Privacy
Pre-legal draft
Draft — not yet reviewed by counsel.
This is a working draft, written by the people building Roomful and published early so that what the product does with your data is legible before anyone trusts it with any. It describes the product as it is actually built. It is not legal advice, and a lawyer has not read it.
What we store
- Your account. When you sign in with Google we receive and store your name, your email address and your profile photo. Sign-in asks Google for identity only.
- Your profile. Your handle, headline, role, company, a short bio, pronouns, city, time zone, interests and any links you add. You write all of it and you can change or clear any of it.
- Your contact details. Your email address, plus a phone number and any private links if you choose to add them. These are readable by you and by people you have actually connected with, and by nobody else — handing them over is what accepting a request does.
- Your declarations. The three lines you write for an event — what you are working on, what to ask you about, what you want from the evening — at most 70 characters each.
- Your attendance. Which events you registered for, whether you are going, waitlisted or cancelled, and the moment you checked in.
- Your messages. Direct messages with people you have connected with, event group chat, and announcements hosts send to their guests.
- Your scheduling. Your working hours, your meeting types, and every booking made on your page — including the name, email address, time zone and note the person booking you supplied.
- Your calendar free/busy. If you connect Google Calendar, we read the times you are busy so your booking page does not offer a slot you cannot make. Free/busy is start and end times only: never the title of a meeting, never its guests, never its contents.
- Intake transcripts. If you write your three lines by speaking or by pasting text, we hold the raw transcript while a model turns it into three lines.
- Email we sent you. A record of which emails went out, so we do not send the same one twice.
- Cookies. A session cookie so you stay signed in, and a cookie remembering whether you chose the light or the dark theme. No advertising cookies. No third-party trackers.
What we never do
- We do not sell your data, to anyone, for anything.
- We never send you an SMS. Everything reaches you in the app or by email.
- We never tell anyone that you declined their connection request. See below — this one is structural, not a promise about our manners.
- We never show your email address to another attendee unless the two of you connected, which is a mutual, deliberate exchange.
- We do not use your messages to train models or to build an advertising profile of you.
Who can see what
- An event page is public. It shows how many people are going and the first names of a few of them. If you would rather not appear, set your attendance to hidden when you register.
- Your three lines are visible only to people who are checked in to the same event and are themselves open to talk. They are not public, not indexed by search engines, and not visible to anyone before they walk in the door. The floor closes 48 hours after the event ends.
- A connection request reaches the person you tapped. If they accept, the two of you exchange cards — that acceptance is the business-card exchange, and it goes both ways at once.
- A decline is invisible. If someone declines your request, we do not tell you: no notification, no email, no message, no change on your screen, and nothing you could query to work it out. A declined request is built to be indistinguishable from one that has simply not been opened yet. This is the one rule in this product we will not trade away for any other feature.
- An event recap stays unlisted until the host chooses to publish it. When it is published it uses first names only, and anyone whose attendance was hidden does not appear on it at all. You can also share a recap of your own: that page is created only when you ask for it, shows your name, your picture and how many people you connected with — never anyone else's card — and you can stop sharing it at any time.
- Your card page is public while your profile is discoverable. Turn discoverability off in Settings and it stops being reachable by handle.
Google Calendar
Connecting Google Calendar is optional, separate from signing in, and asked for only when you need it. These are the permissions and what each one is for:
- openid, email, profile — at sign-in. To know who you are and to have an address to reach you at.
- calendar.freebusy. To read when you are busy so your booking page only offers times you can actually make. It returns busy intervals; it does not return what the meetings are.
- calendar.events. To put the meeting on your calendar when someone books you, and to update or remove it when that booking is rescheduled or cancelled.
Google lets you grant one of these and refuse the other. If you refuse the second, we tell you plainly and your booking page keeps working without writing to your calendar.
The access and refresh tokens Google issues are encrypted at rest. They are never sent to a browser and never readable by another user; only server-side code that talks to Google can use them.
You can disconnect at any time in Settings. Meetings already on your Google Calendar stay where they are and simply stop syncing; new bookings skip Google entirely.
AI features
Three surfaces send text to a model provider through Vercel AI Gateway: turning what you said or pasted into three lines, drafting an event description for a host, and writing the one-line reason two people at an event might want to talk. What is sent is the text those features are about — your three lines, the event details — never your messages and never your calendar. Every one of these features falls back to a plain template when the model is unavailable, so nothing depends on it.
How long we keep it
- Voice and paste transcripts are purged within 24 hours of your saving the three lines they produced. The three lines stay; the raw transcript does not.
- Everything else stays until you remove it or delete your account.
Deleting your account
Settings → Account → Delete account. You will be asked to type a confirmation first, because this is not reversible. Deleting takes your profile, your declarations, your RSVPs, your messages, your connections and your booking history with it.
One exception, and it is deliberate: if you have hosted events, the database refuses to delete a host out from under a published event — the people who attended it have a stake in it too. Write to us and we will transfer those events to another host or take them down, whichever you want.
Who else touches your data
Roomful runs on Supabase (database, sign-in, file storage) and Vercel (hosting). Email is delivered by Resend. Calendar features talk to Google. AI features talk to a model provider through Vercel AI Gateway. That is the whole list.
Asking us something
Any question about your data, including a request for a copy of it, goes to support@roomful.co.in. A person answers.