Privacy Policy

Last updated: September 2, 2026

This Privacy Policy explains how Ruligent, currently a free, pre-commercial service operated by its founder as an individual in New York, United States, collects, uses, discloses, and retains information when you use www.ruligent.com, app.ruligent.com, api.ruligent.com, and the Ruligent service. No separately registered Ruligent entity or completed assumed-name filing is represented.

1. Information we collect

2. How we use information

3. Data minimization and restricted data

Ruligent is designed to operate on governance metadata and bounded summaries, not unrestricted copies of customer payloads. Do not intentionally send payment-card data, protected health information, government secrets, export-controlled technical data, or other specially regulated information unless a separate written agreement expressly authorizes that processing.

4. Retention

5. Service providers and disclosures

Ruligent uses service providers to operate the product, including Vercel for hosting, Supabase/Postgres infrastructure for data storage, Stripe for payments, and Resend for transactional email when enabled. Sentry and PostHog may be used where configured. The current list is maintained at /legal/subprocessors. We may also disclose information when required by law, to protect rights or security, in connection with a business transaction, or with your direction or consent.

6. What we do not do

7. Your choices and rights

Depending on your location, you may have rights to access, correct, delete, export, restrict, or object to certain processing. Submit requests through the Ruligent contact page. We may need to verify your identity before acting on a request. Authorized-agent requests may require proof of authority where applicable.

8. Customer and processor roles

For account, billing, security, and direct business-contact information, the Ruligent service operator generally acts as an independent business/controller. For personal data contained in customer-controlled agent activity processed on behalf of an organization, Ruligent may act as a processor/service provider under the Data Processing Addendum.

9. Security

Ruligent uses controls including TLS in transit, organization-scoped access controls, password hashing, credential digests, signed webhooks, security headers, and operational monitoring. No security program can guarantee absolute security. See the Security Policy for current practices and limitations.

10. International users

Ruligent is operated from the United States and its providers may process information in the United States and other countries. Where required, contractual and other transfer mechanisms may be used for customer personal data.

11. Children

Ruligent is intended for business users and is not directed to children under 13. We do not knowingly solicit personal information from children.

12. Commercial identity notice

Ruligent is currently operated by its founder as an individual. No separately registered Ruligent entity or completed assumed-name filing is represented. Privacy obligations described here are undertaken by the individual service operator until the approved commercial identity is completed and this notice is updated.

13. Changes and contact

We may update this policy as the service, providers, or legal requirements change. Material updates will be posted here and communicated where appropriate. Contact the Ruligent operator through the contact page.