Privacy notice
Last updated: September 19, 2026.
This notice covers showcase.rullst.win, including its public demos, Studio and Nexus. The LMS, portfolio, SaaS and other linked services have separate data practices.
Who is responsible
Rullst is responsible for this showcase. For privacy questions or requests, email officialrullst@gmail.com with the subject “Privacy request”.
Data used by the showcase
- Visits and security: network information such as IP address, requested URL, browser headers, request time and security events may be processed by the application and hosting infrastructure to deliver pages, prevent abuse and investigate incidents.
- Public demo posts: the title and content you submit are stored in the showcase database and displayed publicly. Use fictional data. Anyone with access to the public sandbox administration tools can view or change demo posts.
- Chat: the message you send is processed to answer your question. The application does not intentionally save a chat transcript to its database. Messages remain visible in the current page until you leave or reload it; infrastructure or provider logging may have a separate retention period.
- Billing demos: the email, plan and provider you enter are processed to generate a simulated checkout result. Use the supplied fictional email. Following an external checkout link may disclose information included in that link to its destination.
- Privacy requests: your email and the information needed to locate your data are used to verify and respond to your request. Do not send passwords, identity documents or unrelated sensitive information.
Your choice about cloud AI
Cloud AI is off by default. The Showcase Copilot can answer locally. If you select “Use cloud AI”, your submitted message and general framework instructions may be sent to Groq or the AI endpoint configured by Rullst. Public post content is not included in that cloud prompt. Cloud processing only happens when you send a message with that option selected and a provider is available.
You can uncheck the option before your next message or reload the page to return to local mode. Withdrawing this choice stops future cloud submissions; it does not recall messages already sent. Contact us for questions about a previous submission, the currently configured provider, its retention or international processing. The Nexus schema assistant generates its responses locally in this version.
Purposes and legal grounds
We use technical data to operate and secure the showcase, relying on our legitimate interests in providing a working, abuse-resistant service where that legal basis applies. We use the content you submit to provide the demo you request. Optional cloud message processing is based on your affirmative choice. We may also process information to meet legal obligations or respond to privacy requests. Consent can be withdrawn without affecting the lawfulness of earlier processing.
Services, recipients and international processing
The public deployment uses Microsoft Azure hosting. Pages may retrieve technical resources such as scripts, styles, fonts and the logo from GitHub, Google Fonts, unpkg, jsDelivr and Tailwind's CDN; those services receive connection data when resources are loaded. Optional cloud AI adds the provider described above. Email requests are received through Gmail. These services may process data outside your country.
Contact Rullst for details of the providers and transfer safeguards applicable to your request. Social networks, Discord, other showcases and external checkout destinations receive data when you follow their links and are governed by their own notices.
The showcase application has no advertising trackers or analytics scripts and does not sell personal information or share it for cross-context behavioral advertising. It performs no automated decisions with legal or similarly significant effects about visitors. We do not use this showcase to intentionally collect children's personal information.
How long data stays
- Posts: the application keeps up to the latest 50 posts through automatic pruning. This is a quantity limit, not a time limit. Posts may remain until replaced by newer posts, deleted by an administrator, or the database is reset. Copies made by visitors are outside our control.
- Template cache: shared template HTML expires after 60 seconds. It excludes visitor messages and tenant-specific navigation.
- Browser storage: see Cookies & browser storage for session security cookies, temporary UI state and static offline assets.
- Operational records: hosting, security, email and optional AI providers have retention settings separate from the demo database. Contact Rullst for the applicable periods and deletion options. Container sleep or restart is not a guaranteed deletion mechanism.
Your privacy rights
Depending on your location and the law that applies, you may request confirmation of processing, access, correction, deletion, restriction, portability, information about recipients, withdrawal of consent, or object to certain processing. These rights may arise under Brazil's LGPD, the EU GDPR, UK GDPR, California's CCPA/CPRA or other applicable local laws. Their scope and exceptions differ.
Write to officialrullst@gmail.com. Identify the relevant page, approximate submission date and the data or right concerned. We may ask for proportionate information to verify your request. We will respond within the period required by the applicable law, explain any lawful limits, and will not discriminate against you for exercising privacy rights. Do not post privacy requests in public issues or community channels.
You may also complain to your competent privacy authority, including the ANPD, an EU supervisory authority, the UK ICO or the California Privacy Protection Agency, as applicable.
Changes
We will update this notice when the showcase's data practices change. New optional processing that requires consent must be offered as a separate choice before it starts.
