01
Who operates Romy
Romy is a product operated by Tincture, https://tinctu.re. For data protection purposes, Tincture is the data controller for the personal data described in this policy.
Contact: hello@romy.is.
02
What this policy covers
This covers personal data collected when you sign up for Romy, connect accounts or tools to your workspace, use the product, or contact us for support. It does not cover linked third-party sites, which have their own policies.
03
What Romy handles, and why
Romy is a workspace-based product. Data lives inside a workspace and is scoped to it. In rough order of sensitivity:
Open. Public or low-sensitivity material, such as public opportunity signals or content you choose to publish.
Internal. Operational workspace data: goals, deals, tasks, projects, notes, people, strategy artifacts, and company enrichment facts with provenance.
Sensitive. Inbox content, meeting transcripts, financial detail, credentials, and any connected-account data you grant access to (for example Google OAuth scopes).
Billing data. Handled by our payment processor (Stripe). We do not store full card numbers.
04
Connected accounts
When you connect a third-party account (email, calendar, CRM, or similar), Romy requests only the scopes needed for the features you use. Scopes are shown before you grant access, and connections can be revoked at any time from Settings. Tokens are encrypted before storage.
05
How we use your data
Workspace data belongs to the workspace. Romy is the custodian, not the owner. Specifically:
- Workspace data is never sold or used for advertising.
- We may use anonymized, aggregated patterns across workspaces to improve the underlying product and strategy corpus. This never includes identifiable business or personal data, and never targets an identified account.
07
International transfers
Some providers are based outside your country, typically the US or EU/EEA. Where required, transfers rely on standard contractual safeguards.
08
Retention
- Soft-deleted records: recoverable for 30 days, then purged.
- Meeting transcripts: kept until you delete them.
- Connected-account data: retained while the connection is active; deleted within 30 days after disconnection.
- Billing and financial records: kept as required by applicable tax law.
- After these periods, data is deleted or anonymized.
09
Your rights
Subject to your jurisdiction, you can typically ask to access, correct, delete, restrict, or export your data, and withdraw consent where consent is the basis for processing. To exercise these, email hello@romy.is. We aim to respond within 30 days.
10
Security
We use encrypted storage, access controls scoped to what's needed, and workspace-level isolation enforced at the database layer rather than only in the application. If we discover a breach that meets the legal threshold, we will notify affected users and any required regulator without undue delay.
12
Children
Romy is for business use and is not directed at anyone under 18. By using Romy you confirm you are at least 18 years of age, have the legal capacity to enter into a binding agreement, and use the Services only for lawful purposes.
13
Changes to this policy
Material changes will be flagged in-app and may require re-acknowledgement. The "last updated" date will reflect the most recent change.
14
Contact
End of privacy policy.
