Legal

Privacy Policy

How rect.sh collects, uses, shares, and handles information when you use our websites, applications, APIs, and related services.

Last updated: July 21, 2026

This Privacy Policy explains how rect.sh handles information across our products, APIs, and related services.

1. What rect.sh is

rect.sh hosts rects — live, shareable interactive views backed by a JSON view model that people and AI agents edit together in real time. Understanding that model helps this policy make sense: view authors publish reusable templates, agents or people issue live instances from them, and each instance is reachable at a capability URL. Each instance also has independent read and write permissions for anonymous visitors, signed-in users, workspace members, or its owner and administrators.

2. Information we collect

We may collect the following categories of information:

  • Account information, such as name, email address, workspace and team details, and authentication information.
  • Templates you publish, including view HTML, bundled assets, specs, action code, and optional remix source.
  • Instance content: the JSON view model of each issued rect, including everything typed into the view by permitted viewers and everything written to it by AI agents over MCP, the CLI, or the HTTP API.
  • Attachments uploaded to an instance, and their metadata (file name, type, size).
  • Usage and device information, such as log data, IP address, browser type, requests made, and diagnostic events.
  • Billing information if you purchase a paid plan, such as plan, payment status, and transaction metadata. Payment card details are processed by our payment providers, not stored by us.

Some of this content reaches us without a rect.sh account: agents and their users can issue instances anonymously and edit them when the instance explicitly permits anonymous writes. That content is still handled as described in this policy.

3. Capability URLs and who can see instance content

An issued rect is deliberately shareable, but its link does not override its permissions. The instance owner chooses whether anonymous visitors, signed-in users, workspace members, or only its owner and administrators may read or change it. Anyone holding a link can use the access granted to their identity; an anonymous link holder can use it only when anonymous access is enabled.

When anonymous access is enabled, treat the link and its permitted content as shared with everyone the link reaches. Do not put payment card numbers, government identifiers, passwords or credentials, or health information into a publicly accessible view model or attachment.

4. How we use information

We use information to:

  • provide, maintain, troubleshoot, and improve the service — including hosting templates, storing and syncing view models in real time, running view-declared actions, and serving attachments;
  • create and manage accounts, workspaces, and teams;
  • respond to support requests and communicate with you;
  • process payments and manage subscriptions, if applicable;
  • detect abuse, investigate issues, and reduce security risks;
  • comply with legal obligations.

5. AI agents

rect.sh does not send your content to AI model providers. We host the views; the AI agents that read and write them belong to you or to third parties (for example, an assistant connected to our MCP endpoint). What an agent does with data it reads from a rect — and what data it chooses to write into one — is governed by that agent's own provider and its policies, not by rect.sh.

When an agent issues or edits a rect on your behalf, the resulting view model content is stored by rect.sh as instance content under this policy.

6. How we share information

We may share information with:

  • infrastructure providers that host the service — including our database, authentication, file storage, and realtime infrastructure, and our hosting/CDN providers;
  • payment processors, if you purchase a paid plan;
  • teammates and workspace members, according to your workspace settings — team templates and their instances are visible to the team;
  • people and AI agents allowed by an instance's read or write permissions, including anonymous link holders when that access is enabled;
  • authorities or other parties when required by law or needed to help protect rights, safety, and security;
  • a successor in connection with a merger, acquisition, financing, restructuring, or sale of assets.

We do not sell personal information.

7. Data retention

Account data is kept for as long as your account exists and as needed to meet legal and accounting obligations. Free Rect instances are archived 30 days after they are created: their public links stop exposing the content, but the instance and its attachments remain available to the signed-in owner or workspace members. Pro Rects remain publicly available while the workspace has an active subscription. We do not automatically delete archived Rects or their attachments. Log and diagnostic data is retained for a limited period for security and operations.

8. Security

We use administrative, technical, and organizational safeguards designed to help protect information: views run in a sandboxed environment, attachments are stored in private storage and served only through instance-scoped URLs, and access to workspace data is enforced at the database layer. No method of transmission or storage is completely secure. When an instance permits anonymous access, its link grants that access, so guard it accordingly.

9. Your choices

You may update account information, delete templates, instances, and attachments you control, or contact us to request access, correction, deletion, or export of personal information, depending on your location and subject to applicable limits. Permitted viewers can also read instance content through the instance's own URL and API. We may need to verify your identity before fulfilling certain requests.

10. International transfers

rect.sh is operated from the United States, and information may be processed in the United States and other countries where we or our providers operate. These countries may have data protection laws different from those in your location.

11. Children

rect.sh is not intended for children under 13, and we do not knowingly collect personal information from children under 13. If you believe a child has provided personal information to us, contact us so we can take appropriate action.

12. Changes to this policy

We may update this Privacy Policy from time to time. If changes are material, we will take reasonable steps to notify you. The updated policy will be effective when posted unless stated otherwise.

13. Contact

rect.sh is provided by Suri. You can contact us at support@suri.team or by mail at 1111b South Governors Av #88996, Dover, DE 19904, US.