Ruum Privacy Policy

Effective date: 15 August 2026
App: Ruum — remote video calls with high-quality local recording
Provider: First Atlas, Inc. (“we”, “us”)
Contact: support@ruum.cc

Ruum is built to work without user accounts. You never give us your name, email address, or phone number. This policy explains what limited data the app does handle, why, and what control you have over it.

1. Data we process

Identifiers

  • A random device identifier is generated on first launch and stored on your device. It identifies your device in our systems and in invitation links you share. It is not derived from your person or from Apple device identifiers.
  • An anonymous authentication identifier is created to authorize your device’s requests. It is not linked to any personal account.

Call and recording data

  • Video and audio recordings you make are recorded locally on your device and, for the recording feature to work, uploaded to our storage (Amazon Web Services), where the two participants’ recordings are combined into one video. Recordings are private to the call participants and are shared with others only when a participant explicitly creates a share link (links are time-limited).
  • Call connection data: to establish a call, connection metadata (session identifiers, connection candidates) passes through our signaling service and, when a direct connection is not possible, call media is relayed through TURN relay servers. Relayed media is encrypted (WebRTC) and not stored.
  • Device display name (your iPhone’s name, e.g. “Anna’s iPhone”) is used as your caller name shown to the other participant, and in your call partners’ recent-call lists.
  • Recent calls list: the devices you have called (their ruum IDs and display names) are stored so you can call them again.

Push notifications

  • Your device’s push tokens (regular and VoIP) are processed so we can ring your device for incoming calls and notify you when a processed recording is ready. Push delivery uses OneSignal and Apple’s push service.

Technical and diagnostic data

  • Approximate location (country/city, derived from your IP address at first launch) and device metadata (device model, iOS version, language, region, time zone, app version) are collected for operations and diagnostics.
  • During a call, device status relevant to call quality (battery level, headphone connection, network type, orientation, chosen video quality) is shared with the other call participant and our service.
  • Usage analytics and crash reports are collected through Google Firebase Analytics and Crashlytics to understand feature usage and fix defects.
  • Device integrity attestation (Apple App Attest / DeviceCheck via Firebase App Check) is used to verify requests come from a genuine copy of the app. We receive only a pass/fail attestation, no device secrets.

Purchases

  • In-app purchases are processed entirely by Apple. We never see your payment details; we only record that a purchase entitlement exists.

2. What we do NOT do

  • No user accounts, and no collection of your name, email, phone number, or contacts address book.
  • No advertising, no sale of data, no sharing of data with third parties for their own purposes.
  • No tracking across other companies’ apps or websites.
  • Calls are not recorded by us; recording happens only when a participant presses Record, and both participants can see the recording state.

3. Service providers (processors)

We use the following providers to run Ruum, each processing data solely on our behalf:

Provider Purpose Data location
Amazon Web Services Recording storage & processing, API hosting EU (Frankfurt)
Google Firebase Authentication, realtime signaling database, analytics, crash reporting, app integrity United States
OneSignal Push notification delivery United States
Twilio Call relay (TURN) when direct connection fails Global relay points
Apple Push delivery, in-app purchases, app integrity Per Apple’s terms

Where data is processed outside the EU/EEA, transfers rely on the providers’ standard contractual clauses and equivalent safeguards.

4. Retention

  • Recordings are kept until you delete them in the app. Deleting a recording removes the stored video files and the associated records.
  • Call/session records, recent calls, device metadata are kept while your device identifier remains active.
  • Crash and analytics data are retained per Firebase’s standard retention periods.

5. Your controls and rights

  • Delete recordings at any time from the recordings list in the app.
  • Delete the app to stop all further data collection.
  • Depending on your jurisdiction (e.g. GDPR), you may have rights of access, rectification, erasure, restriction, and portability over data we hold. Because Ruum has no accounts, we will ask you for your ruum ID (visible in your invitation link) to locate data belonging to your device. Contact us at the address above.
  • You can disable push notifications and other permissions in iOS Settings; calls and recording require the camera and microphone permissions to function.

6. Security

Requests from the app are authenticated and verified for app integrity; recordings are stored privately and served only through short-lived signed links; access to production data and credentials is restricted and credentialed per-service. Call media uses WebRTC encryption in transit.

7. Children

Ruum is not directed at children under 13 (or the equivalent minimum age in your jurisdiction), and we do not knowingly process their data.

8. Changes

We will update this policy when our practices change and adjust the effective date above. Material changes will be announced in the app.