Privacy Policy
What we collect
Account email; your profile self-descriptions (including city and area, never an exact address); optional photos; and messages you send. We do not collect payment details; Rumi is free to use while we get started.
The waitlist
Joining the pre-launch waitlist stores what you enter on the form: your email, name, date of birth, the answers you pick (gender, practicing level, community, timeline, Louisville area, priorities, and stay details), and an optional phone or note. We use this only to plan the launch and to reach you about your spot. Nothing from the waitlist is shown publicly, and it is never shared. We email you once to confirm your address, then once when we open. Reply to any of our emails to be removed from the list at any time.
How we use it
To operate the directory and matching, and to keep the community safe (moderation).
Public vs. gated
Public: your handle, area, and non-sensitive profile card (to same-gender members). Gated behind a connection: messaging. Gated behind mutual consent: photos and any contact reveal. Your exact location and contact details are never public.
Storage & security
Data is stored with Supabase. Photos live in a private bucket and are served only via short-lived signed URLs; image location metadata (EXIF/GPS) is stripped on upload.
Processors
Supabase (database, auth, storage), Resend (transactional email), Vercel (hosting). We do not sell your data. If paid features launch later, a payment processor will be added here and this policy updated first.
Your rights & deletion
You can request deletion of your account and associated data, including photos and messages. Finalize the exact process and retention windows with counsel.
Children
Rumi is not for anyone under 18.
Changes & contact
We will post changes here. Add your contact email.