rruru
How it worksPrivacyTermsGet in touch

Privacy policy

Your skin story stays yours.

This policy explains what ruru collects, why we use it, which processors help us run the service, and the choices you have. We do not sell your data, use it for advertising, or train AI models on it.

Last updated 18 August 2026

The short version

ruru is a private skin companion. Your account, profile, diary, and images are kept in your private Supabase account. ruru does not store chat history or daily AI reflections and does not use your information to train, fine-tune, or evaluate AI models. When you ask ruru a question or request a daily reflection, the relevant conversation or diary check-in, recent check-ins, and minimum profile context needed for a safe answer are sent to Google Gemini as a service provider and are not retained by ruru after the request.

1. Who is responsible for your data

Venier Technologies, operating ruru ("ruru", "we", "us"), is the controller of the personal data described in this policy when you use the ruru mobile application or this website. For privacy questions, deletion requests, or to withdraw consent, email privacy@getruru.app. For general support, email support@getruru.app.

2. Information we process

InformationHow it arrivesWhy we use it
Account and authentication data: Supabase user ID, anonymous account identifier, email address, sign-in provider, and name you choose.You create or link an account in the app.To authenticate you, restore your account, save your profile, and answer support requests.
Profile and skin information: age range, gender, skin type and sensitivity, goals, concerns, ingredient preferences, current products, sunscreen habits, motivation, and similar onboarding choices.You provide it during onboarding or edit it later.To personalize routines, check-ins, content, and safety-oriented AI context.
Health and sensitive information: chronic or special conditions, pregnancy-related answers, and diary information that may reveal health, habits, mood, sleep, exercise, sun exposure, hydration, or skin changes.You choose whether to provide it.To provide the features you request and make suggestions more relevant and safer.
Images: face-scan/progress photos and profile images.You actively take or choose an image.To show your private progress history, connect a scan to a diary entry, or display your profile image.
Subscription and purchase information: product ID, transaction ID, original transaction ID, app-account token, environment, entitlement status, and expiry/revocation dates.Apple StoreKit and our Apple verification endpoint.To verify access, restore purchases, detect expiry or revocation, and prevent unauthorized premium access. We do not receive your payment card details.
Device-local information: onboarding drafts, local photo files, diary cache, routine reminder preferences, and scheduled local notification content.Stored on your device by the app.To keep the app useful when offline and schedule reminders you request.
AI request content: messages in the current ruru chat or a submitted diary check-in, up to seven recent check-ins, and the minimum profile context needed to answer.You send a chat message or submit a daily check-in.To generate the chat reply or daily reflection you requested. ruru does not save chat transcripts or daily AI reflections or use them to train AI.
Product analytics and diagnostics: simple event names such as an onboarding step completed, a feature opened, or an action succeeded or failed; a random analytics identifier; app version; operating-system version; and a sanitized error category.The app sends these limited events to PostHog when analytics is enabled.To understand onboarding completion, feature reliability, and aggregate product usage. We do not send PostHog your name, email, Supabase user ID, advertising ID, profile or health answers, diary or chat content, photos, precise location, or subscription transaction IDs.
Support communications and technical request metadata.You email or contact us.To respond, protect the service, and investigate errors. Do not send urgent medical information by email.

We do not intentionally collect precise location, contacts, advertising identifiers, browsing history for advertising, or biometric identifiers for identifying or authenticating you. The ruru face scan is a progress/photo feature; it is not facial recognition and we do not create a face template.

3. How we use your information and the EU legal basis

We use data only to provide, secure, support, and improve the ruru service in the ways described above. For people in the EEA, UK, and Switzerland, the legal basis depends on the purpose:

  • Contract, GDPR Article 6(1)(b): account access, profile and diary features, subscription entitlement, and requested support.
  • Consent, GDPR Article 6(1)(a): optional health/sensitive profile answers, face/progress images, optional product analytics, and any optional processing that is not necessary to provide a feature. Where local law requires consent for analytics, PostHog events remain disabled until you choose to allow them, and you can withdraw that choice later.
  • Explicit consent, GDPR Article 9(2)(a): where profile or diary information reveals health, pregnancy, medical conditions, or other special-category information. You may skip those questions and use the rest of the app.
  • Legitimate interests, GDPR Article 6(1)(f): service security, fraud prevention, reliability, and responding to support, balanced against your rights. We do not use this basis to override an explicit consent choice for sensitive data.
  • Legal obligation, GDPR Article 6(1)(c): records we must keep for tax, accounting, dispute resolution, or lawful requests.

We do not use your health or sensitive information for advertising, data brokerage, model training, or unrelated profiling. A refusal to give optional sensitive data does not prevent use of features that do not need it.

4. Face scans, profile images, and local caches

You control every camera or photo action. The iOS face-scan surface does not record or upload video and does not scan in the background. A captured image is kept in the app’s local storage. If you save it as a progress photo or profile image while signed in, the app may back up the JPEG to a private Supabase Storage bucket under your user ID so you can restore it. Supabase row-level and Storage policies limit access to your account.

Face and skin images can be sensitive because they may reveal appearance or health-related information. We do not use them to identify you, build a biometric template, train a model, or share them with advertisers. Delete an image in the app or email privacy@getruru.app; we will remove the cloud copy and associated record, subject to short-lived backups and legal retention described below.

On-device caches include onboarding drafts, local diary data, local photo files, and reminder settings. They remain on the device until the app deletes them, you delete the account, you clear app storage, or you uninstall the app. Notifications are scheduled locally by Apple/your device; ruru does not receive a history of whether you opened a reminder.

5. Service providers

We use carefully scoped providers to operate the service. They process information only for the services they provide to ruru and under the applicable provider terms, data-processing agreements, and security controls.

  • Supabase Auth: authentication and account sessions.
  • Supabase Postgres: private profile, diary, routine, and entitlement records.
  • Supabase Storage: private profile and progress images, protected by user-scoped policies.
  • Apple: App Store payment processing, StoreKit, App Store Server API purchase verification, and subscription status notifications. Apple receives purchase and device information under Apple’s own terms and privacy policy; ruru does not receive card details.
  • Google Gemini API: current chat messages or the submitted diary check-in, up to seven recent check-ins, and the minimum relevant profile context are processed to generate the requested response. The current app does not send face-scan images to Gemini. ruru does not retain the AI request or response and does not use it to train or fine-tune a model. We will configure a commercial/API data-use agreement and appropriate retention controls before an EU release.
  • PostHog: limited, pseudonymous product events and sanitized diagnostics described above. We disable session replay and automatic collection of form, text, diary, chat, photo, and health content; we do not identify people to PostHog by name, email, or ruru account ID; and we do not use this data for advertising.
  • Future AI processors: none are authorized by this policy by default. Before adding one, we will update this list and this policy, put the necessary processor agreement and transfer safeguards in place, and obtain new consent where the law requires it. No future provider may use ruru data to train its models without a separate, affirmative legal basis and disclosure.

Some providers may process data outside your country or the EEA. Where required, we use an adequacy decision, Standard Contractual Clauses, the provider’s data-processing terms, and supplementary safeguards. Ask privacy@getruru.app for the current processor and transfer details.

6. AI responses are session-only

Chat history is held in memory in the app while the chat screen is open. Each request sends the messages needed to continue that conversation. After a diary submission, ruru sends that check-in and up to seven recent check-ins to create a daily reflection. The reflection is shown in the success sheet but is not written to Supabase, a ruru database, analytics, or the user profile. Closing the relevant screen loses the AI response. We also instruct our hosting and AI integrations not to log request bodies; operational metadata such as timestamps, status codes, and error information may exist briefly in infrastructure logs.

AI and health reminder

AI replies can be wrong, incomplete, or unsuitable for you. ruru is not a medical device or healthcare provider and does not diagnose, treat, cure, or prevent disease. For persistent, severe, or worrying symptoms, contact a qualified clinician. In an emergency, contact local emergency services.

7. Retention, deletion, and backups

We keep account, profile, diary, image, and entitlement data while your account is active and for as long as needed to provide the service, handle disputes, prevent fraud, or meet legal obligations. We do not keep chat transcripts. You may ask us to delete your account and associated cloud data at any time by using the in-app deletion flow when available or emailing privacy@getruru.app from your account email.

After verifying the request, we aim to delete the account, Postgres rows, and Storage objects within 30 days. Encrypted backups and security logs may persist for up to 90 days before rolling off, and a limited purchase/account record may be retained longer where required by tax, accounting, fraud-prevention, or legal obligations. Deleting your ruru account does not cancel an Apple subscription; cancel it in Apple’s subscription settings. We will not use retained records for new product personalization.

Withdrawing consent does not affect processing that already occurred lawfully, or processing based on contract or law, but we stop the optional sensitive-data purpose and delete the affected information where possible. If deleting it makes a requested feature impossible, we will explain that clearly.

8. Your rights

Depending on where you live, you may have the right to access, correct, delete, restrict, object to, or receive a portable copy of your personal data; withdraw consent; object to direct marketing; and complain to your data protection authority. In Italy, the supervisory authority is the Garante per la protezione dei dati personali. Contact privacy@getruru.app with the request and the email or user ID associated with your account. We may verify your identity and generally respond within one month, with an extension where the law permits.

9. Security and children

We use TLS in transit, Supabase authentication, private Storage, row-level access controls, least-privilege server credentials, and no client-side secrets for Apple or Gemini. No system is perfectly secure; report a suspected incident promptly to privacy@getruru.app.

ruru is not directed to children under 13, and people in the EEA/UK/Switzerland should be at least 16 unless a parent or guardian and local law permit otherwise. If we learn that we collected a child’s data without the required authorization, we will delete it.

10. DPIA and EU launch commitment

Before launching in the EU, we will document a data-protection impact assessment (DPIA) or the written reasons a DPIA is not legally required. Because ruru can process health/special-category information, face/skin images, and AI-assisted personalization at scale, a DPIA is likely required or strongly indicated under GDPR Article 35. The assessment will cover necessity and proportionality, the Article 9(2)(a) explicit-consent flow, risks of inference and misuse, processor agreements, international transfers, retention/deletion, security, and human escalation. If the residual high risk cannot be mitigated, we will consult the relevant supervisory authority before processing.

11. Changes

We may update this policy when the service, processors, or law changes. We will update the date, give meaningful notice for material changes, and ask for fresh consent when a new purpose or legal basis requires it. The current version is always available at getruru.app/privacy.

rruru

A softer way to understand your skin.

PrivacyTermsSupportEmail us

© 2026 Venier Technologies. ruru is made with care.