Privacy Policy

roomn — Hedefa

Effective April 15, 2026

Last updated: April 15, 2026

Table of Contents

Introduction

Welcome to Roomn, a study buddy matching and social study application developed by Hedefa. Roomn connects students with compatible study partners, provides collaborative study tools, and builds an engaging community around academic achievement.

This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use the Roomn mobile application and associated services. We are committed to protecting your privacy and handling your data with transparency and care.

By using Roomn, you agree to the collection and use of information in accordance with this policy. If you do not agree with the terms of this Privacy Policy, please do not access or use the application.

This Privacy Policy is effective as of April 15, 2026.

Scope

This Privacy Policy applies to:

This Privacy Policy does not apply to third-party services, websites, or applications that may be linked from within the Roomn app. We encourage you to review the privacy policies of any third-party services you access through or in connection with Roomn.

Data We Collect

We collect several categories of information to provide and improve the Roomn experience. Below is a comprehensive breakdown of the data we collect, organized by type.

3.1 Account Data

3.2 Profile Data

3.3 User-Generated Content

3.4 Device & Technical Data

3.5 Usage & Behavioral Data

3.6 Subscription & Purchase Data

Important: We never see or store your payment card details, bank account information, or any financial payment credentials. All payment processing is handled exclusively by Apple through the App Store.

3.7 AI-Generated Content

How We Use Your Data

We use the information we collect for the following purposes:

  1. Providing the core service — enabling study buddy matching, chat, classrooms, study sessions, the community feed, and profile functionality.
  2. Account management — authentication, password resets, and account deletion.
  3. Personalization — discovery ranking, recommended classrooms, and virtual pet progression.
  4. AI report cards — generating weekly study summaries via Cloudflare Workers AI.
  5. Push notifications — sending match alerts, message notifications, classroom activity updates, and study reminders.
  6. Subscriptions and billing — managing premium entitlements through RevenueCat and Apple.
  7. Safety and moderation — reviewing reported content, enforcing community rules, and banning users who violate our terms.
  8. Analytics and product improvement — understanding feature usage and improving the app through PostHog analytics.
  9. Legal compliance — responding to lawful requests and enforcing our Terms of Service.
  10. Communications — sending critical service messages. We do not send marketing communications unless you have explicitly consented.

Legal Bases for Processing (EU/UK Users)

For users in the European Union and United Kingdom, we rely on the following legal bases under GDPR:

On-Device Processing

Certain features in Roomn leverage on-device processing to protect your privacy:

These on-device features mean that the content of your messages is never transmitted to external servers for translation or language identification purposes.

Third Parties & Sub-Processors

We work with the following third-party service providers to operate Roomn. Each provider receives only the data necessary to perform their specific function.

Provider Purpose Data Shared
Supabase Database, authentication, storage, realtime, and edge functions All account, profile, content, and usage data
Apple Sign in with Apple, APNs, In-App Purchases, on-device Translation Auth identifiers, device tokens, purchase receipts
Google Google Sign-In OAuth token, email address, name
RevenueCat Subscription management Anonymous user ID, receipt data, entitlement status
Cloudflare Workers AI for weekly study report generation Aggregated study session data
PostHog Product analytics and feature flags Usage events, device type, anonymized identifiers
We do not sell your personal data to anyone.

AI Disclosure

Roomn uses artificial intelligence to enhance your study experience. Here is a full disclosure of how AI is used within the app:

Children & Minors

Protecting the privacy of young people is especially important to us.

COPPA Compliance

Roomn does not knowingly collect personal information from children under 13 in compliance with the Children's Online Privacy Protection Act (COPPA).

GDPR-K (Age of Digital Consent)

In the European Union and member states, the age of digital consent varies between 13 and 16. Users below the applicable local age of digital consent require verifiable parental permission. Roomn does not currently support a parental consent verification flow; therefore, users in those jurisdictions who are below the local digital consent age should not use the app without parental supervision.

UK Age-Appropriate Design Code

Roomn is designed with the following principles from the UK Age-Appropriate Design Code in mind:

Your Rights

Depending on your location, you may have the following rights regarding your personal data:

To exercise any of these rights, you can use the in-app account deletion feature or email us at [email protected]. We will respond to your request within 30 days.

Data Retention

We retain your data according to the following guidelines:

Data Location & Transfers

Your data may be stored and processed in the following locations:

International Transfers

Security

We implement appropriate technical and organizational measures to protect your data:

While we strive to use commercially acceptable means to protect your personal data, no method of transmission over the Internet or method of electronic storage is 100% secure. We cannot guarantee absolute security.

Push Notifications

Roomn may send push notifications for the following events:

You can disable push notifications at any time through your iOS Settings. Your device token is stored in our device_tokens database table and is deleted when you log out or delete your account.

Location Data

Roomn uses self-reported city information only. We want to be clear about what we do and do not collect:

The city you enter in your profile is used solely to help connect you with nearby study buddies and is displayed on your profile. You can change or remove your city at any time through your profile settings.

Photos & Media

Roomn allows you to upload photos and images in several contexts:

You can delete your own media at any time. All media associated with your account is permanently removed when you delete your account.

Content Moderation

To maintain a safe and respectful community, Roomn provides content moderation tools and processes:

California Privacy (CCPA/CPRA)

If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA).

Categories of Personal Information Collected

Your California Rights

EU/UK GDPR

For users in the European Union and the United Kingdom, the following additional information applies under the General Data Protection Regulation (GDPR) and UK GDPR:

Saudi Arabia PDPL

For users in the Kingdom of Saudi Arabia, the following information is provided in accordance with the Personal Data Protection Law (PDPL):

Note: The scope and application of PDPL provisions should be confirmed with local legal counsel before publication. [CONFIRM]

Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors.

Contact

If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please reach out to us:

We aim to respond to all inquiries within 30 days of receipt.