Privacy Policy
Last updated 15 August 2026.
Rubric is operated by Codeck Software, Inc., 8 The Green, Suite 11307, Dover, DE 19901, USA, which is the controller of the personal data described here. Write to hello@rubric.design about anything on this page.
The short version
We collect what running a metered API requires and nothing else. There are no analytics on this site, no advertising, no third-party trackers and no tracking cookies — which is why you have never seen a cookie banner here. We do not sell or share personal data, and we do not use your audits to train anything.
What we collect
| What | Where it comes from | Why |
|---|---|---|
| Email address, name and avatar URL | Google or GitHub, when you sign in | To identify your account and contact you about it |
| API keys, stored only as a hash | Created by you in the panel | To recognise a key on a call. The key itself is shown once and never stored, so we cannot recover it for you or for anyone else |
| Usage events — which tool, when, what it cost | Your calls | Metering, billing, the free-tier limit, and abuse detection |
| Audits — the URL, vertical and label you give | You, via create_audit |
To store the audit and produce its report |
| Observations you submit against an audit | You, via submit_findings |
To resolve them into findings and keep the report readable later |
| Payment records — amount, currency, Stripe identifiers | Stripe, after a payment | To credit your balance and to keep the accounts |
| Connected applications, if you sign in an agent with OAuth | The authorisation you gave | So you can see and revoke them |
What we do not collect
- Card details. Stripe holds those. They never touch our servers.
- The content of the sites you audit. We store the URL and the observations you choose to send. We do not crawl, fetch or copy the page — your agent does the looking, and only what it submits reaches us.
- Your password. There isn’t one; sign-in is delegated to Google or GitHub.
-
Test runs. A synthetic URL — localhost, a private IP, a
.test/.local/.examplehost — is never written to the database at all. Not the audit, not the findings, not even the usage event.
Why we are allowed to hold it
Where the UK GDPR or EU GDPR applies to you, our lawful bases are performance of a contract (running the service you asked for, and billing it), legal obligation (keeping financial records) and legitimate interests (keeping the service secure and working out what to fix).
Who else processes it
We use a small number of providers, each for one job. They act on our instructions and may not use your data for their own purposes.
| Provider | What it does | Where |
|---|---|---|
| Supabase | Database and authentication | EU (Frankfurt) |
| Netlify | Hosting, CDN and the serverless functions | USA, served from edge locations worldwide |
| Stripe | Payments | USA and EU |
| Google / GitHub | Sign-in, if you choose that provider | USA |
We are a US company, so your data is processed in the United States as well as the EU. Where transfers out of the UK or EEA need a safeguard, we rely on the standard contractual clauses our providers offer.
How long we keep it
- Account, audits and findings: until you delete the account, then removed.
- Usage events: up to 24 months, because they are what a billing dispute is settled from.
- Payment records: as long as tax and accounting law requires, which in the US is generally seven years. These survive account deletion because they must.
How it is protected
- Every customer table is closed by default at the database level. The browser never queries the database directly — every read goes through our own server, which applies the account boundary in one place.
- API keys are stored as hashes. A stolen database yields no usable key.
- Two-factor authentication is available on your account and required for administrative access.
- Everything is served over TLS.
No system is perfectly secure. If a breach affects you we will tell you, and any regulator we must, without undue delay.
Your rights
You can ask for a copy of your data, correction of anything wrong, deletion, restriction of processing, or portability, and you may object to processing based on legitimate interests. Deleting your account from the panel does most of this immediately: it revokes your keys and connected applications and removes your audits and findings.
For anything else, write to hello@rubric.design and we will answer within 30 days. If you are in the UK or EEA and think we have got it wrong, you may complain to your data protection authority. If you are in California, we do not sell or share personal information as those terms are defined by the CCPA, and we will not discriminate against you for exercising a right.
Cookies and storage
The landing page sets nothing. The panel keeps your sign-in session in your browser’s local storage so you are not asked to sign in on every visit, and stores the short-lived verifier that makes the sign-in round trip safe. That is all of it — strictly necessary, no analytics, no advertising identifiers.
Children
Rubric is a developer tool and is not directed at anyone under 18. We do not knowingly collect data from children; if you believe we have, tell us and we will delete it.
Changes
We will update this page when what we do changes, and change the date at the top. If a change is material we will tell you at the email on your account before it takes effect.