Privacy Policy
Effective September 27, 2026
Your coding sessions stay on your device. The website collects audience statistics, and the app shares a roomba count only if you turn it on. This policy explains those separate activities.
Who we are
Nottifai LLC operates Roombai and roombai.com. For privacy questions or requests, email [email protected]. This policy covers our website, official desktop app and sponsorship service. Independently operated forks and linked websites have their own practices.
Website analytics and counters
We use a self-hosted Umami instance on Railway to understand visits, referral sources and campaigns, browser and device characteristics, approximate location, and download-link clicks. Page addresses, referrer information and URL parameters may be included. Please do not put confidential information in page URLs. Umami does not use tracking cookies; network requests still expose an IP address and request metadata to the hosting services.
Our separate public community counters use a random browsing-session ID stored in your browser’s local storage, with activity timestamps. It rotates after 30 minutes of inactivity or 24 hours, and helps avoid counting reloads and tabs as new visits. While the page is visible, it sends a heartbeat about every 30 seconds. Download clicks send a random event ID, asset/platform label and timestamp. The database stores hashes of these IDs. Short-lived hashes derived from request IP addresses limit abuse; our counter code does not store raw IP addresses in its database.
Public figures show aggregate browsing sessions, current activity, shared roomba counts and download clicks. They do not identify individual visitors, and a click does not establish that a download or installation finished. We use these measurements to understand usage, operate the counters and explain the site’s audience.
The desktop app
Roombai reads supported coding-agent activity locally to draw rooms and show status. The community-count feature does not upload conversations, agent IDs, project names, file paths or usernames.
Share roomba count is off by default. If enabled in the app menu, it sends an aggregate roomba count, a random installation ID, a random credential and a sequence number about once a minute. The server stores hashes of the identity and credential. Turning sharing off stops periodic reports and attempts to clear the current count; without another report it stops contributing to “online” after five minutes. The app keeps its random identity and sequence locally across restarts.
Downloads and update checks contact GitHub and its delivery services, which receive normal network metadata. The optional GitHub whiteboard integration uses your locally authenticated GitHub CLI to request repository information from GitHub. These requests are separate from community analytics.
Sponsors and messages
If you email us, we receive your email address and the information you send. To arrange a sponsorship, we use your company name, logo, website, selected placement, purchase information and correspondence to deliver and support that placement. Your approved name, logo and link appear publicly.
Online Stripe checkout is not currently enabled. If made available, Stripe will handle payment and billing details under its privacy policy. Our sponsorship system will store order and payment references, placement dates, status and a hashed management credential; it will not store full card numbers or security codes. The management link is private and should not be shared publicly.
Service providers and disclosure
Cloudflare hosts the website and counter database; Railway hosts our Umami analytics instance. GitHub delivers source code, releases and updates. Our email provider processes support correspondence, and Stripe processes payments when used. These services process data needed to deliver, secure and support their functions and may process it in other countries, including the United States. Their own privacy notices describe their independent processing: Cloudflare, Railway and GitHub.
We do not sell visitor or app telemetry to sponsors or give sponsors individual browsing records. Clicking a sponsor’s link takes you to their website, where their privacy policy applies. We may disclose records when legally required or reasonably necessary to investigate abuse, protect users or resolve a dispute.
How long records remain
- Counter visit and download-event records become eligible for deletion after one day; installation records after 30 days without a heartbeat; rate-limit records after about two minutes. Cleanup runs on subsequent qualifying requests, so deletion is not immediate at the threshold.
- Aggregate visit and download totals have no automatic expiry. Our website code does not configure an automatic deletion schedule for the self-hosted Umami instance; analytics may remain until deleted.
- The browser’s stored session can remain until it is replaced on a later visit or you clear site storage. The app’s local count-sharing identity remains until its local data is removed.
- We keep support and sponsorship records as needed to provide the service, handle refunds and disputes, and meet accounting or other legal obligations. Removal of a public placement does not automatically delete its transaction records. Provider logs and backups follow their applicable retention practices.
Your choices and rights
You can turn off Share roomba count in the app menu. The website’s community-counter code skips visit and click reporting when your browser sends Do Not Track or Global Privacy Control. That check applies to our counters; the separately loaded Umami script is not currently covered by it. Browser tracker-blocking tools can block Umami. Clearing local storage removes the browser’s session ID but does not opt you out of future visits.
Depending on the laws that apply to you, you may have rights to request access, correction, deletion, portability or restriction of personal information, object to processing, or complain to your local privacy authority. Contact us at [email protected]. We may need to verify a request, and aggregate statistics or random identifiers may not be linkable to you. We may retain records where the law permits or requires it.
We use information to deliver requested services, respond to you, understand and protect the service, and meet legal obligations. Where consent is required, it must be obtained separately; this notice itself is not a request for consent.
Children and policy changes
Roombai is intended for developers and is not directed to children under 13. If you believe a child has supplied personal information, contact us so we can address it. We will update this page and its date when our practices change, and provide additional notice where required.