Back to Rubiun

Legal

Privacy Policy

This policy explains what Rubiun may collect, how it may use that information, and what privacy controls should exist for an EU-focused launch.

Last updated: 13 September 2026

Draft notice: this page is a realistic privacy draft for launch preparation. It is not legal advice and must be reviewed against the final EU country of operation, hosting, billing, analytics, transform providers, and production setup before public release.

1. Scope

This Privacy Policy applies to Rubiun accounts, boards, collaboration features, admin tools, subscription screens, transforms, security logs, and related product pages. It applies when you use Rubiun as an account holder, board member, workspace owner, invited collaborator, or site visitor.

Rubiun is being prepared as an EU-focused service. Some final details depend on the production deployment, operator country, payment provider if any, email provider, analytics provider, transform integrations, and legal entity operating Rubiun.

2. Information Rubiun May Collect

Rubiun should collect only information needed to operate, secure, support, and improve the service.

Category Examples Purpose
Account information Name, email address, password hash, role, account status, acceptance of terms. Authentication, account management, access control, communication.
Workspace content Boards, objects, labels, notes, relationships, comments, saved transform results, and uploaded attachments. Provide the investigation workspace and collaboration features.
Collaboration activity Board membership, invites, permissions, comments, activity history, admin actions. Shared workspaces, auditability, abuse prevention, support.
Technical and security data Session metadata, request timestamps, rate limit events, login events, error logs, and limited technical network data needed to operate security controls. Security, fraud prevention, debugging, abuse detection, service reliability. Rubiun does not plan to use raw IP addresses as an official user profile field or admin lookup field.
Billing data Plan, seat count, billing status, payment provider reference, invoice metadata, and transaction metadata once paid billing is enabled. Subscriptions, plan management, receipts, taxes, fraud prevention, and billing support once payment processing is enabled.

3. How Information Is Used

  • To create accounts, authenticate users, manage sessions, and keep accounts secure.
  • To provide boards, objects, notes, search, collaboration, sharing, and admin features.
  • To run transforms and return results requested by users.
  • To enforce permissions, subscriptions, plan limits, and workspace settings.
  • To detect spam, abuse, attacks, unauthorized access, policy violations, and service misuse.
  • To troubleshoot bugs, maintain reliability, and improve the product.
  • To communicate important service, security, billing, or account messages.

5. Sharing and Disclosure

Rubiun should not sell personal information. Information may be shared only in limited situations:

  • With workspace members or collaborators according to board permissions.
  • With service providers needed for hosting, email, security, analytics, support, billing, or infrastructure.
  • With transform providers when a user chooses to run a transform.
  • When required by law, court order, legal process, or to protect safety and security.
  • During a business transfer, merger, acquisition, or restructuring, subject to appropriate safeguards.

6. Transforms and Third-Party Providers

Transforms may send user-provided input, such as usernames, emails, phone numbers, domains, IP addresses, or other search terms, to third-party providers only when a user chooses to run a transform. Those providers may process the submitted data under their own terms and privacy policies.

Before public launch, each enabled transform should have a clear provider disclosure explaining what data is sent, why it is sent, and whether results are stored on the board.

7. Security

Rubiun should use layered security controls, including server-side authentication, password hashing, secure cookies, CSRF protection, rate limiting, authorization checks, security headers, audit logging, and careful separation between client UI and server secrets.

No internet service can guarantee perfect security. Users should use strong passwords, keep devices protected, and report suspicious activity quickly.

8. Data Retention

Rubiun should keep data only as long as needed for the service, legal obligations, security, backups, billing records, dispute handling, or abuse prevention. Deleted account or board data may remain in backups for up to 30 days before scheduled deletion.

  • Account data should remain while the account is active.
  • Board content should remain while the board exists or while a workspace needs it.
  • Security logs may be retained for abuse prevention and incident investigation.
  • Deleted data may remain in backups for up to 30 days before scheduled deletion.

9. Privacy Rights and Choices

Depending on location, users may have rights to request access, correction, deletion, export, objection, restriction, or withdrawal of consent. Rubiun should provide a clear request channel before public launch.

Some requests may be limited by legal obligations, security needs, abuse prevention, investigation integrity, or rights of other users.

10. Children

Rubiun is not intended for children or teenagers. Users must be at least 18 years old to create an account or use the service.

11. International Data Transfers

Rubiun is being prepared for EU-focused use. If Rubiun is hosted, supported, or processed outside the European Economic Area, appropriate transfer mechanisms and provider agreements should be finalized before launch where required.

12. Changes to This Policy

This Privacy Policy may be updated as Rubiun changes. Material updates should be communicated through the service, email, or another reasonable method. The updated date should show when the policy last changed.

13. Contact

For privacy, account, security, or support requests, contact Rubiun at [email protected].

Before launch: add the legal operator name, any required business address, data processor list, retention schedule, and transform provider list.