Privacy Policy
This policy covers the RUŌOD Lab Android application and this website at ruood.com/lab. It describes what the application stores, where it stores it, and every occasion on which anything leaves your device.
1. Summary
RUŌOD Lab is an offline-first application. Your materials, formulas, notes and settings are stored on your own device. There is no RUŌOD account, no RUŌOD server holding your library, and no background synchronisation.
The application contacts exactly three things, and two of them only if you ask it to:
- Google — only once you connect Google Drive for backup, and only from then on;
- Google Play — for subscription status, through the Play Billing service already on your device;
- A public announcements file hosted on GitHub Pages, which the app reads to show in-app notices. This is the one request that happens without you asking.
There is no analytics, no crash reporting, no advertising and no tracking of any kind in the application or on this website.
2. Who we are
RUŌOD Lab is developed and published by RUŌOD. For anything in this policy, write to info@ruood.com or developers@ruood.com.
3. Data stored on your device
Everything you create in RUŌOD Lab is written to the application's own private storage on your device, using your device's app storage and — for Google sign-in tokens only — the Android secure keystore. RUŌOD does not receive any of it.
| What | Where it is kept |
|---|---|
| Materials, material collections and their pictures | App storage; pictures as image files in the app's own directory |
| Formulas, formula entries and formula collections | App storage |
| Notes and note collections | App storage |
| Suppliers, fragrance families, Formula Hub calculations | App storage |
| Field, layout, display, search and status-bar settings | App storage |
| Undo / redo history | App storage; deliberately never included in a backup |
| Announcement state — which notices you have read, and a cache marker | App storage |
| Drive backup metadata — the time of the last backup and your chosen schedule | App storage |
| Google sign-in tokens, and the email address and name of the connected account | The device's secure storage (Android keystore), never ordinary app storage |
All of this is removed when you uninstall the application, and can be removed without uninstalling by using Factory Reset in Tools → Data Management. See Retention and deletion.
4. What RUŌOD does not receive
We want to be precise rather than reassuring, so this section is about the application's behaviour rather than about a promise.
RUŌOD operates no server that the application talks to. There is no endpoint belonging to us for your data to be sent to. As a consequence, none of the following reaches us: your materials, your formulas, your notes, your settings, your backups, your device identifiers, your location, your contacts, your Google account details, or any record of how you use the app.
The application contains no analytics SDK, no crash-reporting SDK, no advertising SDK and no tracking library. It does not build a user profile, and there is no user identity in it to build one against.
5. Every request the app makes
These are all of them. No other network destination appears anywhere in the application.
| Destination | When | What is sent |
|---|---|---|
| Google's OAuth service | When you tap Connect on Google Drive backup, and when an expired access token is renewed | The standard OAuth exchange. No data from your library. |
| Google's user-info endpoint | Immediately after you connect | Your access token, to read back the email address and name of the account you chose, which are shown in the Backup section so you can see which account is connected. |
| Google Drive API | When a backup is written, listed, restored or deleted | Your access token and, for an upload, the backup file itself. |
| A public announcements file on GitHub Pages | Once per app launch, and at most once every six hours otherwise | An ordinary HTTP request for a public file. No account, no identifier and no data from your library is included — see section 9. |
| Google Play Billing | When the subscription screen is opened | Handled by the Google Play app already on your device — see section 8. |
Until you connect Google Drive, the only request the application makes is the announcements file. Nothing about your library is ever part of any request except a backup you initiated.
6. Google Account sign-in
Signing in with Google is optional and exists for one purpose: backing your library up to your own Google Drive. The application works fully without it, and it does nothing until you tap Connect in Settings → Backup.
What is requested
Sign-in uses Google's standard OAuth 2.0 flow with PKCE, requesting these scopes:
| Scope | What it allows |
|---|---|
openid, profile, email |
Identifying the account you chose. The application reads back the email address and display name of that account and shows them in the Backup section, so you can confirm which account your backups are going to. |
drive.file |
Access to only the files and folders this application creates in your Drive. This is Google's most restricted Drive scope. It does not grant access to your existing Drive contents: the application cannot see, read or list any file it did not create itself. |
Tokens
The access token, the refresh token, the token expiry, and the connected
account's email address and name are stored in your device's
secure storage (the Android keystore), never in ordinary
app storage. They stay on your device. They are not included in a backup and
are not sent anywhere except to Google, as the Authorization
header of a request to Google.
A refresh token is requested so the connection survives beyond the roughly one-hour life of an access token — without it, a scheduled backup could not run on a device left alone overnight.
Disconnecting
Disconnect in Settings → Backup deletes every stored token and the stored account details from your device. You can also revoke the application's access entirely from your Google Account, at myaccount.google.com/permissions. Backup files already in your Drive belong to you and are not removed by either action — delete them from Drive, or from within the app before disconnecting.
7. Google Drive backup
When it happens
A backup is written when you start one, or on the schedule you choose — Manual, Daily, Weekly or Monthly. Because the application runs no background service, a scheduled backup is checked for and performed when you next open the app and one is due. Nothing is uploaded while the application is closed, and nothing is uploaded at all unless you have connected an account.
What a backup contains
A complete snapshot of your application data as it currently stands: materials and their pictures, material collections, formulas and formula entries, formula collections, notes and note collections, suppliers, fragrance families, Formula Hub calculations, and your settings. Records are carried whole.
Two things are deliberately excluded: your Google sign-in tokens and any other secure-storage item, and your undo/redo history.
Where it goes
Into your own Google Drive, in a folder the application
creates called RUOOD Lab / Backups, under the Google account you
connected. RUŌOD does not hold a copy, does not receive a notification, and
has no access to your Drive. Once the file is in your Drive it is governed by
your agreement with Google and by
Google's Privacy Policy;
you control it there as you control any other file you own.
Restoring
Restoring a backup replaces your current application data rather than merging with it. The application asks for confirmation and states what is about to be replaced before it does anything.
RUŌOD Lab does not synchronise. It writes a backup file when asked. It does not continuously mirror your library, and it does not keep your data on any RUŌOD infrastructure — there is none.
8. Google Play Billing and subscriptions
RUŌOD Lab offers a subscription, RUŌOD Lab Premium, sold exclusively through Google Play Billing. There is no other payment path in the application — no card form, no web checkout, and no third-party payment processor.
At the time of writing, no feature of the application is placed behind the subscription. Every screen behaves the same whether or not you subscribe.
What the application sees
Purchases are handled entirely by the Google Play app already on your device. RUŌOD Lab receives from Play only the purchase records for this application — the product, its state, and the token Play uses to identify the purchase — and the localized price Play displays. From those records the application works out, on the device, whether a subscription is currently active.
The application never receives your payment card number, your bank details, your billing address or your Google Play account credentials. Those are Google's to handle, under Google's Privacy Policy.
Your subscription status is not stored anywhere by the application — not in app storage, not in secure storage, and not in a backup. It is derived from Play's records each time it is needed, and it is not sent to RUŌOD, because there is nowhere to send it.
Managing or cancelling a subscription is done in Google Play's own subscription settings.
9. In-app announcements
RUŌOD Lab can show notices — a new release, something you should know about.
To find out whether there are any, it reads a single public file
published at
adil-asad.github.io/ruood-announcements, hosted on GitHub Pages.
This is the only request the application makes that you did not start, so:
- It is made once per app launch, and otherwise at most once every six hours.
- It is a plain request for a public file. It carries no account, no device identifier, and nothing from your library — no materials, no formulas, no notes, no settings.
- The request is conditional, so a file that has not changed returns nothing at all.
- Which notices you have read is recorded on your device and is never reported back.
As with any request to any web server, GitHub receives the technical information a web request necessarily contains, including your device's IP address, and handles it under GitHub's privacy statement. We do not receive that information, and the file is served identically to everyone who asks for it — there is no per-user targeting and no response that could identify you.
10. Files you import and export
Exports are generated on your device and written where you choose — the location you pick in your device's file picker, or the destination you select from the share sheet. Imports are read from the file you pick. Neither passes through RUŌOD, and no copy is kept by the application.
Once an exported file leaves the application — sent, shared, or saved to a cloud folder — it is outside the application's control and subject to whatever service you sent it to.
11. Device permissions
| Permission | Why |
|---|---|
| Internet | Google Drive backup, Google sign-in, Play Billing and the announcements file. Everything else works offline. |
| Photos / media | Requested only when you choose a picture for a material, and only so the picker can read the image you selected. The application does not browse or index your photo library. |
| Storage | Saving an export to a location you choose, and reading a file you choose to import. |
| Billing | Required by Google Play in order to offer a subscription. |
| Vibration | Brief haptic feedback on interface controls. |
12. This website
This site — every page under ruood.com/lab — is
static HTML, CSS and a small amount of JavaScript. It was
built to collect nothing:
- No cookies are set, by us or by anyone else.
- No analytics, no tracking pixels, no session recording and no advertising.
- No third-party requests. There are no external fonts, no CDN-hosted scripts, no embedded videos, no maps and no social widgets. Every file the page loads comes from this domain.
- No forms and no accounts. The contact page offers email addresses as links; there is nothing here that submits data anywhere.
- The JavaScript is used only for the mobile navigation menu, and stores nothing in your browser — no cookies, no local storage.
As with any website, the hosting provider that serves these pages processes the technical information every web request contains, such as your IP address and browser user-agent, in the course of delivering the page and keeping the server secure.
The only links that leave this site are the ones you can see: the email links, the link to ruood.com, and the links to Google's and GitHub's own policies in this document.
13. Cookies and tracking
This website sets no cookies and uses no tracking technologies of any kind. There is accordingly no cookie banner, no consent choice to record, and nothing to opt out of. The application likewise contains no advertising identifier and no tracking SDK.
14. Third-party services
The complete list. Two of these are reached only if you choose to use the feature that needs them.
| Service | Used for | Optional? |
|---|---|---|
| Google (Sign-In and Drive) | Backing up to, and restoring from, your own Google Drive | Yes — only if you connect an account |
| Google Play (Billing) | Offering and verifying the subscription | Yes — only if you open the subscription screen or subscribe |
| GitHub Pages | Hosting the public announcements file the app reads | No — but it carries nothing about you or your library |
There is no other third party. In particular the application uses no analytics provider, no crash-reporting provider, no advertising network, no payment processor other than Google Play, and no RUŌOD backend.
15. Security
Your library is kept in the application's own private storage, which Android isolates from other applications on the device. Google sign-in tokens are held in the Android keystore rather than in ordinary app storage. All network requests the application makes use HTTPS.
Two things it is only fair to be plain about. The application does not separately encrypt your library with a password of its own: it relies on your device's own protection, so a device lock and Android's own device encryption are what protect it, and anyone with access to an unlocked device has access to the app. And a backup file placed in your Google Drive is protected by your Google account and by Google's own security, not by anything RUŌOD does to the file.
No method of electronic storage or transmission is completely secure, and we cannot guarantee absolute security.
16. Retention and deletion
RUŌOD holds nothing, so there is nothing for us to retain or delete. Your data is kept on your device for exactly as long as you keep it there.
- Individual records — delete them in the app.
- Everything in the app — Tools → Data Management → Factory Reset returns the application to an empty state: every material, formula, note, collection, supplier, family and calculation is removed, stored pictures are deleted, the undo history is cleared and every setting returns to its default. Google sign-in is deliberately left alone by a reset, so disconnect separately if that is what you want.
- Everything, including tokens — uninstalling the application removes its storage, including the secure-storage items.
- Drive backups — delete them from within the app's backup list, or from Google Drive directly. They are your files and remain in your Drive until you remove them.
- Google's access — Disconnect in the app, and/or revoke at myaccount.google.com/permissions.
- Subscription — cancel in Google Play. Play retains purchase records under its own policy; we have no copy.
17. Your controls
Because your data stays on your device, you exercise control over it directly rather than by asking us:
- Access — everything is visible in the application.
- Portability — export your library as PDF, CSV, Excel or JSON at any time, or write a complete backup file.
- Correction — edit any record in the application.
- Erasure — as described in section 16.
- Withdrawing consent — disconnect Google Drive at any time; the application continues to work.
If you believe RUŌOD holds personal information about you — for example because you have emailed us — you can ask us about it at info@ruood.com, and we will respond. We use the address you write from only to reply to you.
18. Children
RUŌOD Lab is a professional formulation tool intended for adults and is not directed at children. It has no account system, no social features and no user-generated content that is shared with anyone, and it does not knowingly collect information from anyone — including children — because it collects no personal information at all.
Perfumery involves materials that require adult handling and judgement. If you believe a child has used the application in a way you are concerned about, contact us at info@ruood.com.
19. International use
RUŌOD Lab keeps your data on your own device, wherever in the world that is, and there is no transfer of it to RUŌOD in any country. If you choose to use Google Drive backup, your backup file is stored on Google's infrastructure, which may be located in countries other than your own; that processing is governed by your agreement with Google and by Google's Privacy Policy.
20. Changes to this policy
If the application's behaviour changes — a new feature that contacts a service, or a new kind of data it handles — this policy will be updated before or alongside that release, and the date at the top of the page will change with it. Material changes will be described in the application's own announcements.
21. Contact
Questions about this policy, about what the application does, or about your data:
- General — info@ruood.com
- Technical — developers@ruood.com
See also the contact page.