Skip to content
ProductSecurityPricingChangelog
Log inStart free
LEGAL

Privacy Policy

Last updated: July 29, 2026

ON THIS PAGE
IntroductionPersonal Data We CollectHow We Use Personal DataHow We Share Personal DataRetentionSecurityYour Rights and ChoicesInternational Data TransfersPolicy ChangesContact Us

Introduction

We at Upmoni LLC, which operates Rubic ("Rubic", "we" or "us") are strongly committed to respecting your privacy and keeping secure any information you share with us. This Privacy Policy explains how we collect, use, disclose, and process your personal data when you use Rubic's software, platform, APIs, documentation, and related tools, including the website at rubic.io, and all related software made available by Rubic to plan, implement, test, review, preview, and prepare software changes for delivery ("Service"). It also tells you how you can access and update your personal information and describes the data protection rights that may be available under your country's or state's laws.

Please read this Privacy Policy carefully. By accessing or using the Service, you acknowledge that you have received this notice. This Privacy Policy does not treat your use of the Service as consent where applicable law requires a different legal basis or a separate affirmative choice.

Rubic acts as a controller for account administration, billing, fraud and security, website analytics and consent choices, product communications, and our own support operations. Where a business customer controls personal data placed in repositories, tasks, attachments, Runtime Env values, generated work, or related project content, Rubic generally processes that data on the customer's behalf under the applicable customer agreement. Our Data Processing Addendum governs customer personal data within its scope and is incorporated into the Terms of Service. The customer remains responsible for its notices, instructions, and legal basis for that data.

1. Personal Data We Collect

We collect the following categories of personal data:

A. Personal Data You Provide to Us Directly

We collect personal data if you create an account to use our Service or communicate with us. This includes:

  • Account Information: Your name and email address when you sign up for a Rubic account or to receive information about our Service.
  • Payment Information: Your payment information if you seek to access any paid Rubic products and services.
  • Inputs and Suggestions: The Service allows you to submit content ("Inputs"), which generate responses ("Suggestions") based on your Inputs. If you include personal data in your Inputs, we will collect that information and it may be reproduced in the Suggestions we provide.
  • Repository Data: When you connect GitHub repositories, we access your code to provide our AI agent services. This includes file contents, commit history, and repository metadata necessary to provide the Service.
  • Project and Task Content: Project settings, task descriptions, prompts, chats, plans, reviews, approvals, generated work, file-change metadata, and related workflow history.
  • Attachments and Configuration: Files and extracted text you attach to a task, and development or preview configuration you place in Runtime Env or repository settings. Runtime Env is not a production secret vault, and you should not place production credentials or production data in it.
  • Communication Information: If you communicate with us, we collect your name, contact information, and the contents of any messages you send. For emails sent through our communications provider, we may also receive delivery status, whether an email was opened, and whether a link in the email was clicked.
  • Feedback: While using the Service, you may provide feedback, including ideas and suggestions for improvement or rating a Suggestion in response to an Input. If you provide Feedback on the Service, we may store the entire exchange as part of your Feedback.

B. Personal Data We Receive From Your Use of the Service

When you use the Service, we also receive certain technical data automatically. This includes:

  • Device Information: Your device or browser automatically sends us information about when and how you access or use our Service. This includes your device type, browser information, operating system information, and mobile network or ISP.
  • Log Information: We collect information about how our Service is performing, including your IP address, browser type and settings, error logs, and other ways that you interact with the Service.
  • Usage Data: We collect information about your use of the Service, such as the dates and times of access, pages and features viewed within the Service, search actions performed within the Service, and links you click.
  • Cookies & Similar Technologies: We and our service providers utilize cookies, pixels, scripts, or similar technologies to operate and manage the Service and improve your experience.
  • Location Information: For security and performance reasons, we may infer an approximate location, such as country or city, from your IP address. The Service does not request precise GPS location.

C. Sensitive Data and Children

The Service is not designed to require sensitive or special-category personal data. However, repositories, prompts, attachments, logs, generated work, or Runtime Env values submitted by a customer may contain health information, government identifiers, credentials, or other sensitive data. You must not intentionally submit special-category, regulated health, payment-card, government-ID, or similarly sensitive data unless Rubic has expressly agreed in writing to process it and appropriate safeguards have been documented.

Rubic does not knowingly collect information from or direct any of our Service or content to children under the age of 18. If we learn or have reason to suspect that a user is under the age of 18, we will investigate and, if appropriate, delete the personal data and/or the account.

2. How We Use Personal Data

We may use personal data for the following purposes:

  • To provide and maintain the Service, including optional features that enhance functionality and user experience.
  • To create, manage, and administer your account, including facilitating payments and responding to inquiries.
  • To improve and develop the Service and conduct research, including debugging and identifying or repairing issues that impair functionality.
  • To communicate with you, including sending updates, information about the Service, and events. Emails may contain a small tracking pixel and tracked links that allow us and our communications provider to measure delivery, opens, and clicks so we can understand engagement and improve our communications.
  • To prevent, detect, and investigate fraud, abuse, security incidents, and violations of our Terms of Service.
  • To comply with legal obligations and protect the rights, safety, privacy, and property of users, Rubic, or third parties.
  • To investigate and resolve disputes or security issues.
  • To enforce our Terms of Service and other applicable agreements.

Legal Bases for Processing

The legal basis depends on the processing activity and applicable law. The principal activities and bases on which Rubic relies as a controller are:

Activity and data Purpose Legal basis
Account, subscription, billing, and service communications Provide and administer the Service and customer relationship Performance of a contract or steps requested before entering a contract
Service usage, support requests, diagnostics, and error data Operate, support, debug, and maintain the Service Performance of a contract and Rubic's legitimate interests in reliable and secure operations
Account, access, IP, device, and security-event data Prevent fraud and abuse, secure accounts, and investigate incidents Rubic's legitimate interests in protecting the Service and compliance with legal obligations where applicable
Optional website analytics and similar non-essential technologies Understand website use and improve communications and navigation Consent where required and as presented in the consent controls
Product and marketing communications, including engagement data Send requested information and understand communication engagement Consent where required, or Rubic's legitimate interests in relevant business communications where permitted by law
Billing, tax, legal, fraud, and dispute records Meet legal duties and establish, exercise, or defend legal claims Compliance with legal obligations and Rubic's legitimate interests in protecting its legal rights

Where Rubic processes Customer Personal Data on behalf of a business customer, the customer determines the applicable legal basis and Rubic processes the data under the customer's documented instructions and the Data Processing Addendum. When Rubic relies on legitimate interests, we assess those interests against the rights and reasonable expectations of affected individuals.

Code Processing and AI Providers

When you connect a repository, we index your code to enable our AI agents to understand and work with your codebase. Customer content may be sent to approved AI providers as needed to provide an authorized feature.

Rubic does not use customer repositories, Inputs, or Suggestions to train a Rubic model. Our verified provider organization settings disable optional sharing of API inputs and outputs for model improvement. Providers may still process and retain content for service delivery, abuse prevention, safety, legal compliance, and other purposes allowed by the applicable business service terms. Provider retention is not the same as model training.

Product feedback is separate from customer project content. If you intentionally submit content as feedback, we may use that feedback to maintain and improve Rubic as described at the time of collection.

3. How We Share Personal Data

We may disclose your personal data in the following circumstances:

  • Service Providers and Business Partners: We may disclose personal data to third-party vendors and service providers who support our business operations and help us deliver and improve the Service. This includes third-party hosting, cloud infrastructure, AI model providers, analytics, customer support, communications, payment processing (Stripe), and IT providers.
  • Business Transfers: In the event of a merger, acquisition, restructuring, bankruptcy, or other corporate transaction, personal data may be disclosed to counterparties and advisers as part of due diligence or transferred as part of the transaction.
  • Legal Compliance and Protection of Rights: We may disclose personal data to government authorities or other third parties if we believe doing so is necessary to comply with applicable laws, respond to lawful requests, protect the safety or rights of any person, prevent fraud or security incidents, or enforce our Terms of Service.
  • Affiliates: We may share personal data with affiliates, who may use personal data in a manner consistent with this Privacy Policy.
  • Third-Party Services and Integrations: The Service may include integrations with third-party services (such as GitHub). If you choose to interact with these third parties, your personal data may be disclosed to them directly and governed by their own terms and privacy policies.
  • Business Account Administrators: If you're part of a business or enterprise account, administrators may access and manage your use of the Service.
  • With Your Consent: We may disclose personal data when you give us permission to do so.

4. Retention

Rubic retains your personal data only for as long as necessary to operate the Service effectively and to support legitimate business needs such as legal compliance, safety, dispute resolution, and enforcement of our agreements. The appropriate retention period varies depending on the purpose for which the personal data was collected, its sensitivity, potential risks associated with its use or exposure, and any applicable legal requirements.

  • Customer-controlled project content is generally kept while the customer keeps the related project. Following a verified project or account erasure request, we target deletion from active systems within 30 days, subject to documented legal, security, and technical exceptions.
  • Temporary sandboxes, worktrees, previews, signed URLs, queue entries, and similar execution copies follow shorter operational lifecycles.
  • General application logs are generally retained for up to 30 days. Certain required security, audit, fraud, billing, tax, or dispute records may be retained longer when necessary or required by law.
  • Observability data follows provider-specific lifecycles. Current application, browser, tracing, process, and serverless telemetry is retained for 8 days; logs and custom or AI-monitoring data for 30 days; Long Term Memory data for 90 days; and limited infrastructure-integration data for up to 395 days. Browser session replay is not used.
  • AI providers may retain supported API data for up to 30 days under the current standard configurations unless a shorter contract or request-level control applies.
  • Website analytics currently retain event data for two months and user data for 14 months without resetting the period when new activity occurs.

Our email provider retains campaign and engagement statistics for up to 13 months depending on the active provider plan. Email contacts and reusable templates may remain with the provider while our account remains active, so we limit their use and include them in applicable deletion procedures.

When personal data is no longer needed, Rubic and its service providers will follow procedures to delete, erase, de-identify, or anonymize it in compliance with applicable laws.

5. Security

We implement commercially reasonable technical and organizational measures designed to protect personal data from loss, misuse, and unauthorized access, disclosure, alteration, or destruction. These measures include project-scoped access controls, managed execution environments, encryption provided by our infrastructure and storage services, limited signed attachment URLs, monitoring, redaction controls, and backup and incident response practices appropriate to the Service.

However, please remember that no method of transmission over the Internet or method of electronic storage is completely secure. You should use caution when deciding what information to share with the Service. We are not responsible for any circumvention of privacy settings or security features on the Service or on third-party websites linked through the Service.

6. Your Rights and Choices

Depending on where you live and the laws that apply in your country of residence, you may have certain rights in relation to your personal data. These may include:

  • Right to Know: What categories of personal data we collect, the purposes for which we use it, and the types of third parties with whom we share it.
  • Access and Portability: You can request a copy of the personal data we hold about you and, where applicable, ask us to provide it in a portable format.
  • Deletion: You can request deletion of personal data collected from you in connection with your use of the Service, subject to certain exceptions.
  • Correction: You can request correction of inaccurate personal data we maintain about you.
  • Objection: You can object to certain types of processing.
  • Withdrawal of Consent: Where the legal basis for our processing is based on your consent, you can withdraw it at any time.

To exercise any of these rights, you or your authorized agent may contact us at hi@rubic.io. We may request information to verify your identity, authority, and request scope before processing your request. Where we process personal data for a business customer, we may direct your request to that customer.

No Sale or Targeted Advertising: We do not "sell" or "share" personal data for cross-contextual behavioral advertising, and we do not process personal data for "targeted advertising" purposes (as those terms are defined under applicable US state privacy laws).

7. International Data Transfers

Rubic processes your personal data for the purposes described in this Privacy Policy on servers located in various jurisdictions, including in the United States. While data protection laws vary by country, we apply the protections outlined in this policy to your personal data regardless of where it is processed, and we only transfer data in accordance with legally valid transfer mechanisms.

For users in the European Economic Area ("EEA"), when you access our Service, your personal data may be transferred to our United States servers or to other countries outside the EEA and the UK. Where information is transferred outside the EEA or the UK, we use an applicable lawful transfer mechanism. For customer personal data, our Data Processing Addendum incorporates the European Commission Standard Contractual Clauses and the UK International Data Transfer Addendum where they are required. Our current service providers and processing locations are described on the Subprocessor List.

8. Privacy Policy Changes

We may update this Privacy Policy from time to time. When we do, we will publish an updated version and effective date. If a change materially affects how we use personal data or your rights, we will provide additional notice, such as email or an in-product notice, when required by applicable law.

9. Contact Us

We encourage you to contact us if you have any questions about this Privacy Policy.

Upmoni LLC
Rubic
9450 SW Gemini Dr PMB 84485
Beaverton, OR 97008-7105
United States
General and privacy enquiries: hi@rubic.io
Legal notices: legal@rubic.io
Security reports: security@rubic.io

AI that works with your software team.

PRODUCT ProductSecurityPricing
COMPANY ChangelogAboutContact
LEGAL PrivacyTermsDPASubprocessors
CONNECT hi@rubic.io LinkedIn GitHub X
© 2026 Upmoni LLC Built for software teams that value control.