Legal · Draft
Privacy policy
- Version:
- v0.2 — draft
- Drafted:
- July 17, 2026
- Effective date:
- Not yet in effect — takes effect at public launch, after counsel review
This draft describes what Rooms actually does with data today, in plain words. It is published early so you can read it before it binds anyone — and so that when it does take effect, nothing in it will be a surprise.
Section 1
What this policy covers
This policy covers the Rooms product — the public pages and the signed-in app — in its current sandbox reference stage. It describes the data that exists, why it exists, how long it lives, and what you can do about it.
Section 2
The data that exists
- Your account
- Your name, your email address, and a scrypt hash of your password. The password itself is never stored and cannot be recovered from the hash — not by us, not by anyone.
- Your preferences and consents
- The settings you choose: locale, timezone, display currency, theme, reduced motion, amount privacy, and notification switches — plus a dated record of each consent you grant or withdraw (analytics, marketing), so your choices are as auditable as everything else.
- Rooms and the record
- Every meaningful change in a room is an append-only event: who committed, what was collected, what changed, when. This record is visible to the members of that room — that visibility is the product — and to no one else. Events are never edited or deleted; corrections are new entries.
- Security records
- Sessions (stored as token hashes, with the browser description and timestamps), an audit log of security-relevant actions on your account, and short-lived hashed verification, recovery, and invitation codes. These exist so you can see what happened to your account and revoke what you don’t recognize.
- Your address is used for sign-in verification, recovery, and the notifications you switch on. In the current sandbox stage, no real email is delivered at all — messages render to a local outbox in the reference environment.
SandboxThe current environment is a sandbox: money is simulated, email never leaves the machine, and the data above lives in a reference database that may be reset between build stages.
Section 3
The data that doesn’t exist here
- No card numbers, bank credentials, or payment details — money moves through payment partners, and payment credentials are theirs to hold, never ours.
- No third-party trackers, advertising pixels, or analytics vendors on these pages. Product analytics is an internal, schema-only event log.
- No sale of data, no sharing for advertising, no profiles built for anyone else’s benefit.
- No silent collection: if a kind of data isn’t listed in section 2, the product doesn’t hold it.
Section 4
How long data lives
- Sessions expire on their own: after 14 days of inactivity, and 90 days at the outside. Expired and revoked sessions remain in the security record so you can review them.
- Verification and recovery codes are single-use and short-lived; they are stored only as hashes and become useless the moment they’re used or expire.
- Room history is retained for the room: the record belongs to the group that made it, and it stays readable to those members even after individual people leave.
- The audit log is retained so that questions about account security can be answered with facts.
Section 5
Your choices
Settings is where your choices live, and every switch there does what it says: edit your profile, change preferences, grant or withdraw analytics and marketing consent, see every signed-in session, and revoke any of them instantly.
Closing your account starts from settings as well. When an account closes, your sign-in ends everywhere and your account data stops being used. What closing never does is rewrite shared history: events you created in a room remain part of that room’s record, because the record belongs to everyone who lived it.
Section 6
Changes to this policy
This policy is versioned like the product. Any change produces a new version with a new date at the top of this page, and material changes will be announced before they take effect. The current version is v0.2 — draft, drafted July 17, 2026.
Section 7
Questions
The plain-language version of these commitments — boundaries, security, and money definitions — lives on the trust page. A monitored privacy contact address arrives with launch; in the sandbox stage there is deliberately no pretend inbox here.