↗getratchet.
Home
GETRATCHET · LEGAL

Privacy and Data Use.

How GetRatchet handles account and tool execution data.

Updated September 25, 2026

What GetRatchet does

GetRatchet records and helps recover AI agent tool calls. An organization sends runs, steps, attempts, and worker information to the service so its members can inspect failures, retry eligible work, and understand service health. This notice describes the live product as of the date below.

Information we collect

For accounts, we store your email address, display name, password hash when you use password sign-in, organization membership, sessions, invitations, and security or audit events. For Google or GitHub sign-in, we obtain your provider account ID, verified email address, and display name to create or access your GetRatchet account. We do not store the provider access token after sign-in, and we do not access your Google Drive, Gmail, Calendar, or repositories through sign-in.

For tool operations, we store run and step metadata, status, timestamps, handler versions, retry policy, worker registrations, and attempts. The producer may send tool input, output, and error information. Dashboard views redact common sensitive field names and truncate previews. Durable job input and successful idempotency results are encrypted because the service needs them for recovery and duplicate responses. Redaction is a safeguard, not a guarantee that every secret in customer-provided text will be detected.

How we use information

We use account and OAuth data to authenticate you, link a provider only when you request it, manage organization access, and send account messages. We use execution data to queue and observe tool calls, retry or recover work that an authorized operator requests, show dashboard history, detect service failures, and protect the service against abuse. Google sign-in data is used for sign-in and account identity only; it is not used for advertising or sold.

External AI diagnosis and recovery planning are not active in the current product. We do not send your tool payloads to an AI provider as part of the current service.

Sharing and processors

The application runs on Vercel and stores operational data in Prisma Postgres. Resend delivers transactional email when configured. Google and GitHub process their own OAuth sign-in flows. These providers receive the information needed to provide their respective services. Members of your organization can see data according to their role and API keys. We do not sell personal information or tool data.

Retention and security

GetRatchet currently keeps account and execution history until it is removed by an authorized process or the organization requests deletion; automatic history expiry is not yet active. A successful idempotency lookup and replay depend on the retained record. Sessions and verification/reset links have shorter technical lifetimes. We use hashed passwords and API keys, secure cookies in production, tenant checks, and encryption for stored values required by durable recovery. No online service can guarantee absolute security.

Your choices

You can update your profile, manage sessions and linked sign-in providers, and ask us about access or deletion using the address below. Organization administrators control members and API keys. Unlinking a provider is blocked if it would remove your final sign-in method. If you want your organization data removed, contact us; we will verify authority and explain which records can be deleted while work is pending.

GetRatchet uses functional cookies for sessions, OAuth state, theme, and language. It does not use advertising cookies in the current product. We may update this notice when features or processors change and will update the date shown here.

Questions about these pages: getratchet@waelfz.com.

Privacy and Data Use | GetRatchet