DATA-HANDLING
Where your data goes, exactly.
The lifecycle of a recording from upload to deletion — spelled out, because "trust us" is not a data policy.
RICS has not launched, so this is the design, not a log. No recording has ever been uploaded to RICS. Steps 01–05 below describe what will happen to a recording when the product ships. The only data we hold today is waitlist entries and contact-form messages — covered under Retention, Subprocessors, and Export below.
The lifecycle of one upload
Upload
Your recording travels over TLS and is encrypted at rest the moment it lands in your workspace's isolated storage partition. It is not end-to-end encrypted: we hold the keys, because the service has to transcribe and summarise the audio to be of any use. If you need encryption we cannot read through, RICS is not that product — and we would rather say so here than hedge.
Processing
Transcription and brief generation run in-region. We will only contract with model providers on zero-retention terms — nothing stored, nothing used for training on their side — and we will name every one of them in the subprocessor list before launch. Those contracts are not signed yet, because there is nothing to process.
Storage
Brief, transcript, and source recording live encrypted in your chosen region — EU by default, Africa-region on request. You can delete the source recording and keep only the brief.
Sharing
A shared brief URL exposes the brief only — never the source recording. Links are revocable; revocation is immediate.
Deletion
Delete anything — one brief or the whole workspace — from settings. Hard-deleted from primary storage immediately, from backups within 30 days. We confirm when it's done. Until settings exist, deletion runs by email: privacy@rics.dev.
Retention defaults
At launch, these are the defaults the product ships with. Briefs and transcripts: kept until you delete them. Source recordings: kept 90 days by default, then auto-deleted — configurable per workspace, including keep-forever and delete-on-brief-generation. The 90-day default and the keep-forever option apply to the source recording only; a brief you have kept is never deleted on a timer. Usage logs: 12 months.
Today, two rules are live. Waitlist entries: deleted on request, or 12 months after launch if you never sign up. Contact-form messages: kept while we deal with your enquiry, and deleted on request.
Subprocessors
Today there is one: Cloudflare, which serves this site and stores the waitlist and contact records. That is the whole list, and it is short because there is no product yet.
At launch we expect to add transcription, LLM inference, email, and payments, and we intend to keep the list at that. We have not published a formal subprocessor list yet — it goes up on this page, with the region for each entry, before the product ships. Ask privacy@rics.dev in the meantime and we will tell you what we are running. Once we have customers, we will give 30 days' notice before adding a subprocessor.
Your export path
At launch: full corpus export — briefs, transcripts, tags, and the 4x4 index — as JSON and Markdown, self-serve, no lock-in. If you leave RICS, your institutional memory leaves with you.
Today there is nothing to export but your waitlist entry. Email privacy@rics.dev and we will send you every field we hold against your address.
RICS ships to design partners in Q1 2027. If you want this lifecycle running on your calls, join the waitlist.