Privacy Policy
Last updated October 9, 2026.
1. Who we are
This policy covers app.rubricary.com — the prompt registry, the eval battery, the anonymous validator, and the API, CLI and MCP server that read from it. Rubricary ("we") is the controller of the personal data described here. Contact: support@rubricary.com. The marketing website, rubricary.com, has its own privacy policy.
2. What the anonymous validator stores
The validator's job is to score a pasted prompt, not to keep a copy of it. Specifically:
- The pasted text itself is not stored. Rubricary keeps only a one-way hash of the trimmed text, used to tell submissions apart, detect a repeat prompt, and serve a cached score without calling a model again.
- Your IP address is not stored either. It is hashed and used only to enforce the daily anonymous quota described in the Terms of Use.
- The submission log keeps the resulting score, which model and provider produced it, the token count and cost, whether it was answered from cache, and — if you were signed in — your account id. This exists to measure one thing: how many visitors who try the validator go on to create an account.
- A scored result is cached under the prompt's hash for 24 hours, so an identical resubmission is answered instantly instead of calling a model again. The cache holds the score, not the prompt text.
3. Which AI providers receive your prompt text
To produce a score, the text you paste is sent, for that one request, to OpenRouter, which passes it to TypeSafe (the Jev model that grades it). If Jev is unavailable, the request may instead go to OpenAI, Anthropic (Claude) or Google (Gemini), whichever is configured as the fallback. Rubricary does not retain that text afterward — see the section above — but each provider handling the request processes it under its own terms and privacy policy, and Rubricary does not control how long those providers' own systems retain it.
Prompts published to the catalog are evaluated differently: the prompt and its eval inputs are sent to OpenAI, which generates each response. The input and the response are then sent through OpenRouter to TypeSafe, which grades it. Published prompts are public, and the responses and verdicts are stored and shown on the prompt's Evals tab.
In local development or preview environments, a simulated provider that calls no external model and sends no data anywhere may be used instead. This substitute is never used in production, so any score you get on the live site was produced by a real provider above.
4. Account data
Signing in is OAuth only, through Google or GitHub (the sign-in itself runs on Google Firebase Authentication). Rubricary receives your name, email address, and which provider you signed in with; it never sees or stores a password. Anything else on your profile — company, location, website, social links — is typed in by you and stays editable or removable from Settings.
5. Cookies and local storage
Rubricary sets one cookie of its own, which is strictly necessary:
- rubricary_session — an HTTP-only session cookie that keeps you signed in. It lasts 14 days and, in production, is scoped to
.rubricary.comso it works across subdomains. It is not used for advertising or tracking and does not need your consent.
Google Analytics sets its own cookies (_ga and _ga_*), but only if you accept them in the cookie notice; see the next section.
Four small entries live in your browser's local storage (or, for sign-in, the storage Firebase Authentication uses) and never leave your device through Rubricary: your light/dark preference (rubricary-theme), the sign-in method you used last (rubricary-last-provider), your cookie choice (rubricary-consent), and the sign-in state kept by Firebase Authentication.
6. Analytics (Google Analytics 4)
If you press Accept in the cookie notice, Rubricary loads Google Analytics 4, a measurement service from Google. If you press Decline, or ignore the notice, it is not loaded and nothing is sent to Google for analytics. You can change your choice at any time with "cookie settings" in the footer; declining after having accepted also removes the analytics cookies.
When enabled, Google Analytics sets a random identifier in a cookie (up to 2 years) and collects:
- the pages you view, how long you stay, scrolling and clicks on outbound links;
- the page or site that referred you;
- your approximate location (city or region), derived from your IP address, which Google Analytics does not store;
- your device, operating system, browser, screen size and language.
It does not receive the text you paste into the validator, prompt content, or your name or email address. We use it only to understand how many people visit and which pages are used — not for advertising, remarketing or audience building, and we do not sell data. Event data is kept in Google Analytics for at most 14 months.
7. Why we process your data (legal bases)
- Contract (GDPR art. 6(1)(b); LGPD art. 7, V) — to run your account and the features you use: signing in, organizations, publishing prompts, API keys.
- Consent (GDPR art. 6(1)(a); LGPD art. 7, I) — for Google Analytics and its cookies. You can withdraw it at any time.
- Legitimate interest (GDPR art. 6(1)(f); LGPD art. 7, IX) — for the hashed validator log and quotas, security, preventing abuse and keeping our AI spending under control, and measuring how many visitors become users. You may object (see section 11).
- Legal obligation (GDPR art. 6(1)(c); LGPD art. 7, II) — where the law requires us to keep or disclose something.
8. Who receives your data
We share data only with providers that help us run the service, under their own terms and privacy policies. We do not sell your personal data.
- AI providers — OpenRouter, TypeSafe, OpenAI, Anthropic and Google, as described in section 3.
- Vercel (hosting and server logs), Neon (database), Cloudflare (storage of prompt repositories) and Upstash (short-lived rate-limit counters, using hashed identifiers).
- Google and GitHub (OAuth sign-in), and Google again for Analytics, only if you accept.
- Public prompts and their metadata are, by design, visible to everyone (see section 12).
9. International transfers
Our providers process data in the United States and other countries. Where the law requires it, these transfers rely on safeguards such as the EU-US Data Privacy Framework or standard contractual clauses (GDPR chapter V; LGPD art. 33).
10. How long we keep data
- The session cookie lasts 14 days; analytics cookies last up to 2 years; Google Analytics event data is kept at most 14 months.
- Validator results are cached for 24 hours; hashed IP quota counters expire daily.
- Validator submission logs (hashes and metadata, section 2) are deleted automatically after 12 months.
- Account data is kept while your account is open. When you ask us to delete it, we delete or anonymize it, except what the law requires us to keep.
11. Your rights
Under the GDPR (if you are in the European Economic Area, the United Kingdom or Switzerland) and the LGPD (Brazil), you may:
- confirm that we process your data, and access it;
- correct it, or have it erased, anonymized or blocked;
- restrict processing, or object to processing based on legitimate interest;
- receive your data in a portable format;
- know with whom it is shared;
- withdraw consent at any time, without affecting what was done before — use "cookie settings" in the footer for analytics;
- complain to your data protection authority (in Brazil, the ANPD; in the EU, the authority of your country).
To exercise a right, write to support@rubricary.com from the email on your account. You can edit or remove your profile details yourself from Settings. Because the anonymous validator stores no prompt text and no IP address, we cannot look up data you submitted without signing in.
12. Prompts and catalog content
A prompt you publish as public — its content, metadata, versions, and star and fork counts — is visible to anyone using the catalog, the API, the CLI, or the MCP server, and is not covered by the rights above once others have copied it under its license. A prompt you mark private is visible only to you and, where applicable, the members of your organization. Do not put personal data in a public prompt.
13. Children
Rubricary is not directed to children under 16, and we do not knowingly collect their data. If you believe a child has given us data, write to us and we will delete it.
14. Security
Traffic is encrypted over HTTPS, there are no passwords to leak, and we keep hashes instead of prompt text and IP addresses where we can. No system is perfectly secure.
15. Changes to this policy
Rubricary may update this policy as the product changes. Material changes — especially anything that adds analytics or a new place data is sent — will be reflected by a new "last updated" date above, and we will ask for consent again where the law requires it.
16. Contact
Questions about this policy, or a request to exercise your rights or delete your data: support@rubricary.com.