Ruber

Legal

Privacy policy

This policy explains what personal data Ruber collects, why, where it is kept and what you can do about it. Sukses360 Ltd is the data controller.

Last updated

01Who is responsible

Sukses360 Ltd, registered in England and Wales under company number 16587307, registered office 71-75 Shelton Street, Covent Garden, London WC2H 9JQ, United Kingdom, is the controller of the personal data described here.

For anything in this policy, write to privacy@ruber.me.

We are registered with the Information Commissioner's Office as a data controller, under registration number ZC021637.

Our representative in the European Union, under Article 27 of the GDPR, is Marsida Buka, based in Granarolo dell'Emilia (Bologna), Italy, reachable at marsida@ruber.me. People in the EU and EU supervisory authorities may contact her about anything in this policy, as well as or instead of us.

02What we collect

  • Account data: the email address you sign up with, your name if you give one, and authentication records.
  • Domain data: the domains you connect and the DNS records we write and verify for them.
  • Mailbox contents: the messages in your mailboxes, including their attachments, while you keep them.
  • Message metadata: sender, recipient, timestamps, size and routing headers. SMTP requires these to move a message, and no mailbox design removes them.
  • Operational logs: IP addresses, connection times and delivery events, kept so that we can run the service, diagnose faults and investigate abuse.
  • Product analytics, only if you agree to it: which screens are opened and which features are used, and error reports, under a pseudonymous account identifier. A small number of account milestones, such as creating an account or connecting a domain, are recorded by our servers without any cookie.
  • Support correspondence: what you write to us and what we write back.

03What we do not do

  • We do not sell personal data, and we do not share it for anyone else's marketing.
  • We do not build advertising profiles from your mail, and we do not use your mail to train models.
  • This website uses no analytics or advertising trackers. The dashboard uses one analytics provider, PostHog, only if you agree to it, under a pseudonymous account identifier and without your email address or mail content. Searches you type and text quoted in error messages are removed before anything is sent.

04Why we are allowed to process it

Under the UK GDPR we rely on the following bases.

  • Performance of a contract — running mailboxes, delivering mail and billing for a plan.
  • Legitimate interests — keeping the platform secure, filtering spam and phishing, investigating abuse and protecting sending reputation. We have considered these against your rights and use the minimum data that works.
  • Legitimate interests — for Smart mailboxes, sorting incoming mail into inbox categories and building the index behind meaning-based search. These process messages from people who wrote to you as well as your own. They run only for Smart mailboxes, never for Private ones, and you can switch categories off in settings, after which nothing more is sent for sorting. You can object to either by writing to us.
  • Legitimate interests — recording a few account milestones on our servers, without cookies, to understand whether people can set the product up. You can object by writing to us.
  • Legal obligation — where we must retain or disclose data by law.
  • Consent — for product analytics in the dashboard, asked for separately at sign-up and never a condition of using Ruber, and for optional product email. You can withdraw it at any time: analytics from the account settings, email from any of those messages.

05Where your data is kept

Mailbox contents are stored on servers in Finland, inside the European Union. The control plane — accounts, domains and mailbox records — runs on Supabase in an EU region. This website and the dashboard are served from a global edge network.

Where a provider processes data outside the UK or EEA, that transfer relies on the UK International Data Transfer Addendum or on standard contractual clauses. The full list of processors is on the subprocessors page.

06How long we keep it

  • Mailbox contents: for as long as the account exists, and until you delete them.
  • Account and domain records: for the life of the account. A deleted account is held for seven days so the deletion can be undone, then permanently removed.
  • Operational logs: no longer than 90 days, unless a log is needed for an investigation of abuse or a security incident that is still open.
  • Product analytics: no longer than 12 months, and removed from a device as soon as you withdraw consent on it.
  • Billing and accounting records: six years after the end of the financial year they relate to, as UK tax law requires.
  • Other records we are required to keep by law, for the period the law requires.

07What we can and cannot see

This is the part most privacy policies are vague about, so it is worth stating plainly. Smart mailboxes are ordinary email: contents are encrypted in transit and then stored unencrypted, and the mail plane can process them, which is what makes server-side search, filtering and integrations work. Staff access is limited to operating the service, responding to a support request you have made, or complying with a valid legal obligation.

Two Smart features send parts of messages to outside providers, both named on the subprocessors page: inbox categories send the sender, recipients, subject and opening text of a message to a language-model provider to decide which tab it belongs in, and meaning-based search sends message text and your searches to a provider that builds the search index. Neither is ever used on a Private mailbox.

Private mailboxes keep message contents — the subject, the body and attachments — encrypted with keys derived on your device. We do not hold those keys, so what is stored is encrypted and we cannot read, search, categorise or index it afterwards. Nothing in a Private mailbox is sent to the language-model providers listed on the subprocessors page.

Mail that arrives from outside Ruber crosses the internet as ordinary email. Our mail servers check it for spam and malware as it arrives, then encrypt it before it is stored. It is protected from that point on; it is not end-to-end encrypted, because it was readable to the systems that carried it, including ours, before it was encrypted.

Encryption of any kind covers content, not metadata. The sender, recipients, date, message identifiers, threading and delivery headers remain visible in both modes, because the protocol needs them to route mail.

08Requests from authorities

We disclose customer data to a public authority only when a request is valid and binding on us under the law that applies to us, such as a court order or a notice under the Investigatory Powers Act 2016, or where there is an immediate risk of death or serious harm. A request from outside the United Kingdom has to reach us through a legal process that binds us here. We check every request, challenge any that are unlawful or broader than the law allows, and disclose no more than is required.

What exists to disclose depends on the mailbox. For any account we hold account details, the metadata of messages and operational logs. The contents of Smart mailboxes are stored readably. The contents of Private mailboxes are stored only in encrypted form, and we hold no key that opens them, so that is the only form in which we could ever produce them.

Unless the law forbids it, or telling you would put someone's life or safety at risk, we will let the affected customer know about a request before we disclose their data.

Requests should be sent to privacy@ruber.me.

09Your rights

You have the right to access your data, to have inaccurate data corrected, to have data erased, to restrict or object to processing, and to receive your data in a portable form. To exercise any of them, write to us and we will respond within the statutory period.

For a Private mailbox, we can provide its contents only in the encrypted form we hold, because we cannot decrypt them; you can read them in Ruber with your own keys. Everything else we hold about you, including the metadata of Private messages, is provided as usual.

If you are unhappy with how we have handled your data you can complain to the Information Commissioner's Office (ico.org.uk). We would rather you told us first.

10Cookies

This website does not use advertising or analytics cookies. The dashboard sets the cookies it needs to keep you signed in, to protect the sign-up form from automated abuse, and to remember your answer about analytics. Those are strictly necessary and are set without asking.

Analytics storage is different. Only if you tick the analytics box at sign-up, or switch it on later in the account settings, does the dashboard store a first-party PostHog identifier in a cookie and in your browser's storage. Until then nothing is stored and nothing is sent. Switching it off removes that storage from the device you switch it off on, and from your other devices the next time you sign in on them. None of these cookies is used to track you across other sites.

11Changes

We will update this policy as the product changes, and we will note the date at the top. Where a change materially affects how your data is handled, we will tell you rather than relying on you noticing.

Sukses360 Ltd

Trading as Ruber. Registered in England and Wales, company number 16587307. Registered office 71-75 Shelton Street, Covent Garden, London WC2H 9JQ, United Kingdom.

Questions: hello@ruber.me