Privacy Policy
Roomiva · Version 2026-09-06.1 · Effective 6 September 2026
This policy explains what Roomiva (the "app") collects, why, who processes it, how long it is kept, and what you can do about it. It is written from the software as it actually behaves. Where a fact depends on something outside the software — such as where a processor stores data — we say so rather than guess.
The operator of the app ("we", "us", "our") is identified in the Operator details section at the end of this document.
1. Summary
- You can use the app without an account. It starts as a guest.
- If you choose Continue with email, we hold your email address so you can sign back in. We do not send marketing email.
- The photo you upload is stripped of location and camera metadata on your device before it leaves, stored privately, and sent to our two AI providers only to produce your designs: Google's Gemini API reads it, plans the design and checks the result; OpenAI's image model draws the design.
- We do not sell your data, do not use it for advertising, and run no advertising, analytics or tracking software in the app.
- Uploads you never use are deleted after 24 hours; the original photo of a project you do not save is deleted after 7 days; everything else stays until you delete it or your account.
- You can delete your whole account from Settings → Legal & Privacy → Delete account, or from the public deletion page linked there.
2. What we collect
2.1 Account and identity
| Data | When | Why |
|---|---|---|
| A random user identifier | Created on first launch, as a guest | To keep your projects yours, even without an email |
| Your email address | Only if you choose Continue with email | To send a secure sign-in link, and to sign you back in |
The sign-in link is issued and checked by our authentication provider; the app redeems it once and never stores or logs it. A guest account and an email account are the same kind of account: when you sign in with an email, the projects you made as a guest are moved into that account by our server.
2.2 Photos and designs
| Data | Notes |
|---|---|
| The photo of your space | Re-encoded on your device before upload, which removes EXIF metadata including GPS location and camera details. Re-encoded again on our server. Stored in a private bucket; never public. |
| Your design choices | Space type, style, palette, materials, lighting and intensity, and an optional short free-text request. |
| Generated designs | The images produced for you, the structured plan behind each one, and the exact instructions sent to the AI providers, kept so a result can be explained and reported. |
| Favourites and reports | Which designs you marked, and any report you file about a result. |
Videos: the app has no video capture or upload today. If a video feature is released, this policy will be updated before it is used.
2.3 Subscriptions
If you subscribe, the purchase is made with Apple or Google through their native purchase flow. We receive the subscription's status (active, in trial, expired, cancelled), the product, the store, and the renewal date from RevenueCat. We never receive card numbers, bank details or billing addresses. Your RevenueCat identifier is your app user identifier.
2.4 Usage, security and diagnostics
| Data | Why | Kept |
|---|---|---|
| A usage ledger of the designs you generate | To apply your plan's allowance | Until the account is deleted |
| Audit events (which action happened, when, for which account) with secrets removed | Security and abuse investigation, and to answer your questions about your account | 365 days |
| Server request logs (request id, route, status, timing, network address) with credentials redacted | Keeping the service running and rate-limiting abuse | See §7 |
| Rate-limit counters keyed by account and network address | Protecting the service | Minutes to an hour, in memory |
| Device preferences (theme, whether you have seen the guide, the job you were waiting on) | Convenience | On your device only |
We do not collect: precise or coarse location (the permissions are blocked in the app), contacts, microphone, your photo library beyond the single image you pick, advertising identifiers, or any cross-app or cross-site tracking data. There is no analytics or crash-reporting SDK in the app.
3. Why we process it and on what basis
| Purpose | Data | Basis |
|---|---|---|
| Providing the service you asked for: storing your photo, generating designs, showing them back to you | Photos, design choices, generated designs, identifiers | Performance of our agreement with you |
| Signing you in and keeping your projects across devices | Email, identifiers | Performance of our agreement |
| Applying and billing your subscription | Subscription status | Performance of our agreement; our legitimate interest in being paid |
| Security, abuse prevention and rate limiting | Audit events, request logs, counters | Our legitimate interest in running a safe service; legal obligations |
| Answering your requests and reports | Reports, account records | Performance of our agreement; legal obligations |
Where your local law requires a specific basis (for example the GDPR), the Operator details section states which regime applies to us.
4. Who we share it with
We share data only with the companies that process it for us to run the service. The current list, with what each one does, is in the Subprocessors document. In outline:
- Supabase — authentication, database, private file storage, and delivery of the sign-in link email.
- Google (Gemini API) — receives the re-encoded photo and your design choices to analyse the space, plan each design and check the finished design against your photo. See §6.
- OpenAI (Images API) — receives the re-encoded photo and the render instruction, which contains your design choices, and draws the design. See §6.
- RevenueCat — subscription status; receives your app user identifier and purchase events from the store.
- Apple App Store and Google Play — payments, under their own terms and privacy policies.
- Render — hosts the API, the background worker and the daily retention job, in Frankfurt (EU).
We do not sell personal data, share it for cross-context behavioural advertising, or give it to data brokers. We may disclose data if the law requires it, to protect the rights and safety of users or others, or as part of a merger or acquisition (in which case this policy continues to apply to the data transferred).
5. Your content and ownership
You keep every right you have in the photos you upload. You give us only the licence needed to store, process, transmit and display them back to you in order to provide the service, and it ends when the content is deleted. See the Terms of Service for the full statement, and the Acceptable Use Policy for what may not be uploaded.
6. AI processing and model training
Two providers take part in every design, each with one job:
- Google (Gemini API) receives the re-encoded photo and your design choices to read the space and write the plan for each design, and receives each generated design afterwards to check that it kept your structure.
- OpenAI (Images API) receives the re-encoded photo and the render instruction — the plan, your design choices and any request text you typed — and draws the design. When you refine a design, it also receives the design being refined. OpenAI processes this in the United States and keeps logs for abuse monitoring, which may contain the photo and the instruction, for up to 30 days unless the law requires longer.
No name, email, user identifier or device identifier is included in any of those requests.
Our own systems train no model on your content. OpenAI's API data-usage terms state that content sent to its API is not used to train or improve OpenAI's models unless the customer opts in; we have not opted in. The Gemini API processes your content under Google's API terms, which differ by service tier; the terms that apply to our account, and the OpenAI terms and contracting entity that apply to it, are stated in the Subprocessors document. We do not claim anything about provider-side model improvement beyond what those terms say.
The designs are conceptual. Please read the AI Design Disclaimer before acting on one.
7. How long we keep it
These periods are enforced by an automatic job that runs every day.
| Data | Kept for |
|---|---|
| An upload that was never used in a design | 24 hours |
| The original photo of a project you did not save | 7 days after the design was made |
| A project you saved, and its designs | Until you delete it |
| A project you deleted | 3 days, recoverable, then permanently erased |
| Your account, email and profile | Until you delete the account |
| Subscription status | Until you delete the account |
| Store webhook records | 90 days |
| Audit events | 365 days |
| Request-replay protection keys | 7 days |
| Signed links to read an image | 10 minutes each |
| Server request logs | Held by our hosting provider; the period is stated in the Subprocessors document |
The Data Retention & Deletion document lists the exact mechanism for each row.
8. Your choices and rights
- See your data. Every project and design is visible in the app under My Designs. Your account details are under Settings.
- Export. Any design can be saved to your photo library or shared from the design screen.
- Correct. Design choices can be changed by creating a new design. To correct an email address, contact us at the privacy address in the Operator details; we will verify that the request comes from the account holder.
- Delete a project. From My Designs, at any time.
- Delete your account. From Settings → Legal & Privacy → Delete account, or from the public deletion page linked there. Deletion removes your photos, designs, records and account. It does not cancel an Apple or Google subscription; cancel that in your store account (the app links to the right place).
- Withdraw consent. Where we rely on your consent, you may withdraw it at any time by the same route you gave it, without affecting processing that happened before.
- Object, restrict, port, complain. Depending on where you live you may have rights to object to or restrict processing, to receive your data in a portable form, and to complain to a supervisory authority. Contact us first at the privacy address; we will respond within the period your law sets, and in any case within 30 days.
We may ask you to confirm the request from the signed-in account or the email on it, so that nobody else can exercise your rights.
9. International processing
Our processors operate in the regions stated in the Subprocessors document, which may be outside the country you live in. Where a transfer of personal data out of your region requires a legal mechanism (for example standard contractual clauses), we rely on the mechanisms our processors provide, as described there.
10. Security
What we do, in specific terms:
- Every request to our API carries a signed token that we verify server-side; the only claim we take from it is your account identifier.
- Your data is protected by row-level security in the database: an account can read only its own rows.
- Photos and designs live in private buckets. They are reachable only through short-lived signed links (10 minutes to read; an upload link lasts 2 hours and can write one file) issued to the signed-in account.
- Location and camera metadata are removed from photos on your device and again on our server.
- Secrets never reach the app. Credentials, sign-in links, signed links and request bodies are redacted from our logs.
- Requests are rate-limited per account and per network address.
- Connections use HTTPS, with HTTP Strict Transport Security in production.
No method of storage or transmission is completely secure, and we do not promise that ours is. If we learn of a breach affecting your data, we will tell you and any authority we are required to notify, in the time the law allows.
11. Grievances and complaints
Send any privacy question, request or complaint to the privacy contact in the Operator details. If your law requires us to name a grievance officer or data protection officer, that person is named there too. If you are not satisfied with our answer, you may complain to the data-protection authority for where you live.
12. Children
The app is not directed at children under 13, and we do not knowingly collect personal data from them. To buy a subscription you must be old enough to enter a binding contract where you live. If you believe a child has provided us with personal data, contact us and we will delete it.
13. Changes to this policy
When we change this policy in a way that matters — new data, a new purpose, a new processor, a shorter right — we will publish the new version at the public URL, show the new version number and effective date in the app, and ask you to accept the new terms before your next upload where the change requires it. The version and effective date at the top of this document identify the text you are reading.
14. Operator details
The legal name, address, country, applicable law and contact addresses of the operator are published below in the app and on the public legal pages.
- Operator: iClick Solutions Inc.
- Registration: State of Delaware, Secretary of State, Division of Corporations — File Number 6657647; filed March 7, 2022.
- Address: 651 N Broad St, Suite 201, Middletown, Delaware 19709, United States
- Country: United States
- Governing law and courts: The laws of the State of Delaware, United States; the state and federal courts located in Delaware
- Support: support@roomivaapp.com
- Privacy contact: support@roomivaapp.com
- Grievance officer / DPO: Viren Makkar, vmakkar@iclicksolutions.us
- EU / UK representative: Viren Makkar, vmakkar@iclicksolutions.us (for the EU and the UK)
- Database and storage region (Supabase): us-east-1 (North Virginia)
- API hosting: Render Services, Inc. — Frankfurt (EU) region, for the API, the worker and the retention job (render.yaml)
- Server log retention: Server request logs are held by Render Services, Inc. in its log store for the retention period of the Render workspace tier in use (7 days on the Hobby tier, 14 days on Pro), then deleted. No log stream to any other provider is configured.
- Sign-in email delivery: Custom SMTP via Resend (Resend, Inc.), Tokyo (ap-northeast-1) sending region; sender no-reply@send.roomivaapp.com
- AI provider terms and data use (Google Gemini API; OpenAI API): Google Gemini API, paid tier (billing enabled): under the Gemini API Additional Terms for paid services, Google does not use prompts or responses to improve its products. OpenAI API, standard paid access: under the OpenAI API data-usage terms, content sent to the API is not used to train or improve OpenAI models unless the customer opts in, which we have not; abuse-monitoring logs are retained for up to 30 days.
- Data-processing agreements: OpenAI: Data Processing Addendum executed by iClick Solutions Inc. on 2026-09-20 (DocuSign envelope E6FAD23DD4D288A181516FF270372C69); the countersigned copy is held by the operator. Supabase, Render, Resend, Google (Gemini API) and RevenueCat: the data-processing terms of each form part of the agreement accepted when the account was created and require no separate signature.