YOUR INFORMATION
Privacy policy
Last updated: September 22, 2026
Room is published by Martin Seigneuret. For privacy questions and requests, contact martin.seigneuret.dev@proton.me. This policy covers the Room app and this website.
Your account and saved records
When you register or sign in, our authentication provider, Supabase, processes your email address, account identifier and authentication information. If you choose Apple or Google sign-in, that provider also processes your sign-in and supplies the account information you authorize. Authentication tokens are stored using your device’s secure storage.
Check-ins, written notes, guided reflections, saved ERP exercises and practice records that you explicitly save are sent to Room’s authenticated service and stored in its database, associated with your account. These records can include moods, timestamps, exercise instructions and sensitive information about health, relationships, beliefs or identity that you choose to write. They are not shared publicly or with other Room users. Drafts and some display preferences remain temporary on your device; unsaved information can be lost when the app restarts.
AI conversations in Talk
When you send a message in Talk, Room sends your message and a limited excerpt of that conversation to OpenAI to generate a reply. Talk does not automatically send your journal or ERP records to OpenAI. Messages and replies are stored in Room’s database so you can return to conversation history. Avoid including identifying or sensitive information you do not want processed by these services.
Our requests disable storage of Responses API responses by OpenAI, but this is not a promise of zero provider retention: OpenAI’s applicable security, abuse-monitoring and legal retention rules may still apply. See OpenAI’s API data controls. AI responses can be inaccurate and are not professional care.
Subscriptions
RevenueCat and Apple process subscription product identifiers, purchase and transaction information, entitlement status and a customer identifier linked to your Room account. This lets Room display offers, validate and restore purchases, and check access to Talk. These services may also process technical and network information, such as app version, platform and IP address. Room does not receive your payment-card details. We do not send journal, exercise or conversation content to RevenueCat.
See RevenueCat’s privacy policy and Apple’s privacy policy.
Reminders and technical services
Reminders are optional notifications scheduled on your device after your permission. Their settings are stored locally. Room does not send your personal content or push tokens to a notification server for these reminders. You can disable them in Room or your device settings.
Supabase hosts authentication and the database, Render hosts the API, Expo delivers app updates, and Vercel hosts this website. These providers process connection and technical information needed to deliver and secure their services. The configured database is in London and the API is in Frankfurt; providers and their subprocessors may also process information in other countries, including the United States. Applicable provider terms describe their international-transfer safeguards.
We do not add advertising trackers or marketing cookies to the app or website. The website has no sign-up, payment or contact form. If you email us, we receive your address and the information you include and use it to respond. Please avoid including health details in support emails.
Why information is used
We use account information and saved content to provide the features you request; purchase information to administer subscriptions; and limited technical information to operate, secure and troubleshoot the service. We do not use your personal reflections to target advertising. Where applicable, you can ask us about the legal basis for a particular use of your information or withdraw consent for optional processing by contacting us. Stopping optional processing may make the associated feature unavailable.
Retention and deletion
Saved account records remain on the service so you can access them again. Deleting a journal entry or ERP exercise removes it from visible history; the current service retains a deleted record in the database rather than immediately erasing its contents. Deleting a Talk conversation clears its stored text from the active conversation record, while identifiers and daily usage counts remain for consistency and usage limits. Provider logs and backups may have separate retention periods.
In app versions with Delete account, open Profile, then Privacy, and confirm Delete account. This permanently erases the account, saved journal entries, ERP exercises, Talk conversations and preferences, including previously deleted content retained in the active database. Purchase and subscription records are managed separately. Contact us for requests concerning these records. Provider logs and backups can have separate retention periods or applicable legal obligations. If you used Sign in with Apple, follow the instructions shown after deletion to revoke Apple access as well.
If your version does not offer account deletion, or you need help with a deletion request, contact us using the address above. We may need to verify your identity before acting. Deleting the app, signing out or clearing local information does not delete server records or cancel an App Store subscription.
Your choices and rights
You choose what to write, whether to use Talk and whether to enable reminders. Depending on applicable law, you may request access, correction, deletion, portability, restriction or objection to processing. Contact us to make a request. You may also raise a concern with your local data-protection authority, including the CNIL in France.
Changes
We update this policy when our practices change. The date above identifies the current version.