legal / rumeqo

Privacy policy

Last updated: August 10, 2026

Rumeqo, Inc., a Delaware corporation (“Rumeqo,” “we,” “us,” or “our”), is the controller of account, website, support, and business-contact personal data described here. When customers place content in rooms, connectors, tools, or agent workflows, we generally process that Customer Content on the customer’s instructions as a processor or service provider.

1. Personal data we collect

  • Account and contact data, such as name, email address, authentication identifiers, organization, role, and support messages.
  • Customer Content and workflow data, such as prompts, messages, files, code, tool calls, approvals, room memory, scheduled tasks, and connected-service data that you direct us to process.
  • Usage and transaction data, such as feature activity, plan, credits, model usage, billing records, and support history.
  • Device, network, and security data, such as IP address, browser and device details, timestamps, referring pages, cookie identifiers, and server or audit logs.
  • Business-contact information from you, your organization, service providers, and publicly available professional sources.

2. How we use personal data

  • Provide, personalize, maintain, and support accounts, rooms, agents, tools, connectors, memory, model access, and requested output.
  • Authenticate users, protect the service, prevent abuse, investigate incidents, enforce limits, and maintain audit records.
  • Process billing, credits, subscriptions, support requests, and service communications.
  • Analyze reliability and improve features, documentation, safety, and performance.
  • Comply with law and establish, exercise, or defend legal claims.

3. AI processing and customer instructions

We send Customer Content to artificial-intelligence and infrastructure providers only as needed to deliver features you request. We do not use Customer Content to train a general-purpose Rumeqo model. Providers process data under contractual restrictions and their applicable service terms. Customers control what their agents can access and are responsible for permissions, connected accounts, and lawful instructions.

4. How we disclose personal data

We disclose personal data as reasonably necessary to these categories of recipients: cloud hosting and storage providers; model and AI infrastructure providers; authentication, security, analytics, communications, support, and payment providers; connectors and third parties you direct us to use; professional advisers; a buyer or successor in a corporate transaction; and courts, regulators, or other parties where required by law or necessary to protect rights and safety.

Depending on the service and feature you use, the categories of personal data we share with third parties are:

  • Account and contact data with authentication, communications, support, and customer-directed connector providers.
  • Customer Content and workflow data with cloud hosting, model and AI infrastructure, and connector providers that process it to deliver the features you request.
  • Usage and transaction data with cloud hosting, security, limited analytics, billing, and payment providers.
  • Device, network, and security data with cloud hosting, security, and limited analytics providers.
  • Business-contact information with communications, support, sales, and professional-adviser providers.

We do not sell personal data for money. We do not use personal data for targeted advertising, and we do not profile consumers in furtherance of decisions that produce legal or similarly significant effects.

We use necessary cookies and local storage for authentication, security, session continuity, consent, and preferences. We may use limited analytics to understand service performance. We do not use third-party advertising cookies. If our practices change, we will honor legally required universal opt-out signals for sale or targeted advertising.

6. Retention

We retain personal data only as long as reasonably necessary for the purposes above, including account operation, customer instructions, security, dispute resolution, and legal, tax, and accounting obligations. Retention varies by data type, sensitivity, risk, contract, account settings, and legal requirements. We delete or de-identify data when it is no longer needed, subject to lawful exceptions and backup cycles.

7. Security

We use reasonable administrative, technical, and organizational safeguards designed to protect personal data, including access controls and security logging. No system is completely secure, and we cannot guarantee absolute security.

8. International processing

We are based in the United States and may process data in the United States and other countries where providers operate. Those locations may have different data-protection laws. Where required, we use lawful transfer mechanisms and contractual safeguards.

9. Your privacy rights

Delaware residents have the following rights under the Delaware Personal Data Privacy Act, subject to applicable statutory exceptions: confirm whether we process their personal data; access personal data; correct inaccuracies; delete personal data; obtain a portable copy; obtain a list of categories of third parties to which we disclosed personal data; and opt out of sale, targeted advertising, or qualifying profiling. We do not currently conduct those three opt-out activities. We will not discriminate against a Delaware resident for exercising a privacy right.

Submit a request to privacy@rumeqo.com with the subject “Privacy Request.” We may verify identity and authority. Where the Delaware Personal Data Privacy Act applies, we will respond without undue delay and ordinarily within 45 days. We may extend once by another 45 days when reasonably necessary and will tell you why. If we deny a request, you may appeal by replying with the subject “Privacy Appeal.” We will respond to the appeal within 60 days. If the appeal is denied, we will explain how to contact the Delaware Department of Justice.

10. Other regional rights

Residents of California, the European Economic Area, the United Kingdom, and other jurisdictions may have additional rights, including rights to know, access, correct, delete, restrict or object to processing, withdraw consent, and complain to a regulator. Withdrawing consent does not affect prior lawful processing. Authorized agents may submit requests where permitted by law.

11. Children

The service is not directed to children under 13, and we do not knowingly collect personal data from children under 13. Contact us if you believe a child provided personal data so we can investigate and take required action.

12. Changes

We may update this policy as our service, practices, or legal obligations change. The date above identifies the current version. We will provide additional notice of material changes where required.

13. Contact

Rumeqo, Inc.
privacy@rumeqo.com