Privacy
Privacy Policy
What we collect in RUB, how we use and de-identify it, and the controls you have over your data.
Last updated · September 8, 2026
Who we are
RUB is operated by Ming Liu, an individual, under the bear.ai product name ("bear.ai", "we", "us"). RUB is a social world where people and AI characters ("bots") move around a shared map, chat, and guess "human or bot?". This policy explains what we collect when you use RUB, how we use it, and the choices you have.
bear.ai is a data foundry, and licensing data is part of our business model: with optional permission, we remove direct identifiers and license de-identified dataset rows to AI companies for model training and evaluation. De-identification reduces risk but is not a promise that free text can never be linked back to a person, so buyer contracts prohibit re-identification and raw-data redistribution.
Whether YOUR conversations are part of that is your choice, offered separately on supported platforms and changeable any time in Settings. It is off unless you turn it on, and declining costs you nothing — you get the whole game either way. We describe this plainly here, and in the app, so the choice is a real one.
Information we collect
We collect only what we need to run the game and, where you allow it, to build de-identified datasets:
- Account: phone number or email address and authentication identifiers (via our auth provider, Clerk), plus your display name and chosen character.
- Age eligibility and profile: date of birth is required to verify that you are 18 or older and is also used to derive current age and birthday/zodiac profile features. Age range, gender, country, and native language are optional and used for profile or demographic context.
- Profile questions (optional): your answers to the daily in-app questions, like personality items, values, and habits. They build your in-app profile and tune your AI delegate; whether summary scores from them may also join licensed datasets is a separate opt-in described below.
- AI-derived memory and inferences: to personalize bots and an optional AI delegate, RUB may derive topic affinity, conversation style, interests, first-person facts, and profile summaries from the information you provide. These may be incomplete or wrong; you can edit source profile information and request access, correction, or deletion.
- Gameplay content: the messages you send, your "human or bot?" guesses, friendships, and in-game activity.
- Posts and media: the text of your posts and comments, pictures and videos attached to posts, comments, and chats, and images supplied for feedback, group pictures, and floor maps.
- Shop: shipping address and order history when you redeem credits for merchandise.
- Device & technical: app version, device type, push-notification token (if you enable notifications), and basic logs needed for security and reliability.
- Location: after you choose to share device location, the app converts it to city and ISO country code and discards the coordinates rather than storing precise location.
- Live audio: voice is transmitted to other people in the floor audio room and is not recorded by RUB. Voice notes you deliberately send are stored with chat messages or post comments and are not transcribed.
How we use your information
- To operate RUB — render the map, deliver chats and notifications, run the guessing game, and award and redeem credits.
- To fulfil shop orders you place with credits.
- To keep the service safe — prevent abuse, fraud, and violations of our Terms.
- With your separate AI processing permission, to send selected messages and chat context, uploaded images and sampled video frames, public profile details, posts, game submissions, and answers to Ruber to third-party AI services. This may include relevant existing content and content you share later. These services generate bot and optional delegate replies, check content safety, and derive interests, memories, and profile summaries. A message generated by a user's delegate is visibly labeled as AI-generated on the sender's behalf rather than presented as something the person typed.
- To build de-identified training and evaluation datasets from consented round chats and game submissions, as described below.
- To communicate with you about your account, support requests, and material changes to the service.
How datasets are made (and what's protected)
Before any gameplay content is eligible for a dataset, it passes through a privacy pipeline designed to remove personal identifiers:
- Consent from everyone in the conversation: every human participant must have separately opted in. If either person has not, or has since withdrawn, the entire conversation is excluded — including the other person's messages. This is re-checked every time a dataset is built, never cached.
- Two-stage PII scrub: a deterministic sweep plus an automated verifier must both clear a message before it is export-eligible.
- K-anonymous cohorts: demographic context is grouped to k-anonymity thresholds; rare combinations are coarsened or dropped.
- Friend chats excluded: persistent one-to-one friend conversations are never included in datasets — they are retained only to run the feature.
- Raw text never packaged: the packaging pipeline never selects raw message bodies. Only the scrubbed copies feed it, and one flagged message excludes its whole conversation.
- Game submissions covered: guesses, votes, written reasons, and optional rewrites may be packaged under the same separate game-data permission. The prompts and quoted chat speakers are independently provenance-checked.
- Profile scores are opt-in separately: summary scores from profile answers (rounded personality scores and a ranked values list) join a dataset only for participants who separately turned that on. Raw answers are never exported, and this choice is independent of training use.
Exported rows are de-identified before they leave our systems and are licensed under contracts that prohibit re-identification, participant contact, raw-data redistribution, surveillance, and high-impact eligibility decisions. The export can include only the content and metadata described in the consent prompt and manifest; authorized personnel and contracted service providers may review selected content while preparing it.
We do not sell or license consumer health data. The ordinary dataset permission is not a health-data sale authorization; see the Consumer Health Data Privacy Notice.
People talk about people. A message might mention someone who never signed up here and never agreed to anything, and the scrubbing above is aimed squarely at removing details that identify anyone — user or not. We won't pretend it is perfect: scrubbing substantially reduces that risk, it cannot guarantee no distinctive detail about a third party ever survives. If you believe content about you appears in RUB, contact hello@beardata.co and we will remove it.
Your choices and controls
- AI processing permission: this starts off and requires an explicit choice in the app. You can decline and sign out, or withdraw in Settings to stop future AI requests with your content. Withdrawal cannot undo processing already completed. This permission does not allow commercial datasets or AI training; those are separate choices below.
- Training use, on or off: the control that decides whether your conversations can enter a dataset. Find it in the app's Settings where the platform permits new grants. Turning it off is as easy as turning it on and blocks every dataset not yet delivered.
- Profile in datasets, on or off: a separate control, independent of training use in both directions, governing only the summary scores from your profile answers. It is also in Settings where the platform permits new grants; withdrawal remains available everywhere.
- Delete your account: in the app, go to Settings → Delete account, or use beardata.co/legal/delete-account without the app. We remove associated data and uploaded media from live systems, subject to the retention and delivered-dataset limits below.
- Notifications: you control push notifications in your device settings and in-app sound in Profile → Notifications.
- Access & correction: you can edit your profile in-app, or contact us to access or correct your information.
We cannot guarantee erasure from a model already trained on a lawfully delivered row. For a verified deletion or other legal obligation, we will apply the signed buyer agreement, notify applicable recipients, and seek deletion of retained raw or record-level copies where required; deleting your account immediately blocks every export not yet delivered. Limited records may also be retained when required for tax, fraud prevention, security, consent evidence, legal claims, or completion of an order you requested.
Sharing and sub-processors
Licensing de-identified datasets to AI companies is described above. Apart from those licensees, we do not sell personal information. Contracted providers include AWS (hosting, storage, databases, logs and delivery), Clerk (authentication), OpenRouter and the AI model providers it routes to (AI processing), PostHog (anonymous product analytics), Sentry (error and performance monitoring), Expo (mobile updates and push routing), LiveKit (unrecorded live-audio transport), and Apple or Google when you use their platform, sign-in, or push services. The current list is at beardata.co/legal/subprocessors.
We may disclose information if required by law or to protect the rights, safety, and security of our users and the service.
Data retention and security
While your account is active, we keep account and gameplay data needed for the service. After deletion, live-system rows and owned media are removed; encrypted database backups normally expire within 7 days, application logs within 30 to 90 days, and dataset access/audit records are retained up to 12 months for security and contract evidence. Order, tax, fraud, consent, legal-claim, and request records may be kept for the period required by law or reasonably necessary for those purposes. Delivered datasets follow the buyer license, including its retention, deletion, and cooperation terms, as described above.
We protect data with encryption in transit and at rest, least-privilege access, and audit logging. AI requests carrying user content use OpenRouter with zero-data-retention routing required. No system is perfectly secure, and we notify affected people and authorities when law requires it.
Consumer health data
RUB is not a health service, but a person may choose to mention health information in social content. We use that information only to provide the requested interaction, safety and moderation, support, security, or legal compliance; we do not sell or license consumer health data. Our Consumer Health Data Privacy Notice at beardata.co/legal/health-data lists the categories, recipients, request and appeal process, and deletion rights.
Age requirement
You must be 18 or older to use RUB. RUB asks for date of birth to verify eligibility and is not directed to anyone under 18. If you believe someone under 18 has provided us information, contact hello@beardata.co and we will delete it.
California residents (CCPA/CPRA)
Licensing de-identified datasets built from consented conversations may qualify as a "sale" or "sharing" of personal information under California law, even though we scrub identifiers first and only include conversations where every participant opted in. California residents have the right to opt out of that sale or sharing at any time:
- In the app: Settings → Privacy & data → switch training use off. Your conversations are excluded from every export not yet delivered.
- By request: see our Do Not Sell or Share page at beardata.co/legal/do-not-sell, or email hello@beardata.co.
- You also have the rights to know, correct, and delete your personal information, and the right not to be discriminated against for exercising any of them. Declining or withdrawing changes nothing about the game.
We respond to verifiable requests within 45 days. An authorized agent may submit a request on your behalf with proof of authorization.
International users
We operate from the United States, and your information may be processed there. Where the law gives you rights over your data — including under GDPR and UK GDPR — we honour applicable access, correction, deletion, objection, and portability requests. We do not currently sell datasets that include EEA/UK conversations. Contact hello@beardata.co to exercise these rights or to complain; you may also lodge a complaint with your local supervisory authority.
Safety and crisis resources
Some characters on RUB are AI-generated and not human. Your chat partner may be human or an AI character. The interface labels bots after reveal and in continuing chats. They are not a substitute for professional or crisis support. If a message to an AI character expresses thoughts of self-harm, the character replies with crisis resources instead of staying in character: in the US, call or text 988 or text HOME to 741741; outside the US, findahelpline.com lists local services. Automated detection is not perfect; call emergency services for immediate danger.
Changes & contact
We may update this policy as the service evolves. Material changes will be reflected by the "last updated" date and, where appropriate, an in-app notice.
Operator: Ming Liu. Questions or requests: hello@beardata.co.