Scope
This Privacy Policy explains how we collect, use, disclose, retain, and protect personal information when you use roseram.com, our coding environment, launch pages, APIs, previews, billing features, communications, and connected integrations, collectively called the Service.
Third-party websites and services have their own privacy practices. This policy does not replace the notices provided by a connected repository host, database, deployment provider, AI model provider, payment processor, or other third party.
Information we collect
We collect information you provide, information generated through your use, and limited information received from services you choose to connect. Depending on the features you use, this can include:
- Account information such as email address, profile details, authentication identifiers, plan, preferences, and support communications.
- Prompts, selected repository files, generated output, edits, project metadata, action history, and other workspace content you intentionally submit or open.
- Integration information such as provider identity, repositories, projects, deployment metadata, connection status, and scoped credentials or authorization tokens.
- Billing information such as customer and transaction identifiers, subscription state, invoices, payment status, plan, and credit balance. Payment providers process full payment-card details.
- Usage and device information such as feature activity, model selection, token or credit usage, browser type, timestamps, diagnostics, approximate location derived from IP, and security events.
- Launch, referral, and communication information such as email subscription status, campaign parameters, consent records, unique or duplicate referral activity, and hashed identifiers used for attribution and abuse prevention.
How we use information
- Provide accounts, authentication, code analysis, generation, previews, deployments, integrations, billing, support, and requested communications.
- Route requests to available models and providers, calculate usage, administer plans and credits, and maintain service reliability.
- Secure accounts and infrastructure, detect fraud and abuse, investigate errors, enforce our terms, and protect users and third parties.
- Measure feature performance, understand adoption, improve workflows, and develop new capabilities using information permitted by your settings and applicable law.
- Send transactional messages and, where you have opted in or applicable law permits, product or launch communications. You may unsubscribe from marketing at any time.
- Comply with legal obligations, respond to lawful requests, and establish or defend legal claims.
AI processing and connected code
When you request generation or analysis, relevant prompts, instructions, code, and context may be sent to the model provider selected in the interface or chosen by intelligent routing. Providers can include our configured private systems and third-party model services. We limit transmitted context to what is reasonably needed for the request.
Only open or connect content you are authorized to process. Avoid submitting secrets, regulated data, or sensitive personal information unless the feature is expressly designed and contractually approved for that information. Generated output and activity records may be stored with your project or account to provide history, recovery, metering, and support.
Retention
We retain information for as long as reasonably needed to provide the Service, maintain account and transaction records, comply with law, resolve disputes, enforce agreements, prevent fraud, and preserve security. Retention varies by data type, sensitivity, account status, contractual commitments, and legal requirements.
When information is no longer needed, we delete or de-identify it where reasonably practicable. Backup copies and legally required records may remain for a limited period. De-identified or aggregated information that cannot reasonably identify you may be retained for analytics and service improvement.
Security
We use administrative, technical, and organizational safeguards intended to protect information, including access controls, scoped provider permissions, server-side secret handling, authentication controls, and monitoring. No online service can guarantee absolute security.
Protect your account, review integration permissions, rotate exposed credentials, and report suspected unauthorized access to security@roseram.com. Never place secret keys in public repositories or public support messages.
International processing
We and our service providers may process information in countries other than where you live. Where required, we use recognized safeguards for international transfers and apply the protections required by applicable law.
Your choices and privacy rights
Depending on where you live, you may have rights to request access, correction, deletion, restriction, objection, or portability of personal information, to withdraw consent, or to appeal a denied request. You may also have the right to complain to a data-protection authority.
Submit a request to privacy@roseram.com. We may verify your identity and authority before acting. Rights can be subject to legal exceptions, including security, fraud prevention, transaction records, the rights of others, and legal claims. Authorized agents may submit requests where permitted by law.
Communications
Transactional messages about authentication, security, billing, service operation, and requested actions are part of the Service. Marketing and launch messages include an unsubscribe method. Unsubscribing from marketing does not prevent essential account or transaction notices.
Children
The Service is not directed to children under 13 or a higher minimum age required by local law. We do not knowingly collect personal information from children below the applicable age. Contact us if you believe a child has provided information improperly.
Changes and contact
We may update this policy as the Service, providers, and legal requirements change. We will post the revised policy and update its effective date. Material changes will be communicated through the Service or another reasonable channel when required.
For privacy questions or requests, contact privacy@roseram.com. For security reports, contact security@roseram.com. For general legal questions, contact legal@roseram.com.