rummet
Privacy policy
Draft — under legal review. The commitments below are how the product is built and will not weaken in the final text.
The short version
Your photos are private by default. Location metadata is stripped the moment you upload. Photos with people in them are rejected. Your photos are never used to train AI models and never appear in our marketing. Originals and renders are automatically deleted 90 days after you last touch them. You can export or delete everything yourself, any time, and it takes effect within 24 hours.
Who we are
Rummet (www.rummet.net) is operated from the Netherlands. Full operator details will be published here and in the imprint before launch. For anything privacy-related, contact privacy@rummet.net.
What we collect, and why
Account data (email address, language preference, sign-in records) — to provide your account. Legal basis: contract.
Photos of your spaces and the renders we generate — to deliver the makeover service. Interior photos can qualify as personal data, and we treat them that way. Legal basis: contract.
Marketing email consent — only with your double opt-in, revocable in one click in every email. Legal basis: consent.
Purchase records — order history and credits. Payment details (card numbers) are handled by our payment provider acting as merchant of record; we never see or store them. Legal basis: contract and legal obligations.
Usage analytics — cookieless, EU-hosted product analytics to understand how the studio is used, plus error logs to keep it working. Legal basis: legitimate interest.
Fraud and abuse signals (rate limits, IP-based throttles) — to protect the service. Legal basis: legitimate interest.
Your photos, specifically
Private by default — nobody but you can access them. Sharing a render is an explicit opt-in per image and you can revoke it at any time, after which the shared page stops working within a minute. EXIF metadata including GPS location is removed on upload. Photos containing people are rejected at the gate. We never train AI models on your photos, and our marketing imagery is generated from synthetic example spaces only.
Who processes data for us
Vercel (hosting, AI gateway, and cookieless traffic analytics), Google (AI model inference and photo screening, via the gateway — never for sign-in), Neon (database, EU region), Polar (payments, as merchant of record), Resend (email). Analytics and error tracking run on EU-pinned services (PostHog EU, Sentry). We list every processor with its data-processing agreement on this page and announce additions here before they receive any data.
How long we keep things
Photos and renders: deleted 90 days after your last interaction with them, or immediately when you delete them. A render you have published with a share link counts as in use while people are still opening it, so a live link does not go dead underneath you; revoke the share and the 90 days run from then. Account data: until you delete your account. Support conversations: 12 months. Purchase records: as long as tax law requires. Operational audit logs: 24 months.
Your rights
You can access, export, correct, or delete your data — self-serve from your account, or by emailing privacy@rummet.net. We verify identity via your sign-in email and act within 24 hours by design (30 days is the legal maximum). You can object to legitimate-interest processing, and you can complain to the Dutch data protection authority (Autoriteit Persoonsgegevens) or your local one.
Cookies
We use only the strictly necessary session cookie that keeps you signed in. No advertising cookies, no third-party tracking cookies, and cookieless analytics — which is why there is no cookie banner.