LEADERSHIP ROOM

Privacy Policy

Last updated August 8, 2026

Room is a behavioral coaching and education product for working professionals. This policy explains what we collect, how we use it, and the choices you have. It is not a medical, clinical, or mental-health service. By using Room at room.coach (the “Service”), you agree to this policy.

1. What we collect

Information you provide

Information generated as you use Room

Payment information

Subscriptions and trials are processed by Stripe. Stripe handles your payment details directly. We do not receive or store your full card number. We store your subscription status and a Stripe customer identifier.

Technical & device information

Our infrastructure providers process standard technical data such as IP address, browser/user-agent, request URLs, and timestamps in server logs for security, reliability, and abuse prevention. Room uses your browser’s local storage to stay fast and offline-capable and to hold your signed-in session.

2. How we use information

3. Artificial intelligence

Room’s coaching is powered by large language models operated by a third-party AI provider (currently Fireworks AI). When you use the coach, the messages you send and certain context — your progress signals and AI-derived memory — are transmitted to the AI provider to generate a response and to compute vector embeddings used for retrieval. We store AI-generated summaries of your interactions, linked to your account, so the coach can maintain continuity over time.

We may use your interactions and content to operate, evaluate, and improve the Service, including developing and improving our features and models. AI-generated coaching can be inaccurate, incomplete, or unsuitable for your situation. It is for reflection and skill practice only and is not professional, medical, psychological, legal, or financial advice. We do not use AI to make decisions that produce legal or similarly significant effects about you. Please do not enter sensitive personal information, or other people’s personal data, that you would not want processed by a third-party AI provider.

4. Legal bases (EEA/UK)

If you are in the European Economic Area or the United Kingdom, we rely on these legal bases:

5. How we share information

We share information with the service providers below, and as otherwise described here.

RecipientPurpose
SupabaseAuthentication, database, and hosting of your account, synced progress, and AI-derived memory, protected by row-level security.
Fireworks AILarge-language-model inference and text embeddings that power the AI coach and retrieval.
GoogleOptional “Sign in with Google” authentication, only if you choose it.
StripePayment processing, subscriptions, and trials.
VercelHosting and delivery of the web application.

We may share or sell de-identified or aggregated information for any lawful purpose. If we sell or share personal information as those terms are defined by applicable law, we will provide the notices and opt-out mechanisms that law requires. We may also disclose information to comply with law, respond to lawful requests, protect our rights, users, or the public, or in connection with a merger, acquisition, financing, or sale of assets.

6. International data transfers

Our providers may process your information in the United States and other countries whose data-protection laws may differ from your own. Where required, we rely on appropriate safeguards, such as the European Commission’s Standard Contractual Clauses, for cross-border transfers.

7. Data retention

We keep your account information and synced data for as long as your account is active or as needed to provide the Service, and we retain limited records where required for legal, tax, security, or dispute-resolution purposes. When you delete your account, we delete or anonymize associated personal data within a commercially reasonable period, except where retention is legally required or where information has been de-identified or aggregated.

8. Your rights and choices

Depending on where you live — including under the EU/UK GDPR and the California Consumer Privacy Act as amended — you may have the right to access, correct, delete, or receive a copy of your personal information, to object to or restrict certain processing, and to withdraw consent. Where applicable law grants a right to opt out of the sale or sharing of personal information, you may exercise it using the contact below.

To exercise any right, contact josh@room.coach. We may need to verify your identity. If you are in the EEA/UK, you may also lodge a complaint with your local supervisory authority.

9. Security

We use technical and organizational measures appropriate to the risk, including encryption in transit, row-level access controls on your records, and least-privilege secret handling — application clients never receive service-role or AI-provider keys. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

10. Children

The Service is intended for adults (18+) in a professional context and is not directed to children. We do not knowingly collect personal information from anyone under 16. If you believe a child has provided us personal information, contact us and we will delete it.

11. Changes to this policy

We may update this policy from time to time. We will revise the “Last updated” date above and, for material changes, provide additional notice where required. Your continued use of the Service after an update means you accept the revised policy.

12. Contact

Questions or requests: josh@room.coach.