RallyCompute Privacy Policy
Effective: August 28, 2026 Last updated: August 28, 2026
RallyCompute is a U.S.-only research preview operated by Ishan Anand ("RallyCompute," "we," "us," or "our"). This Privacy Policy explains how personal information is handled when you use RallyCompute's websites, browser application, distributed-computing rooms, model downloads, and related services (the "Service").
1. Scope and important features
The Service distributes AI computation among room participants' browsers. Information needed for a computation may therefore be processed on other participants' devices, outside RallyCompute's direct control. Only join rooms whose participants you trust.
The preview is offered only in the United States and only to people who are at least 18 years old.
2. Information we collect
Account and consent information
We collect your email address, display name, internal user identifier, account and verification status, authentication records, and the versions and acceptance time of the Terms and Privacy Policy presented at signup. Amazon Cognito handles authentication; RallyCompute's room application and room database do not receive your plaintext password.
Rooms, membership, and sessions
We process room names and identifiers; ownership, membership, invitation, and coordinator status; selected models; device and session identifiers; machine names; participant roles; creation, update, last-seen, and expiration times; device capacity; connection status; and actions taken to create, rename, join, leave, coordinate, or delete a room.
Other room participants may see your display name, machine name, role, abbreviated session identifier, capacity, and connection status. We do not intentionally expose your email address to other participants.
Device, capacity, and performance information
The Service may detect or receive browser and device capabilities, including browser features, WebGPU or CPU capability, graphics-adapter information made available by the browser, estimated or entered GPU capacity, model-shard cache inventory, compatibility results, runtime version, assigned layers, memory use, processing timing, throughput, transfer size, and errors or readiness status. Information necessary to coordinate computation is shared with the coordinator and relevant participants.
Prompts, output, and workspace content
The Service processes prompts, instructions, token sequences, generated output, selected files and file paths, coding tasks, proposed patches, diffs, approval or rollback information, and intermediate model data when you choose to use those features.
In the normal distributed-inference path, RallyCompute's hosted room API does not intentionally store or inspect prompt text, selected file contents, or generated output. Participating devices necessarily process parts of the computation, and a coordinator may receive the prompt and output. Depending on its assigned stage, another participant's device may receive tokens, workspace content, or intermediate data that reveals or permits inferences about your content. Do not treat a participant's device as a confidential enclave.
Diagnostic reports may contain prompts, output, runtime details, measurements, and event logs. A report is copied or exported only at your direction.
Network, logs, and downloads
When you access the hosted Service, RallyCompute and its infrastructure providers receive your IP address and standard technical information such as request time, request identifier, route, method, status, protocol, response size, authentication or authorization failures, errors, and model-download grants.
RallyCompute uses WebRTC without a TURN relay. Establishing direct connections may disclose your public IP address and related network-routing information to RallyCompute's infrastructure, Cloudflare's STUN service, and connected participants. WebRTC offers, answers, and ICE candidates pass through AWS AppSync signaling.
When you request a model, we process your user identifier, requested model and file, and the temporary download-link expiration. Delivery providers receive standard request and network information.
Communications and information from others
We collect information you send when requesting support, responding to research or product messages, or providing feedback. Other users may provide information about you when inviting you to or operating a room.
3. Information stored on your device
The Service uses browser storage and user-authorized local filesystem access. Local data may include authentication state; a device identifier and machine name; preferences and performance profiles; model files and shards; manifests and compatibility results; a folder handle; selected workspace metadata; proposed or applied edit snapshots; local event logs; and the current prompt or output while the page is open.
You can usually remove this information through your browser's site-data controls. Doing so may sign you out, remove cached models and rollback snapshots, and require downloads again. Revoking folder access or clearing site data does not undo changes already written to your files.
4. How we use information
We use personal information to:
- create, authenticate, secure, and support accounts;
- provide, coordinate, and troubleshoot rooms and distributed computations;
- identify connected participants and assign model work based on capacity;
- provide downloads and maintain runtime integrity;
- prevent abuse, protect users and the Service, enforce the Terms, and investigate incidents;
- maintain, debug, measure, and improve the Service;
- communicate about accounts, security, support, the preview, product updates, and feedback requests;
- comply with law and valid legal process; and
- establish, exercise, or defend legal claims.
We do not use prompt text, workspace files, or generated output to train AI models unless we first provide a separate clear notice and obtain any consent required by law.
5. How we disclose information
We disclose information as follows:
- Room participants. We disclose identity, machine, role, capacity, connection, network, prompt, workspace, output, and intermediate computation information as described above and as needed to operate a room. Only join rooms whose participants you trust.
- Service providers. We use Amazon Web Services, including Amplify, Cognito, API Gateway, Lambda, DynamoDB, AppSync, CloudWatch, S3, CloudFront, and Secrets Manager, and Cloudflare's STUN service. Providers process information for us under their applicable contracts.
- Legal, safety, and rights. We may disclose information to comply with law or valid process, protect rights or safety, prevent abuse or incidents, or enforce agreements.
- Service transfer. If responsibility for the Service or related assets is transferred or reorganized, information may be included subject to appropriate protections.
- At your direction. We disclose information when you invite someone, connect to peers, download or copy a report, or authorize local-folder access.
We do not sell personal information for money, share it for cross-context behavioral advertising, or use third-party advertising cookies.
6. Retention
We retain information only as reasonably necessary to provide and secure the Service, comply with law, resolve disputes, and enforce agreements. Current practices include:
- Accounts and profiles: retained while an account is active and afterward as reasonably necessary. You may request deletion by contacting us.
- Rooms and memberships: retained while needed to operate a room. The current preview archives certain room and membership records rather than erasing each database record immediately when a room is deleted. Contact us to request deletion of associated personal information.
- Active sessions: coordinator leases expire after about 45 seconds and worker sessions after about 60 seconds without heartbeats. DynamoDB removes expired records asynchronously.
- Service logs: production CloudWatch log groups are currently configured for 14-day retention. Provider security, billing, or delivery records may have separate schedules.
- Signaling: ordinary signaling is transient and is not intentionally stored as a durable application record, although errors and provider records may be logged.
- Prompts, workspace content, and output: not intentionally retained by the hosted room API after the distributed operation. Copies may remain on participant devices, in page memory, local snapshots, copied reports, or export destinations.
- Local information: remains until you clear browser data, revoke access, delete it, or overwrite or delete the related files.
- Backups: DynamoDB point-in-time recovery can preserve table data for a rolling period of up to 35 days. Deleted information may remain in recovery systems until it ages out, unless it must be retained longer for security, legal compliance, or a claim.
7. Security
We use safeguards designed to protect personal information, including authenticated access, encryption in transit, server-side database encryption, short-lived room sessions, expiring download links, and encrypted WebRTC data channels. No system is completely secure. Protect your credentials, invitation links, devices, local files, and information shared with participants.
8. Your choices and requests
You can update certain profile or machine information, leave or delete a room, sign out, clear local browser data, and revoke folder access. Account deletion is not currently self-service. To request access, correction, deletion, or another privacy action, email support@rallycompute.ai. We may need to verify your identity and authority.
During the free research preview, signup consent covers account and beta email, including product updates and feedback requests. You can ask us to stop nonessential messages at support@rallycompute.ai; necessary account, security, and Service messages may continue.
The Service does not sell or share personal information for targeted advertising, so browser Global Privacy Control and "Do Not Track" signals do not change its behavior.
9. Children
The Service is intended only for people who are at least 18. We do not knowingly collect personal information from children. Contact us if you believe a child has provided personal information.
10. U.S.-only service
The Service is operated and hosted in the United States and is not offered to users in the EEA or United Kingdom. No EU or UK representative has been appointed, and no Data Protection Officer has been appointed. Room participants must also be in the United States during this preview.
11. Changes to this Policy
We may update this Policy by posting the revised version and changing the "Last updated" date. If a change materially affects how we use information already collected, we will provide additional notice or obtain consent where required.
12. Contact
Ishan Anand, PO Box 410, Issaquah, WA 98027, United States. Privacy and support: support@rallycompute.ai