Privacy Policy

How Romy handles workspace data, connected accounts, product usage, and support contact.

Last updated

Sections

01

Who operates Romy

Romy is a product operated by Tincture, https://tinctu.re. For data protection purposes, Tincture is the data controller for the personal data described in this policy.

Contact: hello@romy.is.

02

What this policy covers

This covers personal data collected when you sign up for Romy, connect accounts or tools to your workspace, use the product, or contact us for support. It does not cover linked third-party sites, which have their own policies.

03

What Romy handles, and why

Romy is a workspace-based product. Data lives inside a workspace and is scoped to it. In rough order of sensitivity:

Open. Public or low-sensitivity material, such as public opportunity signals or content you choose to publish.

Internal. Operational workspace data: goals, deals, tasks, projects, notes, people, strategy artifacts, and company enrichment facts with provenance.

Sensitive. Inbox content, meeting transcripts, financial detail, credentials, and any connected-account data you grant access to (for example Google OAuth scopes).

Billing data. Handled by our payment processor (Stripe). We do not store full card numbers.

04

Connected accounts

When you connect a third-party account (email, calendar, CRM, or similar), Romy requests only the scopes needed for the features you use. Scopes are shown before you grant access, and connections can be revoked at any time from Settings. Tokens are encrypted before storage.

05

How we use your data

Workspace data belongs to the workspace. Romy is the custodian, not the owner. Specifically:

  • Workspace data is never sold or used for advertising.
  • We may use anonymized, aggregated patterns across workspaces to improve the underlying product and strategy corpus. This never includes identifiable business or personal data, and never targets an identified account.

06

Who we share data with

Service providers who help run Romy, each under a data processing agreement: Supabase (database and storage), Vercel (hosting), Stripe (payments), PostHog (product analytics), Anthropic, OpenAI, and Google (AI processing), and any email delivery provider in use. A full list of subprocessors is available in the Help Center of the platform.

We also share data with authorities where legally required.

07

International transfers

Some providers are based outside your country, typically the US or EU/EEA. Where required, transfers rely on standard contractual safeguards.

08

Retention

  • Soft-deleted records: recoverable for 30 days, then purged.
  • Meeting transcripts: kept until you delete them.
  • Connected-account data: retained while the connection is active; deleted within 30 days after disconnection.
  • Billing and financial records: kept as required by applicable tax law.
  • After these periods, data is deleted or anonymized.

09

Your rights

Subject to your jurisdiction, you can typically ask to access, correct, delete, restrict, or export your data, and withdraw consent where consent is the basis for processing. To exercise these, email hello@romy.is. We aim to respond within 30 days.

10

Security

We use encrypted storage, access controls scoped to what's needed, and workspace-level isolation enforced at the database layer rather than only in the application. If we discover a breach that meets the legal threshold, we will notify affected users and any required regulator without undue delay.

11

Cookies

We use cookies only to track traffic and to enhance our user experience.

12

Children

Romy is for business use and is not directed at anyone under 18. By using Romy you confirm you are at least 18 years of age, have the legal capacity to enter into a binding agreement, and use the Services only for lawful purposes.

13

Changes to this policy

Material changes will be flagged in-app and may require re-acknowledgement. The "last updated" date will reflect the most recent change.

14

Contact

hello@romy.is

End of privacy policy.