Last updated 29 July 2026
NextGen Software Ltd trading as Ratelytics (“Ratelytics”, “we”) operates ratelytics.io. This policy says what we collect, why, where it lives, and how to take it away. It is written to be read.
Ratelytics has read-only access to usage metadata. No prompt or content data is ever collected: the keys you connect are not capable of exposing it.
Provider keys and webhook URLs are encrypted at rest with AES-256-GCM under a key held only in the server environment, decrypted server-side at sync time, displayed masked, and stripped from logs by a redaction layer. Deleting a connection destroys its key immediately.
Contract (running the service you signed up for), steps taken at your request before entering a contract (the free autopsy teaser: you ask for it by choosing a file, and it exists only to show you what the paid report would contain), legitimate interest (security, abuse prevention including the hourly upload caps described above, product analytics), and consent where required (marketing emails: each has a one-click unsubscribe). Affiliate details are held on the basis of contract — the referral agreement between us — and, for the payout records specifically, legal obligation, because we are required to keep records of money we have paid out.
Data lives as long as your workspace does. Deleting a workspace (Settings → Data, typed confirmation) hard-deletes every row and key after a 24-hour cancellation window, confirmed by email. The full CSV export is available on every plan, any time.
Affiliate records do not follow a workspace, because an affiliate does not have one. If you leave the referral programme we delete your payout method and payout reference on request and stop using your details for anything else. We keep the record of commissions and payouts already made for six years, which is the period UK company records must be retained for; that record is the amounts and dates, and it is kept because it is an account of money that moved.
The abuse-prevention counts described above are deleted by the same hourly job, and are never retained beyond the two hours the hourly cap needs. They are not exported, not shared, and not used for anything except refusing the next upload.
The free autopsy teaser is the one thing that exists before a workspace does, so it has its own rule. The uploaded file itself is never stored. The computed findings are deleted within two hours of being produced, whether or not you buy, by the same hourly job that runs every other deletion. Two hours is not an arbitrary figure: it is the one-hour lifetime we set on the payment page, plus the hourly clean-up’s worst-case wait before it collects the row. To remove a teaser sooner, close the tab and email privacy@ratelytics.io with the reference shown on the result page; there is no account to sign in to, so that reference is the only way we can find it.
The UK GDPR set: access, rectification, erasure, portability, restriction, objection. Most are self-serve (export, delete); for the rest, email privacy@ratelytics.io. If you used the free autopsy teaser there is no account to sign in to, so quote the reference from the result page and we will delete it on receipt. Otherwise it goes on its own within two hours. You may also complain to the ICO.
This policy and any dispute under it are governed by the laws of England and Wales, and NextGen Software Ltd trading as Ratelytics is the data controller.
Material changes are announced by email and in the changelog before they take effect. The date at the top is the date that counts.