The short version
- Roomy is a link page drawn as a room. Rooms are public: anyone with the link can see yours.
- To make a room, you sign in with Discord, with Google or with a link we email you, unless we made it for you before launch, with your agreement. There are no passwords.
- We keep what we need to run your room, and little else.
- Visiting a room needs no account. We count visits without cookies, and you can ask us not to count yours.
- A video or song in a room loads from its provider (YouTube, Vimeo, Spotify, SoundCloud or Apple Music) only if you press play.
- We don't sell your information, and there are no ads.
- You can delete your account yourself in Settings, at any time, or ask us at privacy@roo.my.
- Roomy is for people aged 13 and over.
- Keep private details out of your room: no home address, school or phone number.
Who we are
Roomy, at roo.my, is run by Quartz Apps LLC. We decide how your information is used, so under UK and EU law we are its "controller".
Write to us about privacy at privacy@roo.my.
What we collect, and why
When you visit a room
- Connection details. Our host, Cloudflare, receives your IP address and browser details to send you the page, as every website's host does. Technical logs of requests (what was asked for, when, and connection details) are kept for 7 days, to fix faults and stop attacks.
- Visit counts. A room shows how many visits it has had and, while knocking is turned on, how many knocks visitors have left. To count each visitor once a day, we keep two scrambled codes (keyed hashes) for each room you visit: one made from your network address, your browser's description and the date, and one from your network address and the date alone, so one address can't count as many visitors. They can't be turned back into your address, they are different every day, and we delete them after two days. No cookie is used. If your browser sends Global Privacy Control, or you pressed "Don't count my visits", your visits and knocks aren't counted.
- Link opens. A room's owner can see how many times each link in their room was opened, each day. When you open one, your browser tells us which link it was, and we count you once a day per link with the same kind of two codes, deleted after two days. The link still goes straight to its website, and no cookie is set for it. If you are signed in, your sign-in cookie comes along with the open, and we read it only so a room's owner opening their own links isn't counted; nothing from it is kept. Only the room's owner, and our moderators when they review a room, see the numbers. If your browser sends Global Privacy Control, or you pressed "Don't count my visits", your opens aren't counted either. Pressing play on a video or song counts as opening it, under the same rules.
- Links you tap. A link in a room takes you to another website, which has its own privacy policy. We don't tell that site which room you came from.
- Videos and songs. A room can play a video or a song from a provider such as YouTube or Spotify. Visiting the room loads nothing from the provider, and your browser contacts it only if you press play. See Videos and songs.
- Analytics. See Analytics.
When you report a room
A report records the room, the reason you picked, the time, and a scrambled form (a keyed hash) of your connection's network address. For newer (IPv6) addresses, we use the network parts of the address, not the whole of it.
We never ask for your name, your email or a message. The room's owner is never told who reported it.
We use the hash to stop one person sending a flood of reports, and to see when many reports come from one place. A hash of an IP address still counts as personal information, and we treat it that way.
Checking that you're a person
Cloudflare Turnstile checks that you are a person and not a script when you ask for a sign-in link, save a room before signing in, claim or change a name, or send a report. To do that, it looks at your browser and connection, and Cloudflare uses what it sees only to tell people from bots.
When you sign in with Discord
Discord asks you to let Roomy see some details. This is what we do with them.
- Your Discord user ID. Kept, so we know it's you next time.
- Your username and display name. Shown in the editor so you can see who is signed in. Kept only in your sign-in cookie, never in our database.
- Your email address. Kept only if Discord says it has verified it. Then you can also sign in with an email link, and if you already have a Roomy account with that address, the two become one account.
- The accounts connected to your Discord profile, like Spotify or GitHub. Read once, to suggest links for your room. We only use the ones you've made visible on your profile and that Discord has verified. Suggestions start unticked, and nothing is kept except the links you choose to add.
- Knock DMs and server neighbourhoods. Knock DMs work only while knocking is turned on, and are off until you switch them on in Settings; then our Discord bot uses your Discord user ID to message you when your room gets knocks. If you press Join on a Discord server's Roomy neighbourhood, we keep your Discord user ID for that server and list your room's address in its message, even if your room is Unlisted, until you press Leave, your room is paused or deleted, or the server removes Roomy. If you add Roomy to a server, we keep your Discord user ID as the person who added it, until the server removes Roomy.
Discord also sends some profile details we don't use, such as your avatar. We discard them. The access Discord gives us when you sign in is used once and never stored. Roomy stays listed under Authorized Apps in your Discord settings until you remove it there.
When you sign in with Google
Google asks you to let Roomy see your name and email address.
- Your email address. Used only if Google says it has verified it. It's how we find your account, the same one you'd reach with a link we email you, and it's kept like any address you sign in with.
- Your name. Shown to you while you're signed in. We don't keep it.
We don't keep your Google account ID, your profile picture or the access Google gives us. Roomy stays listed under "Third-party apps & services" in your Google Account until you remove it there.
When you link Roomy to a Discord role
Some Discord servers give a role to members who have a room. If you link yours, Discord lets Roomy see your Discord user ID and update your Roomy connection. We send Discord your room's address, and whether it is open, when you claimed it and how many links it has, even if your room is Unlisted. Discord shows the address on your profile beside "Roomy", and the server uses the rest to decide your role. We don't keep the access Discord gives us, so what Discord shows stays as it was when you linked, even if you later pause, rename or delete your room, until you link again or remove Roomy under Connections in your Discord settings.
When you sign in with email
- Your email address, kept with your account.
- A record of each sign-in link: a scrambled form (a hash) of the link, never the link itself; your email address; a simplified form of it that we use to count requests; a scrambled form (a keyed hash) of your network address or, on a browser that has signed in before, of a random code that browser keeps; and when the link was made, when it expires and when it was used. A link works once, for 15 minutes.
- A short-lived cookie that remembers the address you typed, so the link signs you in with one tap on the same device.
We send sign-in emails through Cloudflare. Cloudflare keeps a copy of each email we send, sign-in links included, for about 7 days.
A room you make before signing in
You can make a room before you have an account. Your browser keeps it as you go. When you press Save, we keep the name you asked for and the room you made (its layout, colours and links), with no account and no address, so you can sign in and claim it. After a day it can't be claimed, and we delete it.
Your room
Your room is public. Anyone with its link can see it. You can make it Unlisted in Settings: then it is shown only to people who have the link, is never suggested on other rooms, and asks search engines not to list it. We keep:
- your handle, the name in roo.my/@name;
- if you changed your handle, the old one and when; your old address sends visitors to your new one for 90 days;
- your room's layout: which objects, where, in which colours, and what each one does when it's tapped;
- your links: each address, which site it is for, and the result of our safety check;
- your videos and songs: each address, the title and author the provider gives, and our own copy of its thumbnail picture (see Videos and songs);
- your notes and the line over your mailbox, if you write them. Anyone can read them;
- your pictures (see below);
- your bio, if you write one;
- whether the room is public, unlisted or paused, and when it last changed;
- the room you came from, if you made yours after pressing Make your own on someone's room or opening their invite link: its address, for our own counts. Its owner isn't told, and it earns nothing.
Messages
If an owner opens their mailbox, people signed in with a room can leave them up to 500 characters, with no links.
- When you leave one, we keep your words, your roo.my name, the room and the time. The owner sees your name and words and can delete, block or report. We check the words as we check bios, and count your messages to stop floods.
- Messages left for you show only to you, on your room page. We don't email you.
- A report of a message keeps its words, the reason and a keyed hash of your account. The sender isn't told who reported it.
- A message is deleted 90 days after it was sent, or sooner if the owner deletes it. A block lasts until it's lifted.
Pictures of your room. We make a share card, with your handle, its address and any pictures you have hung, so the link looks good when someone shares it, for example in Discord, and smaller pictures without the words for Settings and More rooms. We keep each for 30 days. Apps that have already shown a card may keep their own copy, which we can't recall.
Link safety checks. When you save a link, a video or a song, we check its address against the sites we have blocked. A link to a site that could be anywhere on the web is also checked against Google's list of unsafe sites, when it is saved and again about once a week: only the link's address is sent to Google, and nothing about you. If you remove a link, a video or a song, we keep its address and the result of its last check until your room is deleted, so an unsafe link can't come straight back.
Videos and songs
A room's owner can set a TV or computer to play a YouTube or Vimeo video, or a record player or radio to play a Spotify, SoundCloud, Apple Music or YouTube song. The owner pastes an address.
- When the owner pastes an address, for the preview, and again when they save it, our server, not anyone's browser, reads the provider's public oEmbed service for the title and the author, and fetches the provider's thumbnail picture. Apple Music has no oEmbed, so its title comes from the address itself. We check the address as we check any link (see Link safety checks, above). These requests come from our servers and carry nothing about the owner or any visitor.
- What we keep is the address, the title and author the provider gives, and our own copy of the thumbnail, which we re-encode and serve from roo.my. We check the title as we check bios, and anyone who sees the room can read the title and author.
- How long: the title, the author and the thumbnail, as long as the video or song is on the room; the address, as we keep a link's (see Link safety checks, above). A thumbnail that no video or song uses, such as one from a preview that was never saved, is deleted like any picture no room shows: once it is 7 days old, by the daily clean-up (see Pictures you upload).
- Until you press play, a room loads nothing from these providers. It shows our own copy of the thumbnail, and your browser doesn't contact them.
- When you press play, your browser loads that provider's player inside a limited box on the page (a sandboxed iframe). From then on the provider receives what any embedded player receives, such as your IP address, which site the player is on (roo.my), the cookies your browser keeps for that provider, and what you play. The player is the provider's, not ours, and may show its own ads. What it does with that information is covered by its own privacy policy:
- A play counts as an open, as a link's does: see Link opens, under When you visit a room.
Pictures you upload
A picture hangs in a frame in your room. Your phone or computer does the cropping, so your original photo never leaves your device. We receive only the crop, at a fixed size: 992 by 864 pixels (or 480 by 864), as a JPEG or PNG file. We keep that crop, usually under 250 KB and never over 512 KB, and nothing else. It carries no location or camera details: we remove everything from the file but the picture itself. A picture uploaded before 9 October 2026 is kept at the smaller size it was sent at, 248 by 216 pixels (or 120 by 216), and for those we also make a smaller copy (WebP) to send. Cloudflare keeps copies of what we send near visitors for up to 10 minutes.
- We keep a record of which account uploaded which picture, and when. It limits uploads to 6 a day and helps us act on reports.
- A picture that no room shows, not even a paused one, is deleted once it is 7 days old, by a daily clean-up. Until then, anyone who has its exact address can still load it.
- When we take a picture down, we keep it out of sight instead of deleting it, so it can't be uploaded again and can be put back if we got it wrong. A picture taken down for child safety is kept for a year after we report it, as US law requires. One taken down after a copyright notice, or for breaking the rules, is kept until the matter is settled, for example so it can be put back after a counter-notice.
- When we ban a picture, we delete it and keep only a fingerprint of it (not the picture), so it can't be uploaded again.
- We use Cloudflare's CSAM Scanning Tool, which compares what our site serves against known child sexual abuse material.
If we hold a name for you
If we hold a handle for someone, for example a creator who asked before launch, we keep the name, a short note, and the email address it is held for. We keep them while the name is held, and after it is claimed as our record of who it was for, until it is released or that account is deleted.
If we made your room for you
If we made your room for you before launch, with your agreement, we keep the address or Discord ID you gave us and the room and links you sent, as for any room. We also keep when and how you agreed, in our record of what we did to your room, which stays after an account is deleted.
Coins
Coins are Roomy's currency: you earn them and spend them inside Roomy, and nobody can buy them (see the Terms). To keep every balance right, we keep:
- every change to your coins: how many, what for (a claimed room, an invite, a tip, something you got for your room, a gift or one that came back, a correction), and when. For a tip or a gift, it also records the other account. An entry is never changed or deleted: a correction is a new entry, with a note of why for our team.
- what you have got with coins, like a colour pack or a bigger room, so your room can use it.
- your gifts. For each gift, we keep who sent it, what it was, the name it was sent to, and whether it was kept or came back.
- your balance, which is always the sum of those entries.
- your invites. When someone claims a room after opening your invite link, we record who invited whom, when, what our bot check said about the claim, and whether the invite was paid, or why not.
- the network your room was claimed from, as a scrambled code (a keyed hash) of your connection's network address. It stops one person earning coins by inviting their own extra accounts, or by claiming room after room from one place. It can't be turned back into your address.
- the inbox your room was claimed with, as a scrambled code (a keyed hash) of your email address, or of your Discord ID if your account has no email. For a Gmail address the code ignores dots and anything after a +, because Gmail delivers all of those to one inbox. It means one inbox earns the claim coins once, and can be invited once, even after deleting an account. It can't be turned back into your address or your Discord ID.
- your Discord ID, as the same kind of code, when your account with a room has Discord linked, at the claim or later. It stops a deleted account earning the claim coins again through the other way of signing in. It can't be turned back into your Discord ID.
Who sees it. Your Wallet (roo.my/wallet) shows only you your balance, your history and your invites. When you tip a room, its owner sees your room's address in their Wallet. When you send a gift, the person it's for sees your room's address with it, and your Wallet shows the name you sent it to and whether it came back. If you claim a room after opening someone's invite link, they see your room's address in their list of invites, and once the invite is paid you see theirs in yours. Nobody else sees any of it.
When we act on a room
When we take something down, pause a room or suspend an account, we keep a record of what we did, when, and why. If it happened to your room, we tell you in the editor, and by email if your account has an address. We keep the record after an account is deleted, because it is how we answer complaints and appeals.
When you email us
We keep your message and our reply, so we can help you and keep a record.
Our legal reasons (UK and EU)
UK and EU law asks us to give a legal reason for each use of your information.
| What | Legal reason |
|---|
| Your account, sign-in, room, links, videos, songs, pictures and messages | Contract: it's the service you asked for |
| A room saved before signing in | Contract: steps you asked for before your room is made |
| Knock DMs, server neighbourhoods and Discord roles | Contract: features you switched on or asked for |
| Your old handle forwarding to your new one | Legitimate interests: old links keep working |
| Coins, invites and tips | Contract: they are part of the service you use |
| The room you came from | Legitimate interests: knowing how people find Roomy |
| The network and inbox codes from a claim | Legitimate interests: stopping one person from farming coins with extra accounts |
| Link suggestions from Discord | Legitimate interests: a quicker setup, and you pick what stays |
| Joining your Discord and email accounts | Legitimate interests: one person, one account |
| Logs, limits, bot checks and IP hashes | Legitimate interests: keeping Roomy safe and working |
| Visit counts, link opens and plays | Legitimate interests: showing a room's owner its visits, and which links, videos and songs are opened or played, each visitor counted once a day |
| The player of a video or song | Consent: you press play, and nothing is loaded from the provider before that |
| Reports, moderation and link checks | Legitimate interests: keeping people safe |
| Keeping and reporting illegal material | Legal obligation, where a law we're under requires it |
| Answering your emails | Legitimate interests |
| Analytics | See Analytics |
Where we rely on legitimate interests, you can object, and we will stop unless there is a strong reason to go on, such as someone's safety.
Cookies and storage
Roomy stores things on your device only when you sign in, use the editor, open an invite link, or ask us not to count your visits. None of them follow you around other websites.
__Host-roomy_session, 30 days: keeps you signed in. It holds your account ID and display name, signed so nobody can change them. Signing out removes it.__Host-roomy_oauth, 10 minutes: protects a Discord sign-in, or linking a Discord role.__Host-roomy_mail, 30 minutes: remembers the email address you typed, so your link signs you in with one tap on this device.__Host-roomy_known, 1 year: remembers, as a scrambled code and never as the address itself, that this browser has signed in to your inbox before, so other people asking for links to your address can't lock you out. Signing out removes it.__Host-roomy_offers, 30 minutes: carries link suggestions from Discord to the screen where you choose your name.__Host-roomy_ref, 30 days: set when you open someone's invite link, so that if you then claim a room, the invite counts. It holds their account ID and when it expires, signed so nobody can change them.__Host-roomy_nocount, 1 year: set only when you press "Don't count my visits". It says nothing but that.__Host-roomy_to, 10 minutes: remembers the room you were on when you started signing in with Discord, so you land back on it. Signing out removes it.__Host-roomy_draft, 1 day: set when you press Continue with Discord on a room you made before signing in, so only this browser can claim it.__Host-roomy_via, 30 days: set when you go on from Make your own on someone's room, or open their invite link, so the room you then claim records the room you came from. It holds only that room's name and which of those ways you came. It isn't set, and nothing is recorded, if your browser sends Global Privacy Control or you pressed "Don't count my visits".roomy.inventory3d, until you close the tab: remembers where you were in the editor's tray.roomy.sound, until you clear it: remembers whether you turned the editor's sound on.roomy:draft:<name>, until you clear it: the room you made before signing in, so a reload doesn't lose it.
All of these but __Host-roomy_via are needed for something you asked for, so they don't need your consent. __Host-roomy_via is for our own counts, and stops when you object as above. Our cookies are locked to roo.my and can't be read by scripts.
Players. If you press play on a video or song, the provider's player may keep cookies or other storage on your device. They are the provider's, not ours, and its privacy policy covers them (see Videos and songs). Until you press play, none is set.
Analytics
We count visits with Cloudflare Web Analytics. It sets no cookies and stores nothing on your device. It tells us which pages are visited, which site sent the visitor, and broad facts such as the type of device and the country. We never count sign-in, editing or settings pages. Legal reason: legitimate interests, knowing which parts of Roomy people use.
You can object in two ways. If your browser sends the Global Privacy Control signal, we don't count your visits. Or press "Don't count my visits" below: it sets the one cookie above, and you can press "Count my visits" to undo it.
Who we share it with
We don't sell your information, and we don't share it for advertising.
These companies help us run Roomy, and handle your information only to do that:
- Cloudflare (USA): hosting, our database, storage, email sending, bot checks, analytics and security.
- Discord (USA): sign-in, Discord roles, knock DMs and server neighbourhoods, only if you choose them. For those, Discord receives your room's address.
- Google (USA): sign-in, if you choose it, and link safety checks, which send only the link.
- Our email provider: stores the messages you send to our @roo.my addresses, which Cloudflare forwards to it.
We also share information:
- when the law requires it, or to protect someone from serious harm. If we find child sexual abuse material, we report it to the National Center for Missing & Exploited Children (NCMEC) in the US, and keep what the law requires;
- if Roomy changes hands, with the new owner, who must keep these promises or tell you first;
- when you ask us to.
Video and song players are not ours. If you press play on one, its provider (YouTube, Vimeo, Spotify, SoundCloud or Apple Music) gets your details from your browser, not from us. See Videos and songs.
Only the people who run and moderate Roomy can see account details, and only to do that work.
We are in the United States. Our providers store information in the US and across Cloudflare's worldwide network. If you are in the UK or the EU, your information goes to the US. Our providers protect it with approved safeguards, such as the EU-US Data Privacy Framework with its UK extension, or standard contractual clauses.
How long we keep it
- Your account (its ID, your Discord ID and email, when you last signed in): until you delete it.
- Your room, its links, videos, songs and notes, and any change of handle: until you delete your account, or remove the link, the video, the song or the note.
- Messages: 90 days, or less if deleted. A reported message's words: 12 months. Blocks: until lifted, or an account is deleted.
- A room saved before signing in: until it is claimed, or it expires a day after Save.
- Links, videos and songs you removed, with their last safety check: until your room is deleted.
- Your coin entries, gifts and invites: as long as Roomy runs, because every balance is the sum of its entries. If you delete your account, they stay with an account that has nothing left in it: no email, no Discord ID and no room.
- The network, inbox and Discord codes from your claim, and the network code from an invite's claim: as long as the account, and after a deletion, with what is left of it, so deleting an account and claiming again with the same inbox can't earn the claim coins twice, or be invited twice.
- The room you came from: as long as the account, and after a deletion, with what is left of it, as your invites are.
- Visit counts, and how many times each link, video or song was opened or played each day: as long as the room, or the link, video or song.
- The daily visitor codes: 2 days.
- Pictures, and the thumbnails of videos and songs: while a room shows them, then until the daily clean-up once they are 7 days old.
- Who uploaded each picture: until the picture is deleted, or you delete your account, whichever comes first.
- Fingerprints of removed pictures: as long as Roomy runs.
- Pictures taken down for child safety: a year after we report them, as US law requires.
- Pictures taken down after a copyright notice, or for breaking the rules: until the matter is settled.
- Sign-in link records: a day or two after the link expires or is used, by a daily clean-up.
- Reports: kept as our record of moderation. The IP hash in a report is deleted after 12 months.
- Our record of what we did to a room or an account: kept as our record of moderation.
- Messages telling you what we did: about a year after we've told you.
- Names held for someone: until released, or until the account they were held for is deleted.
- Counters that limit how often something can be done: until their time window closes.
- Pictures of your room: 30 days.
- Technical logs: 7 days.
- Copies of emails we send: about 7 days.
- Emails with us: 2 years.
- Backups: our database keeps 30 days of history for recovery, and we keep weekly copies of it outside Cloudflare for about 8 weeks. So deleted information is fully gone about 8 weeks after it is deleted. Pictures held for child safety are never in those copies.
We keep anything longer only when the law requires it. For example, US law says to keep material reported to NCMEC for a year after the report.
Your rights
Wherever you live, you can ask us to:
- show you the information we have about you, and give you a copy;
- correct it;
- delete it;
- send it to you in a standard format, to take elsewhere;
- stop or limit a use of it, or object to one;
- withdraw a consent you gave.
Do it yourself. If you have a room, Settings (roo.my/settings) lets you change your email address and delete your account. For a copy of your information as a file, ask us as below.
How to ask. Email privacy@roo.my with your handle. If your account has an email address, write from it. To protect you, we check that the request comes from you before we act. If your account has no email address, sign in with Discord and delete it yourself in Settings, or add an address there and write from it. If you signed in but never claimed a room, we hold only how you signed in and when: write to us, and we will tell you how to show it's you. We reply within 30 days.
Deleting your account. Delete it yourself in Settings, and it happens at once. Or email privacy@roo.my with your handle, and we delete it within 30 days. That removes:
- your account and your sign-in records;
- your room, its links, videos and songs, its visit counts, link opens and plays, and the notices we sent you;
- the messages you left and were left, and who you blocked;
- any change of your handle;
- your pictures, unless another room shows the same picture or someone else uploaded it too;
- the record of what you uploaded;
- the email address on any name we were holding for you;
- your coins, which can't be used again, and what you got with them;
- any gift still waiting for you, whose coins go back to the person who sent it.
Pictures of your room stop being shown at once, and are deleted within 30 days. The thumbnails of your videos and songs are deleted by the daily clean-up, once they are 7 days old. Your handle is then held for 90 days before anyone else can claim it, so old links to your room don't lead straight to a stranger's. If you linked Roomy to a Discord role, remove Roomy under Connections in your Discord settings too.
We keep only: reports about your room, and our record of what we did to it, as our moderation record; pictures we took down and are keeping out of sight, for as long as the list above says; your coin entries, gifts and invites, the network and inbox codes from your claim, and the room you came from, with your account emptied, as the list above says; any purchase records the law makes us keep, with your account removed from them; and anything else the law requires. If the law requires us to keep an account, for example while a child-safety report is open, we can't delete it until that ends.
Complaints. If you're unhappy with how we handled your information, please tell us first at privacy@roo.my. You can also complain to your data protection authority: in the UK, the Information Commissioner's Office (ico.org.uk); in the EU, the authority in your country.
Children
Roomy is for people aged 13 and over. We don't knowingly collect information from anyone younger. If we learn that an account belongs to a child under 13, we delete it.
If you're a parent or guardian and think your child under 13 has a Roomy account, email privacy@roo.my with the handle, and we will delete it.
Roomy is built with young people in mind: there are no private chats, no comments, no location tracking and no ads. Mailbox messages hold no links, and the owner can delete, block or report them.
Keeping it safe
- There are no passwords to steal. Sign-in links work once, for 15 minutes, and we store only a scrambled form of them.
- In our database, IP addresses are stored only as scrambled hashes, for counting.
- If a security problem ever puts your information at risk, we will tell you, and the authorities, as the law requires.
Found a security problem? Tell us at security@roo.my.
Changes to this policy
When we change this policy, we change the date at the top. If a change matters, we tell account holders before it takes effect, by email where we have an address, and with a notice on roo.my.