Last updated: August 2026
01
Introduction
R³ is committed to protecting the privacy of its users. This Privacy Policy explains what personal data we collect, how we use it, who it is transferred to, and what your rights are — in accordance with the Israeli Privacy Protection Law 5741-1981 (including Amendment 13) and the Privacy Protection Regulations (Data Security) 5777-2017.
R³ comprises a website, browser applications, a desktop application (R³ CORE) and a Revit add-in (RVTS). Some components — the desktop application in particular — collect categories of data that are not self-evident: screen captures, clipboard content, meeting recordings and mailbox content. Sections 04–08 set these out explicitly. Please read them.
Use of the Services constitutes acceptance of the collection and processing described here.
חוק הגנת הפרטיות, תשמ"א-1981 · Privacy Protection Law 5741-1981
02
Data Controller
R³ is the data controller (מחזיק המאגר) as defined under the Israeli Privacy Protection Law 5741-1981.
Address: Tel Aviv, Israel
Email:
support@rcube.cloud
Phone:
054-497-7409
Where an architecture office subscribes to the Services on behalf of its employees, that office decides who is granted access and which tools are enabled. Requests concerning an employee's data will be handled together with the subscribing office.
03
What We Collect
- Account data: email address, first and last name, display name, phone (if provided), date of birth (if provided), profile photo, team and role within the office, office affiliation.
- Authentication data: one-time OTP codes (automatically deleted after 10 minutes), invitation tokens, and a per-device session identifier.
- Content you create: projects, prompts, uploaded and generated images, documents, presentations, notes, chat messages and attachments, questions put to our AI assistants, and saved calculations.
- Usage data: we log tool usage events — your email and username, the tool, the action, and a timestamp — for each meaningful action.
- Technical data: browser type and operating system, display geometry (used to position the toolbar), and last-active time.
- IP address: stored only for external chat guests (together with the browser user-agent) for security and audit purposes. For registered users the IP address is used for rate limiting only and is not written to the database.
- Support communications: messages sent to our support team.
- Payment data: company name, company/dealer number, and billing address. Card details are captured and secured directly by our payment provider — R³ never sees or stores card numbers or CVV, only a payment token and a customer identifier issued by the provider.
04
The R³ CORE Desktop Application
R³ CORE is an application installed on your work computer. Beyond account data it includes the capabilities below. All of them run only when you trigger them or after your office enables them — but you should know exactly what they do.
- Screen capture (SNPS): captures your full screen or a chosen window, including via a global hotkey that works even when the tool's own window is closed. The capture is written to your system clipboard and stored locally. If you choose to enhance a capture or send it to chat, the full-resolution image is uploaded to R³ servers and from there to an external AI provider. Whatever is on your screen at that moment is included in the capture.
- Video recording: the tool can also record a selected screen region as video.
- Clipboard (TRNS): the translation tool binds a global hotkey. When triggered it copies the selected text, reads your clipboard, sends the text to an external translation service, and writes the result back to the clipboard. This means text you have selected in any application on your computer — including non-R³ applications — may leave your machine. Use the tool only on text you are permitted to transmit.
- Local environment (PATH): the list of installed applications, folder paths and saved websites you configure in the toolbar is synchronised to your account on our servers so it is available on every device. Do not enter login credentials into the free-text fields of these items. Each saved domain is sent to Google's favicon service to display an icon.
- Presence and version checks: the application sends a heartbeat to the server every 5 minutes, which updates your last-active time and checks your software version. An "appear offline" setting is available. The heartbeat carries no information about the computer itself.
You may uninstall the application at any time through Windows settings. Uninstalling ends all local collection.
05
Meetings, Recordings and Transcripts
The meeting-summary tool (VIBE) processes recordings of meetings — by manual upload, local recording, or by connecting a Zoom account.
When a meeting is processed we store: the recording, a full transcript separated by speaker, speaker names, screen frames captured during the meeting, and an AI-generated summary and task list.
The recording is uploaded to an external transcription provider. Please note that the file's address at that provider is not password-protected — anyone holding the exact address can retrieve the file. We recommend not uploading meetings of exceptional sensitivity.
Recording a meeting also concerns the other participants. It is the recording user's responsibility to obtain participants' consent before recording, as required by law.
06
Mailbox Access
Some tools allow you to connect a Gmail or Outlook mailbox. The connection is made on your initiative, through your mail provider's own consent screen, and can be revoked at any time from your Google or Microsoft account.
Depending on the tool, the permission may include reading messages, sending messages, and updating message state. Access tokens are stored by us in encrypted form.
When you ask the system to draft, summarise or reformat a message, the content of that message is sent to an external AI provider for that purpose. The finance inbox additionally stores the message body itself in order to extract amounts and supplier details.
We access mailboxes only to provide the functionality you requested. We do not scan mail for advertising, and we do not use mail content to train models.
07
What Your Office Can See
When you use R³ as part of a subscribing office, your office administrator can see information about your activity. We think transparency here matters:
- Work clock (TICK) — accumulated work minutes per day and per project.
- Last-active time and presence status (unless you have enabled "appear offline").
- Tool usage log — which tools were used and when.
- Credit consumption and attributed costs.
- Content you create in the office workspace: projects, documents, office chat channels and shared files.
This information is intended for operational management and billing. It does
not include your screen captures, your clipboard content, or the content of your personal mailbox — these are not available to your office administrator through the system.
Monitoring of employees is subject to Israeli law and to the employer's own policy. The subscribing office is responsible for informing its employees and obtaining their consent where required.
08
Project Location Data
Our planning and site-information tools operate on project addresses, block/parcel numbers and coordinates. In order to retrieve planning information, plan documents, transaction data, GIS layers, maps and street imagery, the address or coordinate is sent to external public and governmental services, including the Planning Administration, the Survey of Israel, govmap, the real-estate transactions registry, municipal GIS systems, and commercial mapping services.
This is information about land, not about a person. That said, a project address may be associated with a particular client — bear this in mind when entering projects.
The full list of services that receive data appears in our
sub-processor list.
09
Artificial Intelligence and Sub-Processors
A substantial part of the Services is powered by third-party AI engines. In order to deliver the function you requested, the relevant content is sent to the appropriate provider and processed there.
Content types that are sent: text prompts, uploaded and generated images, meeting audio, document text, email message content when you request drafting or summarisation, clipboard text when translating, and screen captures you choose to send.
We do not use customer content to train models, and we do not sell personal data to anyone.
The full and current list of sub-processors — including AI, storage, payment, email and infrastructure providers — is published on a dedicated page:
rcube.cloud/sub-processors.
10
Purposes of Processing
- Providing, maintaining and improving the Services.
- Authenticating users and preventing unauthorised access.
- Sending service communications (OTP codes, system notifications, invitations).
- Billing, subscription management and credit-consumption accounting.
- Analysing usage patterns and improving features.
- Technical support and responding to enquiries.
- Complying with legal obligations and enforcing our Terms of Use.
11
Legal Basis for Processing
- Contract performance: processing necessary to provide the Service you subscribed to.
- Consent: for non-essential capabilities — including screen capture, clipboard interception, meeting recording and mailbox connection. Each of these is activated on your initiative and can be revoked.
- Legal obligation: compliance with Israeli law, including record-keeping and tax obligations.
- Legitimate interest: fraud prevention, security and product improvement — to a proportionate extent.
12
Data Retention
We prefer to state this as it is, rather than promise automatic deletion that does not actually happen.
- OTP codes: automatically deleted within 10 minutes.
- Invitation tokens: automatically deleted after 7 days.
- File-conversion jobs: the files themselves are not retained; the job record is automatically deleted after 30 days.
- Sync events: automatically deleted after 7 days.
- Account data, content you create, messages, meetings, usage logs and billing records: retained for as long as the account is active, and after closure until deleted on request as described in section 13 — subject to statutory retention obligations (principally billing documents, retained for 7 years).
If your office requires a defined retention policy, contact us and we will agree it contractually.
13
Your Rights and Deletion
Under the Israeli Privacy Protection Law 5741-1981 (sections 13–14) you have the right to:
- Access: request a copy of the personal data we hold about you.
- Correction: request correction of inaccurate data.
- Deletion: request deletion of your data, subject to statutory retention obligations.
- Objection: object to certain processing activities.
- Withdrawal of consent: withdraw consent at any time, without affecting the lawfulness of processing carried out beforehand.
How to delete an account: there is currently no self-service delete button in the product. Send a request from the account's email address to
support@rcube.cloud and we will delete the account and its associated content — including messages, meetings, uploaded assets and usage records — within 30 days, except for documents we are required by law to retain. We will confirm once complete.
We respond to any rights request within 30 days.
חוק הגנת הפרטיות, תשמ"א-1981, סעיפים 13-14
14
Cookies, Local Storage and Tracking
We do not use cookies at all.
Instead, the applications store information in your browser's local storage on your own device: your login token, and display preferences such as theme and language. This information stays on the device and is not sent to other sites. Clearing site data in your browser will sign you out.
We run no third-party analytics. There is no Google Analytics, no tag manager, no advertising pixels, no session recording and no cross-site tracking anywhere in our products.
We do keep an internal tool-usage log, as described in section 03.
Please note that our web pages and some of our emails load fonts from Google's font service. Your IP address is disclosed to Google when those load.
15
Sharing with Third Parties
We do not sell personal data. We share data with:
- Sub-processors — AI, cloud storage, payment, email and infrastructure providers as detailed in our sub-processor list, and only to the extent needed to deliver the Service.
- Your subscribing office — as detailed in section 07.
- Authorities — where required by law, court order, or to protect our rights.
- A successor entity — in the event of a merger or acquisition, subject to prior notice.
16
International Transfers
Some of our sub-processors store or process data outside Israel, principally in the European Union and the United States. Where this occurs we work to ensure appropriate safeguards are in place, including contractual undertakings from the provider, in line with the Privacy Protection Regulations (Transfer of Data Abroad) 5761-2001.
תקנות הגנת הפרטיות (העברת מידע אל מאגרי מידע שמחוץ לגבולות המדינה), תשס"א-2001
17
Children's Privacy
The Services are not directed to persons under the age of 18. We do not knowingly collect data from minors. If you become aware that a minor has provided data without the consent of a parent or guardian, contact us immediately at
support@rcube.cloud and we will ensure the data is deleted.
18
Data Security and Incident Reporting
We apply technical and organisational security measures in accordance with the Privacy Protection Regulations (Data Security) 5777-2017: encryption in transit (TLS), access controls, encryption of mailbox access tokens, and signed, time-limited URLs for chat attachments.
That said, no system is impenetrable and we cannot guarantee absolute security.
Incident reporting: in the event of a severe security incident affecting personal data, we will notify the Privacy Protection Authority and affected users without delay, as required by law.
Found a security weakness? We would like to hear about it:
support@rcube.cloud.
תקנות הגנת הפרטיות (אבטחת מידע), תשע"ז-2017 · Privacy Protection Regulations 5777-2017
19
Changes to This Policy
We may update this Policy from time to time. Material changes will be published on our website with the revised date, and where appropriate also by an in-product notice. Continued use of the Services after publication constitutes acceptance of the updated policy.