Legal
Privacy Policy
Last updated: September 11, 2026
This Privacy Policy explains how Rare X Labs Inc. ("Rare," "we," "us"), a company incorporated in British Columbia, Canada, collects, uses, and discloses personal information through the hosted version of Rare CRM at rarecrm.ai (the "Service").
We're a relationship-journal product built around a genuinely portable data format — you can read what that design commitment means for your data in Section 8.
1. Two kinds of personal information
This is a relationship-journal product, so we handle two different kinds of personal information, and they're subject to different rules:
- Account information — about you, the person or organization who signed up: your name, email, authentication details, billing information, and how you use the Service. Rare is the one responsible for this information, as described below.
- Journal content — the entries, contacts, notes, and attachments you write into your journal, which routinely includes personal information about other people (your contacts, clients, colleagues — "Third-Party Data"). For this information, you are the one responsible for the data, and Rare acts only as your service provider — we store, sync, and process it on your instructions, to provide the Service to you, and not for our own purposes. If you're on a team or business plan, your organization is responsible for this data, not Rare.
If you are a person whose information appears in someone else's Rare journal (rather than a Rare account holder yourself), see Section 9.
2. What we collect
From you directly
- Account data: name, email address, authentication credentials (or identity from your login provider), organization/team details.
- Billing data: handled by our payment processor on our behalf — see Subprocessors — we receive subscription status and the minimum needed to reconcile billing, not your full card number.
- Journal content: everything you write or import into your journal, including any Third-Party Data within it, and any files you attach.
- Voice recordings: if you use voice capture, your audio clip is processed to produce a transcript (see Section 3 and Section 5).
- Waitlist/application data: if you join the waitlist before an account exists, we collect your email and any answers you provide to qualify and review applications.
- Support communications: anything you send us at contact@rarecrm.ai.
Automatically
- Usage and diagnostic data: log data, device/browser information, IP address, and how you interact with the Service, for security, debugging, and reliability.
- Cookies / local storage: used for session management and basic product functionality, as well as analytics cookies that help us understand how the Service is used — see Subprocessors for which providers we use.
From connected third parties, at your direction
- Google Contacts: if you connect Google Contacts sync, we access the contact data your Google account authorizes, under the scope you grant, to compare and merge it with your journal. You control the connection and can disconnect it at any time in Settings. We don't access your Google account for anything beyond what the sync feature does.
Google user data ("Limited Use")
Rare CRM's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. In practice, that means the contact data your Google Contacts connection authorizes is used only to provide and improve the sync feature you turned on — never for advertising, never transferred to a third party except as needed to provide that feature or as required by law, and never reviewed by a human except with your consent, to investigate abuse or a security incident, or to comply with the law.
3. How we use it
We use personal information to:
- provide, operate, and maintain the Service (store your journal, serve the web/mobile apps, run sync, keep your data durable and versioned);
- power the Service's AI features — the relevant journal content, your prompt (if any), and (for voice capture) your audio are sent to the configured AI/transcription provider to generate a response or transcript;
- authenticate you and secure your account;
- process billing and payments;
- communicate with you — service notices, security alerts, and, only with your consent or as permitted by law, product updates;
- monitor, debug, and improve the Service's performance and reliability;
- review waitlist applications and manage early access;
- meet legal obligations and enforce our Terms of Service.
We may also create aggregated or de-identified data from the information we collect — data that doesn't identify you or any other individual — and use it for any purpose, including analytics, benchmarking, and improving the Service.
We do not sell personal information.
4. Legal basis (for users in regions that require one)
Where applicable privacy law (such as PIPEDA or BC's PIPA) requires a stated basis, we rely on: your consent (where you give it, e.g. connecting Google sync or opting into product email), performance of our contract with you (running the Service you signed up for), and our legitimate interests in operating and securing the Service, balanced against your rights. For Third-Party Data, the legal basis is yours to establish — see Section 9.
5. Subprocessors and third parties
We use a small number of service providers to operate the Service — hosting and storage, authentication, payments, the AI and transcription models behind the assistant and voice capture, product analytics, and (only if you connect it) Google Contacts sync. Each processes personal information only as needed to perform its function for us, under its own confidentiality and data-protection commitments, and we keep the current list on a dedicated page — see Subprocessors — rather than here, so it can be kept accurate as our stack changes without requiring a full revision of this policy. If you want notice before we add or replace a subprocessor, you can ask to be added to the subprocessor change list, as described on that page.
We may also disclose personal information: to comply with a legal obligation (a valid court order, subpoena, or similar); to protect the rights, safety, or property of Rare, our users, or the public; or in connection with a merger, acquisition, or sale of assets, with notice to you where required by law.
6. Where data is processed and stored
We and our subprocessors may process and store your information in one or more countries, which may include countries other than the one you're located in. We choose our infrastructure providers and locations based on performance, reliability, and cost, and this may change as the Service grows.
7. How long we keep it
- Active accounts: journal content, including its version history, is kept for as long as your account is active, so you always have your full history available.
- After cancellation or deletion: your data is retained for 30 days — from the date you delete your account, or from cancellation or suspension for non-payment (see Terms of Service, Section 7) — in case of accidental cancellation, then permanently deleted from active systems.
- Billing records: kept as long as required by tax and accounting law (in Canada, generally six years).
- Waitlist data: kept while your application is pending, and for a reasonable period after a decision for our own records, unless you ask us to delete it sooner.
8. Exporting and deleting your data
Your journal is built to be portable: you can export the whole thing — every entry, every version — at any time, and use it independently of Rare. This isn't a compliance afterthought; it's how the product is built.
To delete your account and data, use the in-product deletion option or email contact@rarecrm.ai. We'll delete your account data within the retention window in Section 7, except what we're required to keep by law (e.g., billing records).
9. If you're a contact, not an account holder
If someone else's Rare journal contains information about you, Rare is processing that information as their service provider, on their instructions — we don't control why they collected it or what they use it for. To exercise a right over that data (see, correct, or ask to have it deleted), the right place to start is the account holder who wrote it. If you're unable to resolve it with them, you can contact us at contact@rarecrm.ai and we'll pass on requests we're able to act on consistent with our obligations to our customer and the law.
10. Your rights
Depending on where you are, you may have the right to:
- access the personal information we hold about you;
- correct inaccurate information;
- request deletion, subject to legal retention requirements;
- withdraw consent (e.g., disconnect Google sync, opt out of product email) without affecting the lawfulness of processing before that;
- (California/CCPA) know what personal information is collected, request its deletion, and not be discriminated against for exercising these rights;
- complain to a supervisory authority — in Canada, the Office of the Privacy Commissioner.
To exercise any of these, email contact@rarecrm.ai. For account data, we handle this directly. For journal content about you specifically as a third party, see Section 9.
11. Security
We use technical and organizational measures appropriate to the sensitivity of the data — encryption in transit, access controls scoped per tenant, and versioned, auditable storage. No system is perfectly secure, and we can't guarantee absolute security.
12. Children
The Service isn't directed at children, and we don't knowingly collect personal information from anyone under 18 (or the age of majority in their jurisdiction). If you believe a child has provided us information, contact us and we'll delete it.
13. Changes to this policy
We may update this policy as the Service evolves. For a material change, we'll give notice — for example, by email or an in-product notice — before it takes effect.
14. Contact
Questions, requests, or complaints about this policy: contact@rarecrm.ai.
This document works together with the Terms of Service and the Subprocessors page. Where this policy and the Terms conflict on how personal information is handled, this policy controls.