Legal
Privacy Policy
Railit is accounting software. That means the data you put into it is your business — every invoice, every salary, every supplier. This page says exactly what we collect, where it is kept, who else touches it, and how you get it back or get it deleted. No part of it is written to be skipped.
01The short version
The detail is below and the detail is what binds us. This is the same thing said in six lines.
- Your ledger is stored in Germany, on Amazon Web Services in Frankfurt. Not in Bahrain.
- When you use the AI agent, the parts of your ledger needed to answer are sent to OpenAI. That is how it works, and section 6 says precisely what goes.
- Card numbers are typed into Stripe's own fields and never reach us. We could not leak a card number we do not have.
- We do not sell data, and we do not use your books to advertise to you or anyone else. There is no second business model here.
- Railit sets no cookies, and the site carries no analytics or advertising trackers. Section 10.
- You can export everything, and you can ask us to delete it. Section 9.
One note on timing, because it matters for how you read the rest: This policy applies from the moment your account opens. It describes how the service handles your data, and we hold no data for anyone who has not opened an account, so nothing here is retrospective. It is the commitment that applies from the moment your account opens — it describes how the service is built and how it will treat your data, not a history of data we are already holding.
02Who we are
Railit is operated by JOIN FUTURE SOLUTIONS, LLC, a limited liability company registered in the State of Delaware, United States. Where this policy says "we", "us" or "Railit", that is the company it means, and it is the same company that appears on your card statement.
JOIN FUTURE SOLUTIONS, LLC
131 Continental Dr, Suite 305
Newark, DE 19713
United States
[email protected]
Controller, or processor — it depends which data
The distinction is not pedantry; it decides who you ask when you want something changed.
- Your account data — your name, your email, who is in your workspace, what you were billed — is data we decide the use of. For that we are the controller, and this policy is our promise to you about it.
- The business records you put into Railit — your customers, your suppliers, your employees and their pay — belong to your company. You decide what goes in and what it is for. You are the controller; we are your processor, acting on your instructions and on the instructions your team gives the software.
So if one of your customers asks you to delete their details, you can do that yourself inside Railit. If they write to us instead, we will tell them to ask you, and pass the message on.
03What we collect
What you give us to open an account
- Your name and email address, and a password stored only as a hash.
- Your company's name and the country it trades in.
- The people you invite, and the role you give each of them.
What you put into the ledger
Everything the software is for: invoices and quotations, expenses and bills, payments, bank accounts you record, customers and suppliers with their contact details, employees with their salaries and payroll history, contracts, and the documents you upload — receipts, statements, photographs of paperwork. Some of that is personal data about people who are not you, which is why section 2 matters.
What we record because software has to
- Technical logs: the IP address a request came from, the browser or app that made it, the time, and what it asked for. These exist to keep the service up and to spot someone trying to break into your account.
- An audit trail inside your workspace: who created, changed or approved a record, and when. In accounting this is a feature, not telemetry — it is how the books stay defensible.
- How much of your AI allowance a request consumed, so the meter in your dashboard is honest.
What we deliberately do not collect
- Card numbers. They are typed into fields hosted by Stripe. They never reach a Railit server. We store Stripe's identifiers for your customer record and subscription — not your card.
- Tracking data. No advertising pixels, no analytics scripts, no third-party tags. See section 10.
- Anything from your device beyond what you send us. Railit reads no contacts, no location, no files you have not uploaded.
04Why we use it, and on what basis
Under the GDPR every use of personal data needs a lawful basis. Here is ours, use by use, in plain language.
| What we do | Why | Lawful basis |
|---|---|---|
| Run your workspace — store the ledger, render documents, send what you ask us to send | It is the product you signed up for | Performance of a contract |
| Send your question and the relevant ledger records to OpenAI when someone uses the agent | The agent cannot answer without reading the books | Performance of a contract, on your instruction |
| Charge your subscription and keep the invoices | To be paid, and to keep the records tax law requires | Contract, and legal obligation |
| Keep logs, rate-limit, and investigate abuse | To keep the service standing and your account yours | Legitimate interests |
| Email you about your account — a failed payment, a trial ending, a security matter | You need to know | Contract, and legal obligation |
| Email you about new features or offers | Only if you said yes, and every message can turn it off | Consent |
| Answer a lawful order from a court or regulator | Because we must | Legal obligation |
Bahrain's Personal Data Protection Law (Law No. 30 of 2018) applies to most of our customers as well, and it asks the same questions in different words: data is processed for a stated, legitimate purpose, no more of it than that purpose needs, and not kept longer than the purpose lasts. The table above is written to satisfy both.
05Where your data is stored
Railit runs on Amazon Web Services in the Europe (Frankfurt) region, eu-central-1. Your database, your uploaded documents, the PDFs Railit renders and the encrypted backups of all of it are stored and processed in Germany.
The question everyone asks
Is my data in Bahrain? No. It is in Germany. Bahrain has no data-residency requirement that would forbid this for ordinary commercial bookkeeping, and Germany is one of the more strictly regulated places on earth to hold data — but if residency inside Bahrain is a condition of your business, Railit does not meet it today, and you should tell us before you buy rather than after.
Because the processing happens in the EU, the GDPR applies to it. Because you are most likely in Bahrain, the PDPL is engaged too. We do not treat those as competing regimes to be arbitraged; where they differ, we hold to whichever is stricter.
International transfers
Two things do leave the EU by design, and only because the service cannot be delivered otherwise: payment data goes to Stripe, and agent requests go to OpenAI — both companies operate from the United States. Those transfers are covered by the standard contractual clauses and equivalent safeguards in each provider's data processing terms. Section 7 names them and says what each receives.
06What the AI sees
This is the section most privacy policies bury. It is the honest centre of the product, so it is written out.
Railit's agent is powered by OpenAI. When someone in your workspace asks the agent a question, the content of your ledger relevant to that question is sent to OpenAI so it can answer. There is no version of this product where that does not happen — an assistant that cannot read your books is not an assistant.
What is sent
- The message that was typed or spoken to the agent.
- The records the agent's tools pulled from your ledger to answer it. If you asked about profit, that is revenue and expense totals. If you asked who owes you money, that is customer names and outstanding balances. If you asked about payroll, that is employee names and salary figures.
- The text and images of any document you hand it to read — a supplier invoice, a spreadsheet of staff, a photograph of a receipt.
- The draft entry it prepares back to you.
What is not sent
- Your password, in any form.
- Card details — we do not hold them to send.
- Records the agent did not need. It fetches what the question requires; it does not upload your database.
- Anything at all, when nobody is using the agent. There is no background process feeding your books to a model.
How it is sent, and what OpenAI may do with it
Requests go over an encrypted connection to OpenAI's API — the developer interface, not the consumer ChatGPT product, which has different terms. Under OpenAI's API terms, content sent through the API is not used to train their models by default, and we do not opt in to any such use. OpenAI retains API content for a limited period for abuse monitoring before deleting it, under their own published policy.
If you would rather nothing went to OpenAI
Then do not use the agent. The Starter plan includes no AI credits at all — the in-app assistant, the WhatsApp agent and the Telegram agent are not part of it — so on Starter nothing is sent to OpenAI by us. Starter does include the MCP server, which lets you connect your own AI tool (Claude, ChatGPT or another) to your ledger. If you do that, the records you ask for go to whichever provider you chose, under your agreement with them, not ours. The choice, and the disclosure, sit with you.
Whichever plan you are on, the agent proposes and you approve. Nothing it drafts touches your ledger until a person presses Apply.
07Who we share data with
We do not sell personal data, and we do not share it for anyone else's marketing. The companies below are our sub-processors: each one does a specific job Railit cannot do alone, each is bound by a contract to process data only on our instructions, and each is named so you can read their terms yourself.
| Who | What they do for Railit | What they receive |
|---|---|---|
| Amazon Web Services aws.amazon.com/privacy |
Hosting, database, file storage and backups — Europe (Frankfurt), eu-central-1 | Everything you store in Railit, held encrypted on their infrastructure. AWS does not read it; they run the machines it sits on. |
| Stripe stripe.com/privacy |
Subscription payments, invoices and the billing portal | Your name, email and billing address, the card details you enter into their hosted fields, and what you were charged. Stripe is certified to PCI DSS Level 1; card data is theirs to hold, not ours. |
| OpenAI openai.com/policies/privacy-policy |
The AI agent — the in-app assistant, and the WhatsApp and Telegram agents | The question asked, plus the ledger records and document contents needed to answer it. See section 6, which sets this out in full. |
Only if you switch them on
| Who | When | What they receive |
|---|---|---|
| Meta Platforms (WhatsApp Business Platform) | Only if you buy the WhatsApp add-on and connect a number | The messages exchanged on that number, and the phone numbers at both ends |
| Telegram | Only if you connect the Telegram agent | The messages and files sent to the bot, and the Telegram account that sent them |
| Our email delivery provider | Whenever Railit sends mail — an invoice to your customer, a notice to you | The recipient's address and the contents of the message |
We will name any new sub-processor on this page before it starts handling your data, and the "last updated" date at the top will move when we do.
Three other cases
- People you invite. Anyone in your workspace sees the workspace's data according to the role you gave them. That is your decision to make and to unmake.
- Legal compulsion. If a court or regulator with jurisdiction over us lawfully orders disclosure, we comply — and we tell you, unless we are forbidden from telling you.
- If the company is sold. Your data would transfer with the service to the acquirer, who would be bound by this policy until you were given notice and a chance to leave.
08How long we keep it
Accounting data is worth keeping and dangerous to hoard, so the rule is: as long as your account is open, plus a short, stated window after it closes.
| What | How long |
|---|---|
| Your ledger, documents and workspace | For as long as the workspace is open |
| After you cancel or close the account | 30 days in which you can still sign in to export or reopen. After that we delete it from live systems within a further 30 days. |
| Encrypted backups | Cycle out within 35 days, so deleted data is gone from backups within that window too |
| A trial that is never converted | Deleted on the same schedule as a closed account, counted from the day the trial ends |
| Agent conversations | Kept with the workspace, and deleted with it |
| Technical and security logs | 90 days |
| Our own invoices and payment records for what you paid us | 7 years, because tax and company law require it. This is billing data, not your ledger. |
| Marketing consent and unsubscribe records | Until you withdraw consent, plus a record that you did so |
If a period above cannot be met for a technical reason, we will change the number here rather than quietly miss it.
09Export, correction and deletion
Getting your data out
Your books are yours, and leaving is allowed. Every document Railit produces — invoices, quotations, payslips, statements, contracts — renders as a PDF you keep, and you do not need our permission or our help to take them. For a complete machine-readable copy of a workspace, email [email protected] and we will produce one; we do not charge for it and we do not ask why.
Correcting something
Most of it you can correct yourself in the app. Note that a posted accounting document is never silently edited — a correction is a reversal, and both entries stay visible. That is deliberate, it is what makes the books auditable, and it is not us refusing to fix your data. Your account details, your name and your email you can change at any time.
Deleting it
You can delete records inside your workspace, and you can ask us to delete the whole workspace. Write to [email protected] from the address on the account; we will confirm it is really you before we act, because a deletion request is the one instruction we cannot undo. Deletion then follows the schedule in section 8.
Two limits, stated rather than hidden: we keep our own billing records for the period tax law requires, and if the law obliges us to retain something for a live legal matter, we retain that and nothing else.
10Cookies and browser storage
Railit sets no cookies. Not on this website, and not in the application. There is no consent banner because there is nothing to consent to.
This site loads no analytics, no advertising tags, no social widgets and no third-party fonts — the typefaces are served from our own domain. Nobody is counting you.
When you sign in to the application, your browser's local storage holds two kinds of thing: the token that keeps you signed in, and small interface preferences such as whether the sidebar is collapsed and how wide you dragged the agent panel. Both live on your device, are readable only by railit.ai, and are cleared when you sign out or clear your browser data.
11Security
- In transit. Every connection to Railit is HTTPS, encrypted with TLS. There is no unencrypted route in.
- At rest. The database, uploaded files and backups are stored encrypted on AWS infrastructure in Frankfurt.
- Passwords. Stored as a one-way hash with a modern password-hashing algorithm. We cannot read your password, and neither can anyone who takes a copy of the database.
- Tenant isolation. Every database query in Railit is bound to exactly one organization at the framework level, not by remembering to write it into each query. A request that somehow arrived without an organization fails rather than returning something.
- Least access. Production access is limited to the engineers who need it, and administrative actions leave an audit record.
- Approval gates. The agent cannot post to your ledger. It can only propose, and a person applies.
What we do not claim
Railit holds no security certifications — not SOC 2, not ISO 27001, not PCI DSS. We are a young company and saying otherwise would be a lie you could check. What we can tell you is that card data is handled by Stripe, which is certified to PCI DSS Level 1, and never passes through our systems.
No system is perfect. If we discover a breach affecting your personal data, we will notify the relevant supervisory authority within 72 hours as the GDPR requires, and we will tell you directly and plainly where the breach is likely to put you at risk. If you think you have found a vulnerability, email [email protected] and we will answer.
12Your rights
Because your data is processed in the EU, the GDPR gives you these rights, and Bahrain's PDPL gives you closely equivalent ones. Either way, you exercise them the same way: email [email protected].
- Access — ask what personal data we hold about you and get a copy.
- Rectification — have inaccurate data corrected.
- Erasure — ask us to delete it, subject to the legal retentions in section 9.
- Portability — receive your data in a structured, machine-readable format, or have it sent onward.
- Restriction and objection — ask us to pause a use, or object to one we base on legitimate interests.
- Withdraw consent — where consent was the basis, take it back; it does not undo what was lawful before.
- Complain — to a data protection supervisory authority. In the EU or EEA that is the authority where you live, work, or where the issue arose. In Bahrain it is the national data protection authority. You do not have to come to us first, though we would rather you did.
We answer privacy requests within one month, which is the deadline the GDPR sets; if a request is genuinely complex we may extend that and will tell you why before the month is out. We do not charge for this. We will verify your identity first — usually by requiring the request to come from the email address on the account.
If your data is in Railit because a Railit customer put it there — you are their customer, supplier or employee — then they control it and your request belongs with them. Send it to us anyway if you do not know who they are; we will forward it and tell you that we have.
13Children
Railit is business software, sold to companies. It is not intended for anyone under 18, and we do not knowingly collect personal data from children. If you believe a child's data has reached us, write to [email protected] and we will remove it.
14Changes to this policy
We will change this page when the product changes — a new sub-processor, a new region, a new thing collected. When we do, the "last updated" date at the top moves. If a change materially affects how your data is handled, we will email the account owner before it takes effect rather than relying on you to re-read a web page. The current version is always at railit.ai/privacy.html.
15Contact us about privacy
Privacy questions, access requests, deletion requests and complaints all go to the same place, and a person reads them.
[email protected]
JOIN FUTURE SOLUTIONS, LLC
131 Continental Dr, Suite 305
Newark, DE 19713
United States
This policy is governed by the laws of the State of Delaware, United States, as set out in our Terms of Service — which does not take away any right the GDPR or the PDPL gives you.