Skip to content

Policy

Privacy Policy

What we collect when you use Ramus, why, who helps us process it, and how to have it deleted.

Effective September 24, 2026 · Version privacy-2026-09-24

Who we are

Ramus (“we”, “us”) runs hosted Android devices for building, testing and reviewing apps. This policy covers ramus.dev, the dashboard, the devices we host, the ramus-cli tool, the API, the MCP server, the GitHub App and shared device links.

Questions and requests: privacy@ramus.dev.

What we collect

Your account. You sign in with GitHub, and we need this account data to provide the service. We receive and store your GitHub user ID, username, name, avatar URL and email address (your primary GitHub email when GitHub shares it, otherwise your GitHub no-reply address). We also store the GitHub sign-in tokens needed to keep you signed in.

Sign-in sessions. When you sign in, we store a session record with the IP address and browser user agent of that sign-in, and set a session cookie.

Apps you upload. We store the APK files you upload, including their file names, and record details read from each app: package name, version, signing certificate fingerprint and whether it is debug-signed. We use these to run your app and to enforce the Acceptable Use Policy.

Device sessions. For each device session we record who started it and how (browser, CLI, API or MCP), which app or build it ran, the region it ran in, when it started and ended, and why it ended. While a session runs we record which app is in the foreground, about once a minute. We do not record what you type or the web addresses a device visits, and we do not store video of device sessions.

GitHub repositories. If you install the GitHub App, we read the repositories you select to build pull request previews. We store repository and pull request details (names, titles, authors, branches and commit IDs), build logs and the built app. We clone your code into an isolated build machine and delete the working copy after each build; dependency caches may be kept on the build host to speed up later builds.

API keys and share links. We store only a hash and a short prefix of each API key and share link token, never the full secret.

Trials and demos. To limit anonymous trials and demos, we count requests per IP address, keyed by a hash of the address rather than the address itself. These daily counters are deleted after two days.

Waitlists. If you join a waitlist, we store the name and email address you give us.

Messages. If you email us, we keep the conversation.

Analytics and advertising

On ramus.dev we use PostHog for product analytics and Google’s tag for Google Ads conversion measurement and Google Analytics. They set cookies and use local storage.

  • PostHog records pages you visit, how you arrived (such as referrer and campaign tags) and actions like starting a demo or uploading an app. When you sign in, we link this activity to your account ID, email and name.
  • PostHog also records session replays of how people use the site, to help us fix bugs and improve the product. Replays may include low-resolution snapshots of the viewer, which can show your app on the device. Text typed into forms and fields we mark as private is masked, and the live video stream is not recorded.
  • Google receives page views and a few conversion events (sign-up, GitHub App installed, demo started) so we can measure our ads. We turn off ad personalization and Google signals. In the EEA, UK and Switzerland, Google’s ad and analytics storage is off by default.
  • If your browser sends Do Not Track or Global Privacy Control, we turn off PostHog and Google on ramus.dev entirely.

We do not sell your personal information. We share limited browsing activity with Google to measure advertising, which some US state laws treat as “sharing” for cross-context advertising. Turning on Global Privacy Control opts you out of it.

How we use it

  • To run the service: sign you in, start devices, build and install your apps, and show them to you and the people you share them with.
  • To keep Ramus secure and fair: enforce usage limits and the Acceptable Use Policy, and detect and stop abuse.
  • To understand and improve the product, and to measure our marketing.
  • To contact you about your account, the service, or requests you make.
  • To meet legal obligations.

Who we share it with

We use these service providers to run Ramus. They process data for us under their own terms and security practices:

  • Cloudflare: website hosting and device DNS filtering
  • Fly.io: API servers and network relays (US)
  • PlanetScale: database (US)
  • OVHcloud: file storage and the servers that run devices and builds
  • Grafana Labs: service logs and metrics
  • PostHog: product analytics and session replay (US)
  • Google: advertising measurement and analytics
  • GitHub: sign-in and repository access
  • Buildkite: building and deploying Ramus itself

We also share data when you choose to, for example by sending someone a device link or letting a coding agent use your API key; when the law requires it; to protect Ramus, our users or others from harm; or as part of a merger, acquisition or sale of the service, in which case this policy will continue to apply to your data.

How long we keep it

  • Uploaded APKs, built apps and build logs are deleted automatically after 30 days.
  • A device’s contents are discarded when its session ends. Every session starts from a clean device.
  • Anonymous trial accounts are deleted a few days after they expire.
  • Share links expire after at most seven days.
  • Account, repository and usage records are kept while your account is active and deleted or anonymized when you ask us to delete your account, except where we must keep them for security, abuse prevention or legal reasons.
  • Analytics data is kept according to our providers’ retention settings.

Your rights and choices

You can ask us to access, correct, export or delete your personal data, or object to or restrict how we use it, by emailing privacy@ramus.dev. We may need to confirm your identity first, and we complete verified deletion requests within 30 days. We will not treat you differently for using these rights.

You can revoke API keys in Settings, and remove repositories or uninstall the Ramus GitHub App on GitHub at any time. To stop analytics, turn on Global Privacy Control or Do Not Track in your browser, or block cookies. You can also email privacy@ramus.dev with the subject “Opt out” and we will stop sharing your activity with Google for advertising.

If you are in the EEA, UK or Switzerland, you can also complain to your local data protection authority.

Security

Builds run in isolated virtual machines that never receive your GitHub credentials, every device session starts from a clean device, and secrets like API keys and share tokens are stored only as hashes. No system is perfectly secure, so keep secrets out of the apps and builds you upload. See Security for details, and report vulnerabilities to security@ramus.dev. If an incident affects your personal data, we will notify you and the authorities where the law requires. A data processing agreement is available on request.

Where data is processed

Ramus and most of its providers operate in the United States. If you use Ramus from elsewhere, your data is transferred to and processed in the US, where data protection laws may differ from yours.

Children

Ramus is not for children. You must be at least 16 to use it, and we do not knowingly collect data from anyone younger. If you believe a child has given us personal data, email privacy@ramus.dev and we will delete it.

Changes

We may update this policy as Ramus changes. The version and effective date above change when we do, and we will tell you about material changes before they take effect.