Who we are
Railio Systems, Inc. ("Railio", "we", "us") provides an AI copilot for rail maintenance that grounds its answers in a customer's own manuals, federal regulations (49 CFR), unit history, and senior technician notes. This policy explains how we handle information collected through our website and product.
Information we collect
- Information you give us. When you submit our contact form or book a demo, we collect your name, email, company, areas of interest, and anything else you choose to share.
- Account information. When your organization uses Railio, we process account and profile details needed to authenticate users and separate one organization's data from another's.
- Content you put into the product. Messages, photos, tickets, parts records, and notes you or your technicians create while using Railio, together with the reference material your organization brings with it, such as OEM manuals, unit history, and senior technician notes.
- Voice dictation. If you dictate instead of typing, the audio clip is sent to our transcription provider to turn it into text. Railio does not store the audio.
- Usage and device data. Standard technical information such as log data, approximate location, and browser or device details, used to operate and secure the service.
How your organization's data is kept separate
Every organization on Railio is its own tenant. Assets, tickets, conversations, parts, photos, and reference material all carry the organization they belong to, and every query we run is filtered by it.
- The organization is decided on our server, not by your browser. We read it from the signed in user's verified access token and our own records. Nothing the client sends can name a different organization, so a modified client cannot ask for another customer's data.
- A record belonging to another organization does not exist to you. A request for an asset, ticket, part, or document outside your organization returns "not found" rather than the record.
- Reference material has two tiers. Federal regulation (49 CFR) is shared across all customers because it is public. Everything you bring stays private to your organization: your OEM manuals, your unit history, your technicians' notes. Another customer cannot retrieve it or see that it exists.
- Retrieval is narrowed further inside your own data. A search is scoped to the locomotive model in question and, for unit history, to the specific unit the work is on.
How we use information
- To provide, maintain, and improve the product and respond to your requests.
- To contact you about demos, onboarding, support, and product updates you have asked about.
- To keep the service secure, prevent abuse, and meet our legal and contractual obligations.
We do not sell your personal information, we do not share your content with other customers, and we do not use customer content to train any model, ours or an outside provider's.
How Railio's AI works with your data
Railio's answers are generated by an established commercial model provider that we reach through its API. Every call is made by our backend using our own credentials, and your content goes to no other model provider. We will identify the provider and share its data handling terms with your organization on request.
- What we send. The conversation in the thread you are working in, the passages our search step selected from your own reference material for that question, and any photo you attach to the message. We send those passages, not your database.
- What the model can reach. The model cannot query your data freely. It can call only a fixed set of tools, and the boundary those tools run inside, meaning your organization and the unit on the ticket, is set by our server before the model runs. The model never chooses its own scope, and it never sees another organization's data.
- Training. We do not train or tune any model on your content. Under our model provider's API terms, content sent through the API is not used to train its models either. The provider may hold API content briefly for abuse monitoring, currently up to 30 days, and then deletes it.
- Search index. To make your manuals searchable we convert them into numeric vectors and store those vectors in our database, tagged to your organization. They are used only to find relevant passages for your own users.
- Grounding. Railio answers from your material and cites what it used. When your manuals and notes do not cover a question, it says so rather than filling the gap from the model's general knowledge.
Data retention, deletion, and the audit trail
Railio keeps the conversation record as an append only log linked by hashes so that guidance given at the locomotive can be reviewed later. Because this record is designed to reveal any tampering, individual messages are not edited or deleted in place. A correction is written as a new entry that supersedes the earlier one, and both stay in the record.
We keep your organization's data for as long as your account is active. When your account ends you may ask us for an export, and we delete your organization's content within 30 days of that request or of account closure, except where the law requires us to keep it.
Security
- Sign in runs through our authentication provider. Every request to our API carries an access token that we verify against that provider's public keys before anything is read or written.
- Traffic is encrypted in transit with TLS, and data is encrypted at rest by our hosting provider.
- Uploaded files are held in a private bucket and reached through links that expire.
- The ticket conversation is covered by a SHA-256 hash chain, so a record altered after the fact can be detected.
- Chat is rate limited per user to limit abuse.
No system is perfectly secure, but we work to protect information consistent with industry practice, and we will notify affected customers without undue delay if their data is involved in a security incident.
Your choices
You may unsubscribe from our emails at any time using the link in the message or by contacting us. Subject to applicable law, you may request access to, correction of, or deletion of your personal information by emailing contact@railio.xyz. If you use Railio on behalf of an organization, some requests may be directed to that organization as the controller of its data.
For the content your organization puts into Railio, your organization is the controller and Railio is the processor: we process that content on your instructions in order to provide the service. If your organization requires a signed data processing agreement, email contact@railio.xyz and we will put one in place.
Changes to this policy
We may update this policy from time to time. Material changes will be reflected by updating the effective date above and, where appropriate, by additional notice.
Contact
Questions about this policy or your information? Email contact@railio.xyz.