Skip to content

Privacy policy

Rumoro is a social listening service at rumoro.dev. Here we explain which data we hold, why we hold it, and what you can ask of us. Questions and requests: markus@rumoro.dev.

What you give us

  • Your account. Your name, email address and password, kept only as a salted hash, or, with Google or GitHub sign-in, the name, email address and profile picture of the account you choose.
  • Your workspace. Keywords, your company description, alert rules, notes, tags and the other settings you choose.
  • Connections. If you connect Slack or Telegram, the details needed to post to the channel or chat you pick; Slack tokens and webhook signing secrets are stored encrypted. API keys are stored as hashes and shown to you once.

What we record

  • Usage and billing. Keyword-days and matched mentions, which decide the daily charges, plus a record of every top-up and charge.
  • Logs. Standard service logs (times, request details, errors) for reliability and to prevent abuse.
  • Docs feedback. If you answer “Was this page helpful?” on docs.rumoro.dev, the page, your answer and any comment you write. No account or IP address is stored with it.

We use one cookie, to keep you signed in. There are no advertising or tracking cookies.

Public posts and their authors

Rumoro finds public posts, comments and reviews that mention your keywords on platforms such as Reddit, X, Hacker News, GitHub, Bluesky, LinkedIn, TikTok, Instagram, Stack Overflow, DEV, YouTube, news sites and review sites. For each match we keep the public text, link, time and engagement, and the author’s public name, handle, picture and follower count. On some platforms we also read public profile details such as bio, company, location, website and linked accounts, and an email address only where the person published it on their profile. An AI model scores each post for relevance, sentiment and intent.

We process this data on the basis of legitimate interests (GDPR Art. 6(1)(f)), so that customers can follow and answer public conversations about them. The notes, tags and outreach a workspace adds about a person belong to that workspace, and the customer is the controller for them. Our MCP tools never return a person’s email address.

We keep posts and author details while Rumoro runs, and a post deleted on its platform can stay in Rumoro, except on Reddit (below). Anyone can ask for their accounts to be removed on the removal page or at markus@rumoro.dev. We send a receipt and finish every request within 30 days. A removal deletes the person’s posts from every workspace, with the notes, tags and outreach attached to them, empties their profile, and stops us storing their new posts. Charges for those posts stay in the customer’s billing records.

Reddit

To search Reddit, Rumoro uses Reddit’s Data API with its own registered app once Reddit approves its access: it looks for public posts that name one of your keywords in the title or text. Comments aren’t searched. No Reddit account is linked, and Rumoro never posts, comments, votes or sends messages. From a matching post we store only the title, text, subreddit, links, publish date and the author’s username, and pass it only to the destinations you set up. We check stored Reddit posts again at least every 48 hours: a post deleted or removed on Reddit is deleted from Rumoro with everything attached to it, an edited post is updated, and when a Reddit account is deleted we remove its username and profile link from its posts. Reddit data is never sold, shared as a dataset or used to train AI models, and if our access to Reddit ends, we delete all of it.

YouTube

To search YouTube, Rumoro uses YouTube API Services: it looks for public videos that name one of your keywords in the title or description. It reads public data with an API key alone. No YouTube account is linked, and Rumoro never posts, changes, rates or comments on anything. From a matching video we store only the title, description, channel name, publish date and link, refresh or remove it no later than 30 days after fetching it, and pass it only to the destinations you set up. YouTube data is never sold or used for ads. When you use YouTube results in Rumoro, you also agree to the YouTube Terms of Service, and how Google treats data is set out in the Google Privacy Policy.

How we use data

To run and improve Rumoro, deliver the alerts you set up, bill your usage, keep the service secure and contact you about your account. We don’t sell personal data or show ads, and we don’t train models on your data or on the posts we collect.

Who we share it with

  • Our hosting provider and Neon, which run the service and its database.
  • Cloudflare, for background jobs and AI scoring.
  • HarvestAPI, which searches public LinkedIn posts for the keywords you track. No LinkedIn account is used.
  • Resend, which sends our emails.
  • Polar, our merchant of record, which handles payments and invoices. We never see your card details.
  • Brevo, where we keep a contact record of each account (name, email, sign-up date and method, whether setup is done, and top-up totals) to understand how Rumoro grows. Brevo doesn’t email you.
  • Slack or Telegram, only if you connect them, and Google or GitHub, only if you sign in with them.

How long we keep it

We keep your account and workspace for as long as you use Rumoro, and delete them once you ask us to close your account. Invoices and billing records stay for the period tax law sets. YouTube data is refreshed or removed within 30 days, and posts deleted on Reddit are removed within 48 hours.

Your rights

You can ask for access to your data, or for it to be corrected, deleted, restricted or exported, and you can object to how we process it. Email markus@rumoro.dev. You can also complain to the Austrian Data Protection Authority (Datenschutzbehörde).

Security

Everything travels encrypted, we hash passwords and API keys, connection secrets are encrypted at rest, and only a few people can reach production data.

Changes

We update this page and the date above when the policy changes, and announce important changes in the product or by email.