Privacy Policy
Last updated: August 10, 2026
1. About This Policy
This Privacy Policy explains how we collect, use, and protect your personal data when you use the Ruby software, website, and packet gateway (collectively, the “Service”). It applies alongside our Terms of Service. It is written to satisfy the transparency obligations of the EU/UK General Data Protection Regulation (GDPR) and similar laws (CCPA, PIPEDA, etc.).
2. Data Controller & Contact
The entity operating this website acts as the data controller for the personal data described below. To exercise any right in Section 9, or to ask any question about this policy, contact us through the Discord server linked on the homepage.
3. Data We Collect
- Account data: your email address and a one-way hashed password. We hash passwords with scrypt and never store or transmit them in plaintext.
- Purchase & billing data: the Stripe payment ID, the email you paid with, the amount and currency, and the billing name and country collected at checkout. Card numbers never touch our servers. Stripe handles all card data under its own compliance program.
- Terms acceptance data: when you check the agreement box at checkout, we record your IP address, user-agent, a timestamp, and the exact terms version you agreed to. This is retained as chargeback evidence and is linked to your purchase.
- Device & authentication data: the device labels you create, plus the OAuth access and refresh tokens needed to authenticate the desktop client and enforce per-device revocation. Refresh tokens are single-use: every rotated token is recorded so a replay can be detected, and those records are deleted once they can no longer be presented.
- Usage data: the settings you configure in the dashboard, and gateway connection logs required to operate the gateway securely.
- Technical & security data: IP addresses used for rate limiting and abuse prevention (stored in our database, not just in memory) and request metadata in server logs.
We do not collect sensitive special-category data (health, ethnicity, political opinions, etc.), and we do not sell your personal data.
4. How We Use Your Data
- To create and authenticate your account and to deliver the access you paid for.
- To link a purchase to your account, including retroactively, if a card payment lands before you sign up.
- To authenticate your devices and enforce revocation when a device is removed or your account is deleted.
- To process payments, issue refunds where applicable, and defend disputes using the terms-acceptance and billing records described above.
- To rate-limit, detect fraud and abuse, and keep the gateway and its users secure.
- To retain records where required by tax, accounting, or anti-fraud law.
5. Legal Basis for Processing (GDPR)
- Contract: to deliver the Service you paid for (account, access, device linking).
- Legitimate interest: rate limiting, fraud and abuse prevention, dispute defense, and security logging.
- Legal obligation: retaining payment and tax records as required by law.
- Consent: any non-essential processing for which you opt in.
6. Third Parties & Processors
- Stripe processes card payments and holds the card data you submit at checkout. Stripe's handling of that data is governed by Stripe's Privacy Policy.
- Our hosting provider runs the servers and database the Service operates on. Access is restricted to what is required to run the Service.
- Discord is our support channel. We do not share your account data with Discord; if you contact us there, Discord's own privacy policy applies to your activity on its platform.
We do not share your personal data with advertisers or advertising networks.
7. International Data Transfers
The Service is hosted on servers that may be located outside your country of residence. When transferring personal data out of the EU/UK, we rely on appropriate safeguards such as Standard Contractual Clauses, or a recognized adequacy decision. Stripe and other processors handle their own transfer mechanisms under their published policies.
8. Data Retention
- Account and purchase data is kept for the lifetime of your access, plus the period required by tax and anti-fraud law (up to 7 years for payment records).
- Device tokens and gateway connection logs are deleted when a device is revoked or when you delete your account.
- Rotated refresh-token records are deleted once they can no longer be presented (i.e. once they can no longer be replayed).
- Terms-acceptance and dispute-evidence records are retained for the life of the related purchase and any dispute window.
9. Your Rights
Under GDPR (and equivalent rights under CCPA and similar laws) you have the right to:
- Access the personal data we hold about you.
- Rectify inaccurate or incomplete data.
- Request erasure (“right to be forgotten”), subject to retention required by law or ongoing disputes.
- Restrict or object to processing.
- Data portability: receive your data in a structured format.
- Withdraw consent at any time (without affecting prior processing).
- Lodge a complaint with your local data protection authority.
We respond to verified requests within 30 days. Where we have reasonable doubt about your identity, we may request additional information to confirm it before acting.
10. Cookies
We use only essential cookies (for your session and authentication). We do not use advertising, tracking, or third-party analytics cookies.
11. Security
Passwords are hashed with scrypt and never stored in plaintext. Rate limiting is enforced server-side and persisted in our database (not in per-worker memory), so a restart does not reset the limit. Gateway sessions are re-validated against the database on a recurring sweep and revocations are pushed for immediacy, so a revoked device does not stay connected. Access tokens are short-lived and refresh tokens are single-use. No system is ever fully secure, but we apply these controls to protect your data.
12. Children's Privacy
The Service is not directed at children under the age of digital consent in their jurisdiction, and we do not knowingly process their data. If you believe a minor has provided us personal data, contact us and we will delete it.
13. Changes to This Policy
We may update this Privacy Policy as the Service evolves. Material changes will be reflected in the “Last updated” date above. Continued use after changes take effect constitutes acceptance.
14. Contact
Questions about this policy or your data can be directed to our team via the Discord server.