Privacy Policy
Effective date: June 10, 2026 · Last updated: June 10, 2026
Plain English summary: Rummify collects only what it needs to run your rummy sessions — your phone number for sign-in, the player names and scores you enter, and basic app usage data. We do not sell your data. We do not share it with advertisers. We do not store payment card details.
1. Who we are
Rummify is operated by Rummify, based in Chantilly, Virginia, USA. References to "we," "us," or "our" in this policy mean Rummify.
If you have questions about this policy, contact us at privacy@rummify.ai.
2. What we collect
Account information
- Your mobile phone number, used solely to verify your identity via one-time password (OTP). We use Firebase Authentication to handle this — your number is stored by Google/Firebase, not on our own servers.
Session and game data
- Player names you enter or scan into a session.
- Scores, drops, and results you record during a game.
- Session configuration (rules, buy-in amount, currency preference).
- Settlement amounts calculated at session end.
Device and usage data
- Basic crash and error logs to help us fix bugs.
- App version and device OS version.
What we do NOT collect
- Payment card numbers or bank details. All purchases go through Google Play or the Apple App Store directly.
- Location data.
- Contacts from your phone's address book (you type or scan names manually).
- Any data from players who are not the organizer — only the organizer creates an account.
3. How we use your data
- To authenticate you and keep your session history linked to your account.
- To display scores, calculate settlements, and generate session summaries.
- To restore your purchase entitlements (e.g., scan credits) if you reinstall the app.
- To diagnose crashes and improve app stability.
We do not use your data for advertising, profiling, or any purpose not listed above.
4. Who we share data with
We share data only with the services required to run the app:
- Google Firebase — phone authentication and crash reporting.
- Supabase — secure database hosting for session and player data (servers in the USA).
- RevenueCat — purchase and entitlement management. RevenueCat receives a hashed user ID and purchase receipt; it does not receive your phone number or game data.
- Anthropic Claude API — if you use the guest list scan feature, your scanned image is sent to Anthropic's API for text extraction and is not stored by Anthropic beyond the duration of the request.
We do not sell data to third parties. We do not share data with advertisers.
5. Data storage and security
Your session data is stored on Supabase servers located in the United States. We use row-level security so that only you can read your own sessions and player data.
Phone authentication is handled by Google Firebase, which is SOC 2 and ISO 27001 certified.
We retain your data for as long as you have an active account. If you delete your account, your data is deleted within 30 days.
6. Your rights
- Access — you can view all your session data directly in the app.
- Deletion — email us at privacy@rummify.ai to request deletion of your account and all associated data.
- Portability — contact us to request an export of your session history.
If you are located in the European Economic Area or the United Kingdom, you have additional rights under GDPR/UK GDPR including the right to object to processing. Contact us to exercise those rights.
7. Children
Rummify is not directed at children under 13. We do not knowingly collect data from anyone under 13. If you believe a child has provided us with personal data, contact us at privacy@rummify.ai and we will delete it promptly.
8. Changes to this policy
We may update this policy when we add new features or as required by law. When we do, we will update the "Last updated" date at the top of this page. Continued use of the app after an update means you accept the revised policy.