Roomlyn

Privacy Policy

Last updated: 13 August 2026

This policy explains how Chrometrics Limited (“Roomlyn”, “we”), the operator of roomlyn.com, collects, uses and protects your personal data. We are the data controller. Company no. 14860931, registered in England & Wales. Registered/correspondence address: 167-169 Great Portland Street, 5th Floor, London, W1W 5PF.

Our data-protection point of contact is Steve Padden (Director). For any privacy question or to exercise your rights, contact privacy@roomlyn.com.

What we collect

Account data — your email, name and avatar (from Google sign-in or magic-link) and a sign-in identifier. Content — the room photos you upload, any inspiration images you provide, and the edits/renders you create. Billing — your plan, purchase and token history and a Stripe customer reference; your card details are handled entirely by Stripe and we never see or store them. Usage — edits, token movements and basic activity. Technical — IP address and request logs, used for security and abuse prevention. We do not knowingly process photos that are primarily of identifiable people: uploads are screened and such images are rejected before storage, which deliberately reduces the personal-data and biometric risk surface.

How we use it, and our legal bases

To provide the service — process your edits, manage your account and take payment (legal basis: performance of a contract). To keep the service secure and prevent abuse — rate limits, fraud and content checks (legitimate interests). To send you marketing — only with your separate, opt-in consent, which you can withdraw at any time. To meet legal obligations — for example retaining billing and tax records.

Who we share it with (sub-processors)

We use trusted providers who process data on our behalf under data-processing agreements: Stripe (payments), Google Cloud / Vertex AI (hosting, storage and AI image processing), fal.ai (AI image processing), Neon (database) and Hostinger (sign-in & support email for the roomlyn.com mailboxes). We do not sell your personal data. The current list, with each provider's role and location, is on our Sub-processors page.

AI training

We do not use your photos or edits to train our own AI models, and we do not sell them. Your content is sent to our AI sub-processors (Google Vertex AI and fal.ai) only to generate the edit you asked for. Under our agreements with those providers, content submitted through their business/API services is not used to train their foundation models. If this ever changes, we will update this policy and tell you before it takes effect.

Inspiration links you paste (Pinterest)

If you paste a public Pinterest board, profile or pin link, we fetch that public content through Pinterest's own public widget endpoint — the same one Pinterest's embeddable widgets use — so we can read the images and colours you want your room styled after. We only ever request publicly visible pins; we never sign in to Pinterest, never access private or secret boards, and never post anything on your behalf. The fetched images inform your design and are not shared with anyone else. Pinterest is the source of that content, not a sub-processor of your personal data, and your use of Pinterest remains subject to Pinterest's own terms and privacy policy.

International transfers

Several of our providers process data in the United States. Where we transfer personal data from the UK or EEA, we rely on appropriate safeguards: the UK Extension to the EU-US Data Privacy Framework and the EU-US Data Privacy Framework where the provider is certified (Google, Stripe), and Standard Contractual Clauses together with the UK International Data Transfer Addendum otherwise (including for fal.ai and Neon). Details, and the mechanism per provider, are on our Sub-processors page.

How long we keep it

Account and content data are kept while your account is active. Free-tier rooms and their assets expire automatically after about 30 days; paid plans get longer retention. Billing and transaction records are retained for up to 10 years to meet UK and EU tax/accounting rules — these live with Stripe and our accountant, not in the app, and survive account deletion in anonymised, statement form. Operational logs are retained for about 30 days. When you delete your account, everything else — your photos, edits, rooms, shares and account record — is permanently erased. For disaster recovery we keep encrypted backup copies of stored images for up to 14 days; deleted content therefore leaves our backups within 14 days of erasure, automatically.

Your rights

Subject to applicable law, you can access, correct, export, restrict, object to, or delete your personal data, and withdraw consent at any time. You can download your data or delete your account yourself from your Account page, or email privacy@roomlyn.com. We aim to respond within one month. You may also complain to your data protection authority — in the UK, the Information Commissioner's Office (ICO), ico.org.uk.

Cookies

We set only an essential cookie to keep you signed in, and run no analytics or advertising trackers. See our Cookie Policy for details and your choices.

Children

Roomlyn is not directed to children under 16 (or the minimum age in your country), and we do not knowingly collect their data.

Changes

We may update this policy; we'll post the new date here and, for material changes, notify you.

See also our Terms of Service and Sub-processors list.