Ruru — Privacy Policy
The short version. Ruru has no account, no sign-up, and no server of ours. Your nights, streaks, photos, and name stay on your phone, or sync through your own iCloud where we cannot read them. Three third parties are involved: Superwall, which runs the subscription paywall and receives your onboarding answers so the right paywall can be shown; Google Firebase Analytics and Meta, which receive a small set of usage events — which onboarding screens you reached, whether you subscribed — so we can see where people give up and whether our ads work. With your permission, given through Apple's tracking prompt, Meta may link those events to your device's advertising identifier. Say no, and it can't. Nothing is sold.
Who we are
Ruru is made by Unforkable ("we"). For anything in this policy, contact jonas@tryruru.com.
What stays on your device
Almost everything. The following is stored only on your phone, inside the app's own storage, and never sent to us or anyone else:
- Your night history and streak — which nights the phone reached its charger, and which it didn't.
- The photo of your charger spot, if you take one. It is taken with your camera, saved in the app's private container, and is never uploaded or analysed.
- Your signature from the commitment screen, stored as an image the same way.
- Your first name, if you give one. It is used to address you inside the app. The name itself is never transmitted to anyone — the only thing that leaves the device is a yes/no flag that a name was set.
What syncs through your iCloud
Your plan (bedtime, wake time, chosen nights), your onboarding answers, and your streak are mirrored to Apple's iCloud key-value storage attached to your own Apple Account. This exists so a new phone, or a reinstall, doesn't ask you everything again. It is Apple infrastructure under your Apple Account: we have no server-side access to it and cannot read it. You can remove it by deleting the app's data from iCloud in your device settings (Settings → your name → iCloud).
What Superwall receives
Ruru's subscription paywall is operated by Superwall (Superwall, Inc.), whose SDK is built into the app. When the app runs and when the paywall is shown or a purchase happens, Superwall receives:
- Your onboarding answers, sent as so-called user attributes so the paywall can be chosen and personalised: how you heard about Ruru, your age bracket, your gender (only if you answered — the question is skippable), your screen-time and evening estimates and the figures the app derives from them, what keeps you up at night, whether you have a bedtime ritual, what you'd use the reclaimed time for, your chosen bedtime, wake time, nights and commitment level, where your charger is and whether you moved it, and whether you set a name (never the name itself).
- Basic device and usage information the SDK collects to function: device model and iOS version, app version, language, region and time zone, a device-scoped identifier (Apple's "identifier for vendor"), your IP address as an unavoidable part of any internet request, and events about the paywall and your subscription (shown, purchased, cancelled, restored).
This data is used to decide which paywall to show, to measure whether it works, and to manage your subscription state. Superwall does not use it to track you across other companies' apps or websites, and never receives the advertising identifier. Superwall processes this data under its own privacy policy.
What Google (Firebase Analytics) receives
To see where people stop in the app's setup, Ruru uses Google Analytics for Firebase (Google LLC). It receives a fixed list of events, and nothing you typed or answered:
- Which onboarding screen was shown, one event per screen, and the setup being completed.
- The paywall being shown or closed, a free trial starting, a purchase (product and price), and a restore.
- The first night the phone reached its charger — as a yes, with no times or history attached.
- What Google's SDK collects to function: an app-instance identifier it generates, Apple's identifier for vendor, device model and iOS version, app version, language, region, and coarse session information.
Your name, your onboarding answers, your night history, your photo and your signature are never part of these events. Google processes this data under its own privacy policy; the analytics data is kept for 14 months.
What Meta receives
To measure whether advertising for Ruru works, the app includes Meta's SDK (Meta Platforms, Inc.). It receives the same fixed list of events as above — screens reached, setup completed, trial started, purchase, restore — plus the SDK's own basic app-open and session events, and the device information it collects to function.
Whether Meta may link these events to your device's advertising identifier is your call: Ruru asks once, after setup, using Apple's tracking prompt. If you allow it, Meta can attribute your install and purchase to an ad you saw. If you decline, the identifier is never sent and the events remain unlinked. You can change your answer at any time in Settings → Privacy & Security → Tracking. Meta processes this data under its own privacy policy.
Payments
Subscriptions are bought through Apple's App Store and billed to your Apple Account. We never see your payment details. Apple provides us and Superwall with anonymised transaction information (for example, that a subscription is active) so the app can unlock.
Permissions the app asks for
- Notifications & alarms — so Ruru can call you at your bedtime. Scheduling happens on your device; no push servers of ours are involved.
- Camera — only if you choose to photograph your charger spot. The photo stays on your phone, as described above.
- Tracking — Apple's "Allow Ruru to track your activity" prompt, shown once after setup. It governs only whether Meta may use the advertising identifier, as described above. Everything in the app works the same whichever way you answer.
Ruru does not ask for your location. The night-sky weather in the app is decorative and computed on your device from the calendar date.
What we don't do
- No ads inside the app.
- No selling or renting of data, to anyone, ever.
- No tracking without asking: the advertising identifier is used only if you say yes to Apple's prompt.
- No analytics on what you answer or how you sleep — only on which screens you reach and whether you subscribe, as listed above.
- Ruru is not directed at children, and we do not knowingly collect personal data from children under 13.
Keeping and deleting your data
On-device data lives as long as the app is installed — deleting the app deletes it. The iCloud mirror is yours to remove in your device's iCloud settings. Superwall, Google and Meta retain the data described above under their own policies (Google's analytics data for 14 months); if you would like it deleted, email us at jonas@tryruru.com and we will pass the request on — to Google through its analytics deletion tools, to Meta through its data-deletion request — and confirm when it is done.
Your rights
Depending on where you live (for example under Swiss or EU data protection law), you may have rights to access, correct, export, or delete personal data concerning you, and to object to certain processing. Since we hold no data about you on servers of our own, such requests will usually concern the Superwall, Google or Meta data above — email us and we will handle it with them on your behalf. You can also complain to your local data protection authority.
Changes
If the app's data practices change, this policy will be updated first and the date above will change. Meaningful changes (a new third party, a new category of data) will also be called out in the app's release notes. The 2 September 2026 revision added Google Firebase Analytics and Meta, and the tracking prompt, as described above.
Contact
Unforkable · jonas@tryruru.com · tryruru.com