Rhinal← Back

Privacy Policy

Last updated: 30th June 2026 · Version 1.1

1. Who is responsible for your data

Rhinal is operated by Ayan Mukhopadhyay, an individual based in India ("we", "us"). For privacy questions or requests, contact lynexlabsmedtech@gmail.com. This policy explains what we collect, why, and your rights, in line with India's Digital Personal Data Protection Act, 2023 (DPDP).

2. What we collect

  • Account/identity data: your name and email, via Google sign-in.
  • Integration tokens: an access token for your connected Notion workspace, so the Service can write records there on your behalf.
  • AI provider API keys (optional): if you provide your own keys, we store them encrypted to run the Service for you.
  • Your structured notes: distilled, structured records generated from your inputs are written to your own Notion workspace — we do not keep a copy of the full structured note on our servers.
  • Semantic embeddings (stored on our servers): we generate a vector embedding of each distilled summary using the Jina AI embedding model and store it in our Supabase database. This embedding is a numerical representation of meaning — it powers semantic search and the knowledge graph. The embedding does not contain your raw text verbatim, but it does encode semantic content.
  • Chat history (stored on our servers): every message you send to Rhinal and every assistant reply is stored in our Supabase database (ChatSession and ChatMessage tables). This allows your conversations to persist across page refreshes and devices.
  • Basic technical data: minimal data needed to operate and secure the Service (e.g. session info).

We do not intentionally collect patient-identifiable health data, and you are instructed not to input it (see Terms §5).

3. Why we collect it (purpose)

Solely to provide the Service: to authenticate you, connect your Notion, run the AI model that structures your thoughts, write structured notes to your Notion, power semantic search and the knowledge graph via stored embeddings, and persist your chat history across sessions. We do not sell your data. We do not use your content to train AI models. We do not use embeddings or chat history for any purpose beyond operating the Service for you.

4. How your data is stored and secured

  • Account data, integration tokens, semantic embeddings, and chat history are stored in our database provider (Supabase), hosted in the EU region.
  • Any AI provider API keys you give us are encrypted before storage (AES-256-GCM) and decrypted only momentarily, server-side, to run inference on your behalf.
  • Your structured notes (the full AI-generated record) live in your own Notion workspace, under your control — we do not duplicate them on our servers.
  • Semantic embeddings are numerical vectors derived from your notes' summaries. They are used only to power search and the knowledge graph within your account — we do not use them to train AI models or share them with third parties.
  • Chat messages are stored to provide conversation persistence. They are accessible only to you (scoped to your user ID) and are not used for any purpose other than displaying your history.
  • We take reasonable technical measures to protect your data, but no system is perfectly secure, and this is an early-stage product.

5. Who we share it with

We don't sell or rent your data. It is shared only with the service providers needed to run Rhinal: Google (sign-in), Notion (your storage), your chosen AI model provider (to process your inputs), and our hosting/database providers (Vercel, Supabase). Each processes data per their own policies. When you use a cloud AI model, your input text is sent to that provider to generate the output.

6. International transfers

Some providers process data outside India. By using the Service you understand your data may be processed in other countries by these providers.

7. How long we keep it

We keep your account data, integration tokens, semantic embeddings, and chat history while your account is active. When you delete your account, all data we hold about you — including semantic embeddings (VectorRecord), chat sessions and messages (ChatSession, ChatMessage), API keys, and your Notion token — is permanently and automatically deleted via cascade deletion in our database. No manual steps required. Your Notion records remain in your Notion workspace unless you remove them there.

8. Your rights (DPDP)

You have the right to: access the data we hold about you; correct it; withdraw consent; and request deletion of your account and associated data. To exercise any of these, contact lynexlabsmedtech@gmail.com and we will act on your request. You may also disconnect Google or Notion access at any time from those providers' settings.

9. Consent

We process your data based on the consent you give when you accept this policy at sign-up. You can withdraw consent at any time by deleting your account or contacting us; withdrawing consent means you can no longer use the Service.

10. Children

The Service is intended for users aged 18 and over and is not directed at minors. We do not knowingly collect data from anyone under 18.

11. AI processing notice

Rhinal uses AI models to process your inputs into structured records. Outputs are generated by AI and may be inaccurate — verify before relying on them. Depending on the model you select, processing happens either locally or via a third-party AI provider you choose.

12. Changes to this policy

We may update this policy. Material changes will require you to review and accept the updated version before continuing to use the Service.

13. Contact

Ayan Mukhopadhyay · lynexlabsmedtech@gmail.com

Data deletion

To delete your account and the data we hold, email lynexlabsmedtech@gmail.com with the subject "Delete my account". We will delete your account and the data we hold within a reasonable time. Records in your own Notion workspace must be deleted by you directly in Notion.