How we protect and handle your data
Rōmy ("we," "us," "our," or "Company") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our AI-powered chat platform designed to help small nonprofits find new major donors (the "Service").
This policy applies to all users of Rōmy, whether you use the Service with cloud storage (Supabase) or in local-only mode. By accessing and using the Service, you consent to the data practices described in this policy. If you do not agree with this policy, please do not use the Service.
When you create an account using Google authentication, we collect:
We collect and store:
When you upload files (donor lists, spreadsheets, documents), we collect:
We collect your settings and preferences, including:
We automatically collect:
We may collect:
Through PostHog (optional, when configured):
When you sign in with Google:
When you use the Service with integrated search or data services (e.g., Exa, Linkup):
We use the information we collect to:
If you are located in the European Economic Area (EEA) or United Kingdom, we process your personal data on the following legal bases:
You have the right to object to processing based on legitimate interests. See Section 8 for how to exercise this right.
We retain your data for as long as your account is active or as needed to provide the Service. This includes:
Accounts inactive for 24 months or longer may be subject to deletion after we provide notice (via email or in-app message). You will have 30 days to reactivate your account before deletion.
When you delete your account, we will:
Data stored in your browser's IndexedDB or localStorage remains on your device until you:
We do not have access to this locally stored data unless you explicitly sync it to our cloud services (Supabase).
When you enable cloud synchronization:
When you use local-only mode:
We do not sell, rent, or trade your personal information. However, we may share your data with trusted service providers who assist us in operating the Service:
| Provider | Purpose | Data Shared |
|---|---|---|
| Supabase | Cloud database, authentication, data storage | Account info, chat history, uploaded files |
| OAuth authentication, sign-in | Email, name, profile picture | |
| xAI (Grok) | AI model inference and responses | Prompts, chat content, context |
| PostHog | Usage analytics and product insights | Anonymized usage patterns, event data |
| Exa / Linkup | Third-party search and data enrichment | Search queries, donor data requests |
We remain responsible for your personal information handled by these third parties on our behalf. All vendors are contractually obligated to:
We may disclose your information if required to:
In the event of a merger, acquisition, bankruptcy, or sale of assets:
We may share aggregated, anonymized data that does not identify you personally for:
Essential cookies are required for basic Service functionality:
When PostHog is configured, we use optional cookies to:
You can opt out of analytics cookies by:
Preference cookies store your settings:
We use IndexedDB and localStorage to cache data locally for:
You can control or clear local storage through your browser developer tools or settings. Clearing storage may affect performance and require re-downloading cached data.
You can control cookies through your browser settings:
Consult your browser's help documentation for cookie management options.
Your rights vary depending on your location. Please see the section(s) applicable to you.
If you are located in the EEA or UK, you have the following rights:
Data Protection Authority contacts:
California residents have the right to:
Current Status: Rōmy does not engage in "sales" of personal information or cross-context behavioral advertising. We do not "share" personal information for targeted advertising purposes. If this changes, we will update this policy and provide a "Do Not Sell or Share My Personal Information" link.
If you reside in Colorado, Connecticut, Delaware, Iowa, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Texas, Utah, Virginia, or other states with comprehensive privacy laws, you may have rights similar to California, including:
Please contact us (see Section 10) to exercise these rights. We will verify your identity and respond within 45 days.
If you are located in Canada, you have rights under the Personal Information Protection and Electronic Documents Act (PIPEDA) and applicable provincial privacy laws:
We remain responsible for personal information handled by our service providers on your behalf. We will facilitate your requests with vendors as needed.
To exercise any of the rights listed above, please contact:
Email: privacy@getromy.app
Mailing Address:
Rōmy (GetRomy LLC)
Kerrville, TX 78028
United States
Include in your request:
Our Response:
Appeal: If we deny or partially deny your request, you may appeal our decision by sending a written appeal to privacy@getromy.app with the original request reference number.
When you submit a prompt or content to the Service:
Rōmy's Policy: We do not use your conversations, prompts, or uploaded files to train our own AI models or create derivative models.
xAI's Policy: xAI may use data processed through their API to improve their models, subject to their own privacy policy. Please review xAI's privacy practices at https://grok.com/privacy for details.
You can see which model generated each response in your chat history.
You are not subject to fully automated decision-making that produces legal or similarly significant effects without human oversight. While our Service uses AI to generate suggestions and donor insights, all AI-generated recommendations should be reviewed and verified by you before use in donor identification or fundraising decisions.
When you enable web search features (if available):
We implement industry-standard security measures to protect your information:
Limitations: However, no system is completely secure. You use the Service at your own risk. We cannot guarantee absolute security of data transmitted over the internet. Please take appropriate precautions with sensitive information and use strong, unique passwords.
Your information may be transferred to, stored in, and processed in countries other than your country of residence, including the United States. These countries may have different data protection laws than your jurisdiction.
When we transfer data internationally, we ensure appropriate safeguards are in place:
If you have concerns about international transfers, please contact us at privacy@getromy.app.
Rōmy is not intended for children under 13 years of age (or 16 in the European Economic Area). We do not knowingly collect personal information from children under these ages.
If you believe we have collected information from a child under the applicable age threshold, please contact us immediately at privacy@getromy.app, and we will delete the information within 30 days.
Note: If you are a nonprofit staff member or volunteer under 13 or 16 using the Service on behalf of your organization, please alert your organization's account administrator, and we will work to address it.
The Service may contain links to third-party websites, services, and applications. We are not responsible for the privacy practices of these third parties. We encourage you to review the privacy policies of any third-party sites or services before providing any information or using their services.
This Privacy Policy applies only to information collected through Rōmy. Third-party services are governed by their own terms and privacy policies.
Rōmy is open-source software. You can review our code, data handling practices, and security implementations in our public repository on GitHub. This transparency allows independent verification of our privacy practices and security measures.
We may update this Privacy Policy from time to time to reflect:
Notice of Changes:
We will notify you of material changes by:
Your Rights:
For privacy-related inquiries, concerns, or requests, please contact our team:
Email: privacy@getromy.app
Mailing Address:
Rōmy (GetRomy LLC)
Kerrville, TX 78028
United States
Response Time: We will acknowledge your inquiry within 10 business days and provide a substantive response within 30–45 days.
For EU/EEA Residents: If you have concerns about our privacy practices and wish to escalate, you may lodge a complaint with your national data protection authority:
For Canadian Residents: You may lodge a complaint with the Office of the Privacy Commissioner of Canada:
By using Rōmy, you consent to this Privacy Policy and agree to its terms. If you do not agree with this policy, please do not use the Service.
If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us using the information in Section 17.
Last updated: November 28, 2025
Version: 2.0 (Multi-jurisdiction)