1. Scope
This Privacy Policy applies to Rubiun accounts, boards, collaboration features, admin tools, subscription screens, transforms, security logs, and related product pages. It applies when you use Rubiun as an account holder, board member, workspace owner, invited collaborator, or site visitor.
Rubiun is being prepared as an EU-focused service. Some final details depend on the production deployment, operator country, payment provider if any, email provider, analytics provider, transform integrations, and legal entity operating Rubiun.
2. Information Rubiun May Collect
Rubiun should collect only information needed to operate, secure, support, and improve the service.
| Category | Examples | Purpose |
|---|---|---|
| Account information | Name, email address, password hash, role, account status, acceptance of terms. | Authentication, account management, access control, communication. |
| Workspace content | Boards, objects, labels, notes, relationships, comments, saved transform results, and uploaded attachments. | Provide the investigation workspace and collaboration features. |
| Collaboration activity | Board membership, invites, permissions, comments, activity history, admin actions. | Shared workspaces, auditability, abuse prevention, support. |
| Technical and security data | Session metadata, request timestamps, rate limit events, login events, error logs, and limited technical network data needed to operate security controls. | Security, fraud prevention, debugging, abuse detection, service reliability. Rubiun does not plan to use raw IP addresses as an official user profile field or admin lookup field. |
| Billing data | Plan, seat count, billing status, payment provider reference, invoice metadata, and transaction metadata once paid billing is enabled. | Subscriptions, plan management, receipts, taxes, fraud prevention, and billing support once payment processing is enabled. |
3. How Information Is Used
- To create accounts, authenticate users, manage sessions, and keep accounts secure.
- To provide boards, objects, notes, search, collaboration, sharing, and admin features.
- To run transforms and return results requested by users.
- To enforce permissions, subscriptions, plan limits, and workspace settings.
- To detect spam, abuse, attacks, unauthorized access, policy violations, and service misuse.
- To troubleshoot bugs, maintain reliability, and improve the product.
- To communicate important service, security, billing, or account messages.
4. Legal Bases and User Responsibility
Where EU privacy laws require a legal basis, Rubiun may process information to provide the service, comply with legal obligations, protect legitimate security interests, or follow user consent where required.
Because Rubiun is an OSINT workspace, users are also responsible for having a lawful basis to collect and process investigation data they add to boards or submit to transforms.
6. Transforms and Third-Party Providers
Transforms may send user-provided input, such as usernames, emails, phone numbers, domains, IP addresses, or other search terms, to third-party providers only when a user chooses to run a transform. Those providers may process the submitted data under their own terms and privacy policies.
Before public launch, each enabled transform should have a clear provider disclosure explaining what data is sent, why it is sent, and whether results are stored on the board.
7. Security
Rubiun should use layered security controls, including server-side authentication, password hashing, secure cookies, CSRF protection, rate limiting, authorization checks, security headers, audit logging, and careful separation between client UI and server secrets.
No internet service can guarantee perfect security. Users should use strong passwords, keep devices protected, and report suspicious activity quickly.
8. Data Retention
Rubiun should keep data only as long as needed for the service, legal obligations, security, backups, billing records, dispute handling, or abuse prevention. Deleted account or board data may remain in backups for up to 30 days before scheduled deletion.
- Account data should remain while the account is active.
- Board content should remain while the board exists or while a workspace needs it.
- Security logs may be retained for abuse prevention and incident investigation.
- Deleted data may remain in backups for up to 30 days before scheduled deletion.
9. Privacy Rights and Choices
Depending on location, users may have rights to request access, correction, deletion, export, objection, restriction, or withdrawal of consent. Rubiun should provide a clear request channel before public launch.
Some requests may be limited by legal obligations, security needs, abuse prevention, investigation integrity, or rights of other users.
10. Children
Rubiun is not intended for children or teenagers. Users must be at least 18 years old to create an account or use the service.
11. International Data Transfers
Rubiun is being prepared for EU-focused use. If Rubiun is hosted, supported, or processed outside the European Economic Area, appropriate transfer mechanisms and provider agreements should be finalized before launch where required.
12. Changes to This Policy
This Privacy Policy may be updated as Rubiun changes. Material updates should be communicated through the service, email, or another reasonable method. The updated date should show when the policy last changed.
13. Contact
For privacy, account, security, or support requests, contact Rubiun at [email protected].