Who we are
Rumore is operated by Inevitable AI ("Rumore", "we", "us"). Rumore is a reputation and customer-communication platform for owner-run local businesses: it gathers reviews, messages, listings and social activity into one place and helps owners respond, with AI assistance that the owner approves.
For anything in this policy, write to us at privacy@rumore.ai.
The short version
- We collect only what we need to run the product.
- We never sell personal data, and we never use it for advertising.
- Data from Google and Meta is used solely to show your business its own reviews, messages and comments, and to publish the replies you approve.
- Everything is stored encrypted in the European Union.
- You can ask us to delete your data at any time.
Data we collect
Visitors and the waitlist
If you join the waitlist we store the email address you give us, and the business name and type if you add them. We use them to contact you about early access and nothing else.
We use Google Analytics to see how the site is used. It sets cookies and we do not pretend otherwise. We do not run advertising trackers, we do not sell what it collects, and nothing here builds a profile of you to follow you around other sites. If we add another analytics or session-recording tool, this page says so before it goes live.
The free reputation scorecard
The scorecard is open to anyone, with no account. To know whether it works and whether our ads reach the people we hoped to reach, we keep our own record of a few things when you use it: that a visit happened and on which page, whether the search produced a result, and the short visitor code described below.
These records use no cookies and do not need you to be signed in. To count people rather than clicks, we turn your IP address and browser into a short code using a secret only our server holds. Nobody who gets hold of our database can turn that code back into you, and it is regenerated every night, so it never grows into a history of your visits. We keep visit records for up to a year.
We never keep your IP address or your browser, only the code we make from them, so there is nothing on file to match a request from you against. That is why we cannot pull up your scorecard activity even when you ask us to. Those records are deleted on a timer instead. Anything tied to a Rumore account is different, and we do delete that on request.
We are about to start keeping more, so here is what changes before it does. Soon these records will also carry the campaign label on the link you followed, where you arrived from as a category (an ad, a search, another site, or direct) rather than an address, whether the screen was phone-sized or desktop-sized, roughly how long the page stayed open, how many characters you typed, and whether you picked a suggestion or typed it out. We will take campaign labels only, never the per-click tracking codes ad platforms append, never the address of the page that sent you, and never your browser version. We will also keep the business name you search for, for 30 days, so we can find the searches that come back empty and fix them. That one will be stored on its own, dated only to the day, with nothing attached that could tie it back to you. When this starts, this paragraph moves to the present tense and the date at the top of the page changes with it.
Business account holders
When you create a Rumore account we store your name, email address, password (hashed, never readable by us) and your business details: locations, opening hours, contact details and the profile information you enter. When you connect an external service (Google, Facebook, Instagram, WhatsApp, your booking or CRM tool), we store the access tokens that connection needs, encrypted at rest.
We also keep a record of activity in your account: sign-ins, the actions you take, and errors your browser reports back to us, which include the page you were on when something broke. We use them to support you and to fix faults. Sign-ins and the actions you take are kept for a year. Faults our own servers record are cleared within a week. The reports your browser sends have no automatic expiry yet, so they stay until you close your account, which clears all of it.
Your customers
To do its job Rumore processes data about your customers on your behalf: contact details you import or collect, appointment records from connected booking tools, the messages they exchange with your business, and the reviews they leave publicly. For this data your business is the controller and Rumore is the processor. We act on your instructions, and we support export and erasure for any contact record.
Google user data
This section covers everything Rumore receives from Google APIs. It applies when you sign in with Google or connect a Google Business Profile.
What we access
- Sign-in (scopes
openid,email): your Google account email address and account identifier, used only to create and sign you into your Rumore account. - Business Profile connection (scope
https://www.googleapis.com/auth/business.manage): the list of business locations your Google account manages, each location's public details (name, address, phone, opening hours), the reviews on those locations (star rating, review text, the reviewer's public display name and photo, and timestamps), and the owner replies published on them. Google offers no narrower scope for reading and replying to reviews, which is why this one is requested.
How we use it
We show your reviews inside your Rumore dashboard, notify you when a new one arrives, and publish the owner replies you write or approve back to your Google Business Profile. Our AI assistant reads the text of a review to draft a suggested reply for you. A draft is only a draft: nothing is published until you approve it.
How we store it
Reviews and location details are stored in our database, hosted in the European Union. The OAuth tokens Google issues are encrypted at rest and are never written to logs.
How long we keep it
For as long as your Google connection is active. If you disconnect Google Business Profile, or delete your Rumore account, we delete the stored Google data and revoke the tokens within 30 days.
Who we share it with
No one, beyond the subprocessors that run the service itself: our EU hosting provider stores it, and a third-party AI provider processes review text transiently to draft a reply. The AI provider receives the text only to generate that draft, does not retain it once the draft is returned, and does not use it to train its models. We never sell Google user data, never use it for advertising, and never transfer it to data brokers or analytics products.
Rumore's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Google user data is never used to develop, improve or train generalized AI or machine-learning models.
Meta data (Facebook and Instagram)
When you connect a Facebook Page or a linked Instagram professional account, Rumore stores the Page and Instagram account identifiers and names, the encrypted access tokens for the connection, the messages your customers send your business through Messenger and Instagram, and the comments (with the commenter's public name) on the posts you manage through Rumore. We use this data to show those conversations and comments in your inbox, to let you reply, and to let our AI draft replies for your approval. We do not read anyone's personal timeline, friends or private profile data.
Meta data follows the same rules as everything else here: encrypted EU storage, no selling, no advertising use, deleted within 30 days when you disconnect the Page or delete your account. If you are a Facebook or Instagram user and want data about you removed from Rumore, see our data deletion page. Removing the Rumore app from your Facebook settings also triggers an automatic deletion request to us.
How AI is involved
Rumore uses AI to draft review replies, message responses and social posts from the content your business already handles (a review's text, a customer's message, your business profile). Drafts are suggestions for the owner, and the owner decides what gets published. The AI providers we use process this content only to produce the draft. They do not keep it and do not train models on it. Our AI Policy explains this in full.
Where your data lives and how it is protected
All production data is hosted in the European Union. Data is encrypted in transit and at rest, OAuth tokens and other secrets carry an extra layer of application-level encryption, and access inside Rumore is scoped so that each business can only ever see its own data.
Sharing and subprocessors
We share personal data only with the vendors that run the service: EU-region hosting and database infrastructure, an email delivery provider for the messages you ask us to send, our payment provider for billing, and a third-party AI provider for drafting. Each one is bound by a data processing agreement. The AI provider processes the content only to produce a draft, does not retain it afterward, and does not use it to train its models. We never sell personal data and we never share it for advertising.
Your rights
Under the GDPR (and similar laws elsewhere) you can ask for access to the personal data we hold about you, ask us to correct or delete it, ask for a portable copy, and object to or restrict certain processing. Email privacy@rumore.ai and we will respond within 30 days. If you are a customer of a business that uses Rumore, we may refer your request to that business, since it controls your data, and we will help it respond. You can also complain to your local data protection authority.
Deleting your data
Business owners can disconnect any integration from inside Rumore, which removes the associated external data, or email us to close the account entirely. Facebook and Instagram users have a dedicated path described on the data deletion page. However a deletion request reaches us, we complete it within 30 days. Closing a Rumore account also clears the activity records tied to it.
A few things do not follow that path, and we would rather list them than let you assume otherwise.
- Our records of work the system ran for you, like sending a message, sometimes carry the phone number or email address it went to. We delete those about a month after that work finishes.
- We cannot pick out the scorecard records described above at all, because we hold no IP address or browser to match you against. They expire on their own within a year.
- If you joined the waitlist, that signup keeps your email address separately, and closing an account does not remove it. Write to privacy@rumore.ai and we will delete it.
- We keep a single line recording that the deletion happened, with nothing personal in it, because we have to be able to show that we did it.
Changes to this policy
If we change this policy in a way that matters, we will update the date at the top and, for significant changes, tell account holders by email before the change takes effect.
Contact
Inevitable AI
privacy@rumore.ai