Updated: April 18, 2026
HelloRaven (together with our affiliates, “Raven”, “we”, “our” or “us”) respects your privacy and is strongly committed to keeping secure any information we obtain from you or about you. This Privacy Policy describes our practices with respect to Personal Data that we collect from or about you when you use our website, applications, and services (collectively, “Services”).
This Privacy Policy does not apply to content that we process on behalf of customers of our business offerings, such as our API. Our use of that data is governed by our customer agreements covering access to and use of those offerings.
For information about how we collect and use training information to develop our language models that power Raven and other Services, and your choices with respect to that information, please continue to review the following.
1. Personal Data we collect
We collect personal data relating to you (“Personal Data”) as follows:
Personal Data You Provide: We collect Personal Data if you create an account to use our Services or communicate with us as follows:
* Account Information: When you create an account with us, we will collect information associated with your account, including your name, contact information, account credentials, date of birth, payment information, and transaction history, (collectively, “Account Information”).
* User Content: We collect Personal Data that you provide in the input to our Services (“Content”), including your prompts and other content you upload, such as files, images, and audio, depending on the features you use.
* Communication Information: If you communicate with us, such as via email or our pages on social media sites, we may collect Personal Data like your name, contact information, and the contents of the messages you send (“Communication Information”).
* Other Information You Provide: We collect other information that you may provide to us, such as when you participate in our events or surveys or provide us with information to establish your identity or age (collectively, “Other Information You Provide”).
Personal Data We Receive from Your Use of the Services: When you visit, use, or interact with the Services, we receive the following information about your visit, use, or interactions (“Technical Information”):
* Log Data: We collect information that your browser or device automatically sends when you use our Services. Log data includes your Internet Protocol address, browser type and settings, the date and time of your request, and how you interact with our Services.
* Usage Data: We collect information about your use of the Services, such as the types of content that you view or engage with, the features you use and the actions you take, as well as your time zone, country, the dates and times of access, user agent and version, type of computer or mobile device, and your computer connection.
* Device Information: We collect information about the device you use to access the Services, such as the name of the device, operating system, device identifiers, and browser you are using. Information collected may depend on the type of device you use and its settings.
* Location Information: We may determine the general area from which your device accesses our Services based on information like its IP address for security reasons and to make your product experience better, for example to protect your account by detecting unusual login activity or to provide more accurate responses. In addition, some of our Services allow you to choose to provide more precise location information from your device, such as location information from your device’s GPS.
* Cookies and Similar Technologies: We use cookies and similar technologies to operate and administer our Services, and improve your experience. If you use our Services without creating an account, we may store some of the information described in this policy with cookies, for example to help maintain your preferences across browsing sessions. For details about our use of cookies, please read our Cookie Notice.
Information We Receive from Other Sources: We receive information from our trusted partners, such as security partners, to protect against fraud, abuse, and other security threats to our Services, and from marketing vendors who provide us with information about potential customers of our business services.
We also collect information from other sources, like information that is publicly available on the internet, to develop the models that power our Services. For more information on the sources of information used to develop the models that power Raven and other Services, please review the following:
How Raven’s models are developed
Raven uses OpenAI’s foundation models that are developed using three primary sources of information: (1) information that is publicly available on the internet, (2) information that we partner with third parties to access, and (3) information that our users, human trainers, and researchers provide or generate.
We use OpenAI models as a basis for Raven’s Services for a wide range of tasks, including organizing and summarizing information, assisting with translations, analyzing or generating images, inspiring creativity and ideas, and other everyday activities. Raven is designed to understand and respond to user questions and instructions by learning patterns from large amounts of information, including text, images, audio, and video. During training, the model analyzes relationships within this data—such as how words typically appear together in context—and uses that understanding to predict the next most likely word when generating a response, one word at a time. Similarly, models that generate other forms of content, like images, learn patterns in how pixels relate to each other and to associated captions in the training data.
For example, during the model’s learning process (known as “training”), the model might be tasked with completing a sentence like: “Instead of turning left, she turned ___.” Early in training, its responses are largely random. However, as the model processes and learns from a large volume of text, it becomes better at recognizing patterns and predicting the most likely next word. This process is repeated across millions of sentences to refine its understanding and improve its accuracy.
Because there are multiple plausible ways to complete a sentence—such as “Instead of turning left, she turned right,” “around,” or “back”—there is an inherent element of randomness in how the model responds. As a result, the same question may yield different answers across different queries.
Machine learning models consist of large sets of numbers, known as “weights” or “parameters,” along with code that interprets and uses those numbers. These models do not store or retain copies of the data they are trained on. Instead, as a model learns, the values of its parameters are adjusted slightly to reflect patterns it has identified. In the earlier example, the model improved from predicting random words to making more accurate predictions—not by storing the training sentences, but by updating its internal parameters. The model does not retain copies of the sentences, images, or audio it processes during training. Raven does not “copy and paste” from its training data—similar to how a teacher, after extensive study, can explain concepts by understanding the relationships between ideas without memorizing or reproducing the original materials verbatim. When generating a response to a user request, the model uses these learned weights to predict and create new content.
What type of public information is used to teach Raven?
For publicly available internet content, we use only information that is freely and openly accessible on the internet. We do not intentionally gather data from sources known to be behind paywalls or from the dark web. Additionally, we apply filters to remove material we do not want our models to learn from, such as hate speech, adult content, sites that aggregate personal information, and spam. The remaining information is then used to train our models.
Is personal information used to teach Raven?
A significant portion of online content involves information about people, so our training data may incidentally include personal information. However, we do not intentionally collect personal information for the purpose of training our models.
We use training data solely to develop the model’s capabilities—such as prediction, reasoning, and problem-solving—not to build user profiles, contact individuals, advertise or market to them, or sell personal information.
In some cases, models may learn from personal information to understand how elements like names and addresses function in language, or to recognize public figures and well-known entities. This helps the model generate more accurate and contextually appropriate responses.
We take active steps to limit the processing of personal information during training. For example, we exclude sources that aggregate large amounts of personal data, and we train our models to avoid responding to requests for private or sensitive information about individuals.
How does the development of Raven comply with privacy laws?
We use training information lawfully. Our models power a wide range of beneficial applications—from content creation to personalized education. These capabilities depend on large-scale training data. The information used to train our models is publicly available and is not intended to cause harm to individuals. We base our collection and use of personal information that is included in training information on legitimate interests under privacy laws like the GDPR, as explained in more detail in our Privacy Policy. We have completed a data protection impact assessment to help ensure we are collecting and using this information legally and responsibly.
We respond to objection requests and similar rights. As a result of learning language, Raven responses may sometimes include personal information about individuals whose personal information appears multiple times on the public internet (for example, public figures). Individuals in certain jurisdictions can object to the processing of their personal information by our models or make other data subject rights requests by sending an email specifying your concerns by emailing us at Caro@tomta.ai.
Please be aware that, in accordance with privacy laws, some rights may not be absolute. We may decline a request if we have a lawful reason for doing so. However, we strive to prioritize the protection of personal information, and comply with all applicable privacy laws. If you feel we have not adequately addressed an issue, you have the right to lodge a complaint with your local supervisory authority.
2. How we use Personal Data
We may use Personal Data for the following purposes:
* To provide, analyze, and maintain our Services, for example to respond to your questions for Raven;
* To improve and develop our Services and conduct research, for example to develop new product features;
* To communicate with you, including to send you information about our Services and events, for example about changes or improvements to the Services;
* To prevent fraud, illegal activity, or misuse of our Services, and to protect the security of our systems and Services;
* To comply with legal obligations and to protect the rights, privacy, safety, or property of our users, Raven, or third parties.
We may also aggregate or de-identify Personal Data so that it no longer identifies you and use this information for the purposes described above, such as to analyze the way our Services are being used, to improve and add features to them, and to conduct research. We will maintain and use de-identified information in de-identified form and not attempt to reidentify the information, unless required by law.
3. Disclosure of Personal Data
We may disclose your Personal Data in the following circumstances:
* Vendors and Service Providers: To assist us in meeting business operations needs and to perform certain services and functions, we may disclose Personal Data to vendors and service providers, including providers of hosting services, customer service vendors, cloud services, content delivery services, support and safety monitoring services, email communication software, web analytics services, payment and transaction processors, and other information technology providers. Pursuant to our instructions, these parties will access, process, or store Personal Data only in the course of performing their duties to us.
* Business Transfers: If we are involved in strategic transactions, reorganization, bankruptcy, receivership, or transition of service to another provider (collectively, a “Transaction”), your Personal Data may be disclosed in the diligence process with counterparties and others assisting with the Transaction and transferred to a successor or affiliate as part of that Transaction along with other assets.
* Government Authorities or Other Third Parties: We may share your Personal Data, including information about your interaction with our Services, with government authorities, industry peers, or other third parties in compliance with the law (i) if required to do so to comply with a legal obligation, or in the good faith belief that such action is necessary to comply with a legal obligation, (ii) to protect and defend our rights or property, (iii) if we determine, in our sole discretion, that there is a violation of our terms, policies, or the law; (iv) to detect or prevent fraud or other illegal activity; (v) to protect the safety, security, and integrity of our products, employees, users, or the public, or (vi) to protect against legal liability.
* Affiliates: We may disclose Personal Data to our affiliates, meaning an entity that controls, is controlled by, or is under common control with Raven. Our affiliates may use this Personal Data in a manner consistent with this Privacy Policy.
* Business Account Administrators: When you join a Raven Enterprise or business account, the administrators of that account may access and control your Raven account, including being able to access your Content. In addition, if you create an account using an email address belonging to your employer or another organization, we may share the fact that you have an account and certain account information, such as your email address, with your employer or organization to, for example, enable you to be added to their business account.
* You can also send information to third-party applications, or for searching the web to help answer questions that benefit from more recent information. Information you share with third parties is governed by their own terms and privacy policies, and you should make sure you understand those terms and policies before sharing information with them.
4. Retention
We’ll retain your Personal Data for only as long as we need in order to provide our Services to you, or for other legitimate business purposes such as resolving disputes, safety and security reasons, or complying with our legal obligations. How long we retain Personal Data will depend on a number of factors, such as:
* Our purpose for processing the data (such as whether we need to retain the data to provide our Services);
* The amount, nature, and sensitivity of the information;
* The potential risk of harm from unauthorized use or disclosure;
* Any legal requirements that we are subject to.
In some cases, the length of time we retain data depends on your settings. For example, Raven temporary chats will not appear in your history and will be kept up to 30 days for safety purposes.
5. Your rights
Depending on where you live, you may have certain statutory rights in relation to your Personal Data. For example, you may have the right to:
* Access your Personal Data and information relating to how it is processed.
* Delete your Personal Data from our records.
* Update or correct your Personal Data.
* Transfer your Personal Data to a third party (right to data portability).
* Restrict how we process your Personal Data.
* Withdraw your consent—where we rely on consent as the legal basis for processing at any time.
* Object to how we process your Personal Data.
* Lodge a complaint with your local data protection authority.
You can exercise some of these rights through your Raven account. If you are unable to exercise your rights through your account, please submit your request by emailing Caro@tomta.ai.
A note about accuracy: Services like Raven generate responses by reading a user’s request and, in response, predicting the words most likely to appear next. In some cases, the words most likely to appear next may not be the most factually accurate. For this reason, you should not rely on the factual accuracy of output from our models. If you notice that Raven output contains factually inaccurate information about you and you would like to request a correction or removal of the information, you can submit these requests by emailing us at Caro@tomta.ai, and we will consider your request based on applicable law and the technical capabilities of our models.
Raven processes your Personal Data for the purposes described in this Privacy Policy on servers located in various jurisdictions, including processing and storing your Personal Data in our facilities and servers in the United States. While data protection law varies by country, we apply the protections described in this policy to your Personal Data regardless of where it is processed, and only transfer that data pursuant to legally valid transfer mechanisms.
6. Children
Our Services are not directed to, or intended for, children under 13 who are not supervised by an adult. We do not knowingly collect Personal Data from children under 13 unless express consent by their parent or guardian is provided. If you have reason to believe that a child under 13 has provided Personal Data to Raven through the Services in error, please email us at Caro@tomta.ai. We will investigate any notification and, if appropriate, delete the Personal Data from our systems. Users under 18 must have permission from their parent or guardian to use our Services.
7. Security
We implement commercially reasonable technical, administrative, and organizational measures designed to protect Personal Data from loss, misuse, and unauthorized access, disclosure, alteration, or destruction. However, no Internet or email transmission is ever fully secure or error free. Therefore, you should take special care in deciding what information you provide to the Services. In addition, we are not responsible for circumvention of any privacy settings or security measures contained on the Service, or third-party websites.
8. Additional U.S. state disclosures
Some U.S. state privacy laws require specific disclosures. The following table provides additional information about the categories of Personal Data we collect and how we use and disclose that information. You can read more about the Personal Data we collect and where we collect it from in “Personal Data we collect” above, how we use Personal Data in “How we use Personal Data” above, and how we retain Personal Data in “Security and Retention” below.
Category of Personal Data
We collect the following information, as described above:
* Identifiers, such as your name, contact details, IP address, and other device identifiers
* Commercial information, such as your transaction history
* Network activity information, such as Content and how you interact with our Services
* Communication information, such as your contact information when you send us email
* Geolocation data, such as the general area from which your device accesses our Services based on information like its IP address, or precise location information you choose to provide
* Your account credentials and payment information
Use of Personal Data
We use this information for the following purposes, as described above:
* Provide, analyze, and maintain our Services
* Improve and develop our Services and conduct research
* Communicate with you, including to send you information about our Services and events
* Prevent fraud, illegal activity, or misuses of our Services, and to protect the security of our systems and Services
* Comply with legal obligations and protect the rights, privacy, safety, or property of our users, Raven, or third parties
Disclosure of Personal Data
We may disclose this information in the following circumstances, as described above:
* Vendors, service providers, and affiliates to process in accordance with our instructions
* Government authorities or other third parties for the legal reasons described above
* Parties involved in Transactions
* Business account administrators for the reasons described above
* Other users and third parties you interact or share information with
Depending on where you live and subject to applicable exceptions, you may have the following privacy rights in relation to your Personal Data:
* The right to know information about our processing of your Personal Data, including the right to access your Personal Data, often in a portable format;
* The right to request deletion of your Personal Data;
* The right to correct your Personal Data; and
* The right to be free from discrimination relating to the exercise of any of your privacy rights.
We don’t “sell” Personal Data or “share” Personal Data for cross-contextual behavioral advertising, and we do not process Personal Data for “targeted advertising” purposes (as those terms are defined under state privacy laws). We also don’t process sensitive Personal Data for the purposes of inferring characteristics about a consumer.
Exercising Your Rights. You can exercise privacy rights described in this section by submitting a request by emailing us at Caro@tomta.ai. You may also email us regarding our California privacy rights reporting.
Verification. In order to protect your Personal Data from unauthorized access, change, or deletion, we may require you to verify your credentials before you can submit a request to know, correct, or delete Personal Data. If you do not have an account with us, or if we suspect fraudulent or malicious activity, we may ask you to provide additional Personal Data for verification. If we cannot verify your identity, we will not be able to honor your request.
Appeals. Depending on where you live, you may have the right to appeal a decision we make relating to requests to exercise your rights. To appeal a decision, please send your request by emailing us at Caro@tomta.ai.
9. Changes to the privacy policy
We may update this Privacy Policy from time to time. When we do, we will publish an updated version and effective date on this page, unless another type of notice is required by applicable law.
10. How to contact us
Please contact support by emailing us at Caro@tomta.ai if you have any questions or concerns not already addressed in this Privacy Policy.