Privacy Policy

Last updated 8 September 2026

Rumrly (“we”, “us”) provides go-to-market tools at rumrly.in. This policy explains what we collect, why, and what you can do about it. We keep the data we hold to what the tools actually need.

What we collect

  • Account details. Your email address and a hashed password (hashing is handled by our authentication provider; we never see your password).
  • Connected accounts. If you connect Gmail or HubSpot, we store an access token, encrypted at rest. Gmail is read with a read-only scope and used only to detect your sent outreach emails and their replies. We do not read, store, or send email you receive, and we never send email from your account.
  • What you put into the tools. Competitor names and domains, subreddits, domains you check, and the results the tools compute for you (crawl findings, snapshots, scores, CRM data summaries). This is stored per account and isolated so no other user can read it.
  • Basic usage data. Aggregated, cookie-free page analytics (page views, country, referrer) so we know whether anyone is using the site. It is not tied to your identity.

How we use it

To run the tool you asked for, to keep you signed in, to send you the emails you opt into (sign-in confirmation, and the weekly Competitor Monitor digest if you have it on), and to fix and improve the product. We do not sell your data and we do not use it for advertising.

Who we share it with

We use a small number of service providers to run Rumrly:

  • Supabase: database and authentication.
  • Vercel: application hosting and cookie-free analytics.
  • Resend: sending the transactional and digest emails.
  • Cloudflare: bot protection and rendering pages for the audit tools.
  • Google: the Gemini API classifies text (public competitor pages, the product description you enter, community posts). Google’s OAuth handles the Gmail connection.

We also share data if the law requires it, or to protect Rumrly’s or a user’s rights and safety.

How long we keep it

For as long as your account is open. Delete your account (email us) and we remove your personal data and connected-account tokens within 30 days, except anything we must keep for legal or security reasons.

Your choices

You can ask us to show you the data we hold about you, correct it, export it, or delete it. You can disconnect Gmail or HubSpot at any time from inside the tool, which deletes the stored token. Email us for anything else.

Cookies

We use one kind of cookie: the session cookie that keeps you signed in. Our bot check (Cloudflare Turnstile) may set a short-lived cookie. We do not use advertising or cross-site tracking cookies, and our analytics do not use cookies at all.

Security

Data is encrypted in transit. Connected-account tokens are encrypted at rest. Access to each account’s data is enforced at the database level. No system is perfectly secure, but we treat your connected accounts as the sensitive data they are.

Children

Rumrly is for business use and not intended for anyone under 18.

Changes

If we make a material change we will update this page and the date above, and note it on sign-in where practical.

Contact

Questions or requests about your data: get in touch.