Privacy policy
This policy explains what information Rill collects, how we use it, and the choices you have.
Last updated August 28, 2026.
Who we are
Rill is operated by lomi. Inc (we, us). Affiliates include lomi. Technologies Africa S.A. Rill is a separate service from lomi.africa. Using Rill does not create a lomi.africa merchant agreement, and Rill card funding, Connect verification, and payouts go through Stripe, not lomi.africa payment channels.
Scope
This policy applies to the Rill website, owner dashboard, API, MCP (including guest), pay links under /r/, and the directory (together, the Service).
Information we collect
We collect information in these categories:
- Account: email address, name, company name, handle, and sign-in data when you use an email link, Google, or GitHub.
- Wallets and money: balances, funding records, receipts, withdraw and recycle activity, and whether you are using Live or Test.
- Agent and seller keys: we store hashes and prefixes after a key is created. The full key is shown once at mint. Spend logs may include the URL, amount, rail, status, and a truncated response.
- Webhooks: the endpoint URL, an encrypted signing secret, event subscriptions, and delivery payloads.
- Connected apps: MCP OAuth grants, client name, scopes, and last-used time.
- Guest and bootstrap use: IP address and rate-limit data used to register agents and stop abuse.
- Directory: cached metadata about third-party pay endpoints. A Spend payment does not send your organization profile to the payee unless you include it on the request.
- Communications: messages you send to @userill.com addresses. Inbound mail is forwarded to operators.
- Browser storage: essential sign-in cookies; local storage for theme, Live/Test preference, docs progress, and an optional docs key vault if you choose to store keys in the browser.
How we use information
We use information to:
- Operate Accept and Spend, including wallets, pay links, receipts, and budgets.
- Settle payments through Stripe and open rails (MPP and x402).
- Enforce allowances, allowlists, rate limits, and abuse controls.
- Provide support and respond to legal or security requests.
- Improve reliability and the product.
- Comply with law and enforce our Terms of use.
We do not send marketing email unless you ask us to. Sign-in links, receipts of action you took, and operational notices are not marketing.
How we share information
We do not sell personal information. We may share information with:
- Stripe, to process card top-ups, Connect verification and payouts, and open-rail settlement.
- Authentication and database providers that run accounts and store Service data.
- An email provider for sign-in links and mail you send to @userill.com.
- Website analytics on userill.com.
- Infrastructure hosts that run the website, API, and MCP.
- Affiliates in the lomi. group when needed to operate or support Rill.
- Professional advisers or authorities when required by law or to protect rights, safety, and security.
We may share aggregated or de-identified information that cannot reasonably identify you.
International transfers
The Service is used globally. Information may be stored and processed outside your country, including in the United States, where privacy rules may differ. We take steps designed to keep that information protected to the standards in this policy.
Retention
We keep account data while your account is active and as needed to operate the Service, resolve disputes, and meet legal duties.
If you delete your account in settings or email privacy@userill.com, we remove account access and related records we no longer need. Some payment, ledger, and receipt records may be kept for tax, disputes, Stripe, or other legal requirements. Deleting an account is not a wipe of every historical payment record.
Your rights and choices
Depending on where you live, you may have rights to:
- Access, correct, or delete personal information we hold about you.
- Object to or restrict certain processing.
- Withdraw consent where processing is based on consent.
- Request a copy of your data in a portable format.
You can delete a signed-in account from settings. To exercise these rights, email privacy@userill.com. We may need to verify the account before we respond.
Cookies and similar technologies
We use essential cookies to keep you signed in. The browser may also store theme, Live/Test preference, and docs progress. If you use the docs key vault, keys stay in local storage on your device until you clear them. The website uses Vercel Analytics. We do not use a cookie banner for these essential and first-party measures. If we add non-essential tracking later, we will update this policy.
Agents and automated use
A wallet key or guest MCP session can create logs and payments the same way a signed-in person can. For that wallet, we treat the account owner as the person those records belong to.
Children
The Service is not directed to children under 13, or under 16 where that is the required minimum. We do not knowingly collect personal information from children.
Security
We use technical and organizational measures designed to protect information. See Security for access controls, money safeguards, and how to report a vulnerability.
Changes to this policy
We may update this Privacy policy. We will post the revised version with an updated last-updated date. Continued use after changes means you accept the updated policy.
Contact
Questions about privacy: privacy@userill.com