1. Scope and controller
Rumata LTD (“Rumata,” “we,” “our,” or “us”) operates the Rumata website at rumata.dev, the Rumata platform, APIs, hosted applications, and related services (together, the “Services”). Rumata LTD is the controller of personal information covered by this policy unless a separate agreement says otherwise.
Customer applications may collect information from their own end users. For that information, the customer determines the purposes and means of processing and Rumata generally acts as a service provider or processor under the customer’s instructions. Customers are responsible for giving their end users an appropriate privacy notice.
2. Information we collect
Depending on how you use the Services, we may collect:
- Account and profile information: name, email address, authentication credentials, profile image, preferences, workspace membership, and permissions.
- Project and service content: prompts, chat messages, source code, generated output, project files, secrets you choose to store, database content, deployment configuration, workflow inputs and outputs, and support materials.
- Billing information: plan, subscription status, purchase and usage records, and payment-related identifiers. Polar and its payment providers process payment card details; Rumata does not store full card numbers.
- Communications: messages, feedback, survey responses, and support requests.
- Technical and usage information: IP address, browser and device information, operating system, timestamps, pages and features used, referral information, request metadata, logs, diagnostics, performance data, and security events.
- Integration information: identifiers, configuration, and content received from services you connect, subject to the permissions you grant.
If you provide personal information about another person, you must have the right to do so and provide any notice or obtain any permission required by law.
3. How and why we use information
We use information to:
- create and secure accounts, authenticate users, and manage workspace access;
- generate, build, host, deploy, monitor, and support projects and workflows;
- process subscriptions, usage allowances, purchases, and account administration;
- respond to support requests and send service, security, and billing notices;
- detect fraud, abuse, vulnerabilities, and violations of our Terms of Service;
- measure reliability and product usage, troubleshoot problems, and improve the Services; and
- comply with law, enforce agreements, and protect Rumata, our users, and others.
Where the GDPR, UK GDPR, or a similar law applies, our legal bases are performance of our contract with you, compliance with legal obligations, consent where requested, and our legitimate interests in operating, securing, supporting, and improving the Services. You may withdraw consent at any time, without affecting processing that occurred before withdrawal.
4. AI services
To fulfill AI requests, Rumata sends prompts, relevant project context, and configuration to OpenRouter, which routes requests to the model provider selected by you or by the service configuration. The model provider returns generated output to Rumata. Provider availability and routing may change over time.
Rumata does not use customer project content or generated code to train models owned by Rumata. OpenRouter and downstream model providers have their own retention and training practices, and some providers may retain or use inputs and outputs when the applicable routing or privacy settings allow it. Review the applicable provider terms before submitting confidential, regulated, or sensitive information. See the OpenRouter Privacy Policy for more information.
7. Data retention
We keep information only for as long as reasonably necessary for the purposes described in this policy. Our current baseline schedule is below. A shorter product setting, deletion request, contract, or legal requirement may change a specific period.
| Category | Baseline |
|---|---|
| Account and active project data | For the account or project lifetime, followed by any applicable recovery or deletion process. |
| Canceled or unpaid service data | A recovery window of up to 30 days where the applicable plan and service support it, then deletion. |
| Workflow version and execution history | The selected plan limit; current standard plans range from 1–4 days for versions and 1–30 days for executions. |
| Hosted database recovery data | The selected plan recovery window; current standard plans range from 1–7 days. Custom plans may differ by contract. |
| Operational and security logs | Normally up to 30 days, unless needed longer for an active security, fraud, or legal investigation. |
| Cookie-consent choice | Until you change it, clear site storage, or Rumata changes the consent-policy version. |
| Google Analytics identifiers | Only after consent; Google documents a default cookie duration of up to two years. Withdrawal removes known GA cookies from this site. |
| Billing, tax, fraud, dispute, and legal records | For the period required by applicable law or reasonably needed to establish, exercise, or defend legal claims. |
Residual copies may remain in backups until they are overwritten under normal schedules. When immediate deletion is not possible or appropriate, we isolate the information and restrict further use to the applicable retention purpose.
8. Security
We use administrative, technical, and organizational safeguards designed to protect information, including access controls and protections for data in transit and at rest where appropriate. No internet service is completely secure. You are responsible for protecting your credentials, configuring project access, and promptly telling us about suspected unauthorized use.
9. International data transfers
Rumata and our providers may process information in Israel, the United States, the European Economic Area, and other countries where we or they operate. Those countries may have different data-protection laws. Where required, we use recognized safeguards for transfers, such as adequacy decisions, contractual protections, and vendor security commitments. Contact us if you want more information about an applicable transfer safeguard.
10. Your rights and choices
Depending on your location and subject to legal exceptions, you may ask to access, correct, delete, or receive a copy of your personal information; object to or restrict processing; withdraw consent; or appeal a decision about a request. You may also opt out of marketing communications using the link in the message. Service and security messages are not marketing and may continue while you use the Services.
Submit a request to privacy@rumata.xyz. We may need to verify your identity and authority before acting. You may also complain to the Israeli Privacy Protection Authority or your local data-protection regulator. We will not discriminate against you for exercising a privacy right.
11. Children's privacy
The Services are not directed to children under 16, and we do not knowingly collect their personal information. If local law requires a higher age to consent to data processing, that higher age applies. Contact us if you believe a child has provided personal information without valid authorization.
12. Changes to this policy
We may update this policy to reflect changes to the Services, our practices, or the law. We will post the revised policy with a new date and, when required, provide additional notice before a material change takes effect. We will request consent if a new use requires it.
13. Contact us
Questions, privacy requests, and complaints may be sent to Rumata LTD in Israel at privacy@rumata.xyz.