RuleCue

Privacy Policy

Effective 2026-08-11 · Version 2026.08.11

1. Scope and contact

This Privacy Policy explains how Cody Rasmussen (individual seller), the provider of RuleCue, collects, uses, discloses, and retains personal information for the RuleCue website, application, subscription, support, and related business services. RuleCue serves U.S. business customers and is not intended for personal, family, or household use.

Privacy questions and requests may be sent electronically to info@rulecue.com.

2. Information we collect

RuleCue does not request customer safety documents, employee medical or incident records, government identification numbers, payment-card numbers, biometric data, or other sensitive employee-level data. Customer-document intake and customer-content AI processing are disabled for this release.

3. How we use information

Provider uses personal information to create and secure accounts; deliver selected monitoring, reporting, workspace, billing, support, and cancellation functions; send requested sign-in links and necessary service messages; process subscriptions; prevent fraud and abuse; maintain source and release evidence; diagnose errors; improve service usability and reliability; respond to requests; enforce agreements; and comply with legal obligations.

Provider does not use customer personal information for advertising, does not sell personal information, and does not share personal information for cross-context behavioral advertising. RuleCue does not use advertising pixels or session-replay tools.

4. Sources of information

Provider receives information from Customer and its authorized users, from use of the website and application, from Stripe and transactional-email providers, and from security and hosting providers. Public regulatory information comes from official public sources and is not treated as Customer Personal Data merely because RuleCue collects it.

5. Service providers and disclosures

Provider discloses only the information reasonably needed for the listed function to production providers, including Vercel for application hosting, Supabase for hosted database and private storage services, Cloudflare for domain, delivery, and security services, Stripe for checkout and billing, Resend for transactional access and service email, and Google Workspace for staffed business communications. The current details are in the Subprocessor List.

Stripe acts independently for some payment, fraud, network, tax, and legal-compliance purposes under its own terms and privacy notice. Provider may also disclose information when required by law; to protect customers, Provider, or others; in connection with a financing, reorganization, merger, or sale subject to appropriate confidentiality; or with Customer’s direction or consent.

OpenAI and Anthropic do not receive Customer Personal Data in this release. Outbound marketing email is disabled. Resend and Google Workspace are used only for transactional, requested, support, privacy, and other necessary business communications within the released functions.

6. Retention

Provider keeps business account, workspace, service, and support information while the account is active and afterward only as reasonably needed to provide requested exports, complete deletion workflows, maintain security and audit integrity, resolve disputes, enforce agreements, and meet tax, accounting, and other legal obligations. Billing records and immutable transaction or security evidence may be kept longer when needed for those purposes. One-time links and live sessions expire on much shorter operational schedules. Backups and provider logs are removed through their ordinary secured rotation cycles.

Provider applies the shortest period reasonably compatible with each purpose and may deidentify information instead of retaining it in identifiable form. A verified deletion request will be completed unless retention is required or permitted for security, fraud prevention, legal compliance, dispute resolution, or another documented lawful purpose.

7. Security

Provider uses administrative, technical, and physical safeguards designed for the nature of the information handled, including encrypted network connections, access controls, tenant boundaries, private storage, secret management, audit records, backups, and monitoring. No Internet service can guarantee absolute security. Please report a suspected security issue to info@rulecue.com.

8. Cookies and similar technology

RuleCue uses essential cookies and comparable local browser storage for secure sessions, preferences, request integrity, abuse prevention, and core functionality. Cloudflare and Stripe may use their own security or checkout technology when their services are used. RuleCue does not use advertising cookies or session replay in this release.

9. U.S. service and provider locations

RuleCue is offered to U.S. business customers. Provider and its service providers may process information in the United States and in other locations where they operate, subject to their contractual and legal safeguards. RuleCue does not promise that every provider support or infrastructure operation remains in a single state.

10. Privacy choices and requests

Authorized users can update many workspace and communication settings in RuleCue. A person may ask Provider to access, correct, delete, or provide a copy of personal information, or may appeal a denied privacy request, by emailing info@rulecue.com. Provider may verify identity and authority before acting and may limit a response where an exception applies. An authorized agent may submit a request when legally permitted and must provide proof of authority.

Provider will not discriminate against a person for exercising an applicable privacy right. Because Provider does not sell personal information or share it for cross-context behavioral advertising, no sale or advertising opt-out is needed for the current service. Business contacts may opt out of optional nonessential messages at any time; transactional security, billing, and service notices may continue while an account remains active.

11. Children

RuleCue is a business service and is not directed to children under 13. Provider does not knowingly collect personal information from children through RuleCue.

12. Changes to this Policy

Provider may update this Policy as the service or law changes. The published version will show its effective date. Material changes will be communicated through RuleCue, the account email, or another reasonable electronic method before they apply when required.