Roiko — Privacy Policy
Version 4 — Effective:
1. Controller
The controller for all processing described here is Rodrigo Alonso Corona Davila, Zillertalstraße 41, 81379 München, Germany. For any privacy question or request, contact support@roiko.ai.
2. Scope of this policy
This policy covers both the Roiko website (https://roiko.ai) and the Roiko application (https://app.roiko.ai — "the Service"). It describes what personal data we process, why, on which legal basis under the GDPR, where it is processed, and how long it is kept. The Terms of Service (https://roiko.ai/terms) refer to this policy.
3. Visiting our website
When you visit roiko.ai, our hosting provider (Cloudflare) processes technical connection data — your IP address, browser and operating system, and access time — to deliver the site securely. Legal basis: legitimate interest (Art. 6(1)(f) GDPR) in operating a secure website. Website server logs are kept for 3 days and then deleted.
To show prices in your regional currency we read the coarse country of your connection (Cloudflare's CF-IPCountry signal). This is evaluated per request and not stored.
4. Cookies and consent
By default this website sets no cookies. We ask for your consent before loading any non-essential technology. Without consent we store only two strictly necessary, consent-exempt items: your consent choice itself (kept in your browser’s local storage), and — only if you actively pick a language in the language menu — a functional cookie (roiko-locale, kept for 12 months) that remembers your chosen language. It contains nothing but the language code and is not used for tracking. You can change or withdraw your analytics choice at any time via "Cookie settings" in the footer.
5. Web analytics (Google Analytics 4)
Only if you consent via our cookie banner, we use Google Analytics 4 to understand how the website is used and to improve it. It sets cookies and processes usage data; IP addresses are anonymised. Provider: Google Ireland Ltd. / Google LLC — data may be transferred to the USA under the EU–US Data Privacy Framework. Analytics data is retained for 14 months. Legal basis: your consent (Art. 6(1)(a) GDPR / § 25(1) TDDDG), withdrawable at any time. If you do not consent, Google Analytics does not load.
6. Demo requests and the home-page demo
If you use the demo form, we process the details you enter (name, email, company, country, city, role, phone, and your message) to respond to your request and contact you about Roiko. The data is stored in our application database (Supabase, EU region — see § 13). Legal basis: steps taken at your request prior to a contract, and your consent (Art. 6(1)(b) and (a) GDPR). We keep demo-request data for 24 months after our last contact with you, then delete it; you can ask us to delete it earlier at any time (§ 16).
The home-page demo (structure generator). On our home page you can type a description of a building and have Roiko generate a 3D model from it, without an account. When you press play, the text you typed is sent, exactly as written, to our application server (app.roiko.ai) and from there to Google (Gemini API), which turns it into a structural model. Google is one of the providers named in § 9; unlike the AI assistant inside the Service, the home-page demo uses Google only — there is no fallback to Anthropic on this route. The same rule as in § 9 applies: do not put personal data (such as client names or addresses) in the description; it travels as-is.
What we keep. The demo needs no account and asks for no name or email address. Our application server processes the IP address of the request to limit the demo to a fixed number of generations per connection per day. The record behind that limit is removed once it is no longer needed for it, which in practice means the address is kept for at least 48 hours. The IP address is additionally recorded in our application server’s own event log for 90 days, and in Service server logs for 7 days (§ 12). The description you type is stored as you wrote it — in readable form, not as a fingerprint — in our application database (Supabase, EU region — see § 13), together with the model generated from it, so that the same description can be answered next time without a further AI call. That store has no fixed expiry today: we are introducing a defined retention period for the stored description, and until it is in place the description is kept indefinitely. The store holds no name, no email address and no link to an account, and it is not used to build a profile of you. Because the text is kept exactly as written, do not type personal data into the demo; if you would like a description you typed removed, contact us (§ 16). If a description is unclear, Roiko asks one question back; those question rounds are not stored.
If you sign up from the demo. If you choose to create an account from the demo, the description you typed is passed to the sign-up page in the address of the link, so that it is waiting in your new account. It is not generated again automatically. From that point the rules for your account (§ 7) and the AI assistant (§ 9) apply.
Analytics and the demo. Our own usage events about the demo record only the outcome and a rough duration band — never the text you typed — and only if you consented to analytics (§ 5).
Legal basis for the home-page demo: steps taken at your request prior to a contract (Art. 6(1)(b) GDPR) and our legitimate interest (Art. 6(1)(f) GDPR) in letting you try the product before you sign up; for the transfer to the AI providers, the safeguards in § 13 apply.
7. Your account
When you create an account, we process your email address and authentication data to provide the Service, manage your seats and team, and communicate with you about your account. Legal basis: performance of the contract (Art. 6(1)(b) GDPR). Account data is kept for as long as your account exists; see § 15 for what happens after deletion.
8. Projects and structural models
The projects, structural models, calculations, and reports you create are your content (see Terms § 6.2). We store and process them solely to provide the Service. Legal basis: performance of the contract (Art. 6(1)(b) GDPR).
9. AI assistant
The Service includes an AI assistant. When you use it, your request is processed by external AI providers: Google (Gemini API) as the primary provider, and Anthropic (Claude API) as a fallback if the primary provider is unavailable.
What the providers receive. The request contains the structural definition of your model — geometry, cross-sections, materials, loads — plus the text of your request exactly as you typed it. Identifying free-text fields are excluded by design: the project name and the names and descriptions of elements are never included, and any data field not expressly approved for transmission is withheld by default. Because your typed request travels as-is, do not include personal data (e.g. client names or addresses) in the request text.
No training by the providers. Both providers are used under their commercial API terms: they do not use your data to train their models. Anthropic retains API inputs and outputs for up to 30 days and then deletes them (content flagged for abuse review can be retained longer under the provider’s policy).
Training by us. Whether we may use your data to improve our own models depends on your plan and your choice: on paid plans we do not use your project data for training unless you expressly opt in via the corresponding setting in the product; for the free Sandbox tier, Terms § 7.2 applies. The training consent setting is visible in the product. The text of your requests to the AI assistant is stored by us together with the consent status that applied when the request was made; it is kept until you delete your account — deleting a project or model does not delete the requests you made about it.
Legal basis: performance of the contract (Art. 6(1)(b) GDPR); for optional training use, your consent (Art. 6(1)(a) GDPR).
10. Payments
Paid plans are billed via Stripe. Your card or payment details are entered in Stripe’s checkout and go to Stripe directly — they never pass through our servers. We share the billing identity needed to manage your subscription (name, email, plan, invoicing data). Legal basis: performance of the contract (Art. 6(1)(b) GDPR) and legal obligations regarding accounting records (Art. 6(1)(c) GDPR).
11. Emails we send
Transactional email (currently team invitations) is sent via Resend. An invitation contains the invitee’s email address and the inviting team’s company name. Legal basis: performance of the contract (Art. 6(1)(b) GDPR).
12. Server logs of the Service
Our server logs do not contain the content you submit, your name, or your email address. They contain a pseudonymous account identifier, and our web server records the IP address of requests. We use them to operate the Service securely and diagnose faults. Legal basis: legitimate interest (Art. 6(1)(f) GDPR). Service server logs are kept for 7 days and then deleted. Cloudflare, which sits in front of the Service as a security and delivery layer, keeps its own connection logs under its own retention schedule.
13. Where your data is processed
Application server: DigitalOcean, London, United Kingdom. The UK is covered by an adequacy decision of the European Commission (Art. 45 GDPR).
Database: Supabase, Ireland (EU) — accounts, projects, models, demo requests, and consent records are stored at rest in the EU.
AI providers, payments, email, CDN: Google, Anthropic, Stripe, Resend, and Cloudflare process data in the USA or on global infrastructure. These transfers rely on an adequacy decision of the European Commission or on the Commission’s Standard Contractual Clauses, as applicable, under each provider’s data processing agreement.
14. Processors and recipients
We use the following processors: Cloudflare (website hosting, CDN, and security in front of the Service), DigitalOcean (application hosting, UK), Supabase (database and authentication, Ireland), Google (Gemini API — AI processing; and Google Analytics, only with your consent), Anthropic (Claude API — AI processing, fallback), Stripe (payment processing), and Resend (transactional email). Each acts on our documented instructions under a data processing agreement. We do not sell personal data.
15. How long we keep data
We keep personal data only as long as the purposes above require:
Website server logs (roiko.ai): 3 days.
Service server logs (app.roiko.ai): 7 days.
Analytics (only with consent): 14 months.
Demo requests: 24 months after our last contact with you.
Home-page demo: the IP address of the request for the daily limit (at least 48 hours), in our application server’s own event log (90 days) and in Service server logs (7 days); the description you typed and the model generated from it are stored in readable form with no fixed expiry — a defined retention period for the stored description is being introduced — and hold no name, email address or account link.
Account, projects, models: until you delete them or your account.
AI request texts: until you delete your account (deleting a project does not delete the requests you made about it).
AI provider processing (Anthropic): deleted by the provider after up to 30 days.
Payment and billing records: statutory retention periods (up to 10 years, § 147 AO).
Records deleted from our database may persist in encrypted database backups for up to 7 days before those backups are rotated out. After account deletion, aggregate usage counters (request counts, token totals, timestamps) remain in anonymised form — they contain no content and no identifier — and records evidencing your consent are retained in de-identified form.
16. Your rights
You have the right of access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20), and objection to processing based on legitimate interest (Art. 21). Where processing is based on consent, you may withdraw it at any time with effect for the future. To exercise any right, contact support@roiko.ai.
17. Supervisory authority
You have the right to lodge a complaint with a data protection supervisory authority, in particular in the EU member state of your residence or workplace. The authority competent for us is the Bayerisches Landesamt für Datenschutzaufsicht (BayLDA), Promenade 18, 91522 Ansbach, Germany.
18. Changes to this policy
We update this policy when our processing changes. Each published version carries a version number, an effective date, and a cryptographic fingerprint (SHA-256) of its exact text, available in machine-readable form at https://roiko.ai/privacy.json — so the version you agreed to is verifiable byte for byte. Material changes are announced in the product.