Effective date: September 24, 2026
Rightview (operated by Rightview Technologies Inc., "we," "us," or "our") provides clinical regulatory and document intelligence services at rightview.ai, crx.rightview.ai, and sites.rightview.ai (the "Service"). This Privacy Policy describes how we handle your information across all Rightview products.
Email address. Collected when you sign up or are provisioned an account, used to identify your account and send product communications.
Queries you submit. Questions you send to the Service are processed to generate answers and may be stored for quality review and service improvement. We do not use your queries or the information we collect from them to train AI models.
Account activity. We record when your account was created, when you last signed in, and aggregate usage counts to manage access and understand how the Service is used.
Session cookie. We set a single HTTP-only cookie to keep you signed in. It contains a cryptographically signed token and cannot be read by browser scripts. See Section 5 for product-specific session lengths. You can view, block, or delete this cookie at any time through your browser settings. It is strictly necessary to keep you signed in, so blocking it will sign you out and stop the Service from working. We use no analytics, advertising, or other non-essential cookies.
Server logs. Our hosting infrastructure records standard access logs, which may include IP addresses and timestamps, retained briefly for security and debugging only.
We do not use your queries, account information, or uploaded documents to train AI models, and we do not permit our service providers to do so.
We use third-party service providers for cloud infrastructure, encrypted storage, AI language model inference and embeddings, answer quality monitoring, and web-search augmentation. When queries are processed for quality monitoring, your email address and query text are shared with that provider so responses can be reviewed. When a query is augmented with web search, query-derived text is sent to a search provider to retrieve relevant results. All providers are based in the United States, process data on our behalf only, and are prohibited from using it for their own purposes. We do not sell your data or share it for advertising.
Do not submit protected health information (PHI) or patient-identifiable data to the Service. The Service is not a HIPAA-covered product for storing or processing PHI, and is not designed or approved for that purpose. Our Terms of Service expressly prohibit PHI uploads and submissions.
We maintain security and audit controls (access controls, encryption in transit and at rest, de-identification before certain external AI providers, and audit logging) as defense-in-depth. Those controls do not authorize or invite PHI in the Service, and do not make Rightview your business associate for PHI you are prohibited from submitting.
Where a BAA applies. This prohibition does not apply where your organization has executed a Business Associate Agreement (BAA) with Rightview. In that case, the BAA governs Rightview's handling of the protected health information it covers, and controls over the PHI prohibition in this section and in our Terms of Service.
Rightview CRX (crx.rightview.ai)
Rightview Full Platform (sites.rightview.ai)
Rightview Navigator Chrome extension
Data is encrypted in transit (TLS 1.2+) and at rest (AES-256). Session tokens are stored in HTTP-only cookies inaccessible to browser scripts. We implement industry-standard safeguards but cannot guarantee absolute security.
We retain your account information and query history for as long as your account is active and for a reasonable period thereafter. You may request deletion by emailing info@rightview.ai.
You may request access to, correction of, or deletion of your personal data at any time. Email info@rightview.ai and we will respond within 30 days.
The Service is not directed to children under 18. We do not knowingly collect personal information from minors.
We disclose your information to law enforcement, government agencies, or other parties only when compelled by valid legal process (such as a subpoena, court order, or search warrant) or where disclosure is required by applicable law. We do not grant voluntary or informal access to your data.
How we respond. Every request is reviewed by counsel to confirm it is legally valid, properly served, and issued by an authority with jurisdiction. We reject or require correction of requests that are overbroad, defective, or unauthorized. We disclose only the specific data the request compels — never more — and log each request we receive and each disclosure we make.
Notice to you. Unless prohibited by law or court order, or where notice would create a risk to safety or an investigation, we will make reasonable efforts to notify affected account holders before disclosing their data so they may seek to challenge the request. Where we are barred from giving prior notice, we will notify you afterward once the legal restriction lifts, if permitted.
Requests should be directed to security@rightview.ai or info@rightview.ai.
We may update this policy from time to time and will notify you of material changes by email or by posting a notice on the Service.
Questions? Email info@rightview.ai.