Who we are
Rokn is operated by [FULL NAME], individual entrepreneur (micro-entreprise) registered in France, SIREN [SIREN], [ADDRESS] ("we"). This policy explains what personal data we collect when you visit rokn.dev or use the Rokn app at app.rokn.dev, why we collect it, and your rights under the EU General Data Protection Regulation (GDPR).
For any question or request about your data, write to privacy@rokn.dev.
Two different roles
- We are the controller for data about our own users and visitors: your account, your subscription and billing, your use of the website, and messages you send us.
- We are a processor for the data you and your team put into your workspace about your clients and contacts: names, email addresses, invoices, documents, tickets and so on. For that data your business is the controller, and we handle it only on your instructions, under our Data Processing Agreement. If you are one of our customers' clients, contact that business directly about your data.
What we collect and why
Your account
Your name, email address, password (stored only as a secure hash), optional phone number and profile picture, language, time zone and display preferences, and your two-factor settings. If you sign in with Google or GitHub, we receive your name, email address and profile picture from them.
Why: to create and run your account and provide the Service. Legal basis: performance of our contract with you (Article 6(1)(b) GDPR).
Security and sign-in records
The IP address and browser (user agent) of each session, and security-relevant events in your workspace's audit log, such as sign-ins, permission changes and access to stored credentials, together with the IP address and browser involved.
Why: to keep accounts secure, detect abuse and let workspace owners see who did what. Legal basis: our legitimate interest in securing the Service (Article 6(1)(f)).
Billing
Your plan, subscription status, invoices and payment history. Card details are entered directly with Stripe. We never see or store your full card number.
Why: to charge for paid plans and keep accounting records. Legal basis: performance of the contract, and our legal obligation to keep accounting records (Article 6(1)(c)).
Emails we send you
Account emails (verification, password reset, security alerts), billing emails and notifications you have enabled. We record whether our messages were delivered or bounced. We do not track opens.
Legal basis: performance of the contract. Where we send product news, it is only with your consent, and you can unsubscribe at any time.
The assistant
When you use the in-app assistant, your messages, and the workspace data the assistant reads to answer them, are sent to the AI provider selected for that conversation (Anthropic or OpenAI). Under their API terms, these providers do not use this data to train their models. With OpenAI we also switch storage of conversations off. Conversations stay in your workspace until their author deletes them. Nothing is sent to an AI provider unless someone uses the assistant.
Legal basis: performance of the contract (it is a feature you choose to use).
Contact form and support
When you write to us or use the contact form on rokn.dev, we receive what you send (typically your name, email address and message). The contact form is protected by Cloudflare Turnstile to block bots.
Why: to answer you. Legal basis: our legitimate interest in answering enquiries, or steps before a contract at your request.
Error reports
When something breaks, an error report is sent to our monitoring service, Sentry, hosted in the EU. Reports identify a user only by an internal id. They exclude request bodies, cookies, query strings and credentials.
Legal basis: our legitimate interest in keeping the Service working.
We do not use advertising, tracking pixels or third-party analytics, and we do not sell personal data.
Who we share data with
We use the following providers (sub-processors) to run Rokn. Each receives only what it needs:
- Hetzner Online GmbH (Germany): servers and database hosting, in the EU.
- Cloudflare, Inc. (USA): network protection, content delivery, file storage (R2), backups and bot protection on our forms.
- Stripe (Ireland / USA): payment of Rokn subscriptions and AI credit packs.
- Resend (USA): sending emails.
- Sentry (EU region): error monitoring.
- Anthropic PBC and OpenAI (USA): the assistant, only when it is used.
- Google and GitHub (USA): only if you choose to sign in with them or connect Google Calendar.
Services you connect yourself (your own payment gateway or email provider, webhooks you configure) receive data under your control and their own terms.
We may also disclose data where the law requires it, for example to a court or a competent authority.
Transfers outside the EU
Some providers are based in the United States. Where data is transferred outside the European Economic Area, it is protected by the EU-US Data Privacy Framework where the provider is certified, and otherwise by the European Commission's Standard Contractual Clauses.
How long we keep data
- Account data: for as long as your account exists. When you ask us to delete your account, we delete it within one month, except what we must keep by law.
- Workspace data: until the workspace is closed. A closed workspace can be recovered for 30 days and is then permanently deleted.
- Billing records: 10 years, as French accounting law requires.
- Audit logs: 30, 180 or 365 days, depending on the workspace's plan.
- Assistant conversations: until their author deletes them, or the workspace is deleted.
- Contact form messages and support emails: as long as needed to handle your request, and at most 12 months after the last exchange.
- Backups: kept for up to 30 days, then overwritten. Deleted data therefore disappears from backups within 30 days of its deletion.
Cookies
We use only cookies that are necessary for the site and the app to work, or that remember a choice you made. None of them tracks you, so we do not ask for cookie consent.
- Sign-in session cookies (app): keep you signed in. They expire when your session ends.
- NEXT_LOCALE (app): remembers your language. It lasts 1 year.
- Signing-page cookie (app): proves the one-time code step on a contract signing page. It is short-lived.
- rokn-theme (website): remembers light or dark mode. It lasts 1 year.
- Stripe sets its own cookies on its payment pages, to prevent fraud.
- Cloudflare may set a security cookie to protect against abuse, and Turnstile runs on the contact form.
Your rights
You can ask us to access, correct or delete your personal data, to restrict or object to its processing, and to receive it in a portable format. You can also withdraw any consent at any time. Much of this you can do yourself in the app: edit your profile, or export a workspace as its owner. For anything else, write to privacy@rokn.dev. We answer within one month.
If you believe we have not handled your data properly, you can complain to the French data protection authority, the CNIL (www.cnil.fr), or to the authority in your own EU country.
Security
Connections are encrypted (HTTPS). Workspaces are isolated from each other at the database level. Stored secrets, such as saved credentials and payment keys, are encrypted with AES-256-GCM under a key specific to each workspace. Two-factor authentication is available for every account.
Changes
We will update this policy when our processing changes, and we will tell you in advance of any material change. The date of the current version is shown on this page.