Home

Privacy Policy

Last Updated: May 9, 2026

MC² Ventures FZCO (“we,” “us,” or “our”) operates the Raisolo.com service (the “Service”). This Privacy Policy explains how we collect, use, disclose, and safeguard your information, including your personal data, when you use the Service.

By using the Service, you consent to the data practices described in this policy. This policy is written to comply with the EU General Data Protection Regulation (GDPR), the UAE Personal Data Protection Law (PDPL), and the Google API Services User Data Policy.

1. Information We Collect

We collect only the information necessary to provide and improve the Service.

A. Account Information

  • Email address — serves as your account identifier and the delivery point for the AI-generated summaries you have requested.
  • Profile information from Google (when you sign in with Google) — your name, profile picture, and email address. See Section 4 for full disclosure.

B. User Content

  • The full text, attachments, and metadata of the emails, reports, newsletters, and other documents you forward to the Service for summarization.

C. Usage Data

  • Standard server log files (IP address, browser type, access timestamps), used solely for security, fraud prevention, and operational diagnostics.

2. How We Use Your Information

Your email address is used only for: (a) account authentication and identification, (b) delivery of the AI-generated summaries you requested, (c) service announcements and security notices, and (d) replies to support requests.

We do not send marketing emails, and we do not display your email address to other users. If we introduce an optional marketing newsletter in the future, it will be opt-in only and will not be enabled without your explicit, separately-collected consent.

We use your User Content to:

  • Provide the Service: receive your User Content, process it using our AI models, generate summaries, and deliver those summaries to your email address.
  • Improve the Service (Free / non-Premium tier only): we may use your User Content to train and improve our AI models. For Premium users (and Premium trials), your User Content is never used for AI model training and is processed exclusively to provide the Service to you.
  • Manage your account: handle billing for Premium plans, send service announcements, and provide customer support.

3. How We Share Your Information

We do not sell or rent your personal data. We share it only in the following limited circumstances, and each processor is bound by a Data Processing Agreement that limits use to our instructions:

A. Third-Party AI Providers (Sub-processors)

To generate summaries we send your User Content to AI partners including OpenAI, Google (Gemini), and other model providers we may add over time.

  • For Premium users: contractual terms prohibit these providers from using your content for their own model training or any purpose other than fulfilling the request.
  • For Free / non-Premium users: your content may be used by these providers to improve their services, in accordance with our terms with them.

B. Authentication

Clerk, Inc. provides authentication and session management. Clerk receives your sign-in identifiers (Google OAuth profile and email, or email/password credentials) solely to create and authenticate your Raisolo account. See Clerk's Privacy Policy.

C. Infrastructure

Cloudflare, Inc. provides hosting, edge compute, CDN, and database storage (D1, R2, Workers KV). Other vendors may be used for specific operational needs (e.g., payment processing); they are contractually bound to use your information only to provide services to us.

D. Legal Compliance

We may disclose your information if required by law, or in the good-faith belief that such action is necessary to comply with a legal obligation, protect our rights, or ensure the safety of our users.

4. Google User Data

This section describes how Raisolo accesses, uses, stores, and shares data obtained via Google APIs, in compliance with the Google API Services User Data Policy, including the Limited Use requirements.

A. Data we access

When you sign in with Google, we request only the following OAuth scopes (provisioned through our authentication provider, Clerk):

  • openid, https://www.googleapis.com/auth/userinfo.email, https://www.googleapis.com/auth/userinfo.profile — to identify your account, display your name and avatar within the Service, and use your email address as your account identifier and as the delivery point for AI-generated summaries.

We do not request any scope we do not actively use. We do not access your Gmail messages, Google Drive files, contacts, calendar, or any other Google user data.

B. How we use it

Google user data is used solely to:

  • authenticate you and create or maintain your Raisolo account;
  • display your profile name and avatar within the Service to you;
  • send service-related communications and your AI-generated summaries to your Google email address.

We do not use Google user data to serve advertisements, to build profiles for advertising purposes, or to develop, improve, or train generalized or non-personalized AI/ML models.

C. How we share it

We do not sell or rent Google user data and we do not transfer it to any party for advertising, profiling, credit assessment, or resale. Google user data is shared only with the sub-processors listed in Section 3 (Clerk for authentication, Cloudflare for infrastructure), each under a Data Processing Agreement that limits use to operating the Service.

D. How we store and protect it

Google user data is stored in encrypted databases hosted by Cloudflare. All data is encrypted at rest and in transit (TLS 1.2 or higher). OAuth tokens, where retained, are encrypted at rest with keys held in Cloudflare Secrets. Production database access is restricted to authenticated application code; no employee accesses production data outside of audited break-glass procedures.

E. How long we keep it and how to delete it

We retain Google user data only for as long as your Raisolo account is active or as needed to provide the Service. You may request deletion of your Google user data — including OAuth tokens, profile information, and any User Content stored against your account — at any time:

  • By email: webmaster@mc2.ventures with the subject line “Delete my account.”
  • In-app: via the account settings page (where available).

We will delete your Google user data within 30 days of a verified request, except where retention is required to comply with a legal obligation. You may also revoke Raisolo's access to your Google account at any time at myaccount.google.com/permissions; doing so terminates our ability to access any further Google user data.

5. Data Security

We implement reasonable technical and organizational measures to protect your information, including encryption at rest and in transit (TLS 1.2+), isolated data structures for Premium accounts, restricted access controls, and audit logging. However, no internet-based service is 100% secure, and we cannot guarantee absolute security.

6. Data Retention and Deletion

Beta phase notice: the Service is currently in a Beta phase. We provide no guarantee of data retention during this phase and may delete User Content or generated summaries at any time (for example, during system upgrades). Do not rely on the Service as a data archive.

User-initiated deletion: independent of the Beta caveat above, you may request deletion of your account and all associated personal data at any time:

  • Email webmaster@mc2.ventures with the subject line “Delete my account”; or
  • Use the in-app account settings page (where available).

We will action verified deletion requests within 30 days, except where retention is required to comply with a legal obligation (e.g., tax records).

7. International Data Transfers

Our company is based in the UAE. To provide the Service, your information (including User Content) is processed in the UAE and by our third-party sub-processors, whose servers may be located in the United States, European Union, and other jurisdictions.

Where we transfer personal data of EU/EEA users outside the EEA, we rely on:

  • the European Commission's adequacy decisions where applicable, or
  • Standard Contractual Clauses (SCCs) approved by the European Commission, included in our agreements with sub-processors (Cloudflare, Clerk, OpenAI, Google, etc.).

Copies of the relevant SCCs are available on request. By using the Service, you consent to the transfer of your data to these jurisdictions, which may have different data protection laws than your home country.

8. Your Data Subject Rights

Depending on your jurisdiction (in particular under the EU GDPR and UAE PDPL), you have the following rights regarding your personal data:

  • Access (GDPR Art. 15) — request a copy of the personal data we hold about you.
  • Rectification (Art. 16) — correct inaccurate or incomplete personal data.
  • Erasure (Art. 17) — request deletion of your personal data, subject to legal-retention exceptions.
  • Restriction of processing (Art. 18) — ask us to pause processing while a dispute is resolved.
  • Data portability (Art. 20) — receive your personal data in a structured, machine-readable format.
  • Object (Art. 21) — object to processing based on legitimate interests.
  • Withdraw consent (Art. 7(3)) — withdraw any consent you have previously given, at any time, without affecting the lawfulness of processing performed before withdrawal.
  • Lodge a complaint with your local supervisory authority (in the EU, your national Data Protection Authority; in the UAE, the UAE Data Office).

To exercise any of these rights, contact us at webmaster@mc2.ventures. We will respond within 30 days as required by GDPR Article 12(3).

9. Legal Basis for Processing (GDPR)

For users in the EU/EEA, we process personal data on the following legal bases:

  • Contract (Art. 6(1)(b)) — processing your User Content and account information to deliver the summaries you requested.
  • Legitimate interest (Art. 6(1)(f)) — security, fraud prevention, operational logging, and Service improvement (for non-Premium users) where your interests and rights do not override these interests.
  • Consent (Art. 6(1)(a)) — for the use of Free-tier User Content for AI model training, and for any future optional features (e.g., a marketing newsletter) you may opt into.
  • Legal obligation (Art. 6(1)(c)) — tax and accounting records, lawful disclosure requests.

10. Children's Privacy

The Service is not directed to individuals under 18, and we do not knowingly collect personal data from anyone under 18. If you believe we have collected personal data from a minor, please contact us and we will delete it.

11. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated policy on this page and updating the “Last Updated” date. Continued use of the Service after a change constitutes acceptance of the updated policy.

12. Contact Us

If you have any questions about this Privacy Policy, or to exercise any rights described above, please contact our data controller:

MC² Ventures FZCO
Dubai Silicon Oasis, Building 1
Dubai, United Arab Emirates
Email: webmaster@mc2.ventures

If you are in the EU/EEA, you may contact us by email regarding any GDPR rights request. We will respond within 30 days as required by Article 12(3). You may also lodge a complaint with your national Data Protection Authority.