Privacy Policy
Last updated: January 2025
Rumbolist ("we," "us," or "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, and safeguard your information when you use Rumbolist at rumbolist.com and any associated mobile applications.
By using Rumbolist, you agree to the collection and use of information in accordance with this policy.
1. Information We Collect
Account information. When you create an account, we collect your email address and a hashed password. If you sign in with Google, we receive your email address and name from Google.
Task and project data. We store the tasks, projects, notes, and other content you create within Rumbolist. This data is associated with your account and stored securely in our database.
Usage data. We collect anonymised information about how you use the app, including features used and error logs, to improve the product. We do not track individual behaviour for advertising purposes.
Payment information. If you subscribe to Rumbolist Pro, payment is processed by Stripe. We do not store your credit card number or full payment details. We receive confirmation of payment status and a customer ID from Stripe.
2. How We Use Your Information
- To provide, operate, and maintain the Rumbolist service
- To sync your data across devices when you are signed in
- To process payments and manage your subscription
- To send transactional emails (e.g. password reset, payment receipts)
- To improve the app based on aggregate, anonymised usage patterns
- To respond to support requests
We do not sell your personal data. We do not use your task content or personal information for advertising.
3. AI Features
Rumbolist offers optional AI-powered suggestions powered by Anthropic's Claude API. When you use these features, relevant task data (such as task titles, due dates, and delay patterns) is sent to Anthropic's API to generate recommendations. This data is used solely to produce your suggestion and is not stored by Anthropic beyond the duration of the request, per Anthropic's API usage policies.
AI features are optional. You can use Rumbolist fully without engaging them.
4. Data Storage and Security
Your data is stored in Supabase, a secure cloud database provider. All data is encrypted at rest and in transit using industry-standard TLS encryption. Access to your data is protected by Row Level Security — meaning your data is only accessible by you when authenticated.
While we take reasonable precautions to protect your data, no method of transmission over the internet is 100% secure. We cannot guarantee absolute security.
5. Third-Party Services
We use the following third-party services to operate Rumbolist:
- Supabase — database and authentication (supabase.com)
- Netlify — web hosting and serverless functions (netlify.com)
- Stripe — payment processing (stripe.com)
- Anthropic — AI suggestions, optional (anthropic.com)
- Google — optional sign-in via Google OAuth (google.com)
Each of these providers has their own privacy policy governing their handling of data.
6. Data Retention
We retain your account and task data for as long as your account is active. If you delete your account, your data is permanently deleted from our database within 30 days. Anonymised, aggregate usage data may be retained indefinitely.
7. Your Rights
Depending on your location, you may have the following rights regarding your personal data:
- Access — request a copy of the data we hold about you
- Correction — request that inaccurate data be corrected
- Deletion — request that your account and associated data be deleted
- Portability — export your task data via the CSV export feature in Settings
To exercise any of these rights, please contact us at the email address below.
8. Children's Privacy
Rumbolist is not directed at children under the age of 13. We do not knowingly collect personal information from children under 13. If you believe a child has provided us with personal information, please contact us and we will delete it promptly.
9. Changes to This Policy
We may update this Privacy Policy from time to time. When we do, we will update the "last updated" date at the top of this page. For significant changes, we will notify users via email or an in-app notice. Continued use of Rumbolist after changes constitutes acceptance of the updated policy.
10. Contact Us
If you have questions about this Privacy Policy or your data, please contact us at:
We aim to respond to all privacy-related enquiries within 5 business days.
This policy was written to be clear and readable. If anything is unclear, please reach out — we're happy to explain.