Privacy Policy
Last updated: July 18, 2026
1. Who we are
Rilo ("we", "us", "our") is a Chrome extension and companion website that helps you draft replies to emails in Gmail. This policy explains what information we collect, how we use it, and the choices you have. If you have any questions, email us at support@riloai.app.
2. Information we collect
We collect only what we need to run the service:
- Account information. When you create an account we store your email address. If you sign in with Google, we also receive the display name from your Google profile. Sign-in is handled by Google Firebase Authentication.
- Usage information.We count how many reply generations you have used in the current period, so we can enforce your plan's limit. Because free-plan limits are tied to your email address, this count is associated with your email. We also keep basic rate-limit counters to prevent abuse.
- Settings. Preferences you choose in the extension, such as the name you write as and your default tone.
- Payment information. Payments are processed by Stripe. We store only your Stripe customer ID, subscription ID, and subscription status. We never see or store your card number or other payment details.
- Email content. When you ask Rilo for help with an email by opening it in a Gmail compose window, the extension reads the email thread you are viewing. Section 3 explains exactly what happens to it.
- Contact form messages. If you write to us through the contact form on our website, we keep your name, email address, and message so we can respond.
3. How we handle your email content
This is the most important section of this policy, so here it is in plain terms.
Rilo reads email content only when you ask for its help with an email — that is, when you click the Rilo button in a Gmail compose window, and again when you ask it to generate a draft. At that point the extension reads the open thread from the Gmail page in your browser (the subject, the messages, and who sent them). That content is sent over an encrypted connection to our API at riloai.app, which forwards it to Google's Gemini API to analyze the thread and produce a suggested reply. The suggestion is returned to your browser. The first time you use Rilo, the extension shows a notice explaining exactly this and asks for your agreement before it reads anything.
We do not store your email content. It is processed transiently to generate the reply and then discarded. It is never written to our database and never included in our server logs. The only thing our servers record about a generation is that your usage count went up by one.
To avoid re-analyzing the same thread each time, the extension keeps a short-lived cache of its own analysis of the thread (a brief summary and the context it extracted) on your device, inside your browser. This on-device cache never leaves your machine, is never sent to or stored on our servers, and is cleared when you sign out.
Your email content is not used to train AI models. We use Google's paid Gemini API tier, which does not use submitted content for model training.
Rilo does not read your inbox in the background, does not scan email for advertising, marketing, or analytics, and does not access your Gmail account through any Google API. The extension only reads what is on the page you are looking at, and only when you ask it to.
4. Chrome Web Store Limited Use disclosure
Rilo's collection and use of user data adheres to the Chrome Web Store User Data Policy, including its Limited Use requirements. In particular:
- We use your data only to provide Rilo's single user-facing feature, generating email replies.
- We do not sell user data.
- We do not use user data for advertising.
- We do not allow humans to read your email content, except with your explicit permission (for example, if you send it to us yourself when asking for support).
5. Service providers
We rely on a small number of service providers to run Rilo. Each receives only the data needed for its purpose.
| Provider | Purpose | Link |
|---|---|---|
| Google (Gemini API) | Generates the suggested email replies | Google Privacy Policy |
| Google Firebase | Account sign-in (authentication) and our database | Firebase Privacy |
| Stripe | Payment processing for paid plans | Stripe Privacy Policy |
| Resend | Sends transactional email (password reset codes, contact form) | Resend Privacy Policy |
| Netlify | Hosts our website and API | Netlify Privacy Policy |
6. Cookies and analytics
We do not use analytics, advertising trackers, or third-party tracking scripts, on our website or in the extension. Our website does not set tracking cookies. Your signed-in state is kept by Firebase Authentication in your own browser's local storage, and the extension stores your settings, and the short-lived thread-analysis cache described in Section 3, locally on your device.
7. Data retention and deletion
We keep your account data only as long as your account is active. You can delete your account at any time from the dashboard at riloai.app using the "Delete account" option. Deleting your account cancels any active subscription, deletes your billing profile at Stripe, and removes your data from our database and authentication system, except for the limited information described immediately below.
Data Retention on Account Deletion: When you delete your account, we retain your email address and usage generation count for 90 days to prevent fraudulent re-signup and free tier abuse. After 90 days, this data is permanently deleted. We do not retain your email content, settings, billing profile, or any other data past deletion.
You can also request deletion by emailing support@riloai.app and we will do it for you. Messages sent through our contact form are kept as long as needed to respond and for our records. Password reset codes are stored only as one-way hashes and expire automatically.
8. Security
We take practical, honest measures to protect your data:
- All data is encrypted in transit using HTTPS/TLS.
- Our infrastructure runs on reputable providers (Google Firebase, Netlify, Stripe) that maintain their own strong security programs.
- The AI API key is stored as a server-side environment variable and is never included in the extension you install.
- Every API request is verified against your signed-in session, and endpoints are rate limited.
- We never store card numbers, and password reset codes are stored only as hashes.
- We do not sell user data.
For more detail, see our Security page. No internet service can guarantee perfect security, but we keep the amount of data we hold small, which keeps the risk small.
9. Children
Rilo is not directed to children under 16, and we do not knowingly collect personal information from them. If you believe a child has provided us personal information, email us and we will delete it.
10. International users
Rilo is currently not offered in the European Economic Area. We plan to make it available there later. Our services are hosted in North America. As a courtesy, we will honor reasonable access and deletion requests from any user, anywhere, who emails support@riloai.app.
11. Changes to this policy
We may update this policy from time to time. When we do, we will update the "Last updated" date at the top of this page. If a change meaningfully reduces your rights, we will make reasonable efforts to notify you, for example by email or a notice on our website.
12. Contact
Questions, requests, or concerns: support@riloai.app.