Privacy Policy
How RoomDone handles your information
RoomDone helps you plan a furnished room from a photo. This policy explains what we collect, what we deliberately do not keep, and the choices you have.
Effective August 22, 2026
Your original room photo is never stored.
Your original room photo passes through RoomDone and our AI providers in memory and is never stored. A generated preview is kept only as a short-lived delivery-recovery copy, then deleted after it is safely saved in your browser or within 24 hours.
Scope and controller
RoomDone operates the RoomDone web application at https://roomdone.netlify.app. For privacy questions or requests, contact privacy@roomdone.app.
This policy applies to the RoomDone website and related services. It does not cover third-party retailer websites you may visit from a buying list.
Room photos and previews
- Image preparation and the local quality check happen in your browser.
- The photo is sent to our backend only as in-memory action input for room analysis and rendering.
- OpenAI and, for some steps, Cloudflare Workers AI receive the image or text inputs needed for the requested vision, selection, and render calls.
- The generated preview is temporarily stored as a recovery copy until this browser confirms a durable local save, and never longer than 24 hours.
- Clearing site data deletes local photo and preview copies; deleting a room or account also deletes any active preview recovery copy.
Original room photos pass through our systems in memory only and are never persisted in our database, object storage, logs, or analytics. Generated previews use the limited recovery storage described below and are never included in logs or analytics.
OpenAI may retain API inputs for up to 30 days for abuse monitoring and safety review, and states that API data is not used to train its models by default. Cloudflare Workers AI processes some requests through our proxy under Cloudflare’s terms and privacy policy. RoomDone does not receive a permanent image URL from these providers. In live mode, we create our own short-lived generated-preview recovery copy solely to prevent a suspended mobile browser from losing the result.
Information we collect
Information you provide
- Room purpose, fit preferences, budget, style choices, mattress size, and explicit furniture intent.
- Optional custom instructions typed in the brief (handled as described below).
- If you sign in: email address from a magic link (via Resend) and/or Google account identifier, name, and profile image supplied by Google Sign-In.
- Feedback or support messages you send by email or through the in-app form, plus an optional reply email you choose to provide.
Information generated by the service
- Structured room analysis, product selections, fit statements, totals, buying-list progress, and pipeline status for your plan.
- In live mode, a generated-preview recovery copy held until confirmed browser delivery or for no more than 24 hours.
- A random session token stored in your browser so anonymous same-device use can resume.
- Controlled product-activity events described below.
Information stored only on your device
- Your original room photo in browser IndexedDB, keyed per room.
- The delivered generated preview in browser IndexedDB; the server recovery copy follows the separate 24-hour maximum above.
- Draft intake answers and UI state in browser local storage.
What we do not collect
- Payment card numbers or checkout details from retailer websites.
- Precise geolocation from your device.
- Advertising profiles or cross-site tracking for ad networks.
How we use information
- Provide room analysis, product selection, optional preview rendering, buying lists, and same-device resume.
- Authenticate signed-in users and link prior anonymous work to an account when you choose to sign in.
- Send sign-in magic links and service-related email you request.
- Review feedback, troubleshoot issues, improve RoomDone, and reply when you ask us to.
- Measure product performance with the limited event set described below.
- Protect the service against abuse, enforce usage limits, and maintain security.
- Comply with law and respond to valid legal requests.
We do not sell your personal information. We do not use your room photo or email for advertising.
Legal bases (EEA/UK users)
Where applicable law requires a legal basis, we rely on:
- Contract — to provide the plan you request.
- Legitimate interests — to secure the service, understand product usage, and prevent abuse, balanced against your rights.
- Consent — where required for optional sign-in methods or communications beyond the service you requested.
What RoomDone stores on our servers
No account is required to start. If you choose to sign in, we store your email and standard authentication session records needed to keep you signed in. We use email only to authenticate you, not for marketing newsletters.
For up to seven days on an anonymous session, RoomDone stores structured room analysis, your plan and budget math, product snapshots, buying-list state, and controlled pipeline events tied to that session. Catalog product images are catalog assets, not user room images.
RoomDone never stores your original room photo. We temporarily store a generated preview only to recover delivery when a browser sleeps or disconnects. We delete that copy as soon as the browser confirms a durable local save, and automatically within 24 hours if no confirmation arrives.
When you sign in, your existing session and rooms can be linked to your account. Those user-owned plan records are kept until you delete the room or delete your account — they are not swept away with the seven-day anonymous session expiry.
In-app feedback is stored with its category, message, optional reply email, page, and relevant room or plan identifiers so we can understand and respond to it. It is removed when its seven-day session expires or when you delete the associated account.
If you add Custom instructions, the prose passes through RoomDone and our AI providers in memory while we read the room, choose products, and make the preview. The prose stays only in this browser’s draft and is never saved in room rows, generations, analytics, or model-call logs. A bounded internal interpretation may be saved with the plan so furniture requests can survive the generation workflow.
Service providers
We use trusted processors to run RoomDone. They may process data only to provide their service to us:
- Convex — application database and backend hosting.
- Netlify — static website hosting.
- OpenAI — vision, selection, and image generation API calls.
- Cloudflare Workers AI — some model calls through our proxy.
- Resend — delivery of sign-in magic-link email.
- Google — optional Google Sign-In authentication.
- PostHog — product analytics for the controlled event set described below (US-hosted).
Retailer links may route through RoomDone redirect URLs when affiliate tracking is active for a given product. That process uses a short-lived token tied to the product link, not your room photo.
Product activity
RoomDone records a small controlled set of events such as plan started, item changed, buying list opened, retailer opened, and purchase check changed. They never include the room photo, email, free-form text, or retailer checkout data.
These events are processed by PostHog, along with the page you viewed and a random device identifier. Automatic form and click capture is switched off and we do not record your screen or session replays, so analytics cannot pick up your photo or anything you type. When you sign in, analytics identifies you by an opaque account identifier, never your email address.
Cookies and local storage
RoomDone uses browser local storage and IndexedDB for session tokens, draft answers, and device-local room photos and previews. A live generated preview may also have the temporary recovery copy described above. Our analytics provider sets a first-party cookie and local storage entry holding a random device identifier so repeat visits can be counted once. We do not use third-party advertising cookies or cross-site ad tracking. Authentication providers may set cookies required for sign-in when you use those features.
Retention, deletion, and your choices
Anonymous sessions, room analysis, plans, in-app feedback, and related text records expire from our servers after seven days unless you sign in and link them to an account. Original room photos are never part of server retention. Generated-preview recovery copies are deleted after confirmed browser delivery or within 24 hours, whichever comes first.
- Delete a room. Removes that room’s server-side plan records, buying progress, and any active preview recovery copy. It also removes this browser’s local photo and preview copies.
- This device only. Without signing in, a photo or preview cannot be resumed on another device.
- Clear site data. Removes browser-local photos, previews, drafts, and session tokens immediately.
- Signed-in plans. Account-linked plans stay available until you delete the room or your account.
- Sign out. Ends your authenticated session on this browser; server-side account records remain until deleted.
- Delete account. Deleting an account removes its server-side plan records, any temporary preview recovery copies, and local photo and preview copies immediately; it is not queued. This does not retroactively erase historical product analytics events.
Your privacy rights
Depending on where you live, you may have the right to access, correct, delete, or export personal information we hold about you, and to object to or restrict certain processing.
California residents. We do not sell personal information. You may request access to or deletion of personal information by emailing privacy@roomdone.app. We will not discriminate against you for exercising these rights.
EEA/UK residents. You may lodge a complaint with your local supervisory authority. Contact us first at privacy@roomdone.app and we will try to resolve your request.
For general help using RoomDone, email support@roomdone.app.
Children
RoomDone is not directed to children under 13, and we do not knowingly collect personal information from children under 13. If you believe a child provided us information, contact us and we will delete it.
Security
We use industry-standard safeguards appropriate to the data we hold, including encrypted transport, access controls, and provider security programs. No method of transmission or storage is completely secure.
International transfers
RoomDone is operated from the United States. If you access the service from elsewhere, your information may be processed in the United States and other countries where our providers operate, which may have different data-protection laws than your home country.
Changes to this policy
We may update this Privacy Policy from time to time. We will post the revised policy on this page and update the effective date. Material changes may also be noted in the product where appropriate.