Skip to content
ruam.ai← Back to home
Privacy Policy · Privacy Policy · Privacy Policy · Privacy Policy · Privacy Policy · Privacy Policy · Privacy Policy · Privacy Policy ·

Legal Hub

Privacy PolicyTerms of ServiceCookie PolicySubprocessorsSupport

Privacy Policy

EffectiveSeptember 29, 2026
Last updatedOctober 1, 2026
Applies toruam.ai, the Ruam web app, the Chrome extension, and the macOS desktop app

Never Recorded

By the extension or the desktop app

  • No screenshots, screen recordings, or keystrokes
  • No audio, video, or webcam
  • No full web addresses or file contents
  • Nothing outside your tracked hours
Private browser windows are skipped. The desktop app records them only if you turn that on.

Recorded

During tracked work only

  • Active and idle time
  • Site name and page title in the browser
  • App name on the desktop app
  • Clock-in, clock-out, and breaks on the dashboard clock
Only during your schedule (plus your team's overtime window, up to 60 minutes) or a day you start yourself. Managers and admins can't see page titles.

Security & Safety

How data is protected

  • Encrypted in transit (HTTPS) and at rest
  • Each workspace kept separate (row-level security)
  • Signed device tokens that expire after 30 days
  • Rate limits, bot checks, and audit logs
Stored in the United States (Supabase, AWS US East). Sign-in by Clerk.

1. Who We Are and What This Covers

Ruam AI (“Ruam”, “we”, “us”) is operated by Kratuva Inc., a Delaware corporation, 131 Continental Dr, Suite 305, Newark, DE 19713, United States.

This policy covers our website ruam.ai (including the waitlist), the Ruam web app, the Ruam Chrome extension, and the Ruam macOS desktop app. Questions: privacy@ruam.ai.

2. Your Employer and Ruam

Ruam is used by businesses (“Customers”) for their teams. When your employer or client sets up a Ruam workspace and invites you, they decide to use Ruam, choose settings such as your schedule and review window, and control the work records in their workspace. For that data, the Customer is the controller and Ruam processes it on their behalf and on their instructions.

Ruam is the controller for our own website and waitlist, for the account details we need to run the service, and for information about Customers as our business contacts.

Before any tracking starts, Ruam shows each team member what is recorded and what their team can see, and asks them to acknowledge it. That acknowledgment is a record that you were told. It is not a replacement for any notice or consent your employer owes you under local law. If you have questions about why your employer uses Ruam, ask them first; we will help where we can.

3. What We Collect

3.1 On ruam.ai and the waitlist

  • The email address you enter to join the waitlist, when you joined, and which version of our wording you agreed to.
  • Where your visit came from, if the link carried it: campaign tags (such as utm_source) and the name of the site that sent you. Never the full address of the page you came from.
  • Your team size, if you answer the optional question after confirming.
  • A bot check by Cloudflare Turnstile when you submit the form. It processes technical signals such as your IP address and browser details to tell people from bots.
  • Basic server logs kept by our host (IP address, time, page requested).
  • If you email us at hello@, support@, privacy@ or legal@ruam.ai: your email address and what you write. It is kept in our Google Workspace mailbox so we can reply and keep a record of what we agreed.

To see how many people visit, where they come from, and how many join the waitlist, we use PostHog in cookieless mode, if your cookie choices allow Analytics. It sets no cookies, stores nothing in your browser, and builds no profile of you. With each page view PostHog receives your IP address and browser details, uses them to count unique visitors with a code that changes every day, and does not keep your IP address.

If you allow Preferences or Advertising, Google Tag Manager loads the tools you allowed. Today it loads no advertising tools. In the EU, the EEA, the UK, Switzerland, and India nothing optional runs until you choose; everywhere else you can turn it off from Your Privacy Choices at the bottom of every page. See section 12.

3.2 Account and workspace data

  • Name, email address, and profile picture. If you sign in with Google or LinkedIn, we receive your name and email from them.
  • Your role, your manager, your timezone, and your team and organization.
  • Schedules, projects, time off requests, timesheet submissions, approvals, notes you write, and notifications.
  • If the workspace uses them: hourly bill and cost rates set by the Customer.

3.3 Time and activity data

Recorded only during your schedule (plus your team’s overtime window, up to 60 minutes) or a work day you start yourself:

  • Active and idle time in your browser or the desktop app. A minute with no input, or with your browser in the background, is recorded as idle.
  • The site name and page title during tracked work, and on the desktop app the name of the app in front. Never full web addresses.
  • If you use the dashboard clock: when you clocked in and out, and when each break started and ended.
  • Whether your tracker is running and when it last checked in, and which device type sent the data.

Never recorded: screenshots or screen recordings, keystrokes or mouse movements, audio, video or your webcam, what is in your files, full web addresses, and private browser windows (the desktop app records private windows only if you turn that on, and Safari can’t tell apps which windows are private).

3.4 The daily recap

If your workspace uses the end-of-day recap, we keep your answers, a private note, your plan for tomorrow, and optional mood and energy checks. Section 6 explains who can see which parts.

3.5 Records we keep about the service itself

  • Your acknowledgment of how Ruam works: which version you read, when, and the internet address (IP) you read it from.
  • A permanent history of every change to your recorded time: who changed it, when, and why.
  • Audit logs of admin actions and changes to workspace settings.
  • Error reports and product usage data from the Ruam app (see sections 5 and 7).

4. The Chrome Extension and the Desktop App

4.1 Chrome extension

The extension asks Chrome for these permissions, and uses them only as described:

  • tabs and activeTab: to read the site name and page title of the tab you are using, during tracked work only.
  • idle: to tell active time from idle time.
  • alarms: to check once a minute and send data every few minutes.
  • storage: to keep your sign-in token, your tracking state, and any data waiting to be sent, on your device.

The extension can only send data to the Ruam app. It does not run in incognito windows, and it never reads page content, form fields, or full web addresses. It skips the Ruam app itself and any sites on your workspace’s do-not-track list.

Chrome Web Store Limited Use. The use of information received from the extension adheres to the Chrome Web Store User Data Policy, including the Limited Use requirements. We use it only to provide Ruam’s time tracking to you and your team. We do not sell it, use it for advertising, or use it to determine creditworthiness or for lending, and people at Ruam read it only as described in section 7.

4.2 macOS desktop app

During tracked work, the desktop app reads the name of the app in front. When that app is a web browser, it also reads the site name and page title. The site name is taken from the address on your Mac, so full web addresses never leave your device.

5. How We Use Data

  • To run Ruam: record time, show schedules and attendance, handle time off and approvals, and produce timesheets and reports for your workspace.
  • To sign you in and keep your account secure.
  • To send service emails, such as invitations, approvals, reminders, and summaries you have not switched off.
  • To run the waitlist and tell you when your invite is ready.
  • To fix problems and improve the product. In the Ruam app we use product analytics that identify you by an internal id, not your name, and may record how you use the Ruam app itself with private details hidden. This never covers other apps or sites. Error reports can include your user id and email address so we can help the right person.
  • To comply with the law and to protect Ruam, our Customers, and our users.

We do not sell personal data, we do not share it for cross-context behavioral advertising, and we do not use it to train AI models. If we ever add advertising tools to ruam.ai, they will run only as your cookie choices allow, and this policy will say so before they go live. We honor Global Privacy Control signals as a request to opt out.

5.1 Legal bases (EU and UK)

Where Ruam is the controller, we rely on performing our contract with you or your organization, our legitimate interests in running and securing the service, our legal obligations, and your consent for the waitlist emails. For workspace data, the Customer decides the legal basis as the controller.

6. Who Can See What

Managers see their own reports. Owners and admins see everyone in the workspace. They can see your hours each day and how they compare with your schedule, whether you are tracking right now, dashboard clock times and breaks, late starts and overtime, projects and notes on your time, time you add later and who approved it, time off, your recap’s work answers, how much of your time you kept private (never what it was), and your email and whether your extension or desktop app is connected.

Your manager and admins can’t see in Ruam: page titles, sites and apps you haven’t shared, your private recap note and your plan for tomorrow, your own focus and balance notes, and your mood and energy checks. Mood and energy only ever count in an anonymous team average of five or more people. Teammates only see that you are away, not why.

7. Who We Share Data With

We use a small number of companies to run Ruam. Each only gets the data it needs for its job. The full list, with what each one does and where it is, is on our Subprocessors page.

People at Ruam, including our team working from India through our affiliate Kratuva Technologies LLP, reach your data only to run, secure, and support the service.

We may disclose data where the law requires it, to protect rights and safety, or as part of a merger or acquisition, in which case this policy continues to apply to your data.

8. Your Rights

Depending on where you live (for example under the EU or UK GDPR, the California Consumer Privacy Act, or India’s Digital Personal Data Protection Act), you can ask to access, correct, export, or delete your personal data, to restrict or object to how we use it, and to withdraw consent where we rely on it. We will not treat you differently for asking.

  • You can download a copy of your own Ruam data from Settings in the app, and edit your name and timezone there.
  • For anything else, email privacy@ruam.ai from the address you use with Ruam. We reply within 30 days and may need to confirm who you are.
  • If your request is about workspace data, we will pass it to your employer, who controls those records, and help them answer it.

In the EU, the UK, and elsewhere, you can also complain to your local data protection authority.

9. How Long We Keep Data

  • Detailed activity (each site or app with its time): 365 days, then combined into daily totals per site and the details are deleted.
  • Time records and their change history: at least 3 years, and as long as the workspace exists.
  • Other workspace data: for as long as the workspace exists. When a team member is removed, their records stay in the workspace for the employer’s records until the employer asks us to delete them or deletes the workspace.
  • Trials that end without a plan: the workspace pauses (nothing is tracked; the owner can still see and export everything) for 30 days, then it is permanently deleted.
  • Plans that end: the workspace stays read-only for 90 days so the owner can export it, then it is permanently deleted.
  • Deleted workspaces: after a 14-day window in which the owner can cancel, the workspace’s data is permanently deleted, including time records and their change history.
  • After any deletion: backups roll off within 7 days. We keep only the billing email address, a phone number if one was given, and billing records for as long as tax law requires.
  • Waitlist: until you join Ruam or unsubscribe. A signup that is never confirmed is deleted after 30 days.
  • Billing records, once billing starts: as long as tax law requires.

10. Where Data Is Stored

Ruam stores data in the United States. Our main database is hosted by Supabase in AWS US East (Virginia). The ruam.ai waitlist is kept separately with Cloudflare, in a database set to Eastern North America; Cloudflare may process it elsewhere in its network.

Some of our team work from India through our affiliate Kratuva Technologies LLP and can access data remotely, only to run, secure, and support Ruam. When data about people in the EU, the UK, or other regions is transferred to or accessed from the United States or India, we use safeguards the law recognizes, such as the European Commission’s Standard Contractual Clauses, with our service providers and within our group.

11. Security

  • All connections are encrypted (HTTPS), with HSTS on our domains.
  • Data is encrypted at rest by our database host.
  • Each workspace’s data is kept separate with database row-level security.
  • Extension and desktop sign-ins use signed tokens that expire after 30 days.
  • Rate limits, bot checks, and audit logs protect against abuse.

No system is perfectly secure. If a breach affects your data, we will tell affected Customers and, where the law requires, the people affected and the authorities, without undue delay.

12. Cookies

ruam.ai keeps your cookie choice in your browser, and sets one 30-minute cookie only after you confirm your email, to save your answer to the team-size question. You can change that choice any time from Your Privacy Choices at the bottom of every page. The Ruam app uses cookies and browser storage to keep you signed in and, in production, for product analytics. The details are in our Cookie Policy.

13. Children

Ruam is for business use by people 18 and older. We do not knowingly collect data from children. If you think a child has given us data, email privacy@ruam.ai and we will delete it.

14. Changes to This Policy

When we change this policy, we update the date at the top. For material changes we tell Customers by email before they take effect, and in the app we ask team members to read and acknowledge the new version.

15. Contact

  • Privacy questions and requests: privacy@ruam.ai
  • Legal notices: legal@ruam.ai
  • Help with Ruam: support@ruam.ai
  • Kratuva Inc., 131 Continental Dr, Suite 305, Newark, DE 19713, United States

On This Page

1. Who We Are2. Your Employer and Ruam3. What We Collect4. Extension and Desktop App5. How We Use Data6. Who Can See What7. Who We Share Data With8. Your Rights9. How Long We Keep Data10. Where Data Is Stored11. Security12. Cookies13. Children14. Changes to This Policy15. Contact
Work apart · Stay together · Work apart · Stay together · Work apart · Stay together · Work apart · Stay together · Work apart · Stay together · Work apart · Stay together · Work apart · Stay together · Work apart · Stay together ·
HomePrivacy PolicyTerms of ServiceCookie PolicySubprocessorsSupport

© 2026 Kratuva Inc. All rights reserved.