Privacy Policy

Roomiva · Version 2026-09-06.1 · Effective 6 September 2026

This policy explains what Roomiva (the "app") collects, why, who processes it, how long it is kept, and what you can do about it. It is written from the software as it actually behaves. Where a fact depends on something outside the software — such as where a processor stores data — we say so rather than guess.

The operator of the app ("we", "us", "our") is identified in the Operator details section at the end of this document.

1. Summary

2. What we collect

2.1 Account and identity

DataWhenWhy
A random user identifierCreated on first launch, as a guestTo keep your projects yours, even without an email
Your email addressOnly if you choose Continue with emailTo send a secure sign-in link, and to sign you back in

The sign-in link is issued and checked by our authentication provider; the app redeems it once and never stores or logs it. A guest account and an email account are the same kind of account: when you sign in with an email, the projects you made as a guest are moved into that account by our server.

2.2 Photos and designs

DataNotes
The photo of your spaceRe-encoded on your device before upload, which removes EXIF metadata including GPS location and camera details. Re-encoded again on our server. Stored in a private bucket; never public.
Your design choicesSpace type, style, palette, materials, lighting and intensity, and an optional short free-text request.
Generated designsThe images produced for you, the structured plan behind each one, and the exact instructions sent to the AI providers, kept so a result can be explained and reported.
Favourites and reportsWhich designs you marked, and any report you file about a result.

Videos: the app has no video capture or upload today. If a video feature is released, this policy will be updated before it is used.

2.3 Subscriptions

If you subscribe, the purchase is made with Apple or Google through their native purchase flow. We receive the subscription's status (active, in trial, expired, cancelled), the product, the store, and the renewal date from RevenueCat. We never receive card numbers, bank details or billing addresses. Your RevenueCat identifier is your app user identifier.

2.4 Usage, security and diagnostics

DataWhyKept
A usage ledger of the designs you generateTo apply your plan's allowanceUntil the account is deleted
Audit events (which action happened, when, for which account) with secrets removedSecurity and abuse investigation, and to answer your questions about your account365 days
Server request logs (request id, route, status, timing, network address) with credentials redactedKeeping the service running and rate-limiting abuseSee §7
Rate-limit counters keyed by account and network addressProtecting the serviceMinutes to an hour, in memory
Device preferences (theme, whether you have seen the guide, the job you were waiting on)ConvenienceOn your device only

We do not collect: precise or coarse location (the permissions are blocked in the app), contacts, microphone, your photo library beyond the single image you pick, advertising identifiers, or any cross-app or cross-site tracking data. There is no analytics or crash-reporting SDK in the app.

3. Why we process it and on what basis

PurposeDataBasis
Providing the service you asked for: storing your photo, generating designs, showing them back to youPhotos, design choices, generated designs, identifiersPerformance of our agreement with you
Signing you in and keeping your projects across devicesEmail, identifiersPerformance of our agreement
Applying and billing your subscriptionSubscription statusPerformance of our agreement; our legitimate interest in being paid
Security, abuse prevention and rate limitingAudit events, request logs, countersOur legitimate interest in running a safe service; legal obligations
Answering your requests and reportsReports, account recordsPerformance of our agreement; legal obligations

Where your local law requires a specific basis (for example the GDPR), the Operator details section states which regime applies to us.

4. Who we share it with

We share data only with the companies that process it for us to run the service. The current list, with what each one does, is in the Subprocessors document. In outline:

We do not sell personal data, share it for cross-context behavioural advertising, or give it to data brokers. We may disclose data if the law requires it, to protect the rights and safety of users or others, or as part of a merger or acquisition (in which case this policy continues to apply to the data transferred).

5. Your content and ownership

You keep every right you have in the photos you upload. You give us only the licence needed to store, process, transmit and display them back to you in order to provide the service, and it ends when the content is deleted. See the Terms of Service for the full statement, and the Acceptable Use Policy for what may not be uploaded.

6. AI processing and model training

Two providers take part in every design, each with one job:

No name, email, user identifier or device identifier is included in any of those requests.

Our own systems train no model on your content. OpenAI's API data-usage terms state that content sent to its API is not used to train or improve OpenAI's models unless the customer opts in; we have not opted in. The Gemini API processes your content under Google's API terms, which differ by service tier; the terms that apply to our account, and the OpenAI terms and contracting entity that apply to it, are stated in the Subprocessors document. We do not claim anything about provider-side model improvement beyond what those terms say.

The designs are conceptual. Please read the AI Design Disclaimer before acting on one.

7. How long we keep it

These periods are enforced by an automatic job that runs every day.

DataKept for
An upload that was never used in a design24 hours
The original photo of a project you did not save7 days after the design was made
A project you saved, and its designsUntil you delete it
A project you deleted3 days, recoverable, then permanently erased
Your account, email and profileUntil you delete the account
Subscription statusUntil you delete the account
Store webhook records90 days
Audit events365 days
Request-replay protection keys7 days
Signed links to read an image10 minutes each
Server request logsHeld by our hosting provider; the period is stated in the Subprocessors document

The Data Retention & Deletion document lists the exact mechanism for each row.

8. Your choices and rights

We may ask you to confirm the request from the signed-in account or the email on it, so that nobody else can exercise your rights.

9. International processing

Our processors operate in the regions stated in the Subprocessors document, which may be outside the country you live in. Where a transfer of personal data out of your region requires a legal mechanism (for example standard contractual clauses), we rely on the mechanisms our processors provide, as described there.

10. Security

What we do, in specific terms:

No method of storage or transmission is completely secure, and we do not promise that ours is. If we learn of a breach affecting your data, we will tell you and any authority we are required to notify, in the time the law allows.

11. Grievances and complaints

Send any privacy question, request or complaint to the privacy contact in the Operator details. If your law requires us to name a grievance officer or data protection officer, that person is named there too. If you are not satisfied with our answer, you may complain to the data-protection authority for where you live.

12. Children

The app is not directed at children under 13, and we do not knowingly collect personal data from them. To buy a subscription you must be old enough to enter a binding contract where you live. If you believe a child has provided us with personal data, contact us and we will delete it.

13. Changes to this policy

When we change this policy in a way that matters — new data, a new purpose, a new processor, a shorter right — we will publish the new version at the public URL, show the new version number and effective date in the app, and ask you to accept the new terms before your next upload where the change requires it. The version and effective date at the top of this document identify the text you are reading.

14. Operator details

The legal name, address, country, applicable law and contact addresses of the operator are published below in the app and on the public legal pages.