Privacy Policy for RoCode.ai
Last Updated: July 2026
1. Introduction
Welcome to RoCode.ai. I am committed to protecting your privacy. This Privacy Policy explains how I collect, use, disclose, and safeguard your information when you use my website and services. By using RoCode.ai, you agree to the collection and use of information in accordance with this policy.
2. Information I Collect
I collect information that you provide directly to me and information that is automatically collected when you use the service.
- Personal Information: When you register for an account, I collect your email address. Sign-in uses a one-time verification code sent to that email, or optional Google / Discord sign-in; I do not collect or store passwords.
- Payment Information: I do NOT collect or store your credit card information. All payments are processed securely by my third-party payment processor, Stripe. I only receive a token from Stripe confirming your payment status.
- Usage and Conversation Data: I collect and store the prompts you submit to the AI and the responses you receive. This conversation history is linked to your account to provide you with a continuous experience.
- Technical and Product Analytics Data: I automatically collect limited technical and product-usage information to operate, secure, and improve the service. This includes pseudonymous visitor and session IDs, page paths, feature and reliability events, successful Studio verification signals, campaign tags you arrived with (such as UTM values), the referring site's hostname, browser type, operating system, and IP address used for security and rate limiting. I record only the advertising platform associated with a click ID, not the click ID itself. Pseudonymous analytics events may be linked to your account after you sign in so signup, activation, and subscription reporting is not counted twice.
- Country Attribution and Scale Measurement: When available from the hosting edge, I store a coarse two-letter country code with product analytics events and visitor first/last-touch fields. This is used to decide when localized pages may unlock and to measure acquisition quality. I do not use precise location or street-level geolocation. Paid-ad spend figures entered by operators are measurement records only and do not change your account data.
- Lifecycle Communications: I record which onboarding, successful-build, inactivity, or cancellation-rescue email was sent so retries are idempotent and you are not sent the same message repeatedly. You can turn off these lifecycle emails from the link in each message; essential authentication, security, billing, and payment-recovery emails are unaffected.
- Checkout and Subscription Journey: I record the plan and billing period selected, the product surface that opened checkout, a coarse device category (desktop, tablet, mobile, or unknown), and whether Stripe Checkout was completed, expired, or recovered. I do not store full payment-card details. If you begin cancellation, I record the reason category and any optional feedback you provide, together with whether you kept, changed, paused, or canceled the subscription. This is used to improve checkout reliability, measure voluntary and payment-failure churn separately, prevent repeated retention offers, and honor your billing choice.
- Referrals: If you create a referral link, I store your referral code, Stripe promotion-code identifier, click and conversion counts, retained-referral outcomes, quality scores used to allocate incentives toward cohorts that verify and retain, and a 45-day attribution window for referred signups. Self-referrals are blocked.
- Experiments: I may assign a pseudonymous visitor or account to a product variation and record when that variation is shown. This is used to compare product outcomes and does not involve selling your information.
3. How I Use Your Information
I use the information I collect for the following purposes:
- To provide, operate, and maintain my services.
- To create and manage your account and process your subscriptions.
- To improve my AI models and the overall user experience.
- To communicate with you, including sending sign-in verification codes and important service announcements.
- To provide relevant onboarding and lifecycle guidance based on setup and verified-build milestones, subject to your email preferences.
- To prevent fraud and ensure the security of my platform.
4. How I Share Your Information (My Sub-Processors)
I do not sell your personal information. I only share your information with trusted third-party service providers who help me operate my business. These include:
- Supabase: My backend provider for database hosting and user authentication. They store your user account information and conversation history.
- Google / Discord: If you choose social sign-in, those providers authenticate you and share your email so I can create or sign you into your RoCode account. I only keep the email (not name, avatar, or other profile fields). The same email always maps to the same account whether you use email codes, Google, or Discord.
- Stripe: My payment processor for handling all subscription payments. I share your email and user ID with them to manage your subscription.
- OpenRouter: I send your prompts and conversation history to OpenRouter's AI routing services to generate responses. Your data is subject to OpenRouter's API policies.
- Resend: My email delivery provider for transactional, onboarding, lifecycle, and payment-recovery messages. I share your email address and the message content required for delivery.
I have agreements with these providers to ensure they use your information only to provide services to me and protect it with appropriate security measures.
5. Data Security
I use industry-standard security measures, including HTTPS, to protect your data. However, no method of transmission over the Internet or method of electronic storage is 100% secure. While I strive to use commercially acceptable means to protect your Personal Information, I cannot guarantee its absolute security.
6. Data Retention
I retain your personal data for as long as your account is active. Expired Stripe Checkout recovery links are removed after they expire, optional free-text cancellation feedback is cleared after 180 days, and raw checkout-attempt records are deleted after 400 days. Expired referral click attributions are marked expired after 45 days. If you choose to delete your account, your personal information and conversation history will be permanently deleted from my systems in accordance with the data deletion process.
7. Your Rights
You have the right to access, update, or correct your information. You can turn off optional lifecycle emails using the preference link in each such email. You also have the right to delete your account at any time from your "My Account" page. Deleting your account is a permanent, irreversible action.
8. Children's Privacy
My service is not intended for use by children under the age of 13. I do not knowingly collect personal information from children under 13. If I become aware that I have collected such information, I will take steps to delete it.
9. Changes to This Privacy Policy
I may update my Privacy Policy from time to time. I will notify you of any changes by posting the new Privacy Policy on this page. You are advised to review this Privacy Policy periodically for any changes.
10. Contact Us
If you have any questions about this Privacy Policy, please contact me at: ozzie.bad.studios@pm.me