Effective: August 20, 2026
Last updated: August 20, 2026
Version: 1.0
This Privacy Policy explains what happens to information when you use Ruse, a mobile application for iOS and Android published by Liontude, LLC (“Liontude”, “we”, “our”, “us”), a limited liability company registered in Florida, United States.
Liontude, LLC is the data controller for the processing described here.
This policy covers the Ruse app on both the Apple App Store and Google Play. Where the two platforms behave differently, we say so. It does not cover the liontude.com website, which has its own policy.
Where Ruse is available. Ruse is not currently offered to users located in the European Economic Area, the United Kingdom or Switzerland, and is not distributed through the app stores in those territories. We nonetheless apply the European standard — lawful basis, consent for analytics, and full access, correction and deletion rights — to every user of Ruse, everywhere. If we make Ruse available in those territories in future, we will appoint the representative required by Article 27 GDPR and name them in this policy before doing so.
We wrote this to be read, not skimmed. If anything is unclear, email info@tryruse.com.
1. The short version
- We do not know who you are. Ruse has no sign-up, no email, no password, no username. The app creates an anonymous identifier so your purchase and usage limits can follow you. We cannot connect it to your name.
- Most of your data never leaves your phone. Personas, photos, context text, recordings and your call history are stored locally on your device.
- We do not request location access on either platform. Our analytics and error-reporting providers derive an approximate location (country, region) from your IP address — see §4.6.
- We show no ads. There are no advertising SDKs, we do not collect an advertising identifier, and we do not track you across other companies’ apps or websites.
- We do use analytics and crash reporting to understand which features are used and to fix crashes. You choose whether they run, and you can change your mind at any time. See §4.6.
- What else leaves your phone: a push token so a scheduled call can ring, scheduling data, and — only when you use an AI feature — the text you wrote and the audio of the conversation.
- We do not sell or share your personal information.
- You can delete everything. In-app, or at https://tryruse.com/delete-data without installing the app. See §11.
This summary does not replace the rest of the document.
2. Why this data is sensitive
Ruse produces an unusual kind of record. The fact that you needed an excuse to leave a date on a Tuesday at 9:40pm — and the sentence you wrote to explain the situation to an AI — is more revealing than it looks, even with no name attached.
We designed the app to keep that on your device wherever possible. Where it cannot stay on your device, this policy says so and names who receives it.
One consequence you control: the context you type for an AI conversation is free text. If you write details about a specific person, your health, your relationships or your whereabouts, that text is transmitted and processed as described in §6. Write only what the call needs.
3. Information stored only on your device
The following is stored locally on your phone. None of it is transmitted to us, with one exception: if you use a live AI conversation, the persona’s name, the relationship and your context text are sent to us to build the AI instructions, as described in §6.1.
| What | Detail |
|---|---|
| Personas | Name, initial, colour, the photo you selected, optional fictional phone number |
| Exits | Mode, settings, and the free-text context you wrote |
| Audio clips | Clips you recorded, clips downloaded from our library, clips generated for you |
| Insistence patterns | Steps, timings, behaviours |
| Call history | Persona name, colour, label and date of calls you triggered |
| Preferences | Theme, AI language, trigger settings, cached subscription state |
There is no backup and no cloud sync. We do not copy this data to our servers, and on Android we disable the operating system’s automatic backup so that it is not copied to your Google Drive either. If you delete the app or lose your device, this data is permanently gone and we cannot recover it. That is a deliberate design choice.
Photos you choose are copied into the app’s private storage. Ruse does not browse your photo library beyond the image you pick, and does not access your contacts.
4. Information we receive
4.1 Anonymous identifier
On first launch the app creates an anonymous session through Firebase Authentication (Google), producing a random user ID (your “Ruse ID“). It is not linked to an email address, phone number, social account, Apple ID or Google account. We use it to attach your subscription and usage quotas to you.
You can view and copy your Ruse ID in Settings ▸ About. You will need it to make a data request (§12.4).
Because we hold no email address or phone number for you, we have no way to contact you — not about a change to this policy, not about a problem with your subscription, not about a security incident. Notices appear inside the app and on this page. See §10 and §14.
Reinstalling generates a new Ruse ID. Your subscription follows your store purchase receipt rather than the ID, so purchases survive a reinstall; usage counters are tied to the receipt as well, to prevent quota resets by reinstalling.
4.2 Push token and device registration
So a scheduled call can ring while your phone is locked, we register your device and store:
- A push token — on iOS, a VoIP push token issued by Apple; on Android, a registration token issued by Firebase Cloud Messaging. Either is an opaque string identifying this installation on this device. It is not a phone number and cannot be used to call you.
- An installation identifier generated by the app.
- Your Ruse ID.
Without this, scheduled calls only ring while the app is open.
4.3 Scheduling data
When you schedule a call or an insistence pattern we store the scheduled time, the ring behaviour and duration, a reference to the exit, your Ruse ID, and the resulting status.
For a scheduled call without live AI we do not receive the persona’s name, photo or your context text — those stay on your device and are applied locally when the call fires.
4.4 Purchase and subscription data
Purchases are made through Apple or Google. We never receive your card details, billing address, Apple ID or Google account.
Through RevenueCat (our subscription infrastructure provider) and the stores, we receive: the product purchased, purchase and expiry dates, renewal, cancellation and refund events, the storefront country, and an anonymised transaction or receipt identifier.
4.5 Usage counters
To enforce plan allowances we count, against your Ruse ID and store receipt: AI scripts generated today, AI audio clips generated today, and in-editor conversation previews used today. These are counters, not content.
Live AI conversations are additionally limited by fixed maximum call and silence durations enforced on our side. If we introduce per-minute metering of a monthly conversation allowance, we will record the duration of each conversation against your identifier, and we will update this policy before doing so.
4.6 Analytics, crash and error reporting
We use two providers to understand how the app is used and to find and fix defects:
| Provider | Purpose | What it processes |
|---|---|---|
| Google Analytics for Firebase | Which features are used, retention, drop-off | A resettable app-instance identifier, screen and event names, session counts, app version, device model, OS version, language, and an approximate location (country/region) derived from IP address |
| Sentry | Crashes, errors and performance | Crash and error events, stack traces, breadcrumbs of the actions preceding a failure, device state at the time of the failure, app and OS version, device model, an installation identifier generated by Sentry, and technical request metadata including IP address |
What these do not receive. We do not send them your persona names, your photos, your context text, your recordings, your call history, or the content of AI conversations. We do not set a user identifier tied to your real identity. Event names record that a feature was used, not what you wrote in it.
We do not collect an advertising identifier (Apple’s IDFA or Android’s Advertising ID) on either platform, we do not use these tools for advertising, and we have disabled data sharing between Google Analytics for Firebase and Google’s advertising products. Because Ruse does not track you across other companies’ apps or websites, the iOS app does not present an App Tracking Transparency prompt.
Your choice.
- Analytics, crash and error reporting are off until you agree. The app asks once, on first launch, and no analytics or diagnostic data is collected before you answer. The anonymous session described in §4.1 is still created at launch, because the app cannot reach our servers without it.
- You can change your answer at any time in Settings ▸ Privacy.
- Turning them off stops future collection. It does not delete what was already collected — for that, see §11.
Turning analytics off does not restrict any feature of the app.
4.7 Technical logs
We do not deliberately log personal data on our servers. However, our web framework and our hosting provider record standard request logs by default, which include IP address, timestamp, endpoint, response status and general device and app-version information. We use these for security, abuse prevention and debugging only, and not to build a profile of you.
4.8 What we do NOT collect
Name · email address · phone number · postal address · payment card details · device location from a location permission · contacts · calendar · SMS or call logs · health data · advertising identifier · biometric identifiers or voiceprints · browsing history · data from other apps on your device.
5. Device permissions
Ruse asks for the minimum it needs. Most are optional and the app still works without them, with reduced function. The exceptions are marked below.
5.1 iOS
| Permission | Why | Optional? |
|---|---|---|
| Microphone | To record a clip in your voice, and to carry your side of a live AI conversation | Yes — the app then uses library audio or silence |
| Photos | To attach a photo to a persona; only the image you select is read | Yes |
| Notifications / VoIP push | To make a scheduled call ring when the app is closed | Yes — scheduling then works only in the foreground |
| Siri & Shortcuts | To trigger an exit by voice, Back Tap or Shortcuts | Yes |
5.2 Android
| Permission | Why | Optional? |
|---|---|---|
| Microphone | Same as iOS | Yes |
| Photos and media | To attach a photo to a persona | Yes |
| Notifications | To deliver scheduled calls and app alerts | Yes — scheduling then works only in the foreground |
| Full-screen notifications | To show the incoming-call screen over the lock screen, the way a calling app does | Required for a scheduled call to appear as a call |
| Foreground service (microphone) | To keep a live AI conversation running while the call screen is showing | Active only during a call |
| Exact alarms | To fire a scheduled call at the minute you chose when your device cannot be reached by push | Required for reliable scheduling |
| Vibrate, wake lock, run at startup | To vibrate before ringing, wake the screen for a call, and restore scheduled calls after a reboot | No |
Ruse does not request access to your phone state, call log or contacts on Android, and never places a real call.
You can change any permission in your system settings at any time. Microphone audio is captured only while you are actively recording a clip or while a live AI conversation is running — never in the background. Both platforms show their own microphone indicator whenever the microphone is in use.
6. AI features — read this section
This is the only part of Ruse where the content of what you write or say leaves your device.
6.1 Live AI conversation
When you answer a call with live conversation enabled:
- The app requests a session from our server. Our server assembles the AI instructions, which include the persona’s name, the relationship, the situation you described in the context field, and the conversation language. Your context text is transmitted to us at this point.
- Those instructions are attached to a real-time audio room hosted by LiveKit Cloud (United States).
- Your microphone audio is streamed into that room and relayed to our AI agent, which forwards it to Google’s Gemini Live model and streams the generated voice back to you.
- When the call ends, the room is destroyed.
We do not record your calls. Our servers relay audio and do not store it. Our agent is not configured to save recordings or transcripts. Audio is encrypted in transit.
Our AI provider does receive your audio and your context text, because that is how a response is generated. We use the paid Gemini API, under which Google states that it does not use prompts or responses to train or improve its models, and applies no human review for training purposes. Google retains prompts and responses for a limited period for abuse monitoring, safety and legal compliance.
6.2 AI-generated scripts and audio clips
When you ask the app to write a script or generate a spoken clip, the text you supply, the chosen voice and the style are sent to our server and on to our AI provider for synthesis. The resulting audio is downloaded to your device.
We cache generated audio on our servers, keyed by the combination of voice, text and style, so that repeating the same phrase is not generated and charged twice. The cache stores the text and the resulting audio. It is not keyed to your Ruse ID, and a cached item may be reused for any user who submits identical input. Do not put personal details into a generated script if you do not want that text held in a shared cache.
6.3 What the AI is
Voices are synthetic and come from a prebuilt library. They do not replicate any specific real person. Ruse does not offer voice cloning and does not create a voiceprint from your recordings. Your recorded clips are never used to build or train any voice model.
6.4 Your recordings
Clips you record with your own voice stay on your device and are never uploaded.
7. Who else receives data
Apple and Google act as independent controllers for the app-store, payment and push data they collect from you under their own privacy policies. We do not control or direct that processing, and their policies apply to it. Every other provider below acts as a processor on our instructions, under a signed data processing agreement.
| Provider | Role | What it receives | Location |
|---|---|---|---|
| Apple Inc. | iOS distribution, in-app purchase, push delivery | Purchase and subscription events; VoIP push tokens and push payloads | United States / global |
| Google LLC (Google Play) | Android distribution, in-app purchase, push delivery | Purchase and subscription events; FCM registration tokens and push payloads | United States / global |
| Google (Firebase Authentication) | Anonymous session | Ruse ID, IP address, basic device and app-instance data | United States / global |
| Google (Firebase Analytics) | Product analytics | The data listed in §4.6 | United States / global |
| Google (Gemini API / Gemini Live) | AI conversation, script and speech generation | Conversation audio, AI instructions including your context text, script text | United States / global |
| Functional Software, Inc. (Sentry) | Crash, error and performance monitoring | The data listed in §4.6 | United States |
| LiveKit, Inc. (LiveKit Cloud) | Real-time audio transport and agent hosting | Call audio in transit, room metadata including the AI instructions, participant identifiers | United States |
| RevenueCat, Inc. | Subscription management | Ruse ID as app user ID, purchase and receipt data, subscription events | United States |
| DigitalOcean, LLC | Application hosting, managed database, audio storage and CDN | The server-side data described in §4; IP addresses of clients downloading library audio | United States |
We may also disclose information where legally required, to enforce our Terms, or to prevent serious harm — and to a successor entity in a merger or acquisition, on notice to you.
We do not sell your personal information, and we do not share it for cross-context behavioural advertising, as those terms are defined under US state privacy laws.
8. Legal bases for processing
We are not currently subject to the GDPR, because we do not offer Ruse in the EEA, the UK or Switzerland. We use its framework anyway, because it is the clearest way to say why we process anything. This is the basis for each purpose:
| Purpose | Legal basis |
|---|---|
| Delivering the app’s core functions, including ringing scheduled calls and delivering AI conversation | Performance of a contract (Art. 6(1)(b)) |
| Processing purchases and managing subscriptions | Performance of a contract (Art. 6(1)(b)) |
| Enforcing plan allowances and preventing abuse | Legitimate interests (Art. 6(1)(f)) — keeping the service viable and protecting it from misuse |
| Security and technical logs | Legitimate interests (Art. 6(1)(f)) — securing and maintaining the service |
| Analytics, crash and error reporting | Consent (Art. 6(1)(a)), given on first launch and withdrawable at any time in Settings ▸ Privacy |
| Microphone, photo and notification access | Consent (Art. 6(1)(a)), given through the system permission prompt and withdrawable in system settings |
| Complying with legal obligations | Legal obligation (Art. 6(1)(c)) |
Special category data. Ruse is not designed to process special category data. The free-text context field could contain it if you choose to write it — information about your health or your relationships, for example. Where that happens we rely on your explicit consent (Art. 9(2)(a)), given by choosing to type it and send it. You can avoid this entirely by keeping the context general.
9. International transfers
We are based in the United States and every provider listed in §7 processes data in the United States. If you use Ruse from outside the United States, your data is transferred to and processed there, under United States law.
Our data processing agreements with those providers include the European Commission’s Standard Contractual Clauses. They are not currently engaged, because we do not offer Ruse in the EEA, the UK or Switzerland, but they are in place and would govern those transfers if we did. You may request a copy by emailing info@tryruse.com.
10. Security
All connections between the app and our servers use TLS. Real-time audio is encrypted in transit. Data at rest on our infrastructure is encrypted. Paid endpoints require an authenticated session and a verified subscription. AI credentials are never present in the app and cannot be extracted from it; session tokens for audio rooms are short-lived and grant no other access.
Local data on your device is protected by the operating system’s file protection and by your device passcode.
No system is perfectly secure and we cannot guarantee absolute security. If we become aware of a breach affecting your personal information, we will notify you and the relevant authorities without unreasonable delay, within the timeframes required by the breach-notification law of your state.
How we would reach you. Because Ruse has no account, we hold no email address or phone number for you and cannot contact you individually. We would therefore give notice by the substitute means those laws permit where contact details are not held: a prominent notice inside the app, a notice posted at https://tryruse.com/privacy, and notification of the relevant state authorities.
11. Deleting your data, and how long we keep it
11.1 Delete it yourself
Most of Ruse’s data is not ours to delete. Your personas, exits, context text, recordings and call history live on your phone, so deleting the app is the deletion for nearly everything. What we hold on our servers is a short list: your device registration, any calls you have scheduled, your usage counters, and your subscription record.
- On your device: delete any persona, exit, clip or history entry inside the app. Deleting the app destroys all locally stored data permanently.
- Server-side, in the app: Settings ▸ Privacy ▸ Delete my data. This removes your device registration, your usage counters and your Ruse ID. It also cancels any call you have already scheduled — the app tells you how many before it proceeds.
- Server-side, without installing the app: https://tryruse.com/delete-data. Identify yourself with either your Ruse ID (Settings ▸ About, while you still have the app) or the order number on your App Store or Google Play receipt, which the store emailed you when you subscribed and which we can match to your records.
Your subscription record stays while a subscription is active. It is what proves you paid, and deleting it would revoke access you are entitled to. Cancel in the App Store or Google Play first if you want it gone; after that we keep only what tax and accounting law requires.
The one time we collect an email address. If you submit a request through the deletion page or by email, we hold the address you write to us from so that we can confirm the request and tell you when it is done. We use it for nothing else, never add it to a mailing list, never link it to your Ruse data, and delete it when the request is closed.
What we cannot delete: purchase records, for as long as tax and accounting law requires; entries in the shared generated-audio cache described in §6.2, which is keyed by the text and voice rather than by you, and cannot be traced back to a single person; and any data already anonymised or aggregated so that it can no longer be linked to you.
11.2 Retention periods
| Data | How long we keep it |
|---|---|
| Data on your device | Until you delete it, or until you delete the app |
| Push token and device registration | Until replaced, or 12 months after the last successful registration |
| Scheduled calls | Deleted 30 days after the call fires or is cancelled |
| Usage counters | Daily counters reset daily; underlying rows purged after 90 days |
| Generated-audio cache | 12 months from last access |
| Server request logs | 30 days |
| Analytics data | No longer than 14 months |
| Crash, error and performance events | No longer than 90 days |
| Subscription and purchase records | The life of the subscription plus the period required by tax and accounting law, typically 7 years |
| Call audio | Not retained by us |
12. Your rights
12.1 Everywhere
At any time, without contacting us, you can: delete data in the app or at the deletion page (§11.1); turn analytics and crash reporting off in Settings ▸ Privacy; revoke microphone, photo, notification or voice-assistant permissions in your system settings; delete the app; and cancel your subscription in the store.
12.2 Rights we give every user
Wherever you live, and regardless of whether the law in your country requires it, you may ask us to give you access to your data, to correct it, to delete it, to restrict how we process it, to give you a copy in a portable format, and to stop processing based on our legitimate interests. Where processing rests on your consent, you may withdraw it at any time, without affecting what was lawful before you withdrew.
We do not carry out automated decision-making that produces legal or similarly significant effects.
12.3 United States
Depending on your state of residence you may have the right to know what personal information we collect and why, to obtain a copy, to correct it, to delete it, to opt out of sale, sharing or targeted advertising, to limit the use of sensitive personal information, and not to be discriminated against for exercising any of these rights. Several states also give you the right to appeal a refused request; to appeal, reply to our decision email and we will respond within the statutory period.
We do not sell or share personal information, and we do not process it for targeted advertising or profiling. There is therefore nothing to opt out of. Universal opt-out signals such as Global Privacy Control are a web-browser mechanism and cannot currently be transmitted by a mobile app; if a recognised mobile equivalent is established, we will honour it.
Categories we collect, in the statutory language US state laws use. We collect the following, for the purposes described in §4, from you and from your device and app store. We disclose them only to the providers in §7, and we sell and share none of them.
| Statutory category | What that is, here |
|---|---|
| Identifiers | Your Ruse ID, installation and push identifiers, IP address |
| Commercial information | Which subscription you bought, and renewals, cancellations and refunds |
| Internet or other electronic network activity | Which screens and features you used — only if you agreed to analytics |
| Audio or similar information | Live AI conversation audio, relayed to our AI provider but not stored by us (§6.1) |
| Geolocation data | An approximate country or region derived from IP address only |
| Sensitive personal information | The content of your AI conversations and the context text you write may fall in this category. We use it only to deliver the feature you asked for, never to infer anything about you and never for advertising |
12.4 How to make a request
Email info@tryruse.com with the subject line Privacy Request, and include either your Ruse ID from Settings ▸ About or the order number from your store receipt. We respond within 30 days (45 days for US state requests, extendable where the law allows).
Please include one of those two identifiers. Because Ruse has no account, they are the only ways we can locate data relating to you. Without either, we may be unable to identify any records, and we will tell you so rather than guess. We will ask only for what we need to find your data, and we will not collect more personal information than that requires.
12.5 Authorised agents
You may use an authorised agent where the law permits. We may require proof of authorisation and verification directly from you.
13. Children
Ruse is not intended for anyone under 16 and our Terms require you to be 16 or older. We do not knowingly collect personal information from children. If you believe a minor has provided us with information, email info@tryruse.com and we will delete it.
14. Changes to this policy
We may update this policy. When we do we will change the “Last updated” date and post the new version at https://tryruse.com/privacy. If a change materially affects how we handle your information we will give you notice in the app before it takes effect, and obtain consent where the law requires it. The current version is always available inside the app and at that address.
15. Contact
Liontude, LLC
1319 N University Dr #118
Coral Springs, FL 33071
United States
Email: info@tryruse.com
Phone: +1 (954) 800-3932
Web: https://liontude.com
Ruse is a product of Liontude, LLC.