RUMI

Privacy Policy

Last updated: 6 September 2026

Rumi redesigns a room from a photograph of it. That means we handle photographs of the inside of your home, so this page sets out plainly what we collect, where it goes, and how to get rid of it. It is written to be read, not to be impenetrable.

What we collect

  • Your email address, so you can sign in and we can send you a confirmation link.
  • Room photos you upload — the pictures of your own space that you want redesigned.
  • Inspiration images you upload, if you choose your own reference instead of one of ours.
  • The redesigns Rumi generates from those photos, plus the room name, room type and style you picked.
  • Basic usage data — how many renders you have used against your allowance, and standard server logs kept by our hosting provider.

We do not ask for your name unless you choose to add one, and we never ask for payment details, your address or your phone number.

Why we collect it

To provide the service and nothing else. Your email identifies your account. Your photos are the input to the redesign. The results are stored so you can come back and look at them later, rather than losing them when you close the app. The usage count exists to stop any one account running up an unlimited bill against our image provider.

We do not sell your data, we do not advertise to you, and we do not use your photos to train any AI model of our own.

Who else sees your data

Rumi is a small app built on three services. Each one is named here because each one genuinely holds some of your data.

Supabase — accounts, database and file storage

Your email address, your password (stored hashed, never in a form we can read), your room records and every image you upload live in a Supabase project. Supabase is the database and storage provider; they hold the data on our behalf.

fal.ai — the AI that makes the redesign

Your uploaded room photo is transmitted to fal.ai in order to generate the redesign. There is no way to produce a redesign without sending them the picture. If you supply your own inspiration image, that is sent as well, as a second reference. In practice we hand fal.ai a temporary, expiring web link to the image rather than a permanent copy, and that link stops working after ten minutes — but the plain fact is that your photograph leaves our systems and reaches theirs. The finished redesign comes back from fal.ai and is saved to your account.

fal.ai processes the image under their own terms. We do not control how long they retain what they receive.

Vercel — hosting

The Rumi website and its server run on Vercel. Like any web host, Vercel processes the network requests your device makes and keeps standard operational logs, which include IP addresses.

How your images are stored

Every image — your original photo, your inspiration image and the generated redesign — goes into a private storage bucket. Private means there is no public web address for your photos. They cannot be found by guessing a URL, and they are not indexed by search engines.

When the app needs to show you one of your images, it asks the server for a short-lived signed link that works for one hour and then stops working. The link handed to fal.ai during a render is shorter still, at ten minutes. Database rules enforce that you can only ever reach files stored under your own account, checked by the database itself rather than by the app.

Rights in the images

You own the redesigns Rumi generates for you. We claim no rights over them and you may use them personally or commercially.

You own the photos you upload. You give us permission to process them for one purpose only: producing your redesign. That processing includes sending the photo to fal.ai, as described above.

You must own or have rights to any image you upload as inspiration. If you supply your own reference picture instead of one of ours, it must be yours or you must have permission to use it. Do not upload copyrighted images you have no rights to.

Full detail is in the Terms of Service.

How long we keep it

Your rooms and images are kept until you delete them. Deleting a room removes its record and every image belonging to it — the original, the redesign and any inspiration image. Deleting your account removes everything.

Server logs held by our hosting and database providers are retained on their own schedules, which we do not control.

Your rights

You can, at any time:

  • See what we hold — every room and image is visible in the app under My Rooms.
  • Correct it — rename a room, or change your name and password in Settings.
  • Delete it — remove any individual room, or your whole account.

Account deletion is available in the app, in Settings → Account → Delete account. It removes your database rows, your stored images and your authentication record. It is immediate and cannot be undone.

If you would rather we did it for you, or you want a copy of your data, email us at the address below.

Children

Rumi is not intended for anyone under 13, and we do not knowingly collect data from children under 13. If you believe a child has created an account, contact us and we will delete it.

Changes to this policy

If this policy changes in a way that affects what we do with your data, we will update the date at the top and, where the change is significant, tell you in the app.

Contact

Questions, requests or complaints: Rumi.ai.app@gmail.com

Governing law

Rumi is operated from the United Arab Emirates, and this policy is governed by the laws of the United Arab Emirates.