Privacy Policy
Effective Date: April 6, 2026
1. Introduction
Welcome to RipeText. This Privacy Policy is provided by nibnab, Inc., a Delaware corporation doing business as RipeText ("RipeText," "we," "us," or "our"). This Privacy Policy describes how we collect, use, disclose, and otherwise process personal information in connection with our website, platform, and related services (collectively, the "Service"), as well as your rights and choices regarding such information.
RipeText is an AI-powered customer support analytics platform that helps organizations analyze support conversations, extract insights, identify trends, and improve the quality of their customer service operations. By accessing or using our Service, you acknowledge that you have read, understood, and agree to the practices described in this Privacy Policy. If you do not agree with this Privacy Policy, please do not access or use our Service.
This Privacy Policy applies to all users of the Service, including organizational administrators, team members, and any other individuals who interact with our platform. It covers information collected through our website, application, APIs, and any other means through which you may interact with RipeText.
2. Information We Collect
We collect information in several ways depending on how you interact with our Service. The categories of information we collect include the following:
2.1 Account Information
When you create an account on RipeText, we collect personal information necessary to establish and maintain your account. This includes your name, email address, and profile picture. You may register using Google Single Sign-On (SSO), in which case we receive your name, email address, and profile image from Google, or via Magic Link email authentication, in which case we collect the email address you provide. We store authentication session data in our database to manage your access to the Service.
2.2 Organization Data
RipeText operates on an organization-based model. When you create or join an organization, we collect the organization name and manage member roles and permissions within that organization. This information is used to facilitate collaboration and access control within your team.
2.3 Support Platform Data
The core functionality of RipeText involves ingesting and analyzing customer support data from third-party platforms. When you connect your support platform accounts, we collect data from the following integrated systems:
- Zendesk: Support tickets, conversations, messages, agent metadata (names, roles, performance metrics), and customer metadata (names, email addresses, interaction history).
- Intercom: Conversations, messages, agent metadata, customer metadata, and related support interaction data.
- Front: Conversations, messages, agent metadata, customer metadata, and associated communication records.
This data is connected via OAuth authorization and webhooks. When you authorize a connection, you grant RipeText permission to access and retrieve data from the respective platform on your behalf. Webhook integrations enable real-time data synchronization, allowing RipeText to receive new conversations and updates as they occur in your support platform.
2.4 Usage Data and Analytics
We automatically collect information about how you interact with our Service. This includes pages visited, features used, actions taken, time spent on the platform, browser type, device information, IP address, and referring URLs. We use the following analytics services to collect and process this data:
- PostHog: Product analytics including feature usage, user flows, and behavioral data.
- Google Analytics: Website traffic analysis, user demographics, and engagement metrics.
- Vercel Speed Insights: Performance monitoring including page load times and web vitals.
2.5 Error Tracking Data
We use Sentry for error tracking and application performance monitoring. When errors occur, Sentry may collect technical information including error messages, stack traces, browser and device information, and the state of the application at the time of the error. This data is used solely for diagnosing and resolving technical issues.
2.6 Payment Information
We use Stripe as our payment processor. When you subscribe to a paid plan, your payment card details are collected and processed directly by Stripe. We do not receive or store your full credit card number, CVV, or other sensitive payment card data. We retain only your Stripe customer ID, subscription status, and billing history to manage your account and provide customer support related to billing inquiries.
3. How We Use Your Information
We use the information we collect for the following purposes:
3.1 Providing and Operating the Service
We process your support platform data using artificial intelligence and machine learning to deliver the core features of RipeText, including:
- AI-powered analysis of customer support conversations to surface actionable insights.
- Topic generation to automatically categorize and cluster support interactions by subject matter.
- Issue extraction to identify recurring customer problems and pain points.
- Agent evaluation to assess support representative performance and identify areas for improvement.
- Training recommendations to suggest targeted coaching and development opportunities for support teams.
- Sentiment analysis to gauge customer satisfaction and emotional tone across interactions.
- Anomaly detection to alert you to unusual patterns or spikes in support volume, sentiment, or other key metrics.
3.2 AI and Machine Learning Processing
To power our analytical capabilities, we send conversation data to third-party AI providers, specifically OpenAI and Anthropic, via their APIs. These providers process the data to generate analysis results, summaries, and insights. Additionally, we generate vector embeddings of conversation data and store them in a Weaviate vector database to enable semantic search functionality, allowing you to find relevant conversations based on meaning rather than exact keyword matches.
3.3 Improving the Service
We use usage data and analytics to understand how users interact with our platform, identify areas for improvement, develop new features, optimize performance, and enhance the overall user experience. We may also use aggregated, de-identified data for research and development purposes.
3.4 Communications
We use your email address to send transactional communications related to your account and use of the Service, such as account verification, magic link authentication emails, subscription confirmations, billing receipts, and important service updates. Transactional emails are delivered through Postmark. We may also send you product announcements and feature updates, from which you may opt out at any time.
3.5 Payment Processing
We use Stripe to process subscription payments. Your payment information is transmitted directly to Stripe and is subject to Stripe's privacy policy. We use your Stripe customer ID and subscription status to manage your access to paid features and maintain billing records.
4. Data Sharing and Third-Party Services
We do not sell your personal information. We share information with third parties only as described in this Privacy Policy and as necessary to provide and improve the Service. The following categories describe the third-party services with which your data may be shared:
4.1 AI Processing Providers
We transmit customer support conversation data to OpenAI and Anthropicvia their respective APIs for the purpose of AI-powered analysis, insight generation, and natural language processing. Data sent to these providers is used solely to generate responses and analysis for your account and is subject to each provider's data processing agreements and privacy policies.
4.2 Cloud Infrastructure
Our Service is hosted on cloud infrastructure provided by Amazon Web Services (AWS) and Google Cloud Platform (GCP). AWS S3 is used for object storage, and GCP provides additional compute and service infrastructure. These providers process data on our behalf pursuant to their respective data processing agreements.
4.3 Analytics Providers
We share usage data with PostHog for product analytics, Google Analytics for website traffic analysis, and Vercel Speed Insights for performance monitoring. These services receive information about your interactions with our Service to help us understand usage patterns and improve performance.
4.4 Error Tracking
Sentry receives technical error data, including stack traces, browser information, and application state at the time of errors, to help us identify and resolve issues with the Service.
4.5 Payment Processing
Stripeprocesses all payment transactions. When you provide payment information, it is transmitted directly to Stripe and is subject to Stripe's privacy policy and PCI-DSS compliance standards.
4.6 Email Services
Postmark is used to deliver transactional emails, including magic link authentication emails, account notifications, and billing communications. Postmark receives recipient email addresses and email content necessary to deliver these messages.
4.7 Support Platform Integrations
When you connect your accounts on Zendesk, Intercom, or Front, bidirectional data exchange occurs via OAuth-authenticated API connections and webhook integrations. This enables RipeText to ingest your support data for analysis and, where applicable, to provide functionality that interacts with your support platform.
4.8 Other Third-Party Services
- Slack: We may send webhook notifications to Slack channels you configure, containing alerts and summaries related to your support data analysis.
- Calendly: Scheduling links may be provided for demos or support calls. Calendly collects scheduling information subject to its own privacy policy.
4.9 Legal and Compliance Disclosures
We may disclose your information if required to do so by law or in the good faith belief that such action is necessary to comply with a legal obligation, protect and defend our rights or property, prevent fraud, protect the personal safety of users of the Service or the public, or protect against legal liability.
5. Data Storage and Security
We take the security of your data seriously and implement industry-standard technical and organizational measures to protect the information we collect and process.
5.1 Data Storage Infrastructure
Your data is stored using the following systems:
- PostgreSQL: Our primary relational database, used to store account information, organization data, ingested support data, and application state.
- Weaviate: A vector database used to store conversation embeddings that power semantic search and similarity-based retrieval features.
- Redis: An in-memory data store used for caching, session management, rate limiting, and transient operational data.
5.2 Hosting and Deployment
Our Service is hosted on cloud infrastructure provided by Amazon Web Services (AWS) and Google Cloud Platform (GCP). Our application is deployed and managed using Kubernetes, which provides automated scaling, self-healing, and secure orchestration of our service components.
5.3 Security Measures
We implement the following security measures to protect your data:
- Encryption in transit: All data transmitted between your browser and our servers, and between our internal services and third-party providers, is encrypted using TLS (Transport Layer Security).
- Access controls: Role-based access controls ensure that users can only access data within their authorized organization and permission level.
- Infrastructure security: Our Kubernetes-managed deployment includes network policies, resource isolation, and automated security patching.
- Third-party security: We select third-party service providers that maintain robust security practices and compliance certifications.
While we strive to protect your personal information, no method of transmission over the Internet or method of electronic storage is completely secure. We cannot guarantee the absolute security of your data, but we are committed to implementing and maintaining reasonable safeguards appropriate to the sensitivity of the information we process.
6. Data Retention
We retain your personal information for as long as your account is active or as needed to provide you with the Service. The specific retention periods depend on the type of data and the purpose for which it was collected:
- Account information is retained for the duration of your active account and for a reasonable period thereafter to fulfill legal obligations and resolve disputes.
- Ingested support data is retained for as long as your organization maintains an active subscription and the relevant integration remains connected.
- Analytics and usage data is retained in accordance with the retention policies of the respective analytics providers (PostHog, Google Analytics, Vercel Speed Insights).
- Error tracking data is retained by Sentry in accordance with their data retention policies, typically for a limited period sufficient for debugging purposes.
- Payment records are retained as required by applicable tax and financial regulations.
Upon account deletion or at your request, we will delete or anonymize your personal information within thirty (30) days, except where retention is required by law or for legitimate business purposes such as fraud prevention or compliance with legal obligations. Ingested support data, vector embeddings, and cached data associated with your organization will be permanently removed from our systems, including PostgreSQL, Weaviate, and Redis, within this same period. Backup copies may persist in encrypted backups for up to an additional sixty (60) days before being automatically purged.
7. Your Rights
Depending on your location and applicable law, you may have certain rights regarding your personal information. We are committed to honoring these rights and will respond to valid requests in a timely manner.
7.1 General Rights
All users of our Service have the following rights:
- Right to Access: You may request a copy of the personal information we hold about you.
- Right to Correction: You may request that we correct inaccurate or incomplete personal information.
- Right to Deletion: You may request that we delete your personal information, subject to certain legal exceptions.
- Right to Data Portability: You may request a machine-readable copy of your personal information for transfer to another service.
7.2 California Residents (CCPA)
If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA), including:
- Right to Know: You may request that we disclose the categories and specific pieces of personal information we have collected about you, the categories of sources from which it was collected, the business purpose for collecting it, and the categories of third parties with whom we share it.
- Right to Delete: You may request deletion of your personal information, subject to certain exceptions permitted by law.
- Right to Opt Out of Sale: We do not sell personal information. However, if our practices change, you will have the right to opt out of any sale of your personal information.
- Right to Non-Discrimination: We will not discriminate against you for exercising any of your CCPA rights.
7.3 European Residents (GDPR)
If you are located in the European Economic Area (EEA), the United Kingdom, or Switzerland, you may have additional rights under the General Data Protection Regulation (GDPR) or equivalent legislation, including:
- Right to Restrict Processing: You may request that we restrict the processing of your personal information in certain circumstances.
- Right to Object: You may object to our processing of your personal information where we rely on legitimate interests as our legal basis.
- Right to Withdraw Consent: Where we process your personal information based on consent, you may withdraw your consent at any time without affecting the lawfulness of processing carried out prior to withdrawal.
- Right to Lodge a Complaint: You have the right to lodge a complaint with your local data protection supervisory authority.
To exercise any of these rights, please contact us at info@ripetext.com. We will respond to your request within thirty (30) days, or within the timeframe required by applicable law. We may ask you to verify your identity before fulfilling your request.
8. Cookies and Tracking Technologies
We use cookies and similar tracking technologies to operate and improve our Service. Cookies are small data files stored on your device that help us recognize your browser and capture certain information.
8.1 Types of Cookies We Use
- Essential Cookies: These cookies are necessary for the Service to function properly. They include session management cookies that maintain your authenticated state and enable secure access to your account. You cannot opt out of essential cookies as they are required for the Service to operate.
- Analytics Cookies: We use cookies from PostHog and Google Analytics to collect anonymized data about how users interact with our Service. This includes information about pages visited, features used, session duration, and navigation paths. These cookies help us understand user behavior and improve our platform.
- Performance Cookies: Vercel Speed Insights uses cookies and tracking scripts to monitor the performance of our website, including page load times and Core Web Vitals metrics.
8.2 Managing Cookies
Most web browsers allow you to manage your cookie preferences through browser settings. You can set your browser to refuse cookies or to alert you when cookies are being sent. Please note that if you disable essential cookies, certain features of the Service may not function properly. For analytics cookies, you may opt out through the respective provider's opt-out mechanisms.
9. Children's Privacy
Our Service is not directed at individuals under the age of sixteen (16). We do not knowingly collect personal information from children under 16. RipeText is a business-to-business platform designed for use by organizations and their authorized adult representatives. If we become aware that we have inadvertently collected personal information from a child under 16, we will take steps to delete such information promptly. If you believe that a child under 16 has provided us with personal information, please contact us immediately at info@ripetext.com so that we can take appropriate action.
10. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technologies, legal requirements, or other factors. When we make material changes to this Privacy Policy, we will notify you by updating the "Effective Date" at the top of this page and, where appropriate, providing additional notice such as an email notification or a prominent notice within the Service.
We encourage you to review this Privacy Policy periodically to stay informed about how we are protecting your information. Your continued use of the Service after any changes to this Privacy Policy constitutes your acceptance of the updated policy. If you do not agree with the revised Privacy Policy, you should discontinue use of the Service and contact us to request deletion of your account and associated data.
11. Contact Information
If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us using the information below:
nibnab, Inc. dba RipeText
Attn: Nikolay Tsenkov, CEO
2810 N Church St PMB 89178
Wilmington, DE 19802-4447
United States
Email: info@ripetext.com
Phone: +1 (302) 990-0582
We will make every effort to respond to your inquiry within thirty (30) days. For requests related to the exercise of your privacy rights, please include sufficient information for us to verify your identity and specify the nature of your request.