RUMR Privacy Policy
Effective date: 09/16/2026
This policy explains what information RUMR collects, how we use it, who we share it with, and the choices you have. RUMR is operated by Enovate Consulting, Inc., a US company ("RUMR", "we", "us"). If you have questions, email privacy@myrumr.com.
This policy replaces all earlier RUMR privacy policies.
The short version
- We collect what you give us (your phone number or sign-in account, your profile, and what you post and send) plus basic technical information needed to run the app.
- Posts, stories, comments, likes and profiles are social. Other people can see them, depending on your settings.
- Direct messages are private between the people in the conversation, but they are not end-to-end encrypted. They are stored on our servers.
- We do not sell your personal information. We do not show ads, and we do not use advertising or analytics trackers.
- We do not access your contacts or your device's location.
- You can delete your account in Settings.
Information you give us
Account information
- Phone number, if you sign in with a text-message code.
- Google account details, if you sign in with Google: your email address, name and a Google account identifier.
- Apple account details, if you sign in with Apple: an Apple account identifier, and the email address and name Apple shares with us. If you choose "Hide My Email", we only receive Apple's relay address.
Profile information
- Username, display name, bio and profile photo.
- Your account settings, such as whether your account is private.
Your username, display name, bio and profile photo are visible to other RUMR users, even if your account is private.
Content you create
- Photos and videos you post, with captions.
- Stories (photos and videos that disappear from the app after 24 hours).
- Comments, likes and follows.
- Direct messages, including text, photos and emoji reactions.
- Reports you file about other users or content, including the reason you pick and any details you add.
- The list of accounts you have blocked.
Photos and videos can contain hidden information added by your camera, such as the date or the place they were taken. RUMR does not read or use this information, but it may stay in the file you upload. If you do not want to share it, turn off location tagging in your camera settings before you take the photo or video.
Information collected automatically
- Device and app information: device type, operating system, app version, and the push notification token for your device.
- Crash reports: if the app crashes or hits a serious error, a crash report is sent to Google Firebase Crashlytics. It includes the device model, operating system version, app version, the technical details of the error, and an identifier for the app installation. It does not include your posts or messages.
- Server logs: our service providers record technical details when the app connects to our servers, such as IP address, request time and error information. These are used for security and troubleshooting.
- Activity inside RUMR: for example, when you last read a conversation, so we can show unread counts.
Some information stays only on your phone and is never sent to us, such as which stories you have already watched and your theme and notification sound choices.
Device permissions
RUMR asks for permission before using these features of your phone. You can change them at any time in your phone's settings.
- Camera: to take photos and videos for posts, stories, messages and your profile photo.
- Photos and media: to choose existing photos and videos to share. We only upload the items you pick.
- Notifications: to send you push notifications.
We do not access your contacts or your device's location.
How we use your information
We use your information to:
- Create and secure your account, and verify your phone number or sign-in.
- Show your profile and content to other users, according to your settings.
- Deliver direct messages and notifications.
- Build your feed, including posts from people you follow and public posts.
- Enforce blocks, private accounts and follower-only posts.
- Review reports and keep RUMR safe, including investigating abuse, spam and violations of our Terms of Service.
- Fix bugs and crashes and keep the service running.
- Respond to you when you contact us.
- Comply with the law and respond to valid legal requests.
We do not use your information for advertising, and we do not build advertising profiles.
Who can see what
Public accounts: your posts marked "Public", your stories, and your follower and following counts can be seen by any RUMR user.
Private accounts: only followers you approve can see your posts and stories. Your profile basics (username, display name, bio, photo) are still visible to everyone.
Followers-only posts: only your approved followers can see them.
Blocking: when you block someone, neither of you can see the other's profile, posts or stories, and they cannot message you. They are not notified that you blocked them.
Comments and likes on a post can be seen by people who can see that post.
Direct messages can be read by the people in the conversation.
Links to media: photos and videos in posts, stories and profile photos are delivered from links that are long and hard to guess. The app only shows them to people allowed to see them, but anyone who obtains a direct link to one of those files could open it. Photos sent in direct messages are protected and can only be opened by people in the conversation.
Sharing: if you use the share button on a post, the app creates a link to that post and hands it to the app you choose. Only people allowed to see the post can open it in RUMR.
Direct messages
Messages are protected in transit (encrypted between your phone and our servers) and access-controlled so only people in the conversation can read them through RUMR. They are not end-to-end encrypted. This means messages are stored on our servers in a form that our authorized staff and service providers could technically access. We only access message content when needed to investigate a report, protect someone's safety, maintain the service, or comply with the law.
If you report a message, the reported message is included with your report.
Push notifications for new messages show who sent the message, not what it says.
Push notifications
If you allow notifications, we send them when someone follows you or requests to follow you, likes or comments on your content, replies to your comment, accepts your follow request, or messages you. To deliver them we store a token for your device and send notifications through Google Firebase Cloud Messaging (Android) or Apple Push Notification service (iPhone).
You can turn notifications off at any time in your phone's settings.
How we share information
We do not sell your personal information, and we do not share it for cross-context behavioral advertising.
We share information only in these situations:
With other users, as described in "Who can see what".
With service providers who run parts of RUMR for us. They may use your information only to provide their service to us:
- Supabase (database, file storage, sign-in and real-time messaging): stores your account, profile, content and messages.
- Twilio (text messages): receives your phone number to send your sign-in code. Supabase passes your number to Twilio for this.
- Google Firebase (Cloud Messaging and Crashlytics): delivers push notifications on Android and receives crash reports.
- Apple (Push Notification service): delivers push notifications on iPhone.
- Google Sign-In and Sign in with Apple: confirm your identity when you choose those sign-in options. Your use of them is also covered by Google's and Apple's own privacy policies.
- Vercel (server hosting): runs the part of our service that sends push notifications and hosts these policies.
For legal reasons, if we believe in good faith that it is required by law, a court order or other valid legal process, or needed to protect the safety, rights or property of any person, RUMR or the public, including to prevent fraud or abuse.
In a business transfer, such as a merger, acquisition or sale of assets. We will tell you before your information becomes subject to a different privacy policy.
With your permission, in any other case.
How long we keep information
- Your account and profile: while your account exists.
- Posts, comments and likes: until you delete them or delete your account.
- Stories: removed from the app 24 hours after posting. We delete the stored files within 30 days after that.
- Direct messages: while the conversation exists. When you delete a message you sent, it is removed from the conversation for everyone, and we delete it from our systems within 30 days.
- Reports: up to 2 years after they are resolved, so we can spot repeated abuse, unless a longer period is required by law.
- Push tokens: until you delete your account or the token stops working. We keep at most 10 devices per account.
- Crash reports: up to 90 days, as set by Google Firebase Crashlytics.
- Server logs: kept for a short period by our service providers, generally no more than 90 days.
Deleted information may remain in encrypted backups for up to 30 days before it is overwritten. We may keep information longer if the law requires it, or if it is needed to resolve a dispute, investigate abuse, or enforce our Terms.
Deleting your account
You can delete your account in Settings. When you do:
- Your profile, posts, stories, comments, likes, follows, blocks, privacy settings and notifications are deleted.
- Photos and videos you uploaded are deleted from our storage when the deletion is carried out.
- Messages you sent may remain visible to the other people in those conversations, without your name or profile attached. Messages already delivered to someone are part of their conversation too.
- Your push tokens are removed, so you stop receiving notifications.
- Reports you filed, and reports about you, may be kept as described above.
Deleting your account starts a 30-day grace period. From the moment you ask, your profile, posts and stories are hidden from everyone else and your account cannot be found or followed. If you sign in again within those 30 days, your account is restored exactly as it was.
After 30 days the deletion is carried out and is permanent. It cannot be undone, and the username becomes available to somebody else. If you cannot access the app, email privacy@myrumr.com from the email address or with the phone number linked to your account and we will help you.
Your choices
- Edit your profile at any time in Settings > Edit profile.
- Make your account private in Settings > Privacy.
- Choose who sees a post when you create it.
- Delete posts, stories and messages you sent.
- Block accounts, and manage your blocked list in Settings > Blocked accounts.
- Turn off notifications or device permissions in your phone's settings.
- Delete your account in Settings.
Your privacy rights
Depending on where you live, you may have the right to:
- Know and access the personal information we hold about you.
- Correct information that is wrong.
- Delete your personal information.
- Get a copy of your information in a portable format.
- Object to or restrict certain uses of your information.
- Withdraw consent where we rely on it, such as for notifications.
To make a request, email privacy@myrumr.com. We will confirm your identity before acting, usually by asking you to contact us from the email or phone number linked to your account. We respond within 45 days, or sooner where the law requires. We will not treat you differently for exercising your rights.
You may use an authorized agent to make a request for you. We may ask the agent for proof of your permission and ask you to confirm your identity directly.
If we deny your request, you can appeal by replying to our decision. If you are not satisfied, you can contact your state attorney general or your local data protection authority.
California residents
Under the California Consumer Privacy Act (CCPA), in the last 12 months we have collected these categories of personal information, for the purposes described in "How we use your information":
- Identifiers: phone number, email address, name, username, account identifiers, device tokens, IP address.
- Customer records: profile information you provide.
- Internet or network activity: interactions with posts, stories, comments and messages inside RUMR; technical logs.
- Audio-visual information: photos and videos you share.
- Inferences: none.
- Sensitive personal information: the contents of your direct messages, and the account credentials you use to sign in. We use these only to provide the service and keep it secure, not to infer characteristics about you.
We disclose these categories to the service providers listed above for business purposes. We do not sell or share personal information as those terms are defined in the CCPA, and we have no actual knowledge of selling or sharing information of anyone under 16.
We do not respond to Do Not Track signals because we do not track you across other sites or apps.
Users outside the United States
RUMR is operated from the United States. If you use RUMR from another country, your information will be transferred to and processed in the United States and other countries where our service providers operate, which may have different data protection laws than yours.
If you are in the European Economic Area, the United Kingdom or Switzerland, we process your information on these legal bases:
- To provide the service you signed up for (contract): your account, profile, content, messages and notifications.
- Our legitimate interests: keeping RUMR safe and secure, handling reports, and fixing crashes, balanced against your rights.
- Legal obligations: responding to lawful requests.
- Your consent: push notifications and device permissions, which you can withdraw at any time.
You also have the right to lodge a complaint with your local data protection authority.
Children
RUMR is not for children under 13. We do not knowingly collect personal information from anyone under 13. If we learn that someone under 13 has created an account, we will delete the account and its information. If you believe a child under 13 is using RUMR, email privacy@myrumr.com.
Users aged 13 to 17 must have permission from a parent or legal guardian to use RUMR.
Security
We protect your information with measures including:
- Encrypted connections between the app and our servers.
- Database access rules that limit each account to the data it is allowed to see.
- Private storage for photos sent in direct messages.
- Keeping sign-in sessions in your phone's secure storage.
- Keeping server credentials off your device and out of the app.
No service can be completely secure. If we learn of a breach that affects your personal information, we will notify you as required by law. If you find a security issue, report it to privacy@myrumr.com.
Changes to this policy
We will update this policy when our practices change. The effective date at the top shows when it was last changed. If we make material changes, we will tell you in the app or by another reasonable method before they take effect.
Contact us
Enovate Consulting, Inc.
Privacy questions and requests: privacy@myrumr.com
Legal notices: legal@myrumr.com