1. Overview & Data Ownership
RAGChat is an open-source, local-first application. We believe that your personal and workspace data belongs entirely to you. All document chunks, vector embeddings, email indexes, spreadsheet data, and conversation logs are processed and stored locally on your own hardware. We do not operate central data harvesting servers.
2. Account Linking & OAuth Authentication
When connecting third-party services (such as Google Workspace, Microsoft 365, Telegram, or Discord), authentication is handled directly through the official authorization servers of those respective providers:
- Your passwords are never requested, accessed, or stored by RAGChat.
- Authentication passes and refresh tokens are stored locally on your machine (
~/.config/ragchat/). - Tokens are used exclusively to communicate directly between your machine and the connected service API.
3. Artificial Intelligence & LLM Provider Choices
RAGChat gives you complete transparency and control over how your queries are processed by language models:
- Local Models (Ollama): When using local models, all data inference occurs 100% offline on your device, ensuring zero data leaves your machine.
- Cloud Model APIs (OpenAI, Gemini, Claude): If you choose to connect a cloud AI provider API key, only the relevant document context required to answer your specific query is transmitted to that provider.
4. Zero Telemetry & Analytics
We do not collect usage analytics, tracking cookies, diagnostic telemetry, or behavioral metrics. Your application interactions remain strictly private to your computer.
5. Contact & Open Source Transparency
RAGChat source code is publicly available for audit on GitHub at github.com/soumen888/Rag-Chatbot. For any questions regarding privacy practices, you can review the codebase directly or open an issue on the repository.