1. Data we collect
We collect account details such as your name, email address, password hash, subscription status, credit balance, and security-session records. We also process room photos, written design directions, generated images, technical logs, and limited request metadata needed for security and reliability.
2. How we use data
We use data to authenticate accounts, generate and store designs, deliver transactional email, process subscriptions, prevent abuse, diagnose failures, respond to support, and meet legal obligations. We do not need advertising profiles to operate Roomkind.
3. AI processing
Room photos and prompts are sent to the image-generation provider configured by the operator—Google Gemini by default—to produce requested output. Provider handling is governed by the operator’s selected API terms and data settings. Do not upload content you are not permitted to send to that provider.
4. Payments
Stripe processes payment details. Roomkind stores Stripe customer and subscription identifiers, plan status, and billing events, but does not store full card numbers or card security codes.
5. Email
The configured SMTP provider receives the destination address and message content needed to send verification, reset, and service email. Marketing email is not enabled by default in this application.
6. Storage and access
Source photos and renders are stored in the configured private storage volume and served through authenticated routes. Database access is limited to the application and authorised operators. Use TLS, strong secrets, encrypted backups, and restricted Coolify network settings in production.
7. Retention
Account records and designs are retained while the account is active and as needed for security, billing, dispute handling, and legal obligations. Deleting a design removes its database record and stored files. Deleting an account removes its database records; the operator should configure backup expiry so deleted data ages out of protected backups.
8. Your choices
You can review designs, download outputs, delete individual designs, update your profile, change your password, manage billing, and delete your account from the studio. Depending on where you live, you may also have rights to access, correct, export, restrict, object to, or erase personal data.
9. Cookies
Roomkind uses an HTTP-only session cookie to keep you signed in. It is marked SameSite=Lax and Secure in production. The application does not include advertising or cross-site tracking cookies by default.
10. International processing
Infrastructure, AI, payment, and email providers may process data in countries other than yours. The operator is responsible for selecting appropriate regions, contracts, and transfer safeguards for its users.
11. Security and incidents
No system is risk-free. We use password hashing, private file routes, session expiration, rate limits, webhook signatures, and origin checks. If a qualifying personal-data incident occurs, the operator will investigate and notify affected people or regulators when required.
12. Contact
Privacy questions or requests can be sent to [email protected]. Before launch, the operator should add its legal entity, address, data-controller details, and jurisdiction-specific disclosures.