Who we are
Rumore is operated by Inevitable AI ("Rumore", "we", "us"). Rumore is a reputation and customer-communication platform for owner-run local businesses: it gathers reviews, messages, listings and social activity into one place and helps owners respond, with AI assistance that the owner approves.
For anything in this policy, write to us at privacy@rumore.ai.
The short version
- We collect only what we need to run the product.
- We never sell personal data. We never use your business’s data, or your customers’ data, for advertising. We do use an advertising tracker on this website, for our own ads, and only if you allow it.
- Data from Google and Meta is used solely to show your business its own reviews, messages and comments, and to publish the replies you approve.
- Everything is stored encrypted in the European Union.
- You can ask us to delete your data at any time.
Data we collect
Visitors and the waitlist
If you join the waitlist we store the email address you give us, and the business name and type if you add them. We use them to contact you about early access and nothing else. The free scorecard writes to the same list: giving it your email address opens the full result and puts you on that list at the same time. The scorecard section below says exactly what that means.
We use three analytics tools to see how the site is used: Google Analytics, Microsoft Clarity and PostHog. Google Analytics and Microsoft Clarity set cookies, and we do not pretend otherwise; they are in the table below. PostHog sets no cookies at all, and keeps nothing in your browser between visits. We do not sell what any of them collect.
PostHog also records two things that are about our software rather than about you. The first is an error report when something breaks in your browser: what broke, the line of our code it broke on, and the page you were on, with any sign-in, reset or poster link stripped out of that address before it goes. The second is how quickly a page appears on your screen and how soon it answers your first tap. We use them to find faults and slow screens. Neither one carries anything you typed.
Once you are signed in, PostHog is also told which Rumore account and which business the activity belongs to, as the internal reference codes we use in our own database. That is so we can see how one business gets on rather than a heap of unattached sessions. It is never told your name, your email address, your business name, or anything at all about your Contacts. On our public pages, where nobody is signed in, none of this applies.
We also run one advertising tracker: the Meta pixel, for our ads on Facebook and Instagram. It is the reason we can tell which ad brought someone here rather than guessing, and it lets Meta show our ads to people who look like the owners already using Rumore. It is off until you turn it on. Accepting cookies turns it on; the cookie settings let you keep analytics and refuse this one specifically, and you can change your mind at any time from the link in the footer. It sets the two cookies at the bottom of the table below, and we have turned off Meta’s automatic collection, so it sends only the events we name: a page view, which article, comparison, feature, industry or glossary page you read, running a scorecard, seeing a scorecard result, sending a message in the chat bubble, joining the waitlist, creating an account, and, once trials open, clicking through to start one. It runs on our public pages and on the signup form, and nowhere else: never on a signed-in screen, so nothing about the business you run inside Rumore reaches Meta, and never on a page whose address carries a sign-in or reset link. Joining the waitlist counts once per visitor however many times you ask.
None of those events carries the business name you searched for. Meta is told that a search happened, never what you typed, which is the same line we draw with our own analytics. The name used to sit in the page address while you read your scorecard, and Meta’s pixel reads the address of every page it runs on, so it travelled without our meaning it to. A scorecard now carries an opaque reference code for the listing instead, so the card still has a link you can share and the name stays here.
Three conversions are also reported to Meta from our own servers rather than from your browser: joining the waitlist, creating an account, and the trial actually starting, which is a different moment from the button click above. An ad blocker otherwise turns a real signup into a missing one, and we would be guessing again. The two that also happen in your browser, joining the waitlist and creating an account, carry the same reference number as the browser’s report when there is one, so Meta counts one signup rather than two. The trial starting happens on a page the pixel never runs on, so that one is sent only from us. All three reports carry your email address hashed rather than in the clear, so Meta can match it against an account it already has without us handing over the address itself. Hashing is not anonymising, and we will not pretend it is: anyone holding the same address can produce the same hash, which is exactly how the matching works, so treat it as your address in a different alphabet. Each report also carries the IP address and browser the request came from, which is what Meta uses to tell one person from another, the page you were on with any query string stripped off, and the pixel’s own cookies if you have them (the two named in the table above). Nothing else: never a Business’s own data, and never anything about its Contacts. All of it is sent only for a visitor who turned advertising on. Refuse advertising and nothing goes, from the browser or from us.
Microsoft Clarity is session replay, which means it records how a page is used: where you click, how far you scroll, where you get stuck. We use it to find the parts of the product that confuse people. On every signed-in screen it is set to mask all text, so the recording shows the shape of the page and not the words on it, which keeps your Contacts’ names, phone numbers and messages out of it. That masking is enforced in our code, not in a setting someone could switch off by accident.
Which of these run is your choice, and you can change it whenever you like from Cookie settings at the bottom of this and every other public page, or from the account block once you are signed in. Where the law asks for your permission first, we set no analytics cookie and send no identifier until you give it: Clarity and PostHog do not load at all, and Google’s tag loads in a mode that stores nothing and cannot recognise you. If your browser sends a Global Privacy Control signal, advertising stays off without you having to do anything else, and it stays off even if you accepted cookies here before you turned that signal on, because the signal is the more recent word. It does not switch analytics off over the top of a choice you made yourself in the panel; that one is yours.
Cookies we set
| Cookie | What it does | How long | Whose |
|---|---|---|---|
| rumore_session | Keeps you signed in. Strictly necessary, so it needs no consent. | Session | Ours |
| NEXT_LOCALE | Remembers the language you chose. Strictly necessary. | 1 year | Ours |
| rumore_consent | Remembers this choice, so we stop asking. Strictly necessary. | 6 months | Ours |
| rumore_wcs | Keeps a chat you start with us in one thread, so a reply comes back to the right place. Set only if you open the chat window, never just for visiting. | 30 days | Ours |
| _ga, _ga_<id> | Google Analytics. Counts visits and pages. | 2 years | |
| _clck, _clsk | Microsoft Clarity. Ties a session replay together. | 1 year, 1 day | Microsoft |
| _fbp, _fbc | Meta pixel. Connects a signup back to the ad that led to it. Only set if you turn advertising on. | 90 days | Meta |
We ask again every six months, and straight away if we change what any of this does.
The free reputation scorecard
The scorecard is open to anyone and there is no account to create, though the full result asks for an email address, which has its own paragraph below. To know whether the tool works and whether our ads reach the people we hoped to reach, we keep our own record of a few things when you use it: that a visit happened and on which page, whether the search produced a result, and the short visitor code described below.
These records use no cookies and do not need you to be signed in. To count people rather than clicks, we turn your IP address and browser into a short code using a secret only our server holds. Nobody who gets hold of our database can turn that code back into you, and it is regenerated every night, so it never grows into a history of your visits. We keep visit records for up to a year.
We never keep your IP address or your browser, only the code we make from them, so there is nothing on file to match a request from you against. That is why we cannot pull up your scorecard activity even when you ask us to. Those records are deleted on a timer instead. Anything tied to a Rumore account is different, and we do delete that on request.
The email address is the one thing here that really is you, so it is worth its own paragraph. The score, the business name, the star rating and the review count show without it. Seeing the rest, where you rank against the businesses near you, how the score breaks down, and what your reviews say, asks for an email address first, and we send the business name and type you searched for along with it, so we know which business the person on the list runs. We use that address for three things and nothing else: it opens the result you asked for, it puts you on the same early-access list as the signup forms elsewhere on this site so we can tell you when Rumore opens, and we email you about the scorecard you just opened. That last one is a copy of your result, sent once for each scorecard you open, and then a short series of follow-ups over the two weeks after it. Every one of those emails, the copy of your result included, carries an unsubscribe link that works in one click, and one click stops all of them, including the copy of any scorecard you open later. We do it that way because nothing proves the address typed into the box belongs to the person reading this: if someone put yours in, one click has to be enough to end it. The only mail it does not stop is the kind you need to get into your own account, like a password reset. If you want no email from us at all, write to privacy@rumore.ai and we will take you off. The address is stored on the early-access list, and we do not join it to the visit records above, so handing it over does not turn those back into a history of you. We ask once per browser. If you have already joined the list from anywhere else on this site, the scorecard never asks at all.
So that those emails can quote what you actually saw, we also keep a copy of the result itself beside your address: the business name, the score, the star rating, the review count, where you ranked, the language you were reading in, and your browser’s time zone, which is only there so a follow-up lands in your morning and not at three in the night. We keep that copy for 400 days and then delete it on a timer.
We keep the address itself until you ask us to delete it. There is no timer on this one, unlike the copy of the result and the visit records above, and we would rather say so than leave you to assume there is. Write to privacy@rumore.ai and it goes.
We are about to start keeping more, so here is what changes before it does. Soon these records will also carry the campaign label on the link you followed, where you arrived from as a category (an ad, a search, another site, or direct) rather than an address, whether the screen was phone-sized or desktop-sized, roughly how long the page stayed open, how many characters you typed, and whether you picked a suggestion or typed it out. We will take campaign labels only, never the per-click tracking codes ad platforms append, never the address of the page that sent you, and never your browser version. We will also keep the business name you search for, for 30 days, so we can find the searches that come back empty and fix them. That one will be stored on its own, dated only to the day, with nothing attached that could tie it back to you. When this starts, this paragraph moves to the present tense and the date at the top of the page changes with it.
Business account holders
When you create a Rumore account we store your name, email address, password (hashed, never readable by us) and your business details: locations, opening hours, contact details and the profile information you enter. When you connect an external service (Google, Facebook, Instagram, WhatsApp, your booking or CRM tool), we store the access tokens that connection needs, encrypted at rest.
We also keep a record of activity in your account: sign-ins, the actions you take, and errors your browser reports back to us, which include the page you were on when something broke. We use them to support you and to fix faults. Sign-ins and the actions you take are kept for a year. Faults our own servers record are cleared within a week. The reports your browser sends have no automatic expiry yet, so they stay until you close your account, which clears all of it.
Your customers
To do its job Rumore processes data about your customers on your behalf: contact details you import or collect, appointment records from connected booking tools, the messages they exchange with your business, and the reviews they leave publicly. For this data your business is the controller and Rumore is the processor. We act on your instructions, and we support export and erasure for any contact record.
Google user data
This section covers everything Rumore receives from Google APIs. It applies when you sign in with Google or connect a Google Business Profile.
What we access
- Sign-in (scopes
openid,email): your Google account email address and account identifier, used only to create and sign you into your Rumore account. - Business Profile connection (scope
https://www.googleapis.com/auth/business.manage): the list of business locations your Google account manages, each location's public details (name, address, phone, opening hours), the reviews on those locations (star rating, review text, the reviewer's public display name and photo, and timestamps), and the owner replies published on them. Google offers no narrower scope for reading and replying to reviews, which is why this one is requested.
How we use it
We show your reviews inside your Rumore dashboard, notify you when a new one arrives, and publish the owner replies you write or approve back to your Google Business Profile. Our AI assistant reads the text of a review to draft a suggested reply for you. A draft is only a draft: nothing is published until you approve it.
How we store it
Reviews and location details are stored in our database, hosted in the European Union. The OAuth tokens Google issues are encrypted at rest and are never written to logs.
How long we keep it
We keep the credentials for as long as the connection is active. Disconnect Google Business Profile and that connection's copy of the credentials is overwritten on the spot, while the reviews we already pulled stay as your own record. The access you granted us when you connected is held once for your whole Rumore account, and it outlasts the disconnect: that is what lets you reconnect in one tap instead of going through Google's consent screen again. Closing your Rumore account is what removes it, and there is no button for it before that. To cut our access at the source in the meantime, remove Rumore from your Google account settings, which is the one step we do not do for you today.
Who we share it with
No one, beyond the subprocessors that run the service itself: our EU hosting provider stores it, and a third-party AI provider processes review text transiently to draft a reply. The AI provider receives the text only to generate that draft, does not retain it once the draft is returned, and does not use it to train its models. We never sell Google user data, never use it for advertising, and never transfer it to data brokers or analytics products.
Rumore's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Google user data is never used to develop, improve or train generalized AI or machine-learning models.
Meta data (Facebook and Instagram)
When you connect a Facebook Page or a linked Instagram professional account, Rumore stores the Page and Instagram account identifiers and names, the encrypted access tokens for the connection, the messages your customers send your business through Messenger and Instagram, and the comments on the posts you manage through Rumore. For a comment we store the commenter's public name, their account identifier on the platform, and a link to their public profile picture (the link, not a copy of the photo). Those three are what let the thread show who said what, and often we hold none of them. Facebook withholds a commenter's identity until Meta approves us for the permission to read comments, and it has not. So no comment reaches us with a picture today, and many arrive with no name either. Instagram never sends a picture at all. We use this data to show those conversations and comments in your inbox, to let you reply, and to let our AI draft replies for your approval. We do not read anyone's personal timeline, friends or private profile data.
Meta data follows the same rules as everything else here: encrypted EU storage, no selling, no advertising use.
Disconnect a Page or an Instagram account and two things happen immediately, not on a timer. The Social connection's copy of the access token is overwritten, and the commenter details on every comment we hold from that account are erased: the name, the account identifier and the profile picture link all go. That erasure is permanent, and reconnecting later does not bring them back. Direct messages run on separate connections that stay live until you remove them under Connections too.
What stays is your own record of the exchange: the comment text, your reply, and the Messenger and Instagram conversations. We keep those for as long as your account is open. Deleting your account removes all of it, and deleting your data below sets out the few things that do not follow that path.
If you are a Facebook or Instagram user and want data about you removed from Rumore, see our data deletion page. Removing the Rumore app from your Facebook settings sends us a deletion request too, but that request identifies you by an account id we cannot match against anything we store, so it does not on its own tell us which records are yours. Email us as well and we will complete it within 30 days.
How AI is involved
Rumore uses AI to draft review replies, message responses and social posts from the content your business already handles (a review's text, a customer's message, your business profile). Drafts are suggestions for the owner, and the owner decides what gets published. The AI providers we use process this content only to produce the draft. They do not keep it and do not train models on it. Our AI Policy explains this in full.
What we keep of an AI draft
When the AI drafts a reply to a customer message or to a social comment, we keep that draft from the moment it is written, whether or not you send anything, and we keep your final version next to it when you do send. That is so future drafts can sound more like you. We do not keep a separate AI draft of a review reply. We do keep the reply you send, and where a review site will not accept a reply through us we hold it so you can post it yourself.
All of it stays inside your own business and is never shared across businesses. Messages go when the conversation they belong to reaches your retention window, which is a year unless we have agreed otherwise with you. Social comments and reviews have no separate clock: they stay until you delete your account.
Where your data lives and how it is protected
All production data is hosted in the European Union. Data is encrypted in transit and at rest, OAuth tokens and other secrets carry an extra layer of application-level encryption, and access inside Rumore is scoped so that each business can only ever see its own data.
Sharing and subprocessors
We share personal data only with the vendors that run the service: EU-region hosting and database infrastructure, an email delivery provider for the messages you ask us to send, our payment provider for billing, and a third-party AI provider for drafting. Each one is bound by a data processing agreement. The AI provider processes the content only to produce a draft, does not retain it afterward, and does not use it to train its models. Nobody pays us for personal data, and none of these vendors may use it for their own purposes.
There is one exception to that last sentence, and it is the whole reason this paragraph exists rather than a blanket promise: Meta. If you turn advertising on, the Meta pixel and the two reports we send from our own servers hand Meta identifiers about your visit, and Meta may use them to build an audience of people who resemble the owners already using Rumore. Under California law that counts as sharing for cross-context behavioural advertising, whether or not money changes hands, so this page says it plainly and leaves the choice to you. It happens only if you turn it on, only on our public pages, and you can turn it back off in one click from Cookie settings.
The four measurement vendors above (Google Analytics, Microsoft Clarity, PostHog and Meta) are subprocessors too. Where the law asks for your permission first, none of them stores anything or identifies you until you give it, and everywhere else you can turn them off from the same place; advertising is off until you switch it on, in every country. Microsoft Clarity is the one that reaches furthest inside the product, because session replay covers the signed-in screens and not only this site, so it is named in the Terms of Use along with the masking rule that applies to it. Meta is the one that reaches furthest outward, because it is an advertising network rather than a vendor working only for us, so it is named there as well. If we take on a new subprocessor that handles data from a Rumore account, we tell account holders before it starts and they can object.
Your rights
Under the GDPR (and similar laws elsewhere) you can ask for access to the personal data we hold about you, ask us to correct or delete it, ask for a portable copy, and object to or restrict certain processing. Email privacy@rumore.ai and we will respond within 30 days. If you are a customer of a business that uses Rumore, we may refer your request to that business, since it controls your data, and we will help it respond. You can also complain to your local data protection authority.
Deleting your data
Business owners can disconnect any integration from inside Rumore. That overwrites our copy of that connection's credentials on the spot, and for a Facebook Page or Instagram account it also erases the commenter details described above. Meta leaves a separate direct-message connection behind, which you remove under Connections. Google leaves the access you granted on your account, which goes when you close it. It does not empty your inbox: to remove everything, email us to close the account. Facebook and Instagram users have a dedicated path described on the data deletion page. Once we can tell which records are yours, we complete a deletion request within 30 days. Closing a Rumore account also clears the activity records tied to it.
A few things do not follow that path, and we would rather list them than let you assume otherwise.
- Our records of work the system ran for you, like sending a message, sometimes carry the phone number or email address it went to. We delete those about a month after that work finishes.
- We cannot pick out the scorecard visit records described above at all, because we hold no IP address or browser to match you against. They expire on their own within a year.
- Ask, where you put questions to your AI Employee in your own words, keeps what you typed as the record of that conversation. When a customer asks to be erased we delete every exchange in which Ask looked that person up, question and answer together, but a name you only mentioned in passing leaves us nothing to match on. Those messages go when your retention window closes, which is a year unless we have agreed otherwise with you.
- If you joined the waitlist, or gave the scorecard your email address to open a result, that signup keeps your email address separately, and closing an account does not remove it. Write to privacy@rumore.ai and we will delete it.
- We keep a single line recording that the deletion happened, with nothing personal in it, because we have to be able to show that we did it.
Changes to this policy
If we change this policy in a way that matters, we will update the date at the top and, for significant changes, tell account holders by email before the change takes effect.
Contact
Inevitable AI
privacy@rumore.ai