediary and processor: we provide the interface and routing infrastructure and the encrypted credential storage, we do not read or store your Input or Output content (except for operational logs as described in Section 3.8), and the provider is an independent controller for its processing.

Embeddings used for Memory recall are generated through an embedding provider (currently OpenAI text-embedding-3-small).

6.2 What is sent to model providers

To complete a task, OS3 may send to the selected LLM provider your prompts, conversation history and context, the content of selected files or images decoded into the request, tool definitions and tool-call results, and the Output returned. These request payloads are transmitted to the model provider over TLS and are not persistently stored on rabbit servers; only the resulting conversation turns are persisted in our database as described in Section 3.3. Where you request image generation, your prompt and generation settings (model, size, quality) are sent to the selected image-generation provider.

6.3 Memory feature and your controls

OS3 provides cross-session Memory so that your experience is coherent and personalized. Based on your conversations, OS3 automatically extracts and stores information of reference value (such as your preferences, projects, frequently used files, and contacts). You can view, correct, add to, delete, or disable Memory at any time in OS3 settings. If you disable Memory, OS3 will not extract new Memory entries, but existing Memory will remain until you delete it or delete your account.

6.4 Use of content to improve or train models, your opt-out

We are careful with your conversations and files. We do not sell your conversation or file content. Where we wish to use Input or Output to train, fine-tune, or improve our models, we will do so only where you have not opted out and where permitted by applicable law. You can opt out of the use of your conversation content for model improvement in OS3 settings or by contacting us. Opting out will not affect your ability to use the Services.

6.5 Automated decision-making and human oversight

OS3 automates tasks on your devices at your direction. It is not designed to make, and we do not use it to make, decisions that produce legal or similarly significant effects about you (such as credit scoring, employment decisions, or access to essential services) based solely on automated processing. In accordance with applicable transparency requirements, you are informed that you are interacting with an AI system and that Output is generated by an AI model. You may request human review of any automated outcome by contacting us using the details in Section 14.

6.6 Nature and ownership of Output

LLM Output may be incorrect, incomplete, or unsuitable, and may resemble existing content. You are responsible for reviewing Output before acting on it and for the decisions you make based on it. As between you and rabbit, and subject to the applicable model-provider terms, rights in your Input and in Output generated using a Model belong to you.

7. How We Share and Disclose Your Information

We may disclose aggregated information about our users, and information that does not identify any individual, without restriction. We may disclose personal information that we collect or you provide as described in this Policy:

7.1 Service Providers and Cloud Infrastructure

We use carefully selected recipients who process on our behalf under written agreements or as independent providers. The principal recipients are:

RecipientFunctionPrincipal data involved
Amazon Web Services (AWS)Cloud hosting (US), compute, edge/CloudFront, S3 storage, KMS key managementNetwork/IP, cloud-resident records, encrypted keys
MongoDB AtlasPrimary application database; encrypted at rest (AES-256)Account, chat, memory, node and task records
Auth0 / OktaRegistration, login, password and token managementEmail, account ID, authentication events
Twilio SendGridTransactional email verification codesRecipient email, verification message
Telegram (when paired)Messaging Channel deliveryMessages and files you send through Telegram
SMS/text provider (when used)SMS Channel deliveryPhone number, message content
LLM providers (when you configure a Custom Model) and embedding providerCustom Model inference (BYOK) and embedding processing for Memory recallInput, context, file content, Output (Custom Model inference); Memory entries for embedding generation (OpenAI text-embedding-3-small)
Hardware fulfillment and payment providersOrder processing and payment for rabbit hardwareShipping address, payment information, order details
DatadogOperational observability, logging and APM; debug-level logs may include chat, tool and prompt contentTrace/span IDs, timing/error metadata, user/session/node/task IDs; retained approximately 15 days (US5 region)
SerpApi (when web search is used)Web search results retrieval (Google results) at your directionSearch queries, domain filters, API key; returned titles/URLs/snippets
Zalify (planned, opt-in)Advertising / analytics measurement and re-marketing via web pixel, only after cookie consentPixel/cookie identifiers, page views/events, device/browser, IP, referrer

7.2 Your Own Model and Tool Providers

When you use a Custom Model, a Skill, a connector, or a third-party application, information is sent to that provider through rabbit server as needed for the task, under its own terms and privacy policy. rabbit is not responsible for the processing practices of those providers, and you should review their policies before configuring them.

7.3 Corporate Group and Affiliates

We may share your information with our corporate affiliates and subsidiaries where necessary to provide the Services, subject to appropriate confidentiality and data-processing agreements.

7.4 Corporate Transactions

Your information may be disclosed to third parties in connection with a corporate transaction, such as a merger, sale of assets or shares, reorganization, financing, change of control, or acquisition of all or a portion of our business. In such a case, your information may be transferred as part of the transaction, subject to confidentiality and to this Policy.

7.5 Legal Obligations and Rights

We may access, preserve, and share the information described in Section 3 with law enforcement agencies, public authorities, or other third parties if we have a good faith belief that it is necessary to:

  • Comply with any court order, law, or legal process, including to respond to any government or regulatory request, as consistent with internationally recognized standards;
  • Enforce or apply our Terms of Use and other agreements, including for billing and collection purposes;
  • Protect the rights, property, or safety of rabbit, our customers, or others, including to protect life or prevent imminent bodily harm;
  • Investigate potential violations of and enforce our Terms, or detect, investigate, prevent, or address misleading activity, copyright infringement, or other unlawful activity.

7.6 With Your Consent

We may disclose your personal information for any other purpose disclosed by us when you provide the information, or with your consent.

8. Your Rights and Choices

You have rights and choices when it comes to your information. Some of these rights apply generally, while others will only apply in certain circumstances. Depending on the scenario, these rights may be subject to some limitations and exceptions under applicable law. For users in the EEA, UK, and Switzerland, the rights below apply under the GDPR / UK GDPR. For users in the United States, additional rights under the CCPA and other state laws are described in Section 9.

8.1 Access Your Information

You can ask us, free of charge, to confirm what information we process about you, to provide certain information about the processing, and for a copy of your information. You can access your conversation history, Memory, account information, and Node/Channel settings directly in OS3 settings. For a complete copy of your personal data, please contact us using the details in Section 14.

8.2 Delete Your Information

You can delete or ask us to delete some or all of your information. You can delete individual conversations, Memory entries, paired Nodes and Channels, and BYOK API keys directly in OS3 settings. You can also request deletion of your account and all associated personal data (see Section 12). Deletion requests are subject to identity verification and to the limited exceptions described in this Policy (for example, information we are required to retain by law).

8.3 Rectify Your Information

You can review and change your account information by logging into OS3 and visiting your account settings. You may also change or ask us to change or correct your information where that information is not accurate or complete, by contacting us using the details in Section 14.

8.4 Port Your Information

You have the right to data portability in circumstances where we rely on contractual necessity and consent as our legal basis. This means that you have the right to receive your information in a structured, commonly used, machine-readable format and to transmit it to another controller. You can export your conversation history and Memory in OS3 settings.

8.5 Object to the Processing of Your Information

You have the right to object to the processing of your information in certain circumstances. The right to object applies when the processing you are objecting to is based on legitimate interests or is for direct marketing. In submitting an objection request, you should explain the basis for your objection so that we can assess whether our interests in processing override your rights and freedoms.

8.6 Restrict the Processing of Your Information

You have the right to request the restriction of the processing of your information where:

  1. you are challenging the accuracy of the information;
  2. the information has been unlawfully processed, but you are opposing erasure;
  3. we no longer need the information for the purposes of processing, but you require it for the establishment, exercise, or defense of legal claims; or
  4. you have objected to processing based on legitimate interests, pending verification of whether our grounds override your objection.

8.7 Withdraw Consent

Where we rely on your consent to process your personal information, you have the right to withdraw your consent at any time. You can do this through the website settings (for cookies, Memory, model-improvement opt-out, and optional features) or by sending your request to us using the contact details in Section 14. Withdrawal of consent will not affect the lawfulness of processing based on consent before its withdrawal.

8.8 Automated Decisions

You have the right not to be subject to a decision based solely on automated processing producing legal or similarly significant effects, subject to GDPR Article 22. As described in Section 6.5, OS3 is not used to make such decisions. If you believe an automated outcome has produced such an effect, you may request human review by contacting us.

8.9 Exercising Your Rights

To exercise any of the above rights, please contact us by sending an email via the contact email address provided in Section 14. Before we can respond to a request to exercise one or more of the rights listed above, you may be required to verify your identity. We encourage you to contact us if you are not satisfied with how we have responded to any of your rights requests. We would, however, appreciate the chance to deal with your concerns before you approach the supervisory authority. You also have the right to lodge a complaint with your local data protection supervisory authority at any time.

9. California Privacy Rights

This Section applies to residents of California and supplements the information in the rest of this Policy. It describes your rights under the CCPA/CPRA and how to exercise them.

9.1 Notice of Collection

Although the information we collect is described in detail in Section 3 above, the categories of personal information that we have collected in the past 12 months are as follows:

  • Account and registration information: email address, account identifier, password (managed by identity provider), display name, reported city/region, timezone, device display names;
  • Node pairing and device environment information: Node identifier and public key, connection status, operating system and distribution, architecture, shell, hostname, OS username, rabbit agent version;
  • Conversation, input and task data: chat input and instructions, uploaded files and attachments, task records, prompts and context, tool-call results, Output;
  • Device-control and desktop operation data (DLAM): tool arguments and results, command output, screenshots and on-screen content (transient), input simulation records;
  • File and content data accessed for tasks: content of files accessed during a task (processed transiently, not persistently stored by rabbit);
  • Memory and inferred profile data: Memory entries, embedding vectors, source conversation references;
  • BYOK model credentials and Channel pairing information: provider name, endpoint, API key (encrypted), Telegram user/bot identifiers and bot token, phone number for SMS;
  • Log, usage and diagnostic data: IP address, browser type and version, operating system, device identifiers, access times, usage counters, operational and diagnostic logs, Node lifecycle audit logs;
  • rabbit hardware (r1) data: device identifiers, content uploaded from device, device usage and diagnostic data;
  • Information from third parties: authentication information from identity provider, messages/files from Telegram, SMS content, order and shipping information;
  • Personal information categories listed in the California Customer Records statute (Cal. Civ. Code § 1798.80(e)), including email address and account identifiers;
  • Internet activity information: browsing history, search history, and information regarding your interaction with the Services;
  • Sensitive personal information: where you include it in Input or it is accessed during a task, including financial account information, precise location, biometric data, or government identifiers.
  • SOUL / persona document: profile and personality text provided by you and derived by AI, used to personalize replies;
  • Legacy Journal / Rabbit Hole export: historical data from a prior rabbit product (Journal entries, Hoover/Intern tasks, referenced audio, images, documents) exported as a ZIP where you request it;
  • Optional workspace scan and coding-agent import data: where you opt in, recent file names/paths/metadata, installed application names, inferred work context, and selected coding-agent instructions imported as OS3 Skills;
  • HTTP tunnel and local-proxy data: proxied HTTP/WebSocket traffic to your Node and sealed short-lived proxy tokens, streamed transparently and not persistently stored;
  • Abuse-prevention and onboarding analytics: normalized email-derived bucket hash for rate limiting, and onboarding step, attempt counts and error codes;

For more detail on the information we collect, including the sources we receive information from, please review Section 3 above. In the past 12 months, we have collected and used information from all of the above categories for the business and commercial purposes described in Section 4. We do not sell your personal information, and we do not share it for cross-context behavioral advertising.

When we disclose personal information for a business purpose, we enter a contract that describes the purpose and requires the recipient to both keep that personal information confidential and not use it for any purpose except performing the contract. We will not collect additional categories of personal information or use the personal information we collected for materially different, unrelated, or incompatible purposes without providing you notice.

9.2 Right to Know and Delete

California residents have the right to delete the personal information we have collected from you and the right to know certain information about our data practices. In particular, you have the right to request the following:

  • The categories of personal information we have collected about you;
  • The categories of sources from which the personal information was collected;
  • The categories of personal information about you we disclosed for a business purpose or sold;
  • The categories of third parties to whom the personal information was disclosed for a business purpose or sold;
  • The business or commercial purpose for collecting or selling the personal information; and
  • The specific pieces of personal information we have collected about you.

To exercise any of these rights, please submit a request to our email address provided in Section 14. In the request, please specify which right you are seeking to exercise and the scope of the request. We may require further information from you to help us verify your identity and process your request. If we are unable to verify your identity or your authority to make the request, we may deny your requests to know or delete.

There are certain exceptions to the right to delete. For example, we may deny a deletion request where we need to retain the information to:

  • Complete the transaction for which we collected the personal information, provide a good or service that you requested, take actions reasonably anticipated within the context of our ongoing business relationship with you, or otherwise perform our contract with you;
  • Detect security incidents, protect against malicious, deceptive, fraudulent, or illegal activity, or prosecute those responsible for such activities;
  • Debug products to identify and repair errors that impair existing intended functionality;
  • Exercise free speech, ensure the right of another consumer to exercise their free speech rights, or exercise another right provided for by law;
  • Comply with the California Electronic Communications Privacy Act (Cal. Penal Code § 1546 et seq.);
  • Engage in public or peer-reviewed scientific, historical, or statistical research in the public interest that adheres to all other applicable ethics and privacy laws, when the information's deletion may likely render impossible or seriously impair the achievement of such research, provided you have provided informed consent;
  • Enable solely internal uses that are reasonably aligned with consumer expectations based on your relationship with us; or
  • Make other internal and lawful uses of that information that are compatible with the context in which you provided it.

9.3 Right to Correct

California residents have the right to correct inaccurate personal information that we maintain about you, taking into account the nature of the personal information and the purposes of the processing. You may exercise this right by contacting us using the details in Section 14 or by updating your information directly in OS3 settings.

9.4 Right to Limit Use of Sensitive Personal Information

California residents have the right to limit the use of sensitive personal information to that which is necessary to perform the services or provide the goods reasonably expected by an average consumer who requests such goods or services. Because we process sensitive personal information only when you include it in a task or it is necessary to complete a task you request, and we do not use it for other purposes, you may limit such processing by not including sensitive information in your Input or by contacting us.

9.5 Response Time and Format

We endeavor to respond to a verifiable consumer request within forty-five (45) days after we can reasonably verify your identity and authority to make the request. If we require more time, we may extend the response period by up to an additional 45 days, and we will inform you of the extension and the reason for the delay. The response we provide will also explain the reasons we cannot comply with a request, if applicable. For any request to know, we will select a format to provide your personal information that is readily usable and should allow you to transmit the information from us to another party without hindrance. We do not charge a fee to process or respond to your request unless it is excessive, repetitive, or manifestly unfounded.

9.6 Authorized Agent

You can designate an authorized agent to submit requests on your behalf. You may also act as an agent and make a verifiable request on behalf of your minor child. However, we will require written proof of the agent's permission to act on your behalf, and we may still require you to verify your identity directly with us.

9.7 Right to Non-Discrimination

You have the right not to receive discriminatory treatment by us for the exercise of any of your rights under the CCPA. We will not deny you goods or services, charge you different prices or rates, provide you a different level or quality of goods or services, or suggest that you will receive a different price or rate for goods or services or a different level or quality of goods or services, because you exercised your rights under the CCPA.

9.8 Do Not Sell or Share My Personal Information

We do not "sell" your personal information, and we do not "share" it for cross-context behavioral advertising. You may still submit a request to opt out of any sale or sharing by contacting us or by enabling Global Privacy Control (GPC) in your browser. We honor GPC signals as an opt-out request.

9.9 Children

We do not knowingly "sell" or "share" the personal information of consumers under 16 years of age, and we obtain affirmative opt-in for such processing where required.

9.10 Shine the Light

California's "Shine the Light" law permits users of our Services that are California residents to request certain information regarding our disclosure of personal information to third parties for their direct marketing purposes. We do not share personal information with third parties for their direct marketing purposes. If this law applies to you and you wish to obtain further information about our sharing, please send an email to us via the contact address provided in Section 14.

10. Data Security and Retention

10.1 Data Security

We have implemented appropriate technical, administrative, and physical security measures designed to secure your personal information from accidental loss and from unauthorized access, use, alteration, and disclosure,. These measures include:

  • Transmission encryption: All data transmitted between the rabbit agent, Channels, and our cloud servers is encrypted using TLS;
  • Storage encryption: Hosted database records are encrypted at rest (for example, AES-256);
  • Envelope encryption of BYOK API keys using AWS Key Management Service, with masked display;
  • Sealed, HttpOnly, Secure/SameSite first-party session cookies and short-lived, single-use pairing and proxy tokens;
  • Local generation and retention of Node private keys on your device, access controls, least-privilege permissions, and audit logs of Node lifecycle actions;
  • Network and application security, rate limiting, abuse monitoring, and restricted internal access on a need-to-know basis.

We regularly review our security measures to consider available new technology and methods. The safety and security of your information also depends on you. Where we have given you (or where you have chosen) a password for access to certain parts of the Services, you are responsible for keeping this password confidential and for safeguarding your API keys, paired devices, and Channels.

Unfortunately, the transmission of information via the internet is not completely secure. Although we do our best to protect your personal information, we cannot guarantee the security of your personal information transmitted to our Services. If a personal-data breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the competent supervisory authority without undue delay and, where required by law, notify you without undue delay.

10.2 Data Retention

We retain information for as long as necessary to provide the Services and for the other purposes set out in this Policy. The retention periods differ depending on the type of information and the purposes for which it is used. The principal periods are:

CategoryRetention approach
Account and profile dataFor the life of your account; deleted or anonymized within a reasonable period after account deletion, subject to legal retention requirements.
Conversation history and MemoryRetained while your account is active so the Services can provide continuity; deleted upon account deletion or upon your request.
Files accessed for a taskOriginal files remain on your device; rabbit keeps no copy; task content may appear transiently in operational logs during the technical preview (limited retention).
Uploaded attachments / exportsStored on the selected Node and, where needed for processing, transiently on our servers; not persistently stored as files.
Node pairing and device dataFor the life of the pairing; deleted when you un-pair the Node or delete your account
BYOK API keysStored encrypted while configured; deleted when you remove the key or delete your account.
Operational and diagnostic logsDebug-level operational logs (including Datadog logs) retained approximately 15 days; general operational and diagnostic logs retained up to 90 days.
Marketing and consent recordsRetained for as long as necessary to demonstrate consent and comply with legal obligations
Legal and compliance recordsRetained for as long as required by applicable law, including tax, accounting, and audit records
Node lifecycle audit logsRetained for the life of your account (no fixed TTL) to maintain an audit trail of Node registration, replacement and deletion

Where data no longer needs to be retained, we delete, anonymize, or aggregate it. Deletion requests are subject to identity verification and to the limited exceptions described above; residual copies may persist in backups for a limited period until they are overwritten or deleted.

11. International Data Transfers

The Services are hosted and operated primarily in the United States (including AWS regions and our hosted database), and our providers may process data in other jurisdictions. If you are located in the EEA, the UK, or Switzerland, your personal information may be transferred to, stored in, or processed in countries outside your region, including the United States, where data-protection laws may differ from those in your region.

When we transfer your information outside of the EEA, the UK, or Switzerland, we ensure that appropriate safeguards are in place and that the transfer complies with applicable data-protection laws, including:

  • Adequacy decisions: where we transfer your personal data to a recipient in a country or territory that benefits from an adequacy decision by the European Commission (or the UK Secretary of State), we rely on that adequacy decision. This includes the EU-U.S. Data Privacy Framework and its UK Extension (and, where applicable, the Swiss-U.S. Data Privacy Framework), in each case only to the extent that rabbit or the relevant recipient is certified thereunder and while the relevant adequacy decision remains in force;
  • Appropriate safeguards: where no adequacy decision applies to the specific transfer, or where rabbit or the relevant recipient is not certified under an adequacy framework, we put in place the European Commission Standard Contractual Clauses ("SCCs") and, where applicable, the UK International Data Transfer Addendum, together with any supplementary measures (such as in-transit encryption and access minimization) required to ensure an adequate level of protection;
  • Transfer impact assessments: we assess the laws and practices of the destination country and apply technical and contractual supplementary measures (such as encryption and minimized access) to protect your data;
  • Obtaining a copy: a copy of the relevant safeguards can be requested through the contacts in Section 14.

For Custom Models, Skills, and user-requested destinations, you may direct transfers to providers or locations of your choosing; you are responsible for assessing those providers, and the transfer is governed by your agreement with that provider.

12. Account Deletion and Data After Termination

You may delete your account in OS3 settings or by contacting us. On deletion, we stop providing the Services and delete or anonymize your personal information, including conversation history and Memory, within a reasonable period, subject to the retention exceptions described in Section 10.2. You may request export or retrieval of your data before deletion. Please note that deleting your account removes rabbit’s copy of your API keys but does not revoke or disable those keys on the model provider’s side; you must revoke them directly with the relevant provider.

Upon termination or expiration of your access to the Services, your license ends and you must cease use and uninstall the rabbit agent. Uninstalling the rabbit agent removes the local application and its local configuration directory but does not by itself delete your cloud account or conversation history; you must delete your account separately. After termination, sections of this Policy that by their nature survive will survive, including our rights to retain information as required by law and to enforce our Terms.

13. Changes to This Privacy Policy

It is our policy to post any changes we make to this Policy on this page. The date on which this Policy was last revised is identified at the top of the page. If we make material changes to how we process personal information, we will notify you by posting the revised version with a new "Last Updated" date and, where required by applicable law, by additional means (such as email or in-Service notice). Your continued use of the Services after the effective date of the revised Policy constitutes your acceptance of the changes. You are responsible for ensuring we have an up-to-date active and deliverable email address for you, and for periodically visiting this page to check for any changes.

14. Contact Information, Data Protection Officer and EU/UK Representative

rabbit inc. is the controller and responsible for your personal data.

Full name of legal entity: rabbit inc.

Postal address: 1626 Montana Avenue, Suite 162, Santa Monica, California 90403, USA

For privacy questions, requests, or complaints, contact us at: support@rabbit.tech

For general support: support@rabbit.tech

Data Protection Officer. You may reach our data protection lead at: support@rabbit.tech.

EU / UK Representative. Pursuant to Article 27 GDPR (and the UK GDPR), our representative in the European Union/United Kingdom is:

Dr. Jörg Brettschneider, Rechtsanwalt
Brettschneider Rechtsanwaltsgesellschaft mbH
Alter Wall 32, 20457 Hamburg, Germany
Phone: +49 40 3346 64190 — Fax: +49 40 3567 4881
Email: ra-gdpr@brettschneider.law.

You have the right to make a complaint at any time to the supervisory authority for data protection issues in your jurisdiction. We would, however, appreciate the chance to deal with your concerns before you approach the supervisory authority.