Privacy Policy

Last Updated: August 21, 2026 | Effective Date: August 21, 2026
Local-First Data Sovereignty Ethos: Rake is designed from the ground up as a data-sovereign application. Your operational records—including timesheets, billable rates, client names, invoice totals, and tax calculations—are stored strictly on your local device. We do not upload, host, track, or sell your local operational business data.

1. Our Commitment to Privacy

We are committed to protecting your privacy in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs). Where applicable to international users, we also respect global data protection standards, including the General Data Protection Regulation (GDPR) and California Consumer Privacy Act (CCPA).

This Privacy Policy explains how Rake handles data, what limited information is processed on central servers, and the rights you hold regarding your personal information.

2. Architectural Separation: Local Data vs. Server Data

2.1 Local Device Storage (Your Sovereign Data)

The vast majority of data generated when using Rake remains localized entirely on your hardware within your browser's IndexedDB database. This includes:

Provider has zero visibility into, access to, or central backups of this local database.

2.2 Server-Side Data Collection

To deliver software licensing, facilitate account authentication, process payments, and ensure platform stability, we collect and process limited information on our secure servers:

Data Category When Collected Primary Purpose Retention Period
Account & Billing Info
(Email, Name, Company, ABN)
Account creation, trial activation, or purchase License entitlement, transactional receipts, billing support via Stripe Duration of active account + 12 months after cancellation
Cryptographic License Data
(License Key, Tier status)
Software activation & periodic check-in Verifying subscription entitlement and access rights Duration of active license
Error Telemetry
(Stack traces, browser type)
When application encounters an unhandled exception Identifying software bugs, stability improvements, performance optimization 90 days (auto-pruned)
Product Feedback
(Ratings, text comments)
Voluntarily submitted via in-app feedback dialog Product roadmap development and quality assurance Indefinitely (or until user requests deletion)
Server Security Logs
(Hashed IP, requested path, User-Agent)
Visiting landing page or API endpoints DDoS mitigation, rate limiting, and security auditing (raw IPs are hashed) 90 days (auto-pruned)
Email Delivery Logs
(Recipient email, delivery status)
Sending license keys or password receipts Audit trail, proof of delivery, anti-spam compliance 12 months (auto-pruned)

3. AI Features and Third-Party Data Processing

3.1 Integration with Google Gemini API

Rake offers optional AI-assisted tools (such as automated work log summaries, invoice item description formatting, and project health checks) powered by Google Gemini API.

3.2 Data Flow and Processing Constraints

When you trigger an AI action, specific text context (e.g., project titles, work log task descriptions) is transmitted over encrypted TLS directly to Google's API servers for processing. We enforce the following privacy constraints:

4. Cookies, Tracking, and Analytics

4.1 Zero Ad Tracking

We do not sell advertising space, nor do we employ third-party tracking pixels (such as Meta Pixel or Google Ads tracking), invasive cross-site scripts, or commercial data brokers.

4.2 Essential Cookies and Local Storage

We use a minimal set of essential cookies and local storage tokens:

5. Information Sharing and Third-Party Service Providers

We will never sell, rent, or trade your personal information. We disclose limited server-side data only to trusted third-party service providers bound by strict confidentiality and security obligations, including:

6. Data Security Measures

We employ robust technical and organizational security controls to safeguard data:

7. Your Privacy Rights and Data Control

Under the Australian Privacy Principles (APPs) and applicable privacy laws, you possess clear rights over your data:

8. International Data Transfers

Server-side account and transaction records may be hosted on secure servers located in Australia or with international cloud providers adhering to recognized privacy safeguards (such as Standard Contractual Clauses). By using the Service, you consent to this transfer under equivalent privacy protection standards.

9. Children's Privacy

Rake is designed for business professionals and independent consultants. The Software is not intended for use by persons under 18 years of age, and we do not knowingly collect personal information from children.

10. Changes to This Privacy Policy

We may update this Privacy Policy periodically to reflect changes in our software features, legal requirements, or operational practices. Updated versions will be published on our website with a revised "Last Updated" date.

11. Contact Our Privacy Lead

For any questions, requests, or privacy concerns regarding Rake, please contact:

Rake Privacy & Data Protection
Email: connect@getrake.au
Website: https://getrake.au