RavenPrivacy policy

Your data, in plain words.

What Raven keeps, why, who helps us run it, how long we keep it, and how to have it deleted.

Last updated October 7, 2026

The short version

  • ✓We never sell personal data. No ads, no trackers, no analytics scripts.
  • ✓Your details and messages are used only for your own campaigns. Other customers never see them, and they never train AI.
  • ✓We keep what Raven needs to work and to show you proof, and delete the rest on a schedule.
  • ✓You can get a copy of your data or have it deleted. Write to privacy@raven.work.
  • ✓A business that got a message can ask us to stop.
01

Who we are, and our two roles.

Raven is made by Tidy Work, a company based in California, USA ("we", "us").

For your account and billing, we decide how your data is used (in privacy law, we're the "controller"). For the campaigns you run, we act on your instructions (we're your "processor"): you decide who to contact and what to say. We're also the controller of our shared business database.

Questions about your data, or a request to see, copy or delete it: privacy@raven.work.

02

What we keep about you.

WhatWhat it includes
Your accountto sign you in and reach youYour name, email address and picture from Google, and your workspace's name.
Your detailsto fill in forms for youWhat you put in your profile: name, company, job title, email, phone, website, address, and any other fields you add. If you use Fill with AI, what you wrote for it and the draft it made.
Your campaignsto run themYour messages, the sites you pick or upload (we keep only the web addresses from a file, never the file), your settings, and what happened on each site.
Paymentsto bill you and stop trial abuseWhat you bought, when, and for how much. For the free forms, a one-way code made from your card, so each card gets one free trial. Stripe handles your card; we never see or store your card number.
Messages to usto help youWhat you write when you contact us.

Signing in with Google gives Raven the name, email address and profile picture on your Google account. Raven uses them only to sign you in and show who's signed in, and the email address to write to you about your account. Nothing else in your Google account is read.

03

What we keep about the businesses you reach.

Raven visits public websites and keeps what it needs to send your message and to prove it was sent:

  • +The site: its web address, the business's name, its contact page and the fields on its form.
  • +Contact details the business publishes on its own site, such as an email address, a phone number or a booking link (a few of each).
  • +The proof: screenshots of each step, a copy of the form, what was typed into it, and how the site answered.
  • +Their reply, if they write back to your reply address: the sender, the subject, the text, and a few email headers that tell a person from an automatic reply. Never attachments. Replies written by a person are also forwarded to your own inbox.
  • +Link clicks, if you add a tracked link: when, the visitor's country, their browser type, the site they came from (its name only), and a code made from their IP address that changes every day. Never the IP address itself.
  • +"Remove us" requests, so Raven never contacts that business for you again.

Business data comes from open business data, public business listings and maps, the businesses' own websites, and the lists our customers upload.

04

How we use it, and why we may.

We use data toBecause
Run Raven for youIt's what you signed up for (our contract with you).
Bill you and stop abuseOur contract, our legitimate interest in a fair free trial, and tax law.
Keep Raven secure and fix problemsOur legitimate interest in a service that works.
Make Raven betterOur legitimate interest. We learn from how sites' forms behave and how sends turn out, never from what you typed.
Reach businesses for our customersOur customers' legitimate interest in reaching other businesses. Raven skips forms that say "no solicitation" and honors "remove us".

We don't sell personal data, we don't use it for advertising, and Raven makes no automated decisions about people that have legal or similar effects.

05

How Raven uses AI.

Raven uses an AI model on Google Cloud to read pages, match your details to each form's fields, sort replies, and draft your details when you ask it to.

  • ->To fill a form, the model sees the page's text near the form, the form's fields, and your profile details and message, so it can put each one in the right place. If a send fails, it sees a short note of what happened, to name the reason.
  • ->To sort a reply, it sees the reply's subject and text, not the sender's address.
  • ->To draft your details (Fill with AI), it sees what you wrote about you and your business.
  • ✓No training. Google's terms don't let it train its models on our data.
  • ✓Briefly held. Google may hold a request for up to 24 hours to answer faster, and may keep some to check for abuse.
  • ✓Never shared across customers. Field names and outcomes help Raven work better for everyone; your values and messages never do.
06

Who helps us run Raven.

We use a few providers, and share with each only what it needs, under contracts that require them to protect it:

  • +Supabase: the database where your data is stored, and sign-in.
  • +Vercel: hosts the Raven app.
  • +Google Cloud: runs the engine that visits sites and fills in forms, and the AI model.
  • +Stripe: payments. Packs are sold by Link, Stripe's checkout, as the seller of record; Link's own privacy policy covers your payment details.
  • +Postmark: receives the replies to your reply address.
  • +Apify: searches public business listings when you ask for a fresh list. It gets the words you searched for, not your details.
  • +Capsolver: helps Raven get past human checks (CAPTCHAs). It gets the page's address and the check itself, never your details.

Our public pages load fonts from Google Fonts and a scrolling script from jsDelivr, which see your IP address, as with any page you load. Email to our raven.work addresses is forwarded to us by Namecheap.

We also share data if the law requires it, or to protect someone from harm. If Raven is ever sold or merged, your data moves with it under this policy.

07

Where it's kept, and for how long.

Your data is stored in the United States. Some providers process it elsewhere; the AI model, for one, runs on a worldwide network.

DataKept
Your account, details and campaignsWhile your account is open. Delete it in Settings and you have 30 days to restore it; then everything is deleted, screenshots included.
Screenshots, form copies and what was typed90 days. After that, each site keeps only its outcome: sent or not, and why.
RepliesWhile your account is open.
Each link click30 days. Click totals stay with the campaign.
Server logs90 days.
BackupsUp to 30 days, then overwritten.
Payment recordsStripe keeps them as long as tax law requires. Ours go with your account.
The one-way card codeKept, even after an account is deleted, so a card can claim the free forms only once.

From the EU or UK? When personal data goes from there to the US, it's covered by the EU's standard contractual clauses, with the UK's addendum, in each provider's data terms.

08

Your rights.

Delete your account yourself, in Settings: you have 30 days to change your mind, then everything is deleted. You can also ask to see, copy, correct or delete your data, to move it elsewhere, or to object to or limit how we use it. Where we rely on your consent, you can withdraw it at any time.

In California, you can also ask what we've collected about you and why; we don't sell or share personal data for advertising, and using your rights never changes how we treat you. Someone you authorize can ask for you.

Write to privacy@raven.work. We'll answer within 30 days, and may ask you to confirm it's you. If you're in the EU or UK and you're not happy with our answer, you can complain to your data protection authority.

09

If your business heard from a Raven customer.

A Raven customer chose to send your business a short message through your website's contact form. They wrote it, and they'll answer you themselves.

  • ✓To stop that customer: reply "remove us". Raven won't contact you for them again.
  • ✓To stop every Raven customer: say "no solicitation" on your contact form. Raven skips those forms for everyone.
  • ✓To see what we hold about your business, or have it deleted, write to privacy@raven.work.

Raven always skips forms that say they don't want sales messages. More for website owners: what Raven does on your site.

10

Cookies.

Raven's only cookies keep you signed in, plus two short-lived ones while you sign in. Your browser also keeps a few things on your own device: drafts you haven't saved yet, and whether you've seen the welcome. That's all: no analytics, no ad trackers, no tracking scripts, so there's nothing to accept or decline.

Stripe's and Link's checkout pages set their own cookies under their own policies.

11

Keeping it safe.

  • ✓Walled off. Each workspace's data is kept apart from every other.
  • ✓Private proof. Screenshots are private and open only through links that expire within minutes.
  • ✓Encrypted on the way. Everything travels over encrypted connections.
  • ✓No card numbers here. Card details go to Stripe, never to our servers.

No system is perfectly secure. If something goes wrong that affects your data, we'll tell you as the law requires.

12

Children, changes, and contact.

Raven is for businesses and isn't meant for anyone under 18.

If we change this policy in a way that matters, we'll email customers before it takes effect. The date at the top shows the latest version.

Questions about this policy: privacy@raven.work. Anything else: hello@raven.work.

Send the raven.

Your first 1,000 forms are free.*

*Add a card to start. You're only charged when you pick a pack.