Privacy policy
What romy collects, why, for how long, and how you take it back.
Last updated: 2026-09-03
This is a courtesy translation. romy is sold from France under French law, and the French version is the one that legally applies.
Who is responsible
Aurélien Hubert.
For any question or request about your data: hello@romy.app.
What we collect
romy runs on the following, and nothing is collected just in case:
- Your email address, to create your account and sign you in.
- Your room photo, which you upload yourself.
- The objects detected in that photo and the fate you give each one (keep, remove, replace).
- Your brief: style, renovation level, indicative budget.
- The generated renders, their shopping list, and the internal quality score.
- Your credits and, once purchases open and if you buy a pack, the corresponding receipt.
- Outbound clicks to brand shops, plus technical cost and latency measurements.
We use no advertising cookies, do no profiling, and never track you across sites. On the website, usage measurement happens entirely on our servers: nothing is stored on your device, which is also why you see no cookie banner. The iOS app uses a technical identifier provided by the system (the identifier-for-vendor), shared only across our own apps on your device. It persists between sessions and across updates, and is reset if you delete the app. It cannot be used to follow you into other companies' apps, and we use no advertising identifier.
Why, and on what legal basis
Each use has its own basis, and they are not interchangeable:
- Providing the service (performance of a contract): without the photo there is no render. This covers everything above except the two points below.
- Improving the product (consent): keeping your photo as a test case is a DIFFERENT purpose from delivering your render. It is off by default, asked per room, and as easy to withdraw as it is to give.
- Legal obligations: once sales take place, the matching receipts will be kept because the law requires it, independently of any account deletion. No sale has happened yet.
- Security and abuse prevention (legitimate interest): bot protection at sign-in, per-generation cost ceilings, and request and free-credit ceilings computed from a fingerprint of your IP address — the address itself is not stored.
- Understanding product usage (legitimate interest): knowing which steps succeed and which fail, so we can fix them. These measurements cover your actions, never the content of your photos or the text of your briefs.
For how long
- Room photo, renders, detected objects, briefs: kept as long as you keep the room. You can delete them at any time, and deletion removes the stored images too — not just the database rows.
- Purchase receipts, once there are any: kept to meet accounting obligations, even after the account is deleted. They then stop naming you.
- Waitlist entries, beta access grants, and a fingerprint of the email used to claim free credits: kept after account deletion, so the offer stays one per person. The fingerprint cannot be turned back into the address.
- Clicks and technical measurements: kept without your identifier once the account is deleted. They can no longer be traced back to you and are never re-linked.
If you turned on retention for product improvement, withdrawing it stops any future use of the photo. It cannot undo tests that already ran, and we would rather write that down than let you assume otherwise.
Who else sees it
We do not sell or rent any data. The following providers process it on our behalf:
- Supabase (Ireland, EU) — database, authentication, and storage of photos and renders
- Modal (EU) — running the generation engine
- Google (Gemini API — United States, and any other country where Google or its agents maintain facilities) — analysing your photo and generating the image; your room photo is sent to it as soon as you upload it, and again on every generation. Under the paid terms we use, Google does not use your photo to train its models; it keeps a copy for a limited period only, solely to detect abuse
- Google (Sign in with Google, United States) — if you choose that sign-in method
- Apple (Sign in with Apple, United States) — if you choose that sign-in method
- Sentry (EU region) — technical error reports; they carry your account identifier, never your email. If you report a bug from the iOS app, your message and the screenshot you choose to attach go there too — the screenshot is shown to you and you can remove it before sending
- Resend (United States) — sending sign-in emails
- Cloudflare Turnstile (United States) — bot protection on the email sign-in form (currently not displayed, so no data reaches it; kept declared because the form returns)
- Amplitude (Germany, EU) — product usage measurement: the actions you take in the app, tied to your account identifier
- Vercel (United States) — website hosting
- Stripe (Ireland, EU) — credit pack payments on the website. Purchases are not open yet: to date no data has been sent to it
- RevenueCat (United States) and Apple — purchases from the iOS app, once it is published. They then receive your account identifier and the transaction reference; if you ask Apple for a refund, we also tell Apple, through RevenueCat, that the purchase concerned was delivered to you — never your usage of it
Providers outside the European Union operate under the European Commission's standard contractual clauses.
Shared pages
If you create a share link for a render, that page becomes PUBLIC: it shows the render and your original room photo side by side, and it can appear in search engines. Nothing is shared unless you do this.
You can turn sharing off at any time, and the page stops responding immediately. The preview shown in messaging apps may still be cached on our own delivery network for up to an hour, and an image link already handed out stays valid for up to twenty-four hours. Search engines and messaging apps may keep a copy for longer still, which is outside our control.
Your rights
You have the right to access, correct, erase, port, restrict and object to the processing of your data, and to withdraw your consent at any time.
Write to hello@romy.app; we answer within one month. You may also lodge a complaint with the CNIL, the French data protection authority (www.cnil.fr).