Your data, and your right to take it back.
Romy connects to your calendar, your inbox, your repositories and the tools your business already runs on. That only works if you can see what we hold and end it on your terms.
The rules you can hold us to.
Your rights don’t depend on where Romy is registered. They depend on where you are. We don’t run a different process depending on which one applies to you: there’s one route in, and it’s the same route for everybody.
- GDPREU and EEA
- Access what we hold, correct it, delete it, restrict how it’s processed, take it elsewhere in a portable format, object to processing, and withdraw consent where consent is what we relied on.Your rights, European Commission
- UK GDPR and the Data Protection Act 2018United Kingdom
- The same set of rights, overseen by the Information Commissioner’s Office. Romy is operated from the UK, so this is the regime we run natively.Your data matters, ICO
- CCPA, as amended by the CPRACalifornia
- Know what we collect and why, delete it, correct it, opt out of sale or sharing, limit how sensitive personal information is used, and never be treated worse for asking. Romy doesn’t sell personal information and never has.CCPA, California Attorney General
- Everywhere elseRest of world
- We don’t gate these rights by address. If your jurisdiction gives you a right that isn’t listed here, tell us and we’ll honor it.
If you have any questions, email us on hello@romy.is. We’ll get back to you within 48 hours.
Deletion that actually deletes.
Deletion is the question people ask most. Here’s our step-by-step of how it happens, and the protocols we stand by.
Disconnect a connector
Revoke it in Settings. Romy stops reading from that account straight away, and everything we pulled from it is deleted within 30 days.
Delete a record
Anything you delete inside your workspace stays recoverable for 30 days, then it’s purged for good. The window exists so a mis-click isn’t permanent; it isn’t us holding a copy back.
Delete a meeting transcript
Transcripts are kept until you delete them, and not a day longer. There’s no expiry you have to wait out and no archive behind the delete button.
Delete the whole workspace
Ask, and we remove the workspace and everything scoped to it. The only thing that survives is the billing and tax record we’re legally required to hold on to.
Take it with you first
Ask for an export before you delete anything. Your workspace data is yours, and it leaves in a format you can read and use somewhere else.
None of this needs a ticket you have to chase. Email hello@romy.is and it gets done.
What we hold, and how it’s kept apart.
Romy is a workspace product. Your data lives inside your workspace and is scoped to it. It isn’t pooled with anyone else’s and it isn’t a shared pile we filter on the way out.
Access
- Sign-in built on an audited platform
- Romy’s sign-in runs on Supabase Auth rather than a login written once and never revisited, and multi-factor authentication is enabled on Romy accounts. You can enable this in your settings.
- Isolation enforced by the database itself
- Workspace separation is enforced by row-level security in Postgres, on Supabase. An application bug can’t leak another workspace’s rows, because the database itself won’t hand them over.
- The narrowest scope that works
- Romy asks for the permissions a feature really needs and shows you every scope before you grant it. Read access where reading is enough. Nothing requested speculatively.
Storage
- Encrypted at rest and in transit
- Supabase encrypts customer data at rest with AES-256 and in transit with TLS. Connected-account tokens get a second layer on top: they’re encrypted at the application level before they reach the database, so a copy of the database on its own is no use to anyone.
- Backed up, and restorable
- Your workspace database is backed up every day, so a mistake on our side is something you recover from rather than something you lose a workspace to.
- Payment details we never see
- Stripe handles billing end to end. Romy doesn’t store full card numbers, because Romy never receives them.
Sharing
- Every provider under a written agreement
- Each service that touches your data does so under a data processing agreement, and your workspace data is held in the EU under GDPR. Where an AI provider processes something outside the EU, that transfer relies on standard contractual safeguards.
- Your data remains your data
- We may use anonymized, aggregated patterns across workspaces to improve your outcomes. This is restricted to outcome data only, for example the number of likes a tweet received. It never includes identifiable business or personal data, never data beyond the scopes set out here, and never ever a named account.
- Never sold, never used for advertising
- Not to anyone, in any form, at any price.
Romy is the custodian of your workspace data, and this is something we take very seriously. It isn’t ours, and we don’t behave as though it is.
The standards we build against.
We build to OWASP, the Open Worldwide Application Security Project: the reference the industry uses for what secure software has to get right.
- OWASP Top 10
- The ten failure classes behind most real breaches: broken access control, injection, authentication and session failures, insecure design, and the rest. Every feature that touches workspace data is built and reviewed against them.
- OWASP ASVS
- The Application Security Verification Standard: a line-by-line bar for authentication, session handling, access control, and data protection. It’s what turns "we take security seriously" into a list you can actually check.
Certifications
Romy is early and small, but that doesn’t mean we don’t take your data privacy seriously. We make considered choices to work with services that hold independent certifications of the highest grade, and will always be able to tell you exactly where your data sits, and what those companies are independently certified to.
| Provider | What it holds | Independently certified to |
|---|---|---|
| Supabase | Database and storage | SOC 2 Type 2, ISO 27001 certified, HIPAA compliant |
| Vercel | Hosting and delivery | SOC 2 Type 2, ISO 27001:2013 certified |
| Stripe | Payments | PCI Service Provider Level 1, SOC 1 and SOC 2 Type II |
The full subprocessor list lives in the platform’s Help Center, and the Privacy Policy names every category of provider we share data with. If a security question isn’t answered anywhere on this page, ask it and we’ll answer it directly.
Where the detail lives.
These are the governing legal documents which this page summarizes.
- Privacy PolicyWhat we collect, why, who we share it with, and how long we keep it.
- Terms of ServiceThe agreement between you and Romy, including ownership of workspace data.
- Cookie NoticeWhat runs in your browser, and how to turn the optional parts off.
A question this page doesn’t answer, or a request to exercise any right on it: hello@romy.is

