Raven Privacy Policy
Effective date: 2026-09-27
1. Who we are and what this covers
Raven is run by cch137, an individual developer ("we", "us"). This policy covers the Raven website at raven.cch137.com and its sign-in site, the minion agent and the Wisp browser extension (together, "Raven").
We keep what your account and your work need. Each request to an AI model is sent to the provider that serves it. We show no ads and sell no data. Raven runs no analytics trackers and currently takes no payments.
The Terms of Service govern your use of Raven.
2. Data we collect
| Category | What it includes | Where it comes from |
|---|---|---|
| Account | Email address, username, password (stored only as a hash), roles | You, when you sign up or change them |
| Sign-in and security | Sessions, IP address, browser, operating system, user agent, and a browser fingerprint computed on the sign-in page | Your browser, when you sign in and use Raven |
| Content | Conversations (messages, attachments, tool calls and results), files in Raven Cloud, memory entries, projects, wiki pages, Study materials, Pipe automations and their runs, Imagine images, settings | You, and the tools and agents you use |
| Credentials you store | Secrets and your own AI provider keys or sign-ins, kept encrypted | You |
| Usage and billing | For each billed request: feature, model, token counts and cost; your credit balance, grants and promo codes you redeemed | Raven, as you use it |
| Devices | What minion and Wisp report about the machines and browsers you connect (see sections 12 and 13) | minion and Wisp |
Raven uses cookies only to keep you signed in and to remember interface preferences. It uses no advertising or tracking cookies.
3. How we use data
We use data to:
- provide Raven: answer your requests, run the tools and agents you ask for, and store your work;
- bill usage against your credits;
- keep accounts secure and detect abuse and automated sign-ups;
- send service email, such as verification codes and notices about Raven or this policy;
- fix problems you report.
We do not sell data, use it for advertising, or train AI models on it.
We do not read your content as a matter of course. We access stored data only when you ask us to (for example, to look into a problem with a specific conversation), to investigate security or abuse, or when the law requires it.
4. Who receives data
We share data with the service providers below, as far as each needs for its role.
| Recipient | Purpose | Data it receives |
|---|---|---|
| Anthropic, OpenAI, Google, xAI, Groq | AI models | The content of each request, including tool results such as pages read through Wisp or files an agent opens |
| Modal | Hosting for models we run ourselves | The same, for requests to those models |
| Brave Search | Web search | Search queries |
| Cloudflare | Network and protection for our domains | All traffic to and from Raven |
| Google (Gmail) | Sending email | Your email address and the message |
Raven also uses these models for background work on your content, such as titles and summaries. When you connect your own provider key or account, requests that use it go to that provider under your account and its terms.
Data also reaches:
- Websites that you or an agent fetch, which receive the request from our servers;
- Anyone with a share link you create, who can see the shared part of a conversation until you revoke the link;
- Authorities, when the law requires it;
- A successor, if Raven is transferred to another operator, who takes over this policy for the data collected under it.
5. How long we keep data
The periods below describe how Raven works today. They are approximate and may change with this policy.
| Data | Kept |
|---|---|
| Account, content, credentials, billing records | Until you delete them or your account |
| Deleted conversations | 30 days in the trash, then permanently deleted with the files only they use; you can delete them sooner from the trash |
| Private conversations | Deleted about a minute after you leave; they never enter the trash |
| Sessions and security records | 180 days after the session ends or the record is made |
| Verification codes and sign-in links | 1 day after they expire |
| Text extracted from your files for reading and search | 7 days |
When you delete your account, its data is deleted right away and the stored file contents shortly after. Two things remain: entries you added to a memory container someone else shares with you stay in it without your name, and data already sent to an AI provider is kept under that provider's terms. Deleted data may remain in backup copies until they are replaced.
6. Your choices and rights
- Correct your username, email and password on the account page of the sign-in site.
- Delete conversations, files and other content where they appear in Raven.
- Delete your account on the account page. This deletes your data as described in section 5 and cannot be undone.
- Get a copy of your data, or ask about what we hold, by emailing us from your account's address.
- Ask us to correct, delete or stop processing specific data.
Raven is run by one person, so we reply as soon as we reasonably can. We may ask you to confirm that the account is yours.
7. Where data is processed
We run Raven's servers ourselves. The providers in section 4 process data in their own facilities, which for most of them include the United States. Using Raven means your data may be processed outside your country.
8. Security
All traffic uses HTTPS. Passwords, sign-in tokens and API tokens are stored as hashes, and stored secrets and provider credentials are encrypted. Access to production systems is limited to the operator. No system is perfectly secure, so we cannot guarantee that data will never be exposed.
9. Children
Raven is not for children under 13, and we do not knowingly collect their data. If you believe a child has an account, email us and we will delete it.
10. Changes to this policy
We change this policy by publishing a new version here with a new effective date. For a significant change, we will try to let you know in advance, for example by email or in Raven.
11. Contact
This policy is also published as Markdown at gateway.cch137.com/privacy.md.
12. Supplement: minion
minion connects a computer you choose to Raven. It reports the machine's name, hostname, operating system and version, architecture, OS user name and minion version. It also serves a random token on a loopback port of the computer and reports that port and token, so Raven can tell which of your browsers run on the same computer. Commands an agent runs on it, their output and the files it reads become part of the conversation, and are handled like any other content.
13. Supplement: Wisp
Wisp is a browser extension that lets agents in your own Raven Build conversations use your browser. Which sites a conversation may reach is approved in Raven. Wisp acts only while you are signed in to it and have not pressed Stop, and it sends Raven:
- the titles and addresses of your open tabs outside incognito windows;
- the text and interactive elements of the pages the agent reads, screenshots of its own tabs, and the text of page dialogs in them;
- the device name, browser name and version, operating system and architecture;
- the tokens it reads from the loopback ports Raven names, which tell Raven which of your minion machines run on the same computer.
This data becomes part of the conversation. In your browser, Wisp keeps its sign-in token, device ID, pending results and a list of recent actions; removing the extension deletes them. Sign out revokes its token, and Forget also removes the device from Raven. Wisp does not export cookies or read your browsing history.
The use of information received from Wisp adheres to the Chrome Web Store User Data Policy, including the Limited Use requirements.