Privacy policy
Last updated 28 September 2026
The short version
- Roomy is a link page drawn as a room. Rooms are public: anyone with the link can see yours.
- To make a room, you sign in with Discord or with a link we email you. There are no passwords.
- We keep what we need to run your room, and little else.
- Visiting a room needs no account. We count visits without cookies, and you can ask us not to count yours.
- We don't sell your information, and there are no ads.
- You can delete your account yourself in Settings, at any time, or ask us at privacy@roo.my.
- Roomy is for people aged 13 and over.
- Keep private details out of your room: no home address, school or phone number.
Who we are
Roomy, at roo.my, is run by Quartz Apps LLC, a Wyoming limited liability company whose post goes to c/o Cloud Peak Law, 1309 Coffeen Ave STE 1200, Sheridan, WY 82801, United States. We decide how your information is used, so under UK and EU law we are its "controller".
Write to us about privacy at privacy@roo.my.
What we collect, and why
When you visit a room
- Connection details. Our host, Cloudflare, receives your IP address and browser details to send you the page, as every website's host does. Technical logs of requests (what was asked for, when, and connection details) are kept for 7 days, to fix faults and stop attacks.
- Visit counts. A room shows how many visits it has had, and how many knocks visitors have left. To count each visitor once a day, we keep two scrambled codes (keyed hashes) for each room you visit: one made from your network address, your browser's description and the date, and one from your network address and the date alone, so one address can't count as many visitors. They can't be turned back into your address, they are different every day, and we delete them after two days. No cookie is used.
- Links you tap. A link in a room takes you to another website, which has its own privacy policy. We don't tell that site which room you came from.
- Analytics. See Analytics.
When you report a room
A report records the room, the reason you picked, the time, and a scrambled form (a keyed hash) of your connection's network address. For newer (IPv6) addresses, we use the network parts of the address, not the whole of it.
We never ask for your name, your email or a message. The room's owner is never told who reported it.
We use the hash to stop one person sending a flood of reports, and to see when many reports come from one place. A hash of an IP address still counts as personal information, and we treat it that way.
Checking that you're a person
When you ask for a sign-in link, claim a name or send a report, Cloudflare Turnstile checks that you are a person and not a script. To do that, it looks at your browser and connection, and Cloudflare uses what it sees only to tell people from bots.
When you sign in with Discord
Discord asks you to let Roomy see some details. This is what we do with them.
- Your Discord user ID. Kept, so we know it's you next time.
- Your username and display name. Shown in the editor so you can see who is signed in. Kept only in your sign-in cookie, never in our database.
- Your email address. Kept only if Discord says it has verified it. Then you can also sign in with an email link, and if you already have a Roomy account with that address, the two become one account.
- The accounts connected to your Discord profile, like Spotify or GitHub. Read once, to suggest links for your room. We only use the ones you've made visible on your profile and that Discord has verified. Suggestions start unticked, and nothing is kept except the links you choose to add.
Discord also sends some profile details we don't use, such as your avatar. We discard them. The access Discord gives us is used once, during sign-in, and never stored. Roomy stays listed under Authorized Apps in your Discord settings until you remove it there.
When you sign in with email
- Your email address, kept with your account.
- A record of each sign-in link: a scrambled form (a hash) of the link, never the link itself; your email address; a simplified form of it that we use to count requests; a scrambled form (a keyed hash) of your network address or, on a browser that has signed in before, of a random code that browser keeps; and when the link was made, when it expires and when it was used. A link works once, for 15 minutes.
- A short-lived cookie that remembers the address you typed, so the link signs you in with one tap on the same device.
We send sign-in emails through Cloudflare. Cloudflare keeps a copy of each email we send, sign-in links included, for about 7 days.
Your room
Your room is public. Anyone with its link can see it. You can make it Unlisted in Settings: then it is shown only to people who have the link, is never suggested on other rooms, and asks search engines not to list it. We keep:
- your handle, the name in roo.my/yourname;
- your room's layout: which objects, where, and in which colours;
- your links: each address, which site it is for, and the result of our safety check;
- your pictures (see below);
- your bio, if you write one;
- whether the room is public, unlisted or paused, and when it last changed.
Share cards. We make a picture of your room, with your handle, its address and any pictures you have hung, so the link looks good when someone shares it, for example in Discord. We keep each card for 30 days. Apps that have already shown a card may keep their own copy, which we can't recall.
Link safety checks. When you save a link to a site that could be anywhere on the web, we check its address against Google's list of unsafe sites (Google Web Risk), and we check every such link again about once a week. Only the link's address is sent, and nothing about you. If you remove a link, we keep its address and the result of its last check until your room is deleted, so an unsafe link can't come straight back.
Pictures you upload
Each room has two frames that can hold a picture. Your phone or computer does the cropping, so your original photo never leaves your device. We receive only the crop, at a small fixed size. We shrink it to 62 by 54 pixels (or 30 by 54) and 20 colours, and keep only that version, about 2 KB. It carries no location or camera details.
- We keep a record of which account uploaded which picture, and when. It limits uploads to 6 a day and helps us act on reports.
- A picture that no room shows, not even a paused one, is deleted once it is 7 days old, by a daily clean-up. Until then, anyone who has its exact address can still load it.
- When we take a picture down, we keep it out of sight instead of deleting it, so it can't be uploaded again and can be put back if we got it wrong. A picture taken down for child safety is kept for a year after we report it, as US law requires. One taken down after a copyright notice, or for breaking the rules, is kept until the matter is settled, for example so it can be put back after a counter-notice.
- When we ban a picture, we delete it and keep only a fingerprint of it (not the picture), so it can't be uploaded again.
- We use Cloudflare's CSAM Scanning Tool, which compares what our site serves against known child sexual abuse material.
If we hold a name for you
If we hold a handle for someone, for example a creator who asked before launch, we keep the name, a short note, and the email address it is held for. We keep them while the name is held, and after it is claimed as our record of who it was for, until it is released or that account is deleted.
Coins
Coins are Roomy's currency: you earn them and spend them inside Roomy, and nobody can buy them (see the Terms). To keep every balance right, we keep:
- every change to your coins: how many, what for (a claimed room, an invite, a tip, something you got for your room, a correction), and when. For a tip or a gift, it also records the other account. An entry is never changed or deleted: a correction is a new entry, with a note of why for our team.
- your balance, which is always the sum of those entries.
- your invites. When someone claims a room after opening your invite link, we record who invited whom, when, whether the claim passed the bot check, and whether the invite was paid, or why not.
- the network your room was claimed from, as a scrambled code (a keyed hash) of your connection's network address. It stops one person earning coins by inviting their own extra accounts, or by claiming room after room from one place. It can't be turned back into your address.
- the inbox your room was claimed with, as a scrambled code (a keyed hash) of your email address, or of your Discord ID if your account has no email. For a Gmail address the code ignores dots and anything after a +, because Gmail delivers all of those to one inbox. It means one inbox earns the claim coins once, and can be invited once, even after deleting an account. It can't be turned back into your address or your Discord ID.
Who sees it. Your Wallet (roo.my/wallet) shows only you your balance, your history and your invites. When you tip a room, its owner sees your room's address in their Wallet. If you claim a room after opening someone's invite link, they see your room's address in their list of invites, and once the invite is paid you see theirs in yours. Nobody else sees any of it.
When we act on a room
When we take something down, pause a room or suspend an account, we keep a record of what we did, when, and why. If it happened to your room, we tell you in the editor, and by email if your account has an address. We keep the record after an account is deleted, because it is how we answer complaints and appeals.
When you email us
We keep your message and our reply, so we can help you and keep a record.
Our legal reasons (UK and EU)
UK and EU law asks us to give a legal reason for each use of your information.
| What | Legal reason |
|---|
| Your account, sign-in, room, links and pictures | Contract: it's the service you asked for |
| Coins, invites and tips | Contract: they are part of the service you use |
| The network and inbox codes from a claim | Legitimate interests: stopping one person from farming coins with extra accounts |
| Link suggestions from Discord | Legitimate interests: a quicker setup, and you pick what stays |
| Joining your Discord and email accounts | Legitimate interests: one person, one account |
| Logs, limits, bot checks and IP hashes | Legitimate interests: keeping Roomy safe and working |
| Visit counts | Legitimate interests: showing a room's visits, each visitor counted once a day |
| Reports, moderation and link checks | Legitimate interests: keeping people safe |
| Keeping and reporting illegal material | Legal obligation, where a law we're under requires it |
| Answering your emails | Legitimate interests |
| Analytics | See Analytics |
Where we rely on legitimate interests, you can object, and we will stop unless there is a strong reason to go on, such as someone's safety.
Cookies and storage
Roomy stores things on your device only when you sign in, use the editor, open an invite link, or ask us not to count your visits. None of them follow you around other websites.
__Host-roomy_session, 30 days: keeps you signed in. It holds your account ID and display name, signed so nobody can change them. Signing out removes it.__Host-roomy_oauth, 10 minutes: protects the Discord sign-in step.__Host-roomy_mail, 30 minutes: remembers the email address you typed, so your link signs you in with one tap on this device.__Host-roomy_known, 1 year: remembers, as a scrambled code and never as the address itself, that this browser has signed in to your inbox before, so other people asking for links to your address can't lock you out. Signing out removes it.__Host-roomy_offers, 30 minutes: carries link suggestions from Discord to the screen where you choose your name.__Host-roomy_ref, 30 days: set when you open someone's invite link, so that if you then claim a room, the invite counts. It holds their account ID and when it expires, signed so nobody can change them.__Host-roomy_nocount, 1 year: set only when you press "Don't count my visits". It says nothing but that.roomy.inventory, until you close the tab: remembers where you were in the editor's tray.roomy.sound, until you clear it: remembers whether you turned the editor's sound on.
All of these are needed for something you asked for, so they don't need your consent. Our cookies are locked to roo.my and can't be read by scripts.
Analytics
We count visits with Cloudflare Web Analytics. It sets no cookies and stores nothing on your device. It tells us which pages are visited, which site sent the visitor, and broad facts such as the type of device and the country. We never count sign-in, editing or settings pages. Legal reason: legitimate interests, knowing which parts of Roomy people use.
You can object in two ways. If your browser sends the Global Privacy Control signal, we don't count your visits. Or press "Don't count my visits" below: it sets the one cookie above, and you can press "Count my visits" to undo it.
Who we share it with
We don't sell your information, and we don't share it for advertising.
These companies help us run Roomy, and handle your information only to do that:
- Cloudflare (USA): hosting, our database, storage, email sending, bot checks, analytics and security.
- Discord (USA): sign-in, only if you choose it.
- Google (USA): link safety checks. Only the link's address is sent.
- Our email provider: stores the messages you send to our @roo.my addresses, which Cloudflare forwards to it.
We also share information:
- when the law requires it, or to protect someone from serious harm. If we find child sexual abuse material, we report it to the National Center for Missing & Exploited Children (NCMEC) in the US, and keep what the law requires;
- if Roomy changes hands, with the new owner, who must keep these promises or tell you first;
- when you ask us to.
Inside Quartz Apps LLC, only the people who run and moderate Roomy can see account details, and only to do that work.
We are in the United States. Our providers store information in the US and across Cloudflare's worldwide network. If you are in the UK or the EU, your information goes to the US. Our providers protect it with approved safeguards, such as the EU-US Data Privacy Framework with its UK extension, or standard contractual clauses.
How long we keep it
- Your account (its ID, your Discord ID and email, when you last signed in): until you delete it.
- Your room and its links: until you delete your account, or remove the link.
- Links you removed, with their last safety check: until your room is deleted.
- Your coin entries and invites: as long as Roomy runs, because every balance is the sum of its entries. If you delete your account, they stay with an account that has nothing left in it: no email, no Discord ID and no room.
- The network and inbox codes from your claim, and the network code from an invite's claim: as long as the account, and after a deletion, with what is left of it, so deleting an account and claiming again with the same inbox can't earn the claim coins twice, or be invited twice.
- Visit counts: as long as the room.
- The daily visitor codes: 2 days.
- Pictures: while a room shows them, then until the daily clean-up once they are 7 days old.
- Who uploaded each picture: until the picture is deleted, or you delete your account, whichever comes first.
- Fingerprints of removed pictures: as long as Roomy runs.
- Pictures taken down for child safety: a year after we report them, as US law requires.
- Pictures taken down after a copyright notice, or for breaking the rules: until the matter is settled.
- Sign-in link records: a day or two after the link expires or is used, by a daily clean-up.
- Reports: kept as our record of moderation. The IP hash in a report is deleted after 12 months.
- Our record of what we did to a room or an account: kept as our record of moderation.
- Messages telling you what we did: about a year after we've told you.
- Names held for someone: until released, or until the account they were held for is deleted.
- Counters that limit how often something can be done: until their time window closes.
- Share cards: 30 days.
- Technical logs: 7 days.
- Copies of emails we send: about 7 days.
- Emails with us: 2 years.
- Backups: our database keeps 30 days of history for recovery, and we keep weekly copies of it outside Cloudflare for about 8 weeks. So deleted information is fully gone about 8 weeks after it is deleted. Pictures held for child safety are never in those copies.
We keep anything longer only when the law requires it. For example, US law says to keep material reported to NCMEC for a year after the report.
Your rights
Wherever you live, you can ask us to:
- show you the information we have about you, and give you a copy;
- correct it;
- delete it;
- send it to you in a standard format, to take elsewhere;
- stop or limit a use of it, or object to one;
- withdraw a consent you gave.
Do it yourself. If you have a room, Settings (roo.my/settings) lets you download a copy of your information as a file, change your email address, and delete your account.
How to ask. Email privacy@roo.my with your handle. If your account has an email address, write from it. To protect you, we check that the request comes from you before we act. If your account has no email address, sign in with Discord and delete it yourself in Settings, or add an address there and write from it. If you signed in but never claimed a room, we hold only how you signed in and when: write to us, and we will tell you how to show it's you. We reply within 30 days.
Deleting your account. Delete it yourself in Settings, and it happens at once. Or email privacy@roo.my with your handle, and we delete it within 30 days. That removes:
- your account and your sign-in records;
- your room, its links, its visit counts and the notices we sent you;
- your pictures, unless another room shows the same picture or someone else uploaded it too;
- the record of what you uploaded;
- the email address on any name we were holding for you;
- your coins, which can't be used again.
Your share cards stop being shown at once, and are deleted within 30 days. Your handle is then held for 90 days before anyone else can claim it, so old links to your room don't lead straight to a stranger's.
We keep only: reports about your room, and our record of what we did to it, as our moderation record; pictures we took down and are keeping out of sight, for as long as the list above says; your coin entries and invites, and the network and inbox codes from your claim, with your account emptied, as the list above says; any purchase records the law makes us keep, with your account removed from them; and anything else the law requires. If the law requires us to keep an account, for example while a child-safety report is open, we can't delete it until that ends.
Complaints. If you're unhappy with how we handled your information, please tell us first at privacy@roo.my. You can also complain to your data protection authority: in the UK, the Information Commissioner's Office (ico.org.uk); in the EU, the authority in your country.
Children
Roomy is for people aged 13 and over. We don't knowingly collect information from anyone younger. If we learn that an account belongs to a child under 13, we delete it.
If you're a parent or guardian and think your child under 13 has a Roomy account, email privacy@roo.my with the handle, and we will delete it.
Roomy is built with young people in mind: there are no messages, no comments, no location tracking and no ads.
Keeping it safe
- There are no passwords to steal. Sign-in links work once, for 15 minutes, and we store only a scrambled form of them.
- In our database, IP addresses are stored only as scrambled hashes, for counting.
- If a security problem ever puts your information at risk, we will tell you, and the authorities, as the law requires.
Found a security problem? Tell us at security@roo.my.
Changes to this policy
When we change this policy, we change the date at the top. If a change matters, we tell account holders before it takes effect, by email where we have an address, and with a notice on roo.my.
- Privacy: privacy@roo.my
- Anything else: support@roo.my
- Post: Quartz Apps LLC, c/o Cloud Peak Law, 1309 Coffeen Ave STE 1200, Sheridan, WY 82801, United States