Privacy
How we handle your data.
Ravello is sold on privacy, so this page is written to be read rather than to be survived. It explains exactly what we hold, where it sits, who can reach it, and how you get it back.
Who we are
Ravello ("we", "us") builds and operates a bespoke life-management platform for a small number of individual clients. For anything on this page you can reach us at hello@ravello.life or through Jonathan May on LinkedIn.
Ravello is a trading name of Jonathan May, an independent sole trader based in England and Wales. There is no separate company; Jonathan is the data controller and the person you contract with, and the contact routes above reach him directly.
Two different things, two different answers
It matters which one you are asking about:
- This website (ravello.life) is a static brochure. It collects almost nothing.
- Your platform is the private instance we build and run for you. That holds real, sensitive data, and the rest of this page is mostly about it.
This website
There are no analytics, no cookies, no tracking pixels, no advertising tags and no forms on this site. We do not set a single cookie.
Two things do happen:
- Our web server keeps standard access logs (IP address, timestamp, requested page, browser user agent) as part of running and securing the site. They are not used to profile you and are not shared.
- If you use the light and dark toggle, your choice is saved in your own browser's local storage under
ravello-theme. It never leaves your device.
The site links out to LinkedIn. If you follow that link, you are on LinkedIn's platform under LinkedIn's privacy policy, not ours.
If you get in touch
When you contact us about working together, we keep the correspondence and the notes we make from our conversations, so that we can pick up where we left off. That is it. We do not add you to a mailing list, and we do not sell, rent or share your details with anyone.
Your platform
Your instance is genuinely separate
Every client gets their own instance: its own application, its own database, its own storage and its own credentials. Your data does not sit in a shared, multi-tenant database alongside other clients', because there is no such database. One client's instance cannot query another's, and a compromise of one does not expose another.
You choose the geography your instance runs in. If your circumstances call for it, we can deploy on infrastructure you own, including on-premise.
Encryption
Connections to your instance are encrypted in transit with TLS, and plain HTTP is redirected rather than served. Data is encrypted at rest on the underlying storage. Credentials, API keys and integration tokens are held in a secrets manager, not in the application's source or its database. Access requires two-factor authentication.
If your organisation has a security team, we would rather work with them than around them, and we are happy to answer a security questionnaire or support a review.
Who can see your data
We do not read your data in the ordinary course of running your platform. There are two exceptions, and both are narrow:
- Support you ask for. If you report a problem that we cannot diagnose from error reports alone, we will ask you for access, tell you what we need to look at, and use it only for that. You can revoke it at any time.
- Something breaking. Operational monitoring and error reports can incidentally include fragments of your content, for example a subject line in a failed message. We treat those with the same confidentiality as everything else and keep them no longer than we need to fix the fault.
We do not sell your data, we do not share it for advertising, and we do not use it to build a product for anyone else.
Artificial intelligence
Your platform uses Claude, made by Anthropic, accessed through Anthropic's commercial API.
Two things follow from that, and they are the substance of the claim we make on the home page:
- Your data is not used to train any AI model. Anthropic's commercial API terms provide that inputs and outputs are not used to train their models. We do not train, fine-tune or build models on your data either, and we do not use your data to improve anything we run for another client.
- Each interaction is private to your instance. The model has no memory that carries across clients. What it knows in your instance is the context your instance sends it, and nothing from anyone else's.
To be straightforward about the limits of that: the content of a request does travel to Anthropic to be processed, and Anthropic may hold it briefly for abuse and safety purposes under their own terms. It is not a local model. If that matters to your threat model, tell us during scoping and we will design around it.
The systems you connect
Your platform is useful because it connects to your existing tools, for example your mail, your calendar or your CRM. Data flows to and from those systems only where you have connected them and only within the permissions you granted, which you can withdraw from your side at any time. Those providers handle your data under their own privacy terms, not ours.
Beyond your own integrations and the AI provider above, the only other parties involved are the infrastructure provider hosting your instance and, where relevant, our accountants for billing records. We will name all of them on request.
Access levels
If your assistant, chief of staff or family office uses your platform, we can scope what each person sees. Anyone you grant access to can see what that access allows, so those levels are worth setting deliberately. We will help you set them and you can change them whenever you like.
Export and deletion
Your data is yours. Specifically:
- Export, any time. Ask and we will produce a complete export in open, machine-readable formats you can use elsewhere. Not a screenshot bundle, and not a format only we can read. There is no charge and you do not need a reason.
- Deletion. When you ask us to delete your instance, or after we finish an engagement, we destroy the instance and its data within 30 days.
- Backups. Encrypted backups can persist for up to 35 days after deletion because of how backup rotation works. They are not restored except to recover your own instance, and they age out on their own.
- What we keep. Invoices and the associated records, which UK tax law requires us to hold for six years, and the fact that you were a client. Not your content.
Your rights
Under UK data protection law you can ask us for a copy of the personal data we hold about you, ask us to correct it, ask us to delete it, ask us to restrict or stop a particular use, and ask for it in a portable form. Where our use rests on your consent, you can withdraw that consent.
Write to us and we will respond within one month. Where the data in question is inside a platform we run for you, you are typically the one who decides how it is used and we act on your instructions, which is a distinction worth making explicit in your own agreement with us.
If we get it wrong, you can complain to the Information Commissioner's Office at ico.org.uk. We would rather you came to us first.
Changes
If we change this page in a way that materially affects a current client, we will tell that client directly rather than quietly updating the date at the top.
See also our terms of service.