Privacy Policy
In plain terms This website collects nothing. If you email us or hire us, we keep only what the work requires, and we never sell it.
Rubiconetic ("we," "us," or "our") is an independent software studio. We design and build mobile applications, web applications, and automation systems, both our own products and software built under contract for clients. This policy explains what data we collect, how we handle it, and what you can ask us to do with it.
rubiconetic.com has no analytics, no cookies, no tracking pixels, and no forms. Visiting it leaves no record with us. If you email us, we keep the email. If you become a client, we hold the minimum data needed to build and support your software. We do not sell data to anyone, ever. Our published apps have their own policies, linked in section 6.
1. This Website
rubiconetic.com is a static site served from Cloudflare Pages. It sets no cookies, loads no analytics or advertising scripts, and contains no contact form or lead capture of any kind. We receive no identifying information about you as a result of reading these pages.
Cloudflare, our hosting and network provider, processes standard request metadata (IP address, user agent, requested URL) in transit to route traffic, terminate TLS, and absorb denial-of-service attacks. We do not access, aggregate, or retain that data. See Cloudflare's privacy policy for how they handle it.
Web fonts are requested from Google Fonts, which means your browser makes a request to fonts.googleapis.com and fonts.gstatic.com. Those requests are subject
to Google's policy. No other third-party resource is loaded by this site.
The site stores one item in your browser's localStorage: your light/dark theme
preference. It never leaves your device and is not readable by us.
2. When You Contact Us
If you email hello@rubiconetic.com or call us, we receive whatever you choose to send: your name, email address, phone number, company, and the contents of your message.
We use that information for exactly one purpose: replying to you and, if it goes somewhere, scoping the work. We do not add you to a mailing list, enrich your record against third-party data brokers, or pass your details to anyone else.
Inquiries that don't turn into engagements are deleted within 12 months of the last message, unless you ask us to delete them sooner.
3. When You Hire Us
To design, build, and support software under contract, we typically hold:
- Business contact details: names, emails, and phone numbers of the people we work with on your side
- Project material: requirements, designs, documentation, and anything else you share to define the work
- Repository and infrastructure access: source control, deployment targets, and any credentials you provision for us
- Contractual and billing records: agreements, invoices, and payment history, which we are required to retain for tax purposes
Production data. Where an engagement requires access to a live system containing your users' personal data, you are the data controller and we act strictly as a processor under your written instructions. We request pseudonymised or synthetic datasets wherever the work allows it, keep any production access time-boxed and scoped to named individuals, and delete local copies at the end of the task. Specific handling terms are set out in the relevant agreement or data processing addendum, which takes precedence over this policy.
4. Credentials and Access
Credentials you provide are stored in an encrypted secret manager, never in source control, plain-text notes, chat messages, or email. We ask that access be granted through your own identity provider with the narrowest workable permissions, so it can be revoked by you at any time without our involvement.
At the end of an engagement we ask you to revoke our access, and we delete any credentials still held on our side. If you'd like written confirmation that this has happened, ask and we'll send it.
5. Subprocessors
We keep the list of third parties that can touch client data deliberately short. As of the effective date above, it is:
| Provider | Purpose |
|---|---|
| Cloudflare | Website hosting, DNS, TLS, and DDoS protection |
| Email provider | Studio email correspondence |
| Self-hosted source control | Code, issues, and CI, run on infrastructure we operate |
If a specific project requires an additional provider, like a cloud platform, an error tracker, or an AI API, that provider is named in the project agreement before any data reaches it. We do not add subprocessors to a live engagement without telling you.
6. Our Own Applications
Software we publish under our own name is covered by its own policy, because what an app collects depends entirely on what the app does:
- Scanity: see the Scanity privacy policy. In short: your blocklist and scan history stay on your device.
- MacroMeso is pre-release; its policy will be published before general availability.
Both apps are built local-first: the device holds the record of truth, and anything synced to a server exists to back up and move data between your own devices, not to be analysed, resold, or used to train models.
7. What We Never Do
- Sell, rent, or trade personal data. There is no circumstance in which this changes.
- Run behavioural advertising or share data with ad networks.
- Train machine-learning models on client code or client data.
- Use client production data for demos, portfolio pieces, or case studies.
8. Security
All traffic to our systems is encrypted in transit with TLS. Administrative access requires multi-factor authentication. Secrets are held in an encrypted store with per-project scoping, and access to client systems is granted per-task rather than standing.
No system is perfectly secure, and we won't claim otherwise. If we become aware of a breach affecting your data, we will notify you without undue delay, and in any case within 72 hours of becoming aware. We will tell you what we know, what we don't yet know, and what we're doing about it.
9. Your Rights
Regardless of where you live, you can ask us to:
- Tell you what personal data we hold about you
- Correct anything inaccurate
- Delete it, subject to legal retention obligations such as tax records
- Export it in a portable format
- Stop processing it for a given purpose
Email hello@rubiconetic.com. We respond to legitimate requests within 30 days and don't charge for them. If you're covered by the GDPR, UK GDPR, or CCPA/CPRA, these rights are yours by law; we extend the same handling to everyone else as a matter of policy.
10. Children
Our services are directed at businesses and adults. We do not knowingly collect personal data from anyone under 13. If you believe a child has provided us with personal data, contact us and we will delete it.
11. International Transfers
Rubiconetic operates from the United States, and data we hold is processed there. If you are contacting us or engaging us from outside the US, you are consenting to that transfer. Where an engagement requires data to remain in a specific jurisdiction, say so at the outset and we will architect for it. It is far cheaper to decide before the schema exists than after.
12. Changes
We may revise this policy as the studio's work changes. The effective date and version at the top of this page always reflect the current revision. Material changes affecting active clients are communicated by email rather than left to be discovered.
13. Contact
Rubiconetic
Email: hello@rubiconetic.com
Phone: (928) 327-7724
Web: rubiconetic.com
Arizona, United States
Questions about this document? hello@rubiconetic.com
Back to the studio