Privacy Policy
Last updated: August 9, 2026
1. Who We Are
Gummble ("we", "us") operates gummble.com, a curated library of UI screenshots and design patterns, the Gummble mobile apps, and the Gummble MCP server, which lets AI assistants search that library. This policy explains what data we collect, why, and the choices you have. Questions go to support@gummble.com.
2. Information We Collect
Account information
You can create an account by signing in with an OAuth provider (such as Google) or with an email address and password. With OAuth we receive your email address, name, and profile picture, and we never receive or store your password for that provider. If you sign up with an email address and password, we store the password only as a salted hash — never in plain text — and use it solely to authenticate you. We use this information to create and secure your account, associate your subscription with you, and contact you about your account.
Product analytics
We use PostHog to understand how the product is used: page views, searches you run (including the search text), feature usage, and subscription events, along with device and browser information. Approximate location (country and city level) is derived from your IP address for aggregate analytics; we do not track precise location. Analytics data is associated with your account when you are signed in and is used to improve the product, not sold to anyone.
Session replay
On the Gummble website, for a small subset of sessions — primarily signup, checkout, and sessions of trial or paid subscribers — we use PostHog session replay to record how the interface was used so we can find and fix product problems. Text you type and text on the page are masked before anything leaves your browser, and captured network request URLs are sanitized. Gummble iOS release builds also use PostHog full session replay. iOS replay is unmasked and can include search text, interface text, account or subscription screens, and images rendered in the app. Network request and response contents are not recorded; warning and error logs may be included. The iOS app uses a pseudonymous app-install identifier, and we do not use replay for advertising or cross-app tracking.
Error monitoring
We use Sentry to collect crash and error reports when something goes wrong: the error details, your browser and device information, in some cases your IP address, and — when you are signed in — your account identifier, so we can reproduce and fix the bug. Our analytics tooling (PostHog) also records unhandled errors that occur in the app for the same purpose.
Payment information
Web subscriptions are processed by Polar. iOS subscriptions are processed by Apple through your Apple Account, and RevenueCat helps us validate purchase status and deliver the correct entitlement. Your full payment-card details go directly to the payment provider and never touch our servers. We and RevenueCat store purchase history and subscription details such as product, plan, status, transaction dates, and entitlement state for app functionality, restore-purchase support, fraud prevention, customer support, and aggregate analytics. The iOS app uses an anonymous RevenueCat identifier unless you later choose to link a Gummble account.
Gummble MCP server
When you connect an AI assistant to the Gummble MCP server, we record which tools are called (for example, a search or a screen lookup), when, and by which account. We do not receive or store the content of your conversations with your AI assistant. The MCP server is read-only: it can search and return content from our library, and it does not store any files or documents of yours.
Cookies
We use cookies to keep you signed in, remember preferences, and power the analytics described above. You can block cookies in your browser; signing in will not work without them.
3. How We Use Your Information
We use the data above to provide and improve the service, authenticate you, process payments, prevent abuse, and communicate with you about your account. We do not sell your personal information, and we do not use it for third-party advertising.
4. Sharing
We share data only with the service providers needed to run Gummble — Cloudflare (MCP edge, content delivery, and storage), Vercel (web hosting), Railway (API hosting), PostHog (analytics), Sentry (error monitoring), Polar (web payments), Apple (App Store payments), and RevenueCat (mobile subscription management) — each bound to use it solely to provide their service to us. We may also disclose information if required by law. See the current security and procurement overview for a concise operational summary.
5. Data Retention
We keep account data for as long as your account exists. Analytics and MCP usage data is retained for up to 24 months and then deleted or aggregated. If you delete your account, we delete your personal data within 30 days, except records we must keep for legal or billing reasons.
6. Your Rights
You can request a copy of your data, correct it, or ask us to delete it at any time by emailing support@gummble.com. Depending on where you live, you may have additional rights under laws such as the GDPR or CCPA; we honor those requests regardless of location.
7. Security
All traffic to Gummble is encrypted in transit. Access to personal data is limited to the people and systems that need it to operate the service. No system is perfectly secure, so if we learn of a breach affecting your data we will notify you promptly.
8. Changes
We will post any changes to this policy on this page and update the date above. Material changes will be announced by email or an in-product notice.
9. Contact
Email support@gummble.com with any privacy question or request. See also our Terms of Service.