Rubi ClubPortuguês

Privacy Policy

Policy effective September 19, 2026

Rubi Club is a private app for adults aged 18 or older in Brazil to record meals in a household group. This policy explains what data is processed and why.

Data we process

We process your email address, account identifier, display name, optional profile photo, group membership, published entries, private saved meals, and, when you enable notifications, this iPhone's installation identifier, APNs token, and notification preference. An entry includes a photo, description, and any calories, protein, carbohydrates, and fat you choose to provide. A saved meal may include a name, private notes, default photo, and nutrition. When you tap Generate macros, we process the entry Description or Saved Meal Name to estimate calories, protein, carbohydrates, and fat. We also record the attempt, draft association, outcome, timing, technical identifiers, aggregate token usage, searches performed, estimated cost, whether the result was applied, and sanitized provider responses and nutrition references. When you confirm a new photo with an empty or still automatically filled description, OpenAI analyzes the image in two stages to identify foods and suggest quantities. You can edit the suggested description; nutrition is calculated only when you tap Generate macros. Private Notes are not sent to AI and the photo is not sent again for nutrition calculation. The authentication service securely processes your password; Rubi Club does not receive or store it in plain text.

Purpose and sharing

This data is used to authenticate you, provide app functionality, diagnose macro generation, understand usage, and manage costs. Macro generation is optional, uses the TACO catalog and searches public web sources for unresolved foods, and returns an editable estimate; it is not a recommendation or clinical guidance. Your name, profile photo, and published entries are visible only to members of the same group. Saved meals, their notes, and default photos are visible only to the account that created them. AI technical records are available only to service administrators, not group members. We do not sell data, show advertising, or track you across apps or websites.

Service provider

We use Supabase for authentication, database services, private image storage, generation-limit enforcement, and notification preparation. OpenAI processes the confirmed photo to suggest foods and quantities. When you request Generate macros, it may interpret the Description or Name, search references, and estimate portions and nutrients when details or complete sources are missing. TypeSafe receives the text description to identify food or drink and, when needed, catalog candidates to select nutrition references; it does not receive the photo. Rubi Club calculates portions and totals in code. The request uses a derived safety identifier that does not directly disclose your account identifier and is configured not to store the response for future model use. Apple processes the device token and notification content to deliver it through APNs. A notification may show the member's name and photo, group name, and meal description on the Lock Screen according to the iPhone's preview settings.

You choose separately whether to share usage analytics and diagnostics. On new installations, both categories are on by default after the privacy notice is presented, to improve Rubi Club’s usability and reliability under our legitimate interest. No consent acceptance is required to continue. Saved preferences, including previous refusals, are preserved. The app continues to work with both categories off. You can change your choices in Privacy and improvements, available before sign-in and in Profile. Changes save immediately; you do not have to make a choice to use the app. Accepting the terms of use does not constitute consent to this optional collection. When diagnostics are on, Sentry receives crashes, hangs, sanitized handled errors, sampled operation timings, app version, and technical device and operating-system information. We do not send Sentry your account identity. When usage analytics is on, PostHog receives screen names, actions, feature selections, and operation outcomes and timings associated with a random identifier for this installation, without an account, name or email mapping. Earlier versions associated these events with the account identifier, without email. This data is pseudonymous, not anonymous. We do not use it to infer health conditions or join it with your meals. PostHog processes the events in the US-hosted project. Field completion records only which field was used, never what you typed. We do not send these services photos, meal descriptions, nutrition values, selected dates, passwords, group codes, or HTTP request content. We do not record sessions, take screenshots, or record audio through these services. Disabling a category stops new collection, cancels app uploads and discards that category’s optional local queue. It cannot recall data already received by the provider and does not request historical deletion.

Retention and deletion

Data remains in the service while your account exists. Rubi Club's operational AI record retains the validated Description or Name, structured suggestions, references, and sanitized OpenAI and TypeSafe responses linked to your account and draft identifier until account deletion, even if you first delete the related entry or saved meal. Photos are not copied into the operational AI record; published photos remain in private entry or saved-meal storage. The separate limit record stores your account identifier, operation and each reservation time to enforce the rolling 24-hour window; expired reservations stop counting immediately and are removed at that user's next reservation or account deletion. OpenAI and TypeSafe may retain processed data under their applicable terms and controls; disabling OpenAI response storage does not guarantee zero provider retention. A member of your group may create a private, independent Saved Meal from a published entry, including a copy of its photo, description, and nutrition. That copy belongs to the other member's account and may remain after the original entry or author account is deleted. A notification registration remains while linked to the account and is removed at sign-out; account deletion also removes it. Notifications and signed avatar links expire after 24 hours, and delivery attempts are capped. You can delete your account under Profile → Account deletion. Deletion removes your account, profile, entries, owned saved meals, notification registrations, AI generation history and content, and photos from the active service, but does not remove independent copies owned by other members. Operational provider backups may remain for a limited period before automatic expiry.

In versions with installation-based analytics, the identifier expires 90 days after registration. The service then schedules a request to PostHog to delete the corresponding history. This governs collection and the request; provider removal is asynchronous and may take days, so we do not promise physical removal of all data or backups within 90 days. In Privacy and improvements, Request usage history deletion turns analytics off and requests removal of history associated with this installation, including previous identifiers still retained on the device. Your meals and account are preserved. Confirmation means the request was received, not that deletion is complete. Reinstalling the app may remove these local references; contact us if you need help. The service keeps technical request references for 90 days after provider confirmation to check for reappearing data; problematic requests remain for investigation. Account deletion requests history removal for this installation, and the server preserves requests for older history linked to the account identifier. If a request is not accepted, the operation reports an error and can be retried. Sentry diagnostics are not linked to your account identity and follow the service's configured retention period. Questions or requests about usage and diagnostic data can be sent to the contact below.

Security and choices

Rubi Club uses encrypted connections, private storage, and group-based access controls. You can correct your profile name and photo, delete your own entries, and enable or disable notifications for this iPhone in Profile. You can also control permission and previews in iPhone Settings. The app is intended for adults and is not directed to children.

Contact

Privacy questions can be sent to support@rubiclub.app.