Raven · Legal

Privacy & Cookie Policy

Effective date
September 21, 2026
Last updated
September 21, 2026
Service provider
Utilitay
Service
Raven

This Privacy & Cookie Policy (“Policy”) explains how Utilitay (“Utilitay,” “Raven,” “we,” “us,” or “our”) handles personal information in connection with Raven, the Utilitay account used to sign in to Raven, and this website. It forms part of the agreement governing use of Raven, together with the Raven Terms of Service and the Raven Acceptable Use Policy, and uses the same defined terms.

We have tried to write it the way we build: say what it does, and what it doesn’t. Where something is not done, this Policy says so rather than leaving it out.

1.Who This Policy Covers

Raven is used by schools, businesses, NGOs, institutions, and other organizations (“Organizations” or “Customers”) to send messages to the people they serve. Two groups of people are therefore affected by it, and we stand in a different position to each.

1.1Account Holders

Account Holders are the people who sign in to Raven or to a Utilitay account on behalf of an Organization — administrators, staff, and anyone an Organization has invited. For their account information, Utilitay decides how and why it is used, and is responsible for it.

1.2Recipients

Recipients are the people an Organization sends messages to — for example parents, guardians, members, customers, patients, or policyholders — and the people a message may be about, such as a student. Their information is Customer Content. The Organization decides whose information is placed in Raven, what is sent, and to whom. Utilitay holds and processes that information on the Organization’s behalf, in order to provide Raven.

If you are a Recipient and have a question about why you received a message, or want your details corrected or removed, the Organization that sent it is the right place to start. You may also contact us, and we will pass your request to the Organization and help it respond.

2.Information We Collect

We collect only what Raven needs in order to work.

2.1Account Information

Sign-in to Utilitay is by a third-party identity provider; at present that is Google. We do not ask for, receive, or store a password. When you sign in we receive from the provider your name, your email address, your profile picture, and an identifier for your account with that provider, together with the tokens the provider issues to complete the sign-in.

We also keep the date you last signed in, your language setting, a phone number if you add one, and whether your account is active.

2.2Organization Information

For each Organization we keep its name and legal name, country, address, billing email address, billing phone and WhatsApp numbers, the people who are members of it and their roles, and the invitations it has issued. An invitation records the email address invited; the invitation link itself is stored only in a scrambled (hashed) form.

2.3Recipient Information Provided by an Organization

An Organization may place in Raven, by typing it in or by uploading a spreadsheet, a Recipient’s name, phone number, WhatsApp number, email address, preferred language and channel, and any further details the Organization chooses to add. It may also record the people its messages are about — for a school, a student’s name and details such as class — and how a Recipient is related to them, and may arrange Recipients into groups.

We do not collect this information from Recipients ourselves, and we do not add to it from other sources.

2.4Messages and Delivery Records

For each message sent through Raven we keep the text as it was sent, the Recipient it was sent to, the channel used, who in the Organization sent it, the times it was queued, sent, delivered, or failed, any error returned, and the reference number the delivery provider gave it. This is the record that lets an Organization show what was sent, and when.

When a Recipient replies to an Organization’s WhatsApp number, we receive and keep the reply, the number it came from, the WhatsApp profile name attached to it, and the time it arrived. Replies to SMS messages are not currently received by Raven.

2.5Uploaded Files

Organizations may upload spreadsheets (.csv and .xlsx) of Recipient information, and a logo for use in email. We keep the uploaded file for a limited time (see Section 7), and a record of the upload: its file name, size, who uploaded it, when, and what it changed.

2.6Billing Information

We keep the invoices we issue, the usage they are based on, and a record of each payment received: its amount, date, method, and any reference supplied with it, such as a mobile-money transaction reference. Payments are made to us directly by mobile money, bank transfer, or cash, and are recorded by our staff. Raven is not connected to a payment processor. We do not collect or store card numbers, bank account numbers, or mobile-money PINs.

2.7Technical Information

Our systems keep audit records of significant actions — who did what, and when — and operational logs. Our logs are designed to identify a message by its reference number and not to contain message text or phone numbers.

Where Raven is used through our API, we store API keys only in a scrambled (hashed) form, and we use the IP address a request comes from to limit the rate of requests and to slow repeated attempts with an invalid key. We do not build a profile from it.

2.8This Website

This website has no sign-in, no contact form, and no analytics. The “Talk to us” options open your own email, phone, or WhatsApp application; what you then send us is kept as ordinary correspondence.

3.How We Use Information

We use the information described above to provide, operate, secure, and support Raven: to sign Account Holders in and show them the Organizations they belong to; to deliver the messages an Organization sends, by the channel it chooses, and record what became of them; to honor opt-out requests; to calculate usage, issue invoices, and record payments; to prevent fraud, abuse, and violations of the Raven Acceptable Use Policy; to respond to requests for help; and to comply with applicable law and with the requirements of the messaging providers and telecommunications operators that Raven depends on.

We use Customer Content, including Recipient information and message text, only as reasonably necessary for those purposes, as the Terms of Service provide.

3.1What We Do Not Do

We do not sell personal information. We do not use Recipient information to send messages of our own, or for advertising. We do not send Customer Content to any artificial-intelligence or machine-learning service. We do not use tracking technologies to follow you across other websites.

4.Cookies and Similar Technologies

We use only the cookies needed to keep you signed in. We do not use advertising cookies, analytics cookies, tracking pixels, session recording, or third-party tag managers, on this website or in Raven, and no third-party scripts are loaded by our pages. Fonts are served from our own servers.

4.1Cookies We Set

A session cookie is set when you sign in. It holds, in encrypted form, who you are and which Organizations you belong to, so that you stay signed in across Utilitay’s products. It lasts up to 30 days and is refreshed while you continue to use Raven. It can be read only by our servers, and is sent only over a secure connection.

An organization cookie remembers which of your Organizations you were last working in. It lasts up to 30 days and is removed when you sign out.

While you are signing in, a small number of short-lived security cookies are set to protect the sign-in itself — for example, to confirm that the response from the identity provider belongs to the request your browser made. They are removed when sign-in completes or shortly afterwards.

4.2Browser Storage

We also keep two small preferences in your browser’s own storage: which product to return you to after a visit to your account, which is forgotten when you close the tab, and, on our developers site, the programming language you chose for code samples. Neither is sent to us.

4.3Your Choices

Because these cookies are strictly necessary for signing in, we do not show a cookie banner, and there is nothing to consent to for advertising or analytics. You can block or delete cookies in your browser settings; if you do, you will not be able to stay signed in.

4.4Images in Email

Where an email sent through Raven carries an Organization’s logo, the Recipient’s mail application fetches that image from our file storage. As with any request over the internet, this involves the Recipient’s IP address. We do not use it to track whether an email was opened.

5.Who We Share Information With

Delivering a message means handing it to the networks that carry it. We share personal information only with the service providers that Raven needs in order to operate, and only what each needs.

5.1Messaging Providers

For SMS, we send Ponitor the Recipient’s phone number, the text of the message, and the name the message is sent under. Ponitor passes the message to the telecommunications operators and mobile networks that deliver it.

For WhatsApp, we send Meta Platforms, through its WhatsApp Business Platform, the Recipient’s WhatsApp number and the content of the message, including any details filled into a message template. Meta’s handling of messages on WhatsApp is governed by its own terms and privacy policy.

For email, where an Organization connects its own Google account, messages are sent through Google’s Gmail service from the Organization’s own address. The Organization, not Utilitay, is the sender, and Google receives the Recipient’s email address and the content of the email. We request permission only to send mail on the Organization’s behalf, not to read it.

5.2Infrastructure Providers

Raven runs on Google Cloud, and its databases and uploaded files are hosted by Supabase. Google also acts as the identity provider for sign-in. These providers process information on our behalf and under our instructions.

5.3Organizations

The members of an Organization can see the names, email addresses, and roles of its other members, and, within Raven, the Recipient information and message records that belong to that Organization. One Organization cannot see another’s.

5.4Legal and Safety Reasons

We may disclose information where required by applicable law or a valid order of a competent authority, or where reasonably necessary to investigate fraud, abuse, or a security incident, or to protect Raven, its users, Recipients, or the networks it depends on. If Utilitay or Raven were to be reorganized or transferred, information may pass to the successor, subject to this Policy.

6.Where Information Is Kept

Raven’s servers, databases, and file storage are located in the European Union (at present in Belgium, Germany, and Ireland). Information placed in Raven from Liberia is therefore stored and processed outside Liberia.

Messaging providers, telecommunications operators, and messaging platforms process messages in the countries in which they operate, which may be different again.

7.How Long We Keep Information

Raven removes information it no longer needs on a fixed schedule, which runs weekly:

Messages and their delivery records are kept in the working message log for 12 months, and are then moved to an archive.

Records of scheduled events are removed after 18 months, once no message still depends on them, and the records of why an automatic rule did or did not send are removed after 90 days.

Uploaded spreadsheets are deleted 30 days after the upload was completed or failed; at once, if the upload was discarded; and after 14 days, if it was left unfinished. The row-by-row record of what an upload changed is removed after 30 days. The summary record of the upload — its name, size, who uploaded it, and when — is kept.

Other information is not deleted on a fixed schedule. This includes account and Organization information, Recipient information that an Organization has not itself removed, archived messages, replies received on WhatsApp, invoices and payment records, and audit records. We keep it while the account is active and afterwards for as long as is reasonably necessary for legal, accounting, security, and dispute-resolution purposes. Audit records are kept permanently, because a record of who did what is only useful if it cannot be quietly shortened.

An Organization can correct or deactivate a Recipient’s details in Raven at any time, and can download its own Recipient records. Requests for deletion are handled as described in Section 9.

8.Opting Out of Messages

Utilitay does not decide who receives an Organization’s messages, but Raven gives Recipients and Organizations ways to stop them.

On WhatsApp, a Recipient who replies with exactly STOP, UNSUBSCRIBE, or STOP ALL will no longer be sent WhatsApp messages through Raven by that Organization. Replying START reverses this.

By SMS, replies are not currently received by Raven, so replying STOP to an SMS will not reach us. To stop SMS messages, contact the Organization that sent them, or contact us and we will pass the request on.

An Organization can also mark a Recipient as opted out. Once it has, Raven will refuse to send that Recipient anything. Organizations are required by the Raven Acceptable Use Policy to respect valid opt-out requests however they arrive.

9.Your Choices and Rights

You may ask us what personal information we hold about you, ask us to correct it if it is wrong, ask us to delete it, or object to how it is being used. Contact us using the details in Section 14. We will respond within a reasonable time, and may need to confirm your identity first.

If you are an Account Holder, you can disconnect a linked sign-in provider yourself, and an Organization’s administrator can remove you from the Organization. Closing an account, or deleting an Organization and its records, is carried out by our staff on request.

If you are a Recipient, the Organization that holds your details can correct or remove them directly, and is usually the quickest route. If you contact us instead, we will refer your request to that Organization and assist it.

We may keep information that we are required to keep by applicable law, or that we reasonably need for accounting, security, or the resolution of a dispute, even after a deletion request. Where we do, we will tell you.

10.Security

We take reasonable technical and organizational measures to protect information in Raven. Among them: connections to Raven are encrypted; we never hold passwords; session cookies are encrypted and readable only by our servers; API keys and invitation links are stored only in hashed form; the credentials for messaging providers are held in a dedicated secrets service and never in our databases; each Organization’s records are separated from every other’s at the level of the database; the services that hold data are not reachable from the public internet, and the services that are must prove their identity to reach them; and messages from our providers are accepted only when their signature has been verified.

No system is perfectly secure, and we do not claim that Raven is. If we become aware of a security incident affecting your information, we will notify the affected Organization without undue delay, and will notify others where applicable law requires it.

Account Holders are responsible for keeping their own sign-in secure, as the Terms of Service describe.

11.Children

Raven is a service for organizations, and accounts are intended for adults acting on an Organization’s behalf. It is not directed at children, and children are not intended to be Recipients of messages.

A school or similar Organization may place information about children in Raven — for example a student’s name and class — so that messages about that child can be sent to the child’s parent or guardian. That Organization is responsible for ensuring that it is entitled to hold and use that information. We use it only to deliver the Organization’s messages.

12.Changes to This Policy

Utilitay may update this Policy to reflect changes to Raven, to the providers it relies on, to security requirements, or to applicable law. The updated Policy will be published here with a revised “Last Updated” date.

Where a change materially affects how we handle personal information, we may provide additional notice or require Account Holders to accept the updated Policy before continuing to use Raven.

13.Relationship With Other Raven Policies

This Policy should be read together with the Raven Terms of Service, the Raven Acceptable Use Policy, and, where applicable, the Raven Political Organisations Schedule. If this Policy and the Terms of Service conflict on a question of how personal information is handled, this Policy controls.

14.Contact Us

Questions about this Policy, requests concerning your personal information, and reports of a suspected privacy or security problem may be directed to:

Utilitay - Raven
Old Telecom, Redlight
Paynesville City, Montserrado County
Republic of Liberia
Email: hello@utilitay.com
Phone: +231 881 872 270