Rabbit is made by Smitten, which is the data controller for the personal data described here. This explains what we collect when you use Rabbit, on the website or in the app for iOS and Android, why, on what legal grounds, and what say you have over it. We try to only collect what the product actually needs. For anything data-related, write to hello@tryrabbit.co.
When you sign in with Google, we get your name, email address, and profile photo. During onboarding we ask for your birthday, and you choose a username and can write a short bio.
Beyond that, we store what you do on Rabbit: the Bits you post (uploaded HTML files or links), the comments you write, and the Bits you recommend.
Making a Bit in the creator leaves a draft, and we keep it so you can come back to it: what you asked for, the conversation with the builder, and the document it wrote. A picture you attach to an ask is not part of that — it's passed to the model as direction and never stored. Drafts are yours alone; nobody else sees one unless you post it as a Bit.
Like most websites, our servers also keep short-lived technical logs (things like IP address, browser type, and the pages requested) that we use for security and keeping Rabbit running.
To run your account and show your profile, feed, and the Bits you've posted or recommended to other people. That's performance of our contract with you (GDPR Article 6(1)(b)).
Your birthday tells us you're old enough to use Rabbit, and technical logs help us prevent abuse and keep the platform secure. Those rest on our legitimate interests in running a safe, lawful service (Article 6(1)(f)), and on legal obligations where the law requires age safeguards or that we act on illegal content (Article 6(1)(c)).
To see how Rabbit is actually used and to fix what's broken, we measure what happens in it. On the website, optional analytics uses your consent (Article 6(1)(a)). App analytics and operational diagnostics rely on our legitimate interest in improving the product (Article 6(1)(f)). The section below says what that involves.
We don't run ads, and we don't sell or share your personal data. We do keep an analytics profile of how you use Rabbit, described below, but we don't use it to make automated decisions about you that have legal or similarly significant effects.
Profiles are public: your name, username, photo, bio, and the Bits and recommends attached to your account. Posted Bits, comments, and recommends are public too. Anyone can see them, signed in or not. Your email, birthday, and technical logs are never shown publicly.
Rabbit uses PostHog for product analytics. After you accept optional cookies, in the browser it records the pages you visit, the things you click, and the errors Rabbit hits, and it may also capture session replays: a reconstruction of a visit showing the pages you moved through and where you clicked.
The app measures the same kinds of things, minus the replay: the screens you open, when the app is launched or updated, and a handful of moments the server never sees on its own — playing a Bit and how long you played it, searching, opening a profile, sharing. A search records how long what you typed was, never the words. There is no session replay in the app and nothing recording your screen.
Our servers record the actions themselves — signing in, liking, saving, commenting, following — against your account. For website requests, these analytics events are sent only after you accept optional cookies.
PostHog gives consenting website visitors an analytics profile, whether or not they're signed in, so we can see how people arrive and what they do before they make an account. When you sign in, that profile is joined to your account and tagged with your user id, email, name, username, when you signed up, and whether you've finished onboarding — so the visits before and after your account read as one person rather than two.
It's ours alone: the data goes to PostHog's servers in the EU under a data processing agreement, and it never feeds ads or gets sold. Open here, or under Privacy in Settings when you're signed in, to accept or reject optional tracking or withdraw consent at any time. This stops future website analytics; it does not delete previously collected data. For requests about existing data or app analytics, write to hello@tryrabbit.co and we'll help with your request.
Google handles sign-in and gives us the account details listed above. Vercel and the other cloud providers that host Rabbit store and serve data on our behalf, under data processing agreements, and none of them get to use your data beyond providing that service to us. Uploaded HTML Bits are served in a sandbox, kept isolated from the rest of the app.
PostHog runs the analytics above. Expo delivers the app's notifications and its updates.
Anthropic runs everything on Rabbit that a model does, and it sees what that work needs. When you make a Bit in the creator, that's what you ask for, any picture you attach, the answers you give its questions, anything you talk through with it, and the document being written or revised — including the Bit a remix starts from. When you post a Bit, it's the Bit's title, description, and visible text, so Rabbit can tell which languages it reads in and suggest tags. When you ask for a title, a description, or a poster, it's the Bit's own content and the ask you wrote. While the creator works out what to ask you about, it may search the live web once for a term it doesn't know.
None of it trains a model — Anthropic's commercial terms rule that out — and none of it is kept beyond answering the request and Anthropic's own checks for abuse.
We disclose personal data outside that circle only if the law requires it, for example a valid order from a court or authority.
Our providers may process data outside the European Economic Area, including in the United States. When they do, the transfer is covered by an EU adequacy decision such as the EU-US Data Privacy Framework, or by the European Commission's Standard Contractual Clauses.
On the website, one strictly necessary session cookie keeps you signed in. It's how Rabbit remembers who you are between visits. PostHog sets cookies and browser storage of its own for the analytics above, which aren't strictly necessary and are enabled only with your consent. We remember your choice for six months in an essential preference cookie. We don't use advertising or cross-site tracking cookies, and nothing we store is sold or shared for advertising.
In the app there's no cookie: your session is held in the device's secure storage, the iOS keychain or its Android equivalent, and signing out removes it.
The app talks to the same servers as the website and collects two things the website doesn't. If you allow notifications, it registers a push token for that device and we store it against your account, so we know where to send word of a like, a comment, or a new follower. Notifications travel through Expo's push service and then Apple's or Google's to reach your phone. Signing out withdraws the token, and deleting your account removes it.
On launch the app also asks Expo whether a newer version of itself is available, which tells Expo the platform and version you're running.
The app bundles PostHog for the measurement described above, and no crash reporter. You can delete your account from the app itself; editing your profile and changing settings happen on the website today, and the app links out to it.
We keep your data while your account is active. On the website you can edit your profile any time at /profile/edit, and delete your account from Settings or in the app — the steps are written out at /delete-account. Deleting your account removes your account, your Bits, your comments, your recommends, and your drafts. Copies in backups and technical logs age out on a rolling schedule shortly after, and we may retain specific records longer where the law requires it, for example evidence tied to a report of illegal content.
Under the GDPR you can ask us for a copy of your data, ask us to correct or delete it, restrict or object to how we use it, take it with you in a portable format, and withdraw consent where consent is what we rely on. Write to hello@tryrabbit.co and we'll respond within a month. You also have the right to lodge a complaint with the data protection authority in the country where you live.
Rabbit accounts aren't for children under 13, or under the age in your country for consenting to data processing (up to 16 in parts of the EEA) without a parent or guardian's permission. If we learn an account belongs to a child below that age, we'll delete it and the data that came with it. Parents and guardians can reach us at the address above. Our Child Safety Standards say what is never allowed on Rabbit and how to report it.
We may update this policy as Rabbit changes. If a change is material, we'll let you know before it takes effect.
Questions about this policy or your data? Reach us at hello@tryrabbit.co.