Trust
Everything checkable, nothing blurred
Rooms holds money conversations between people who trust each other unevenly. That only works if you can verify what the product claims. This page is the product’s promises in plain words — what it is, what it never is, and how you can check.
Boundaries
What this product is — and is not
Rooms is
- A shared, auditable record of a group’s commitment
- The place where the plan, the people, and the money states live together
- A coordinator — it collects what the group agreed, when the group agreed
Rooms is not
- Not a bank, and it never pretends to be one
- Not a wallet — there are no stored balances here
- Not escrow, lending, investing, or anything crypto
The practical consequence: your money never sits “in Rooms.” The product keeps the record; licensed payment partners move the money.
Money routing
Where the money actually goes
When a room collects, each payment is processed by a payment partner — a licensed provider whose job is moving money. The room states the destination and timing before you confirm, tracks the partner’s reported state of every payment, and writes each step into the record. Rooms itself never holds a balance for you, and a payment is only ever called settled after the partner confirms it.
SandboxToday, plainly: this is a sandbox. Every payment runs against a simulated partner, and no real money moves here — the full flow is real, the euros are not. Real payment partners arrive in a later stage, behind the same rules.
Your account
Identity and sessions
What we store about how you sign in is deliberately minimal. Your password is never stored — only a scrypt hash of it, which cannot be reversed into the password. Sign-in tokens live in an HttpOnly cookie in your browser; our database keeps only their hashes, so a copy of the database alone can’t impersonate you.
Sessions expire on their own — after 14 days of inactivity, and 90 days no matter what — and you can see every device signed into your account and revoke any of them from settings, instantly. Resetting your password signs out every other session as a matter of course.
A session, as settings shows it
Sample dataiPhone · Safari
This deviceStarted June 2 · last active just now · expires on its own by August 31
Every other session shows here too, each with its own revoke action in settings.
Invitations
Invitation safety
Room invitations are single-purpose links: each token is generated once, stored only as a hash, expires after 14 days, and can be revoked by the organizer at any time. Accepting one twice is harmless. Before you sign in, an invitation shows you only what you need to decide — the room’s name, its purpose, who’s organizing, your expected share, and the deadline. Never the group’s full money detail.
If a link looks off
- Check the domain in your address bar before signing in. A real invitation always lives on this site’s domain — nowhere else.
- We never ask for your password inside a room, in an invitation, or by email. A page that does is not ours — close it.
- When in doubt, ask the organizer to revoke the link and send a fresh one — it costs them two taps.
The record
Every change is an event you can read
A room’s history is append-only. Every meaningful change — a commitment, a payment state, an edited target, a member joining — is written as an event with who, what, and when. Events are never edited and never deleted; corrections are new entries that say what they correct. “Wait, who changed that?” is a question the record answers, not a fight.
The record, inside a room
Sample data- Today, 14:02Priya’s €375.00 is on its way — the payment partner is processing it.
- June 5, 09:41Jonas chipped in €375.00 — settled.
- June 1, 18:20The room opened — Amara set the target and invited three people.
A receipt line, from the ledger
Sample dataJonas Weber’s contribution — Lisbon, June
€375.00
Settled June 5 · entry led_04t8 · caused by event evt_9c2d · confirmed by the payment partner
Every settled amount has a line like this: the amount, the confirmation, and the exact event that produced it. Corrections appear as new lines, never as edits.
Privacy
What we keep, and what we don’t
We store what the product needs to work and show you: your account (name, email, password hash), your preferences, the rooms you’re in with their event history, and a security audit log of actions on your account. Room history is shared with the people in the room — that’s the point — and with no one else.
There are no third-party trackers on these pages and nothing is sold to anyone. Payment credentials are the payment partner’s business, not ours: card and bank details never touch our database. The full draft policy says all of this with dates and specifics — see the privacy draft.
When money misbehaves
Failures, refunds, and disagreements
Failed payments tell the truth. When a bank declines, the room says exactly that — “nothing moved” — shows the broken state distinctly, and offers the retry. A failed payment is never blended into progress, and nothing is ever labeled paid while a partner still reports it processing.
Refunds are entries, not erasures. When money goes back — a cancelled trip, an over-collection, a departing roommate — the refund is its own recorded entry with its own math. History never rewrites; it accumulates.
Disputes start from facts. Because every change is in the record, a disagreement is about what to do next, not about what happened. Most “disputes” in group money are memory problems; the record deletes those before they start.
Availability
When something breaks, we say so
The status page reports what’s actually running. Right now that page describes the sandbox reference environment — honestly labeled, with no invented uptime numbers. Production telemetry arrives with launch, and the same plain-speaking rule will apply to incidents: what broke, whether your data was affected, and what we did.
Definitions
The four money states, in plain words
Every amount in a room is always in exactly one of these states — each with its own word, its own texture, and its own meaning. They are never blended into one number.
- Promised
- Someone said “I’m in.” It’s a commitment everyone can see — and no money has moved.
- On its way
- A payment has started and the partner hasn’t confirmed it yet. We never call this paid, because it isn’t — yet.
- Settled
- The payment partner confirmed the money arrived. The only state that ever reads as paid.
- Needs a retry
- The attempt didn’t go through and nothing moved. The room says why and offers the fix — quietly, without alarms.
The fine print
The legal drafts
The terms and privacy policy are published as clearly-labeled drafts, written in the same plain language as this page and describing what the product actually does today. They’ll be reviewed by counsel before launch — and if anything changes, the change will be visible, like everything else here.