Privacy Policy

Last updated 2026-08-23

RubyRep, of India, is the data controller for RubyRep. This explains what we collect, why, and what you can do about it.

What we collect

From you, as a customer

  • Your name and email address, to create and identify your account.
  • A hash of your password. We never store the password itself.
  • The websites you add, and the pages we read from them in order to answer questions.
  • Billing status and a Razorpay subscription reference. We do not receive or store card numbers.

From visitors to your website

  • The questions they ask your representative and the answers it gave, so you can see what your customers want to know and so the conversation has memory.
  • A random visitor identifier stored in that visitor’s browser, to keep one conversation together. It is not linked to a name or an email.
  • The website the widget was loaded on, and the IP address the request came from, used for abuse prevention.

We do not ask visitors for personal details and the representative is instructed not to solicit them. If a visitor volunteers something personal in a message, it is stored as part of that conversation and is visible to you as the site owner.

Why we are allowed to hold it

For customer account and billing data, because we need it to perform our contract with you. For conversation data, on the basis of legitimate interests — yours in understanding your customers, and ours in operating and improving the service. For abuse prevention, on the basis of legitimate interests in keeping the service available.

Who else sees it

We use a small number of processors, and no more than we need:

  • Cloudflare — hosting, database and object storage. Also our network provider.
  • DeepSeek — generates answers. Question text and the retrieved passages from your site are sent to produce a reply.
  • OpenAI — converts text into embeddings so retrieval can match on meaning.
  • Razorpay — payment processing. They handle card details directly; we never receive them.
  • Brevo — transactional email, such as password resets.

We do not sell personal data, and we do not share it for advertising. We do not train any model on your content or on your visitors’ conversations.

Where it is held

Data is stored on Cloudflare’s network. Our processors may handle it outside your country; where that happens we rely on the safeguards those providers operate, including standard contractual clauses where required.

How long we keep it

  • Account data: until you delete your account.
  • Conversations and indexed page content: until you delete the website or your account.
  • After account deletion: removed from our live systems immediately, and from backups within 30 days.
  • Billing records: retained as long as tax law requires, separately from your account data.

Your rights

You can ask for a copy of your data, correct it, delete it, or object to how we use it. Two of these are self-service and immediate — from your settings you can export everything we hold and delete your account outright. For anything else, email hello@rubyrep.com and we will respond within 30 days.

If you are a visitor to a customer’s website rather than a customer of ours, that business is the controller of your conversation. Contact them first; we will help them action your request.

Cookies

We use a session cookie to keep you signed in. The widget stores a conversation identifier in the visitor’s browser so a conversation survives a page reload. We set no advertising or analytics cookies on customer websites.

Security

Data is encrypted in transit. Passwords are hashed. Access to production is limited to people who need it. No system is perfectly secure, and we will tell affected customers without undue delay if a breach puts their data at risk.

Changes

We will post changes here and, if they are material, email you before they take effect.

Contact

hello@rubyrep.com, or write to us at India.