Skip to content

PRIVACY POLICY · EFFECTIVE 1 AUGUST 2026

Your data stays yours.

The short version: we collect the minimum needed to run RICS, we never sell it, and we never use your discovery data to train models. Ever.

RICS has not launched. There is no product and there are no accounts. The only personal data we hold today is what you have sent us directly — a waitlist entry or a contact-form message. Anything below marked at launch describes what will apply when the product ships, not what happens now.

1. Who we are

RICS is built by The OneCluster Lab Limited ("OneCluster", "we", "us"). OneCluster is the data controller for all personal data described in this policy, and decides why and how it is processed.

To reach the controller about anything on this page, write to privacy@rics.dev. That address goes to the founders.

2. What we collect

Today, if you join the waitlist: your email address, and — only if you choose to give them — your company, role, team size, and region, plus whether you asked to be a design partner. We also record which page the signup came from, your browser's user-agent string, and the country your request came from, which our CDN supplies. If you use the contact form we store your name, email, topic, and message.

At launch we will also hold account data (name, work email, company, role), product data (the recordings, transcripts, and briefs you upload or generate), and usage data (which features you use, so we know what to fix).

We do not collect device fingerprints, advertising identifiers, or anything from third-party data brokers. This site runs no analytics or advertising trackers.

3. What we never do

We never use your discovery data to train AI models — ours or anyone else's.

We never sell or rent your data to anyone.

We never read your briefs except when you explicitly ask us to for support.

We never run advertising or share data with ad networks.

4. Where your data lives

At launch, data is stored in the EU by default, with Africa-region storage available on request for teams with data-residency requirements.

Today, the waitlist and contact records sit in a managed database run by Cloudflare, our hosting provider. If the storage region matters to you, ask privacy@rics.dev before you sign up and we will tell you exactly where it is. See Data-handling for the full storage and retention detail.

5. Your rights

Where NDPR, GDPR, or POPIA applies, you have the rights those laws grant — access, correction, erasure, portability, and objection — and we honour them for everyone regardless of jurisdiction.

Today there is no product and no settings screen, so there is exactly one route and it works: email privacy@rics.dev. Ask for a copy of everything we hold on you, ask us to correct it, or ask us to delete it. We reply within two working days and complete the request within 30 days, backups included. You do not have to give a reason, and deleting your waitlist entry costs you nothing but your place in the queue.

At launch, self-serve export, correction, and deletion arrive in settings — no email required. Until then, email is the mechanism, and we would rather tell you that than point you at a screen that does not exist.

6. Questions

Write to privacy@rics.dev. A founder answers within two working days.

RICS ships to design partners in Q1 2027. If this is the kind of policy you want to be governed by, join the waitlist.