Rooost Privacy Policy

We take your privacy seriously. This Privacy Policy explains what we collect, how we use it, and your rights.

Last Updates: May 4, 2025

1. What We Collect

When you use Rooost, we collect:

  • Account Information: Email address, name, and organization (via Clerk)
  • Uploaded Research Data: Files and text you upload
  • Usage Data: Interactions, queries, and preferences
  • Technical Data: Browser, device type, IP address (standard for security and performance)

2. How We Use Your Data

We use your data to:

  • Provide and improve Rooost services
  • Create dynamic personas based on your uploaded research
  • Communicate with you (product updates, support)

3. Handling Personally Identifiable Information (PII) in Uploaded Research

We systematically detect and scrub personal information from your uploaded research. However:

  • We cannot guarantee 100% removal of PII
  • You are responsible for ensuring no PII is included in your data uploads.
  • Rooost assumes no liability for missed PII.

4. Sharing Your Data

We do not sell your data. We only share it with trusted third-party services as necessary to operate Rooost:

  • OpenAI and Pinecone (for persona data processing) – We use these services to help turn your uploaded research into dynamic personas. Your data may be processed by them as part of this process.
  • MongoDB (for data storage) – We store your uploaded research and related data securely in MongoDB.
  • Clerk (for user account management and authentication) – Clerk handles signups, logins, and secure management of your user account information.
  • Vercel (for hosting and performance monitoring) – Our website and app are hosted on Vercel. This means technical and usage data (like IP address, browser type, and site interactions) may be processed by them to help deliver and optimize Rooost. Vercel does not use this data for marketing purposes.
  • Resend (for email delivery) – We use Resend to send emails related to your account and activity on Rooost. This may include your email address and limited usage details. Resend only uses this data to send the emails we initiate — not for their own marketing.

These providers are required to protect your data and only use it for the purposes outlined above.

5. How Long We Keep Your Data

You can request deletion at any time. We automatically delete your data 90 days after account cancellation, unless required for legal, security, or operational reasons.

6. Security

We take security seriously and use technical safeguards to protect your data.

7. Your Rights and Choices

You can:

  • Access and update your account data
  • Request deletion of your data
  • Contact us for questions about your privacy: hello [at] rooost [dot] co

8. Changes to This Policy

We may update this Privacy Policy from time to time. If we make significant changes, we'll notify you.