Privacy Policy
This describes what RoomFigure actually does with your data. It is not a template.
The part that matters most
Your room photos leave your device. To generate a redesign, RoomFigure uploads the photo you took to our servers and then sends it to a third-party AI model provider — Google's Gemini image models, reached through Vercel AI Gateway. These are photographs of the inside of your home, so we would rather you read that sentence than find it in a footnote.
1. Who we are
RoomFigure ("RoomFigure", "we", "us") is the developer of the RoomFigure iOS app. You can reach us at flamm.alex@gmail.com for any privacy question, request, or complaint.
This policy covers the RoomFigure iOS app and the backend services it talks to. It does not cover the App Store itself, which is operated by Apple under Apple's own privacy policy.
2. The short version
- The app has no sign-in and no sign-up. There is nothing to create, no password, and no email address to give us.
- We collect the photos you choose to submit, the designs the AI generates from them, and records of those generations.
- Your photos are processed by a third-party AI provider (Google, via Vercel AI Gateway). We name every sub-processor in section 6.
- We do not collect your location — not your precise location and not a postal code — nor your street address, your contacts, your advertising identifier, or your payment card details.
- We do not sell your personal information and we do not use it for cross-context behavioural advertising.
- You can ask us to delete everything, and deletion cascades through our database — it is not a flag on a row.
3. What we collect, and why
3.1 Things you give us directly
| Data | Why we have it |
|---|---|
| Room photos you take or pick from your photo library | They are the input to the redesign. Without the photo there is no product. |
| Prompts, style choices, room type, and any notes you type about your space | They steer what the model generates. |
| Project titles you give your rooms | So your saved work is findable. |
| In-app chat messages | The app includes a conversation where you can tell us what you are trying to do with the room. We read these to understand what people want built. We treat this as the most sensitive text in the system, because people mention their home, their landlord, and their budget in it. See section 4. |
3.2 Things the app creates about your use
| Data | Why we have it |
|---|---|
| Generated designs — the images the model returns | So you can see, compare, and re-open your results. |
| Generation records — which model ran, the style and settings used, status, timing, error codes, and what it cost us | To deliver the result, to refund your credit when a generation fails, and to keep the service working. |
| Credit ledger — an append-only record of credits granted, spent, and refunded | It is how we know what you are entitled to. It has to be append-only for the balance to be trustworthy. |
| Subscription status from RevenueCat — plan, entitlement, status, period dates, trial end, and whether the purchase was a sandbox purchase | To unlock what you paid for and to stop unlocking it when you cancel. |
| Install attribution — one record of the marketing campaign, creative, channel, and the raw referral parameter the install link carried | So we know which of our own ads or posts brought you here. This is first-party only. It is never joined to an advertising identifier, and we do not build cross-app profiles with it. |
| Rate-limit counters — short-lived counts of recent requests | Abuse and cost control. Pruned continuously. |
| Experiment assignment — which variant of a screen you saw | To make sense of whether a change helped. |
3.3 Account data
You are anonymous. When you first open the app we create an anonymous account for you. It is a random identifier and nothing else. We do not ask for your name, your email, or a password, and we do not have them.
There is no sign-in. Not an optional one, not one behind a button, not Sign in with Apple. That is a deliberate product decision rather than a gap we are waiting to fill, and it is why we hold no name, no email address and no Apple identifier for you — our application database does not have an email column at all. The trade is real and we will name it: because there is no sign-in, an anonymous account lives on the device it was created on, and a reinstall starts a new one. If we ever add a sign-in that would be a material change, and section 13 says what we do about those.
3.4 What we do not collect
- No advertising identifier (IDFA), and no App Tracking Transparency prompt. We do not track you across other companies' apps and websites.
- No location of any kind. Not precise location, not background location, and not a ZIP or postal code. An earlier version of the app asked for an optional ZIP to regionalise a cost estimate; that feature is not in the app, so nothing asks for one and we hold none.
- No street address.
- No contacts, calendar, microphone, or health data.
- No payment card details. See section 7.
- No access to your photo library beyond the photos you pick. Choosing a photo does not give us the rest of your library.
4. The in-app chat, and what we do with it
RoomFigure includes an in-app conversation. We use it for product research: it is how we learn what people actually want from a room, in their own words. We want to be straight about three things.
- We store what you type. The message text is saved and associated with your account.
- It goes to a third-party model. Your messages are sent to an AI model through Vercel AI Gateway to generate replies and to categorise the conversation.
- We derive labels from it. We tag conversations with themes — for example whether you rent or own, or how price-sensitive the request sounds. Where budget comes up, our intent is to keep only a coarse band rather than the exact figure you named.
Please do not put information in the chat that you would not want stored — payment details, government identifiers, medical information, or anything about other people. Nothing in the chat is required to use the app.
5. Where your photos actually go
Step by step, for a single redesign:
- The app uploads your photo to our storage on Supabase (Postgres, object storage, and edge functions), in a private bucket in the United States (AWS
us-east-1). - Our edge function sends the photo and your prompt through Vercel AI Gateway to a Google Gemini image model, which returns the redesigned image.
- The result is written back to a second private bucket and shown to you.
That is the whole list. Google is the only model provider your photograph reaches, and it reaches nobody else. If that ever changes, it is a material change and section 13 says what we will do about it.
The buckets are private. Nothing is world-readable and nothing is reachable by guessing a URL. When the app needs to display an image it asks our server for a signed link that expires after about one hour.
Row-level security is enabled across our database, so your projects, photos, generations, and conversations are readable only by your own account.
6. Who else processes your data (sub-processors)
We share personal data only with the service providers below, and only so they can perform the function listed. We do not sell personal information, and we do not share it for cross-context behavioural advertising.
| Provider | What they receive | What they do with it |
|---|---|---|
| Supabase | Everything we store: room photos, generated designs, generation records, credit ledger, chat messages, account identifiers | Hosts our database, file storage, authentication, and server functions. United States (us-east-1). |
| Vercel (AI Gateway) | Room photos, prompts, and chat message text in transit | Routes our model requests to the model provider and meters them. Also hosts this website. |
| Google (Gemini image models) | Your room photo and the prompt | Generates the redesigned image. Reached via Vercel AI Gateway. |
| Anthropic (Claude) | Chat message text only — never your room photos | Powers the in-app conversation described in section 4. Your photographs are not sent to Anthropic. |
| RevenueCat | An app user identifier, and the purchase and renewal events Apple reports | Subscription infrastructure — tells our backend whether your subscription is active. Receives no card details. |
| Apple | Your purchase | Processes all payments and operates the App Store, under Apple's own privacy policy. |
We may also disclose data if we are legally required to, or where necessary to investigate abuse, fraud, or a security incident. If we ever add or change a sub-processor, we will update this page.
7. Payments
We never see your card details. All payment is handled by Apple through your Apple ID. Apple tells RevenueCat that a purchase happened; RevenueCat tells our backend that your subscription is active. Card numbers, expiry dates, and billing addresses never reach us and are never stored by us.
8. How long we keep things
Some of this is on a timer and some of it is not, and you should know which. Chat text and rate-limit counters are deleted by scheduled jobs that run whether or not you ask. Your photos and your designs are not on a timer. We do not delete your saved work on a clock you never set — that would be a data-loss feature wearing a privacy costume — so they stay until you remove them.
- Room photos, generated designs, and generation records are kept for as long as your account exists. Nothing deletes them on a schedule. They go when you delete them, or when you delete your account — and then they are actually gone, image files included. If we ever put them on a timer, we will say so on this page before it starts running.
- Chat conversations are redacted 180 days after the conversation starts: the message text is removed and the metadata attached to each message is wiped. A job runs every hour to do it. The remaining shell of the conversation — counts and themes, with no text — is deleted 30 days after that, by a job that runs daily.
- Credit ledger entries are append-only and last as long as your account does, because they are the record of what you were granted and spent. They are removed when your account is deleted.
- Billing records (the raw purchase and renewal events we receive) are retained for accounting and tax purposes after account deletion, with the link to your account identifier removed.
- Rate-limit counters are swept every hour, and nothing older than six hours survives the sweep.
The 180 days for chat is an operational default, not a legal minimum, and we may change it. If we shorten it, we will simply delete more. If we lengthen it — or if we ever start deleting photos and designs on a schedule — we will update this page first.
9. Your rights, and how to actually use them
Delete everything
Do it in the app: Settings → Delete Account. It is in every build, it takes two taps and a confirmation, and it lists exactly what it destroys before you confirm. That is the complete path — you do not need to email us, and we do not make you.
If you cannot reach it — the app will not open, or you have already deleted the app — email flamm.alex@gmail.com and we will do it for you. Tell us anything that could identify the account: roughly when you installed it, and roughly when you last generated a design. Your account is anonymous, so we hold no email address or name to match you by, and with nothing to go on we may not be able to find the right account. That is a consequence of not collecting anything about you, and we would rather have that problem than the other one.
Deletion is a real cascade, not a hidden flag. Removing your account removes, in one transaction, your profile, projects, photo records, generations, credit ledger and balance, subscription record, conversations, and chat messages — and we separately delete both of your storage folders, so the actual image files go too. We have tested it: zero rows left behind across the eleven tables that hold your content.
Two things survive on purpose, and we would rather list them than round "everything" up to an absolute. The first is the billing records described in section 8 — the raw purchase and renewal events, kept for accounting and tax, with the link to your account identifier removed. The second is a daily tally of how many free credit grants we issued, which is a count and a date and nothing else: it holds no identifier of any kind and cannot be traced back to you or to anyone. Everything in the list above goes. It cannot be undone, and it does not cancel your subscription — cancel that in your Apple ID settings first (see Terms).
Get a copy, or ask us to fix something
Email us and we will send you a copy of the personal data we hold about you, or correct anything that is wrong. We will not charge you for it.
Delete a single room instead
You can delete individual projects and photos in the app without deleting your account.
US state privacy rights
If you live in California, Colorado, Connecticut, Virginia, or another state with a comprehensive privacy law, you have rights to access, correct, delete, and port your personal information, and to appeal a refusal. We do not sell personal information, we do not share it for cross-context behavioural advertising, and we do not use it for profiling that produces legal or similarly significant effects. Use the same email address for any of these requests; we will not discriminate against you for making one.
If you are in the UK or EU
You have the rights to access, rectification, erasure, restriction, portability, and objection. Our legal basis is performance of our contract with you for generating and storing your designs, your consent for optional items such as the in-app chat, and our legitimate interest in keeping the service secure and improving it. Your data is processed in the United States. You may complain to your local supervisory authority.
10. Children
RoomFigure is not directed to children. It is intended for people aged 13 and over, and the App Store listing is rated accordingly. We do not knowingly collect personal information from a child under 13. If you believe a child has given us data, email flamm.alex@gmail.com and we will delete it.
11. Security
Data is encrypted in transit. Both storage buckets are private, scoped so a file can only sit under its owner's folder, and served only through short-lived signed links. Row-level security is enforced in the database on every table, so one account cannot read another's rows. Server-only tables — billing events, attribution, internal counters — are not readable by the app at all. No system is perfectly secure, and we will not pretend otherwise; if we ever suffer a breach affecting your data we will tell you.
12. International transfers
We are based in the United States and our infrastructure runs in the United States. If you use RoomFigure from outside the United States, your data — including your room photos — is transferred to and processed in the United States, and may also be processed by our model providers in other countries where they operate.
13. Changes to this policy
If we change this policy we will update the date at the top. If the change is material — a new category of data, a new sub-processor receiving your photos, or a longer retention period — we will say so in the app before it takes effect.
14. Contact
Privacy questions, data requests, or complaints: flamm.alex@gmail.com. We aim to reply within a few business days and to complete deletion and access requests within 30 days.