Privacy Policy

Last updated:

Contents
  1. Who we are
  2. What we collect and why
  3. AI processing
  4. Legal bases
  5. Who we share data with
  6. International transfers
  7. How long we keep data
  8. Your rights
  9. Security
  10. Children
  11. Changes

Who we are

roomvia is an app by 1742 (“we”, “us”). The company behind it, with its legal name, registered address, MERSİS number and contact e-mail, is shown in the company details at the end of this page. That company is the data controller for the personal data described here.

This policy explains what data roomvia collects, how and why we use it, who we share it with, how long we keep it and what your rights are. It covers the roomvia app on iPhone and Android and our roomvia web pages.

For any privacy question or request, write to the e-mail address in the company details below. TODO(founder): add a separate privacy contact address here if you want one.

What we collect and why

Your account

  • Without signing in. On first open the app creates an anonymous account for you. It is identified by random IDs stored on your device (an account ID and an installation ID with a key that never leaves the device). You don’t give us your name or e-mail to use the app.
  • If you sign in with Apple (iPhone) or Google, we receive an account identifier from Apple or Google, your e-mail address (with Apple this can be a private relay address) and, the first time you sign in with Apple, your name if you share it. With Apple we also keep an encrypted token so that we can revoke Sign in with Apple when you delete your account.
  • Why: to run your account, keep your designs and Boosts together and let you use the same account on several devices.

Your device

  • Device and app details: platform, operating system version, device model, app version and build, language, time zone and store country.
  • Device identifiers: on iPhone Apple’s identifier for vendor (IDFV), on Android the App Set ID, and the Firebase app instance ID. We do not collect the iPhone advertising identifier (IDFA). On Android, Google’s Firebase SDK collects the Android advertising ID (see “Advertising measurement”).
  • A device key, which we store only as a one-way keyed hash, and Apple DeviceCheck or Google Play Integrity results. We use these to give free Boosts only once per device, to prevent abuse and to keep the service secure. With DeviceCheck, Apple stores two bits for a device on our behalf (for example “free Boosts already given”); they do not identify you.
  • Network data: your IP address and what our hosting provider derives from it: country, region and network (operator name and number). We never store your city. We use this for security, abuse prevention, the free Boost rules and to show the styles available in your country.
  • Sessions: when you open the app and when it was last used.

Your photos and designs

  • The photos you upload (rooms, buildings and gardens, object and reference photos), the masks you draw, the options you choose (room type, style, palette, material) and any text you type (up to 300 characters).
  • The designs we create, your favourites and ratings.
  • Before upload the app converts each photo to JPEG, resizes it and removes its metadata (such as location data stored by the camera).
  • Why: to create and show your designs. Photos and text are also checked automatically for prohibited content (see “AI processing”).

Purchases and Boosts

  • Payments are taken by Apple (App Store) or Google (Google Play); we never receive your card details.
  • We receive purchase records through the stores and RevenueCat: product, price and currency, dates, transaction IDs, trial and renewal status, cancellations and refunds.
  • Your Boost balance and its history (Boosts granted, used, returned or expired).
  • Why: to give you what you paid for, keep your balance correct across devices, handle refunds and keep accounting records.

Usage and crash data

  • With Google Firebase Analytics we record how the app is used (for example screens and steps you complete, paywall views, styles you tap, updates and links you open), linked to your roomvia account ID and the Firebase app instance ID. Google Signals is off.
  • With Firebase Crashlytics we record crashes and errors with technical details, linked to your roomvia account ID.
  • Firebase Remote Config and Cloud Messaging receive your device language, country, time zone, operating system and Firebase installation ID.
  • Why: to understand how the app is used, fix problems and improve it.

Notifications

  • If you allow notifications, we store your device’s push token and a record of the notifications we send and which ones you open.
  • We tell you when a design is ready or has failed. We may also send notifications about new styles, tips and offers; the app does not ask for separate permission for these. You can turn notifications off at any time in your device settings (on Android also by category) and turn off the “When my design is ready” notification in the app’s Settings.

Advertising measurement

We advertise roomvia on Meta (Facebook, Instagram), TikTok and Google and measure which ads lead to installs and purchases. This is “tracking” as Apple defines it. The app does not show ads.

  • Ad clicks. If you reach the store through one of our ad links, we record the click: IP address, browser user agent and language, the ad network’s click IDs, campaign, ad set and ad names and IDs.
  • Matching the install. When you first open the app we try to match the install to that click: on Android with the Google Play install referrer, on iPhone with Apple Search Ads attribution or, within 24 hours of the click, by comparing the IP address and iOS version of the click and the install. This iPhone match is a probability, not a certainty.
  • Meta and TikTok. For installs matched to their ads we send a free trial that is still active 24 hours after it started, a first subscription payment or a Boost pack purchase to Meta (Conversions API) or TikTok (Events API), with the price and currency, the ad click ID, the IP address and user agent of the click and a one-way hash (SHA-256) of your roomvia account ID. If a purchase is refunded before its event is sent, nothing is sent.
  • Google. Google measures its ads with the Firebase SDK in the app: Firebase Analytics events (such as first open, trial start and purchases) are linked to Google Ads, and remarketing (ads personalisation) is on. On Android this uses the Android advertising ID. On iPhone we use Google’s on-device conversion measurement, which according to Google keeps identifying data on the device, and Apple’s privacy-preserving ad attribution (SKAdNetwork).
  • Your choices. The app has no switch to turn advertising measurement off. Deleting your account stops it: we delete the link between your account and the ad click and send nothing more. Data already sent to an ad network cannot be recalled. TODO(founder): counsel to review this section (no opt-out in the app since 2026-10-09, no consent prompt, also in the EEA / UK / Switzerland).

Support

  • When you write to us from the app, the e-mail contains a block of details that helps us find your account and the problem: app, account ID, support code, a signed reference, app version, platform, operating system, device model, language, time zone, country and, if you came from an error, the design job ID and error code. It never contains your e-mail address, name or IP address. Your e-mail address and what you write reach us with the e-mail.
  • If you use the deletion request form on our website, we receive your e-mail address and, if you enter it, your support code.
  • Why: to answer you and verify that a request comes from the account holder.

Reports

You can report any of your designs in the app. Reporting deletes the design at once. We keep a record of the report (reason, your note, your support code, the tool used, the date and the reported image) in a private chat used only by our team (on Telegram) to watch for abuse. If the report concerns a minor, the image is not sent anywhere; it is kept securely as the law requires (see “How long we keep data”).

Our website

  • Our landing and home pages use Cloudflare Web Analytics, which does not use cookies or identify you. Our legal pages load no scripts.
  • The account deletion page loads Sign in with Apple, Google Sign-In and Cloudflare Turnstile (a security check) so that you can prove the account is yours.
  • If you open our website on a computer after clicking one of our ads, the page shows a QR code that carries that ad click to your phone. We don’t ask for your e-mail or phone number for this.

AI processing

roomvia creates designs with AI models. When you start a design:

  • Your photo (or the earlier design you build on), the mask and the reference images, together with your options and text, are sent to WaveSpeed (WaveSpeedAI PTE. LTD., Singapore and WaveSpeedAI LIMITED, Hong Kong), which runs the AI models. Depending on the tool and speed, the models come from Google, ByteDance, Alibaba, Bria and OpenAI, and your data may be processed by them through WaveSpeed. WaveSpeed receives a link to your photo that expires after one hour.
  • WaveSpeed keeps inputs and results for at most 7 days; we delete them there as soon as we have copied the result to our own storage.
  • Your photos, your text and the results are checked automatically by OpenAI’s moderation service. Content that breaks our rules is blocked and not processed.
  • We do not use your photos to recognise people.
  • On iPhone the app names these providers and asks you to accept before your first design; your answer is stored only on your device and the screen appears again when the list changes. You can stop at any time by not creating designs, deleting your designs or deleting your account.

Legal bases

Under the Turkish Personal Data Protection Law (KVKK, Article 5) and, where it applies, the EU and UK GDPR (Article 6), we rely on:

  • Performance of our contract with you: your account, creating, storing and showing your designs (including AI processing), purchases and Boosts, notifications about your designs and support.
  • Legal obligations: accounting and tax records, content we must preserve by law and requests from authorities.
  • Legitimate interests: security, preventing abuse and fraud (including the free Boost checks), content moderation, crash reports and fixing problems.
  • TODO(founder): counsel to set the legal basis for usage analytics, advertising measurement and marketing notifications. The app asks no consent for these today (founder decisions Q25, Q28, Q49).

Who we share data with

We share personal data only with the parties below, only for the purposes described, and only with parties that provide the same or equal protection of your data as this policy.

  • Cloudflare (USA, global network): our servers, file storage, website, e-mail and support mailbox, security check (Turnstile) and web analytics.
  • Supabase (USA): our database, hosted in the United States.
  • WaveSpeed (Singapore, Hong Kong) and the AI model providers Google, ByteDance, Alibaba, Bria and OpenAI: creating designs (see “AI processing”).
  • OpenAI (USA): content moderation.
  • RevenueCat (USA): managing purchases and subscriptions.
  • Apple and Google: app stores and payments, sign-in, notifications (Firebase Cloud Messaging and Apple Push Notification service), device checks and install attribution.
  • Google (Firebase Analytics, Crashlytics, Remote Config, Cloud Messaging; Google Ads): analytics, crash reports, app settings, notifications and advertising measurement. Google Analytics data is stored in the USA.
  • Meta and TikTok: advertising measurement (see “Advertising measurement”).
  • Anthropic (USA): our team uses Claude to draft replies to support e-mails; a person reviews and sends every reply.
  • Telegram: report records in our team’s private chat (see “Reports”).
  • Authorities, when the law requires it.

If you sign in with the same Apple or Google account in more than one of our apps, our servers link those accounts to one internal record. It is never shown in any app; we use it for sign-in and for security, for example so that a ban for the most serious abuse applies to all our apps.

International transfers

Most of the parties above process data outside Turkey and outside the EEA, mainly in the United States, Singapore and Hong Kong. For these transfers we use the standard contracts of the Turkish Personal Data Protection Board (notified to the Board as KVKK Article 9 requires) and, for the GDPR, the EU standard contractual clauses or another valid safeguard.

TODO(founder): confirm before publishing that these contracts are signed with every provider and notified to the Board, and that the WaveSpeed data processing agreement covers the current company.

How long we keep data

  • Photos and designs: each design and the photos it uses are deleted 90 days after the design is created, whether or not you use the app. Using a design or photo again for a new design keeps it for 90 days from that moment. An earlier design shown as the “before” of a newer one is kept as long as the newer one.
  • Photos not used for any design: 7 days after upload (or 7 days after a design that failed).
  • Results that did not become a design (for example blocked results): 90 days.
  • Designs you delete: removed within 7 days; the text you typed is deleted at once.
  • Reported designs: deleted at once. The reported image is sent to the report record in our team’s chat (see “Reports”). TODO(founder): retention of report records in the Telegram chat. Content reported as involving a minor is not sent anywhere and is preserved for 1 year as the law requires.
  • Your account: until you delete it.
  • Accounts never used again: an anonymous account that never made a purchase is deleted after 12 months without use. TODO(founder): this cleanup job is not built yet (PLAN §6.5); build it before launch or drop this line.
  • Sessions: 13 months; IP addresses are shortened after 30 days.
  • First-open records: IP addresses are shortened after 30 days and ad attribution details are deleted after 13 months; the record itself is kept in pseudonymised form.
  • Ad clicks: IP addresses are shortened and browser language deleted after 30 days, the user agent is deleted after 90 days, click IDs and campaign details after 13 months. Records of conversions sent to ad networks are kept without time limit in pseudonymised form.
  • Purchases and Boost history: 10 years in pseudonymised form, for accounting. RevenueCat event details: 36 months.
  • Moderation checks: 12 months. Reports: 3 years.
  • Design job history: 6 months. AI provider responses: 90 days. Apple DeviceCheck tokens: 30 days.
  • Notification records: 90 days. Push tokens: deleted 30 days after they stop working or after 270 days without renewal.
  • Server logs: 7 days. Crashlytics: 90 days. Google Analytics event data: 14 months.
  • Support: e-mails in our support mailbox are deleted after 180 days, or earlier if you ask. Deletion request form: your e-mail address is deleted 90 days after the request is closed and the request record after 1 year.

Your rights

Under KVKK Article 11 you can ask us whether we process your data and for information about it, the purpose of the processing and whether it is used for that purpose, the third parties we transfer it to in Turkey or abroad, to correct or delete it, to have those changes passed on to the third parties, to object to a result against you that comes only from automated analysis, and to claim compensation for damage caused by unlawful processing. Where the GDPR applies you also have the rights of access, rectification, erasure, restriction, data portability and objection, and the right to withdraw consent.

  • How: write to the e-mail address in the company details below. Include your support code (in the app: Settings → Support) so we can find your account; we may ask for more to verify that the account is yours. We reply within 30 days and free of charge.
  • A copy of your data: there is no export in the app; ask us by e-mail.
  • Deleting your account: in the app under Settings → Delete account, or without the app on our account deletion page.
  • Complaints: you can complain to the Turkish Personal Data Protection Board (KVKK) or, where the GDPR applies, to your local data protection authority.

Security

Data is encrypted in transit. Your photos and designs are stored privately and opened only through short-lived signed links; their storage keys don’t contain your account ID. The app signs in with a key that stays on your device and access tokens expire after 60 minutes. Access to personal data is limited to our team, and our support tools log every account lookup.

Children

roomvia is not directed at children under 13. If you believe a child under 13 has given us personal data, contact us and we will delete it.

Changes

We may update this policy. We will publish the new version on this page and change the date at the top.

1742 TeknolojiTODO(founder): şirket adresi
MERSİS: TODO(founder): MERSİS numarası
support@example.com