Privacy Policy
Last updated: January 2025
1. Introduction and Scope
This Privacy Policy (hereinafter "Policy") describes how RuleBox (hereinafter "we," "us," "our," or "the Company") collects, uses, stores, processes, discloses, and protects information obtained from users (hereinafter "you," "your," or "User") of the RuleBox platform and related services (collectively, "the Service"). By accessing or using the Service, you acknowledge that you have read, understood, and agree to be bound by this Privacy Policy. If you do not agree to this Policy, please do not use the Service.
This Policy applies to all information collected through the Service, as well as any related services, sales, marketing, or events. It does not apply to information collected by third parties, including any third-party websites, services, or applications that you may access through the Service. We encourage you to read the privacy policies of any third-party services you interact with.
We reserve the right to modify this Privacy Policy at any time, for any reason, without prior notice to you. Any changes will be effective immediately upon posting the revised Policy on this page. Your continued use of the Service following the posting of changes constitutes your acceptance of such changes. It is your responsibility to review this Policy periodically for updates.
2. Information We Collect
We collect various types of information in connection with your use of the Service. The types of information we collect depend on how you interact with the Service and the choices you make.
2.1 Information You Provide Directly
When you create an account, submit content, or otherwise interact with the Service, you may provide us with information including but not limited to:
- Account information obtained from OAuth providers (such as GitHub or Google), including your name, email address, profile picture, and unique identifiers
- User-generated content, including rules, configurations, comments, votes, reactions, and any other materials you submit to the Service
- Communications you send to us, including support requests, feedback, and other correspondence
- Any other information you choose to provide to us in connection with your use of the Service
2.2 Information Collected Automatically
When you access or use the Service, we automatically collect certain information, including but not limited to:
- Device information, including device type, operating system, unique device identifiers, browser type and version, and hardware settings
- Log information, including access times, pages viewed, IP address, referring URL, and the page you visited before and after using the Service
- Location information, including general geographic location based on your IP address or, with your consent, more precise location information from your device
- Usage information, including the features you use, the content you view, and your interactions with other users and content on the Service
- Performance data, including crash reports, system activity, and diagnostic information
2.3 Information from Third Parties
We may receive information about you from third parties, including OAuth providers, analytics providers, advertising partners, and publicly available sources. This information may be combined with other information we collect about you.
2.4 Cookies and Similar Technologies
We use cookies, web beacons, pixels, tags, scripts, and similar tracking technologies to collect and store information about your use of the Service. These technologies may be used for various purposes, including authentication, security, functionality, analytics, and advertising. You may be able to control some of these technologies through your browser settings, but disabling certain technologies may affect the functionality of the Service.
We may also use third-party analytics services, such as Google Analytics, to collect and analyze information about your use of the Service. These third parties may use cookies and similar technologies to collect information about your online activities across different websites and services over time.
3. How We Use Your Information
We may use the information we collect for various purposes, including but not limited to:
- Providing, maintaining, and improving the Service and its features
- Processing and completing transactions and sending related information
- Creating and managing your account and authenticating your identity
- Responding to your comments, questions, and requests and providing customer support
- Communicating with you about products, services, promotions, events, and other news and information we think may be of interest to you
- Monitoring and analyzing trends, usage, and activities in connection with the Service
- Detecting, investigating, and preventing security incidents, fraudulent transactions, and other illegal or unauthorized activities
- Personalizing and improving your experience on the Service, including by providing content, features, or recommendations tailored to your interests
- Complying with legal obligations and enforcing our terms, conditions, and policies
- Carrying out any other purpose described to you at the time the information was collected
- For any other purpose with your consent or as otherwise permitted or required by applicable law
We may combine information we collect from different sources and use the combined information for any of the purposes described in this Policy. We may also use aggregated or de-identified information, which is not subject to this Privacy Policy, for any purpose.
4. How We Share Your Information
We may share the information we collect in various circumstances, including:
4.1 Public Information
Information you submit to public areas of the Service, including your profile information, submitted content, comments, votes, and reactions, will be visible to other users of the Service and may be indexed by search engines. User Content submitted to the Service is dedicated to the public domain under CC0 and may be freely used, distributed, and modified by anyone.
4.2 Service Providers
We may share your information with third-party vendors, service providers, contractors, or agents who perform services for us or on our behalf, including hosting, data storage, analytics, payment processing, customer support, email delivery, marketing, and advertising. These service providers may have access to your information only to perform these tasks on our behalf and are obligated not to disclose or use it for any other purpose.
4.3 Business Transfers
We may share or transfer your information in connection with, or during negotiations of, any merger, sale of company assets, financing, acquisition, dissolution, reorganization, bankruptcy, or similar transaction or proceeding involving all or a portion of our assets. In such cases, your information may be among the assets transferred to the acquiring entity.
4.4 Legal Requirements
We may disclose your information if we believe in good faith that such disclosure is necessary to: (a) comply with applicable laws, regulations, legal processes, or governmental requests; (b) enforce our Terms of Service and other agreements; (c) protect our rights, property, or safety, or the rights, property, or safety of our users or others; (d) detect, prevent, or address fraud, security, or technical issues; or (e) respond to an emergency situation.
4.5 With Your Consent
We may share your information with third parties when you have given us your consent to do so, or when you have directed us to share your information with third parties.
4.6 Aggregated or De-Identified Information
We may share aggregated or de-identified information that cannot reasonably be used to identify you with third parties for any purpose, including research, analytics, marketing, and advertising.
5. Data Retention
We retain your information for as long as necessary to fulfill the purposes for which it was collected, including to satisfy any legal, accounting, or reporting requirements, or as otherwise permitted or required by applicable law. The retention period may vary depending on the context of the processing and our legal obligations.
In determining the appropriate retention period for personal information, we consider the amount, nature, and sensitivity of the personal information, the potential risk of harm from unauthorized use or disclosure, the purposes for which we process the personal information, whether we can achieve those purposes through other means, and applicable legal requirements.
User Content that you submit to the Service is dedicated to the public domain and may be retained indefinitely, even after you delete your account. We may also retain certain information as required by law or for legitimate business purposes, such as to resolve disputes, enforce our agreements, or for backup, archival, or audit purposes.
When we no longer need to retain your personal information, we will either delete or anonymize it, or, if this is not possible (for example, because your personal information has been stored in backup archives), we will securely store your personal information and isolate it from any further processing until deletion is possible.
6. Data Security
We implement reasonable administrative, technical, and physical security measures designed to protect your information from unauthorized access, use, alteration, or destruction. However, no method of transmission over the Internet or method of electronic storage is completely secure, and we cannot guarantee the absolute security of your information.
You are responsible for maintaining the confidentiality of your account credentials and for any activities that occur under your account. You agree to notify us immediately of any unauthorized use of your account or any other breach of security. We will not be liable for any loss or damage arising from your failure to comply with this security obligation.
Our Service is hosted by Supabase, which implements industry-standard security measures including encryption at rest and in transit. However, we are not responsible for the security practices of third-party service providers, and you acknowledge that any transmission of information is at your own risk.
7. International Data Transfers
Your information may be transferred to, stored, and processed in countries other than the country in which you reside, including the United States and other countries where we, our affiliates, or our service providers operate. These countries may have data protection laws that are different from the laws of your country.
By using the Service, you consent to the transfer of your information to countries outside your country of residence, including the United States, which may have different data protection rules. We will take appropriate measures to ensure that any such transfers comply with applicable data protection laws and that your information remains protected in accordance with this Privacy Policy.
8. Your Rights and Choices
Depending on your location and applicable law, you may have certain rights regarding your personal information. These rights may include:
- The right to access personal information we hold about you
- The right to request correction of inaccurate personal information
- The right to request deletion of your personal information, subject to certain exceptions
- The right to object to or restrict certain processing of your personal information
- The right to data portability in certain circumstances
- The right to withdraw consent where processing is based on consent
- The right to lodge a complaint with a supervisory authority
To exercise any of these rights, please contact us using the contact information provided below. We may require you to verify your identity before responding to your request. We will respond to your request within a reasonable timeframe and in accordance with applicable law.
Please note that certain rights may be limited in certain circumstances, such as where fulfilling your request would adversely affect other individuals or our trade secrets or intellectual property, where we are legally prevented from disclosing such information, or where the request is manifestly unfounded or excessive.
You may also have the right to opt out of receiving marketing communications from us by following the unsubscribe instructions in those communications. Please note that even if you opt out of marketing communications, we may still send you non-promotional communications, such as those about your account or our ongoing business relations.
9. California Privacy Rights
If you are a California resident, you may have additional rights under the California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA), including the right to know what personal information we collect, use, disclose, and sell; the right to request deletion of your personal information; the right to opt out of the sale or sharing of your personal information; and the right not to be discriminated against for exercising your privacy rights.
We do not sell personal information as that term is defined under the CCPA/CPRA. To exercise your rights under California law, please contact us using the information provided below. We will verify your identity before processing your request.
10. European Privacy Rights
If you are located in the European Economic Area (EEA), United Kingdom, or Switzerland, you may have rights under the General Data Protection Regulation (GDPR) or similar laws, including the rights described in Section 8 above. The legal bases for our processing of your personal information include your consent, the performance of a contract with you, compliance with legal obligations, and our legitimate interests in operating and improving the Service.
If you wish to exercise any of your rights under the GDPR, please contact us using the information provided below. You also have the right to lodge a complaint with a supervisory authority in your country of residence.
11. Children's Privacy
The Service is not intended for use by children under the age of 13 (or such other age as may be specified by applicable law in your jurisdiction). We do not knowingly collect personal information from children under 13. If we learn that we have collected personal information from a child under 13, we will take steps to delete such information as soon as possible. If you believe that a child under 13 has provided us with personal information, please contact us using the information provided below.
12. Do Not Track Signals
Some browsers have a "Do Not Track" feature that allows you to tell websites that you do not want to have your online activities tracked. We currently do not respond to "Do Not Track" signals or other mechanisms that provide consumers with the ability to exercise choice regarding the collection of personal information about their online activities over time and across third-party websites or online services.
13. Third-Party Links and Services
The Service may contain links to third-party websites, services, or applications that are not owned or controlled by us. This Privacy Policy applies only to the Service and does not apply to any third-party websites, services, or applications. We are not responsible for the privacy practices of any third parties, and we encourage you to review the privacy policies of any third-party services you access through the Service.
14. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technologies, legal requirements, or other factors. We will post any changes on this page and update the "Last updated" date at the top of this Policy. We encourage you to review this Policy periodically to stay informed about how we collect, use, and protect your information.
Your continued use of the Service following the posting of changes to this Policy constitutes your acceptance of those changes. If we make material changes to this Policy, we may notify you by email or through a notice on the Service prior to the changes becoming effective, but we are not obligated to do so.
15. Contact Information
If you have any questions, concerns, or complaints about this Privacy Policy or our privacy practices, or if you wish to exercise any of your rights described in this Policy, you may contact us at contact@rulebox.ai. We will endeavor to respond to your inquiry within a reasonable timeframe, but we make no guarantees regarding response times or the resolution of any issues raised.
By using RuleBox, you acknowledge that you have read, understood, and agree to be bound by this Privacy Policy. See also our Terms of Service.