Privacy Policy
Last updated: July 20, 2026
This Privacy Policy explains what information The Room ("we," "us," "the Service," available at theroom.chat) collects, how it's used, and what choices you have. The Service is operated by Alex Avellaneda, based in Thailand, doing business as The Room.
1. Information we collect
Account information. Username, email address, and a password (stored as a one-way hash — we never store or can recover your actual password). If you registered using a beta invite code, we retain a record of that code.
Conversation content. Messages you write and AI responses generated are stored so you can return to past sessions. This includes files you upload (for example, in Handoff mode).
Usage and billing data. We track your usage (measured in credits) to enforce free and paid plan limits. If you subscribe, we store your subscription status and a reference ID linking your account to Stripe, our payment processor. We never see or store your full card number — Stripe handles payment details directly.
Technical and session data. A session cookie keeps you logged in for up to 30 days. We log IP addresses for rate-limiting and abuse prevention, and basic usage events (e.g. when a session starts or completes) to understand and improve the Service. Our operational logs record only technical metadata about AI responses (status, length, timing) — not the content of your messages or the AI's responses.
2. How your content is used
Third-party AI providers. To generate responses, your messages (including relevant conversation history for context) are sent to the AI providers powering the Service: Anthropic (Claude), OpenAI (GPT), and xAI (Grok), depending on the mode and voice in use. These providers process your content to generate a response. We don't control their independent retention practices; as of this writing, OpenAI states API inputs/outputs are not used for training by default, and xAI states API requests are retained for 30 days by default and not used for training without permission — but provider policies can change, and you should review their current terms if this matters to you.
Uploaded files. Supported file types (documents, images, depending on mode) are processed and their extracted content may be stored as part of your saved session and transmitted to the relevant AI provider for that track. In Handoff mode specifically, a file uploaded to one track is still processed by that track's AI provider — it is not kept confidential from that provider merely because it's separated from the other track. Do not upload confidential material, other people's personal data, financial credentials, or content you don't have the right to share.
Automated safety screening. Messages may be automatically screened by an AI classifier for language indicating a mental health crisis or potential self-harm. This screening is automated, not reviewed by a human in real time, and may interrupt the normal response to surface supportive resources. It does not make clinical diagnoses and does not notify emergency services on your behalf. The Room is not a mental health service, and this screening is not a substitute for professional care or emergency services. See Section 8.
Email. If you request a password reset, we send a one-time email via Resend, our transactional email provider.
Information about other people. If you enter information about someone else (for example, in a conversation or uploaded file), you're responsible for having a lawful basis or that person's permission to do so.
3. What we don't do
We don't sell your data. We don't use your conversation content to train our own models. We don't display advertising or share your data with advertisers.
4. Purposes and legal bases
| Processing | Purpose | Typical legal basis |
|---|---|---|
| Account and sessions | Provide the Service | Contract |
| Sending your messages to AI providers | Generate responses | Contract |
| Usage limits, rate limiting | Protect and operate the Service, prevent abuse | Contract / legitimate interests |
| Billing | Manage your subscription | Contract / legal obligation |
| Crisis screening | Provide the safety feature | Contract / legitimate interests |
| Records for tax/accounting | Legal compliance | Legal obligation |
5. Data retention
- Active-account conversations: retained while your account is active.
- A conversation you delete: removed from the app immediately; may persist briefly in routine backups until they roll off our normal backup rotation.
- Full account deletion: see Section 6 — data purged within 30 days of a confirmed deletion request.
- Session cookies: up to 30 days.
- Operational/server logs: approximately 30 days.
- Billing and tax records: retained longer, as required by applicable tax and accounting law (commonly several years).
- Provider-side retention: governed by each AI provider's own policy (see Section 2).
6. Account deletion
The Service does not currently offer self-service account deletion. To delete your account and associated data, email us at support@theroom.chat. We will process deletion requests within 30 days.
7. Your privacy rights
Depending on where you live, you may have rights to access, correct, delete, restrict, or object to our processing of your data, to receive a copy of your data (portability), to withdraw consent where we rely on it, and to lodge a complaint with your local data-protection authority. To exercise any of these rights, contact us at support@theroom.chat.
8. Not a substitute for professional care
Circle mode and other parts of the Service may surface content related to emotionally difficult topics. The Service, including its automated crisis screening, is not a licensed therapist, counselor, or emergency service, and using it does not create a therapeutic or clinical relationship. If you are in crisis or experiencing a medical or mental health emergency, contact local emergency services or a crisis hotline directly.
9. International data transfers
The Service and the third parties we use (Anthropic, OpenAI, xAI, Stripe, Resend) may process data outside your own country, including in the United States. By using the Service, you understand and agree that your data may be transferred to and processed in these countries, and we rely on the standard contractual and security safeguards that these providers already maintain for international data transfers.
10. Children's privacy
The Service is intended for users 18 and older. We do not knowingly collect data from anyone under 18.
11. Security
We take reasonable measures to protect your data, including password hashing and encrypted connections (HTTPS). No system is perfectly secure, and we can't guarantee absolute security.
12. Sensitive information
The Room is not designed as a secure repository for medical records, legal documents, trade secrets, passwords, financial credentials, or other highly sensitive information. Please don't submit this kind of material.
13. Breach notification
If we become aware of a security breach affecting your data, we will notify you and any relevant authorities as required by applicable law.
14. Changes to this policy
We may update this policy from time to time. Material changes will be noted with an updated "Last updated" date.
15. Contact
Alex Avellaneda, operating The Room from Thailand. Questions about this policy: support@theroom.chat.
Une version française de cette politique sera disponible prochainement. En cas de conflit entre les versions, la version anglaise prévaut.
Need help? support@theroom.chat