Privacy policy

Last updated: 5 October 2026

Rubric is run by Chris McCarron, trading as GoGoChimp, who is the data controller for the information described here. This policy explains what we collect, why, and the control you have over it.

What we collect

How we use it

To run your audits and store your reports, to send you the report-ready email and receipts, to send the occasional product email you can switch off, to prevent abuse of the shared crawler, and to understand and improve how Rubric is used. We do not sell your data or use it for third-party advertising.

Payments

Payments for Rubric Pro are processed by Stripe. We store your subscription status and your Stripe customer and subscription identifiers; we never see or store your card details.

Email

We send transactional and product emails through Loops. Receipts and report-ready emails are always sent because they are about actions you took; product emails can be turned off any time from Account → Notifications, and every marketing email has an unsubscribe link.

Local-model advisory

Your Rubric score is a deterministic rules engine. Some advisory panels use a private local model running on our own hardware; that content is never sent to OpenAI, Anthropic or any other cloud model.

Crawling and reports

Rubric crawls the sites you ask it to, as a normal web client, and stores the resulting reports privately against your account. A report is visible only to you unless you create a share link, and share links are tokenised and set to noindex so they are not found or published. We never publish anyone’s score.

MCP and API keys

You can connect your own AI assistant to Rubric through our hosted MCP (Model Context Protocol). To do so you create an API key on the MCP page; the key is shown once and stored only as a one-way hash, it is scoped to your account alone, and you can revoke it any time. Over the MCP, a connected assistant can read your own audits (scores, pillars, issues, pages and the benchmark) and can start a crawl or lint a draft on your behalf; it cannot change your account, your settings or your billing, share your reports, or read anyone else’s data. Which AI client you connect (for example Claude or Cursor) is your choice, and that provider’s own privacy terms apply to what you send through it. Our own model never scores your site and never trains on your data.

Who processes your data

We use a small set of providers to run Rubric: Supabase (database, file storage and sign-in), Stripe (payments), Loops (email), Vercel (hosting) and Google Analytics (site usage). They process data on our behalf under their own terms; we do not share your data with anyone else.

Keeping and deleting your data

We keep your data for as long as you have an account. You can delete your account any time from Account → Profile: that permanently removes your reports, your history and your account, and cancels any active subscription. Anti-abuse hashes and basic billing records may be retained where we are required to keep them.

Your rights

You can access, correct, export or delete your data. Under UK and EU data-protection law you also have the right to object to or restrict certain processing. Change your email or password, or delete everything, from Account → Profile, or email info@gogochimp.com and we will help.

Cookies

We use the cookies needed to keep you signed in and the app working, plus Google Analytics cookies that tell us how visitors find and use the site (shared with gogochimp.com, so we can see which pages lead to an audit). We do not use advertising cookies; Google's ad features are switched off.

Contact and complaints

Email info@gogochimp.com with any question about your data. If you are in the UK and are not satisfied, you can also contact the Information Commissioner’s Office (ico.org.uk).