Last updated: July 23, 2026
This policy explains what Roo Code, Inc., a Delaware corporation (“Roomote”), processes when you use Roomote Cloud, the hosted version of Roomote. Our websites are covered by the separate Website Privacy Policy. Self-hosted deployments are covered by neither — they run on your infrastructure.
The short version: we hold your account and billing details; your code, prompts, and tasks live inside your own isolated deployment; we never train on your content; deleting your workspace destroys the deployment and its backups immediately; and your AI model traffic goes straight from your deployment to your model provider — not through us.
1. Two roles, two kinds of data
Account data — Roomote as controller. Data about you as our customer: account, billing, portal usage, and communications. Sections 2–4.
Customer Content — Roomote as processor. Everything inside your deployment: repositories, prompts, tasks, model outputs, integration credentials, logs, artifacts. You (or your organization) are the controller; we process it only to host and operate your deployment, under the Data Processing Agreement. Section 5.
2. Account data we collect
| Category | Details |
|---|---|
| Account | Email address and password (stored hashed), or Google sign-in (we receive your Google account email and basic profile per the OAuth scopes openid email profile). Email verification codes. Workspace name and optional slug. |
| Sessions & security | Session tokens, IP address, and browser user agent, used to keep you signed in and secure your account. Sessions last up to 7 days. |
| Billing | Handled by Stripe. We share your email and an account identifier with Stripe and retain subscription status, plan, billing-period dates, and peak user counts. We never see or store your full card details — those go directly to Stripe. |
| Deployment operations metadata | Records needed to run your deployment: workspace and deployment identifiers, provisioning state, health status, and operational job records (job payloads are encrypted at rest with AES-256-GCM). |
| Usage telemetry (required) | Your deployment reports a deployment identifier, user counts, and software version to Roomote. We use this to calculate your bill and operate the Service. Because billing depends on it, this telemetry cannot be disabled. It never includes your code, prompts, tasks, or content. |
| Communications | Emails you send us, and delivery records for transactional email we send you (type, status, timestamps — not the message body). |
| Portal analytics (optional) | On the Cloud portal we use PostHog (page views, referrer, campaign parameters) and Intercom (support chat). Where consent is required (e.g., EU), these stay off until you accept; you can refuse or withdraw at any time. |
3. How we use account data
To provide, secure, and bill the Service; to provision and operate your deployment; to communicate with you about your account, trials, deletions, and changes; to understand portal usage (with consent where required); and to comply with law. We do not sell personal information and do not use your data for third-party advertising.
4. Account data retention
| Data | Retention |
|---|---|
| Account & workspace metadata | While your account is active, then up to 30 days after deletion/cancellation. |
| Billing & transactional records | As required by tax and accounting law (typically up to 7 years), regardless of account deletion. |
| Support correspondence | While we handle your request and for a reasonable period after. |
| Email delivery records | Limited operational period; message bodies are not stored by us. |
5. Customer Content: your deployment
Isolation. Each workspace is a dedicated single-tenant deployment — its own application services, database, cache, queue worker, and object storage in a private project. No shared databases, no shared tenancy.
What we can and can’t see. Roomote’s control plane has no product pathway into your deployment’s contents: it performs health checks and sets access state (active/read-only), and it cannot query your data, prompts, code, or logs. Our operations tooling holds privileged infrastructure access (needed to provision, upgrade, and destroy deployments); this access is limited to a small number of authorized personnel and used only for operations, support you request, security, or legal compliance. Formal access audit logging is being expanded as we grow. We never use Customer Content to train AI models.
Task sandboxes. Tasks execute in isolated sandbox environments at our compute provider (Modal). Commands, working files, and repository contents involved in a task are processed in the sandbox for the duration of task execution.
Your model provider. Inference requests go directly from your deployment to the model provider you configure, using your own API key or subscription, under your agreement with that provider. Your keys are held inside your deployment via a local key proxy; they are not placed in task sandboxes and are not transmitted to Roomote’s shared systems. Model providers are not our subprocessors — review your provider’s own data terms.
Deletion — immediate and complete. When you delete a workspace (or cancel your account), the entire deployment is permanently destroyed: application, database, cache, object storage, and associated volume backups and point-in-time-recovery archives, which are deleted with their volumes. This is irreversible.
Trial deployments. If your trial ends without a subscription, your deployment becomes read-only and is permanently deleted 7 days after trial expiration. We send email notices before deletion.
Legal holds. We may preserve specified data where required by law or a valid preservation request, for as long as legally required.
6. Sharing and subprocessors
We share data only with the service providers needed to run Roomote Cloud — hosting (Railway), sandboxes (Modal), DNS (Vercel), email (Resend), payments (Stripe), optional sign-in (Google), and portal analytics/support (PostHog, Intercom, consent-based). The full list, with what each receives, is on the Subprocessors page, where we also announce changes. We may also disclose information when required by law, to protect rights or safety, or in connection with a merger, acquisition, financing, or asset sale.
7. International transfers
Roomote is a US company and Roomote Cloud is currently hosted in the United States. Where GDPR or similar laws apply to your Customer Content, transfers are governed by the Standard Contractual Clauses incorporated in our DPA.
8. Security
Single-tenant isolation per customer; TLS for data in transit; encrypted control-plane job payloads (AES-256-GCM); per-deployment encryption keys and secrets; signed and time-limited internal operations requests; rate limiting and replay protection on sandbox operations; restricted personnel access. No system is perfectly secure, and we do not yet hold SOC 2 or similar certifications (this is on our roadmap). Security reports: see /security.
9. Your rights
Depending on your location, you may have rights to access, correct, delete, export, or object to processing of your personal data. Contact privacy@roomote.dev; we will respond within the legally required period (30 days under GDPR). Workspace deletion and account cancellation are self-serve in the product. For an export of your Customer Content, contact support and we will provide one within 30 days. If your data is in a workspace operated by your organization, we may direct your request to them as the controller. EU/UK individuals may also lodge complaints with their supervisory authority.
10. Children
Roomote Cloud is not directed to children under 18 and requires users to be adults.
11. Changes
We will post updates here and notify you of material changes by email or in-product before they take effect.
12. Contact
privacy@roomote.dev · Roo Code, Inc., 98 Graceland Dr, San Rafael, CA 94901, USA