Privacy policy
Your skin story stays yours.
This policy explains what ruru collects, why we use it, which processors help us run the service, and the choices you have. We do not sell your data or use it for advertising. Neither ruru nor Google uses your information to train AI models.
Last updated 8 September 2026
1. Who is responsible for your data
Venier Technologies, operating ruru ("ruru", "we", "us"), is the controller of the personal data described in this policy when you use the ruru mobile application or this website. For privacy questions, deletion requests, or to withdraw consent, email privacy@getruru.app. For general support, email support@getruru.app.
2. Information we process
| Information | How it arrives | Why we use it |
|---|---|---|
| Account and authentication data: Supabase user ID, anonymous account identifier, email address, sign-in provider, and name you choose. | You create, link, or restore an account in the app. | To authenticate you, restore your account, save your profile, and answer support requests. |
| Profile and skin information: age range, gender, skin type and sensitivity, goals, concerns, ingredient preferences, current products, sunscreen habits, motivation, and similar onboarding choices. | You provide it during onboarding or edit it later. | To personalize routines, check-ins, content, and, if you have agreed to AI sharing, to give safer AI context. |
| Health and sensitive information: chronic or special conditions, pregnancy-related answers, and diary information that may reveal health, habits, mood, sleep, exercise, sun exposure, hydration, or skin changes. | You choose whether to provide it in onboarding or diary answers. | To provide the features you request. If you have agreed to AI sharing, relevant answers may be included in the AI request. |
| Images: face-scan and progress photos, and profile images. | You take or choose an image. Saving a face scan stores a JPEG on this device. If you are signed in, ruru also uploads a private account backup. | To show your private progress history, attach a scan to a diary entry, or display your profile image. If you have agreed to AI sharing, today’s attached face check-in photo is sent with the diary reflection. Profile photos are not sent. Images are not used to train models. |
| On-device face alignment data: live camera frames and a bounding rectangle from Apple’s on-device Vision face-rectangle detection, used only while the scanner is open. | Created on the device after you continue to the system camera permission and open the scanner. | To help you center your face before capture. This geometry is not stored, is not a face template, and is not used to identify you. |
| Subscription and purchase information: product ID, transaction ID, original transaction ID, app-account token, environment, entitlement status, and expiry or revocation dates. | Apple StoreKit and our Apple verification endpoint. | To verify access, restore purchases, detect expiry or revocation, and prevent unauthorized paid access. We do not receive your payment card details. |
| Device-local information: onboarding drafts, local photo files, diary cache, a 20-minute chat cache, AI-sharing choice, routine reminder preferences, and scheduled local notification content. | Stored on your device by the app. | To keep the app useful when offline, continue a recent chat, and schedule reminders you request. |
| AI request content, only after an in-app AI sharing agreement: messages in the current chat, or a submitted diary check-in plus up to seven recent check-ins, plus relevant skin-profile answers, plus today’s face check-in photo when one is attached. | You send a chat message or save a diary check-in after agreeing to AI sharing. | To generate the chat reply or daily reflection you requested, including visible progress from the photo. Processed in ruru’s private Google Cloud project with zero data retention. Not used to train ruru or Google models. |
| AI sharing choice on your account: granted or withdrawn status, and the date of that last choice. | You tap Agree and enable AI, or you turn AI sharing off in Settings. | To remember your choice and to block AI requests on our server when consent is missing or withdrawn. |
| Support communications and technical request metadata such as timestamps, status codes, and sanitized error categories. | You email us, or the app or API records an operational error. | To respond, protect the service, and investigate failures. Request bodies, diary text, chat content, and image bytes are not written to application logs. |
We do not intentionally collect precise location, contacts, advertising identifiers, browsing history for advertising, or biometric identifiers for identifying or authenticating you. The ruru face scan is a progress-photo feature. It is not facial recognition, and we do not create a face template, embedding, landmark set, or skin score.
3. How we use your information and the EU legal basis
We use data only to provide, secure, support, and improve the ruru service in the ways described above. Access to the ruru app requires a paid Apple subscription. For people in the EEA, UK, and Switzerland, the legal basis depends on the purpose:
- Contract, GDPR Article 6(1)(b): account access, profile and diary features, subscription entitlement, and requested support.
- Consent, GDPR Article 6(1)(a): sending chat, diary, or profile information to Google for AI responses, and optional health or sensitive answers you choose to provide for that purpose.
- Explicit consent, GDPR Article 9(2)(a): where profile or diary information reveals health, pregnancy, medical conditions, or other special-category information and is included in an AI request you have agreed to.
- Legitimate interests, GDPR Article 6(1)(f): service security, fraud prevention, reliability, and responding to support, balanced against your rights. We do not use this basis to send personal information to Google AI.
- Legal obligation, GDPR Article 6(1)(c): records we must keep for tax, accounting, dispute resolution, or lawful requests.
Camera permission is not AI permission. Saving a diary entry does not require AI sharing. If you decline or later turn off AI sharing, ruru still stores the diary, photos, and profile features you are entitled to use. Turning off AI sharing stops future AI requests immediately. Information already sent cannot be recalled.
4. Face scans, profile images, and local caches
You control every camera or photo action. After you choose the face check-in, ruru shows a short explanation and a Continue button that opens Apple’s system camera prompt. If you later turn Camera off, ruru cannot show that system prompt again and instead offers Open Settings. The scanner uses the front camera only while that screen is open. It does not record or upload video and does not scan in the background.
While the scanner is open, Apple’s on-device Vision framework detects a face rectangle so the app can tell you to move closer, farther, or into the oval. Those live frames and rectangles stay in memory for alignment. They are discarded when you leave the screen or the camera session stops. ruru does not compute or store landmarks, a face mesh, embeddings, templates, identity scores, or inferred skin-condition scores from the live camera.
If you save a check-in, the captured still is written as a JPEG in the app’s local storage and linked to that diary date when you add it to an entry. If you are signed in, the app also uploads that JPEG to a private Supabase Storage bucket under your user ID so you can restore it. There is no separate in-app switch to skip that account backup for a signed-in save; using the scanner without an account keeps the image on the device only. Profile photos you take or choose are stored the same way: locally, then in your private bucket if you are signed in.
Face and skin images can be sensitive because they may reveal appearance or health-related information. We do not use them to identify you, build a biometric template, train a model, or share them with advertisers. Live camera frames stay on the device. If you have agreed to AI sharing, the saved daily face check-in JPEG attached to that diary entry is sent to Gemini on Vertex AI so the reflection can comment on visible progress. Profile photos are not sent. Zero data retention is enabled, so Google does not keep the photo to train models. Delete an image in You, then Progress photos. That removes the local file and index entry first so a pending backup cannot re-upload it, then deletes the cloud object and diary reference when the network is available. You can also email privacy@getruru.app.
On-device caches include onboarding drafts, local diary data, local photo files, reminder settings, your AI-sharing choice, and chat messages from the last 20 minutes. They remain until the app deletes them (for chat, when the 20-minute window has passed and the app next loads that cache), you sign out, you delete the account, you clear app storage, or you uninstall the app. Notifications are scheduled locally by Apple on your device. ruru does not receive a history of whether you opened a reminder.
5. Service providers
We use carefully scoped providers to operate the service. They process information only for the services they provide to ruru and under the applicable provider terms, data-processing agreements, and security controls.
- Supabase Auth: authentication and account sessions.
- Supabase Postgres: private profile, diary, routine, and account records, including your AI sharing choice.
- Supabase Storage: private profile and progress images, protected by user-scoped policies.
- Apple: App Store payment processing, StoreKit, App Store Server API purchase verification, and subscription status notifications. Apple receives purchase and device information under Apple’s own terms and privacy policy. ruru does not receive card details.
- Google Cloud Vertex AI, Gemini models: if you have a current in-app AI sharing agreement, current chat messages or the submitted diary check-in, up to seven recent check-ins, relevant profile context, and today’s attached face check-in photo are processed inside ruru’s private Google Cloud project to generate the requested response. Profile photos are not sent. Chat does not include images. Zero data retention is enabled, so Google does not keep prompts, photos, or replies to train models. ruru does not retain the AI request or response in its database. Ask privacy@getruru.app if you need more processor detail.
The current app does not send product analytics to PostHog or another advertising or product-analytics SDK. Some providers may process data outside your country or the EEA. Where required, we use an adequacy decision, Standard Contractual Clauses, the provider’s data-processing terms, and supplementary safeguards. Ask privacy@getruru.app for the current processor and transfer details.
6. AI responses, chat cache, and your permission
ruru does not send personal information to Google until you tap Agree and enable AI in the app. That screen names Google Gemini on Vertex AI in ruru’s private Google Cloud project, describes the chat and diary payloads, including today’s face check-in photo for diary reflections, and lets you choose Not now. It also states that zero data retention is enabled and that the request is not used to train models. Opening the chat screen or saving a diary entry does not count as consent. A missing or withdrawn choice is treated as a refusal. Our API also rejects chat and diary-reflection requests without a current granted choice.
Chat history is stored on your device, scoped to the signed-in account, for 20 minutes so you can leave the screen and come back. The app deletes that local copy when the window has expired and it next reads the cache, when you start a new chat, when you sign out, or when you delete your account. ruru does not write chat transcripts to Supabase. Closing the screen does not by itself erase a still-fresh cache.
After a diary submission, if AI sharing is on, ruru sends that check-in, up to seven recent check-ins, and today’s attached face check-in photo when one is available, to create a daily reflection. The reflection is shown in chat and is not written to Supabase. If AI sharing is off, the diary still saves and no reflection is requested, and the photo is not sent to Google.
Turn AI sharing off in You, then Privacy and data. That updates the local choice immediately and syncs it before later AI use. Already transmitted requests cannot be recalled.
7. Retention, deletion, and backups
Transient camera frames and face rectangles exist only in memory during an open scanner session and are discarded when the session stops. Saved local images and diary files stay on the device until you delete the image, sign out, delete the account, clear app storage, or uninstall the app. Active cloud images, profile rows, diary rows, routines, and your account row including the AI sharing choice stay while the account is active.
Chat cache: up to 20 minutes on the device, then deleted the next time the app loads that cache. AI responses are not stored in ruru’s database. Vertex AI requests, including a diary face check-in photo when attached, run with zero data retention enabled, so Google does not keep prompts, photos, or replies to train models. Application logs keep operational metadata such as timestamps and sanitized error codes, not request bodies, photos, diary text, or chat content. Infrastructure logs and database backups follow the hosting provider’s standard cycle. ruru does not publish a separate guaranteed backup-retention number beyond what those providers apply.
Delete a single photo in You, then Progress photos. Delete your account in You, then Privacy and data, then Delete my ruru account. That flow removes local photos, diary cache, chat cache, onboarding data, reminder settings, the private Storage objects we can list for your user ID, Postgres rows including your account and AI sharing choice, and the Auth user. A pending photo backup is removed from the local queue first so it cannot be re-uploaded after deletion. Encrypted provider backups and security logs may persist after that until they roll off under the provider’s backup process. A limited purchase or account record may be retained longer where required by tax, accounting, fraud-prevention, or legal obligations. Deleting your ruru account does not cancel an Apple subscription. Cancel it in Apple’s subscription settings.
You may also email privacy@getruru.app from your account email. After we verify the request, we delete the same cloud records described above. We will not use retained records for new product personalization.
8. Your rights
Depending on where you live, you may have the right to access, correct, delete, restrict, object to, or receive a portable copy of your personal data; withdraw consent; object to direct marketing; and complain to your data protection authority. In Italy, the supervisory authority is the Garante per la protezione dei dati personali. Contact privacy@getruru.app with the request and the email or user ID associated with your account. We may verify your identity and generally respond within one month, with an extension where the law permits.
9. Security and children
We use TLS in transit, Supabase authentication, private Storage, row-level access controls, least-privilege server credentials, and no client-side secrets for Apple or Gemini. No system is perfectly secure. Report a suspected incident promptly to privacy@getruru.app.
ruru is not directed to children under 13, and people in the EEA, UK, and Switzerland should be at least 16 unless a parent or guardian and local law permit otherwise. If we learn that we collected a child’s data without the required authorization, we will delete it.
10. DPIA and EU launch commitment
ruru can process health information, face and skin images, and AI-assisted personalization. Before relying on this policy for an EU-scale launch of those activities, we will document a data-protection impact assessment or the written reasons a DPIA is not legally required, and we will complete any remaining processor, transfer, and consent work that assessment identifies. This section describes a commitment, not a completed filing.
11. Changes
We may update this policy when the service, processors, or law changes. We will update the date, give meaningful notice for material changes, and ask for fresh consent when a new AI recipient, purpose, or disclosed data category requires it. The current version is always available at getruru.app/privacy.