Privacy Policy

Last updated: June 16, 2026

This policy explains what personal data we collect when you use RoCortex, why, who we share it with, and the rights you have over it.

  1. 1. Who is responsible for your data

    RoCortex is operated by Aqleon AB, a limited company registered in Sweden under company registration number 559434-4367, with its registered office at Vasagatan 5A, Sweden (“Aqleon”, “we”, “us”). For the personal data described in this policy, Aqleon is the data controller. This policy explains what personal data we collect when you use the RoCortex website, dashboard, and Roblox Studio plugin (the “Service”), how and why we use it, who we share it with, and the rights you have under the EU General Data Protection Regulation (GDPR) and Swedish data-protection law. You can reach us using the contact details at the end of this policy.

  2. 2. What data we collect

    Account data

    You sign in with your Roblox account through our authentication provider, Clerk. We receive identifiers from your Roblox account — your Roblox user ID, username, and public profile information — which we use to create and manage your RoCortex account.

    Billing data

    If you subscribe to a paid plan, payment is handled by our payment processor, Stripe. Stripe processes your payment-method details; we do not receive or store your full card number. We store a Stripe customer and subscription identifier, your current plan and billing period, and your credit balance, so we can provide and manage your subscription.

    Content you submit (prompts and project context)

    When you use the Service, we process the instructions you write and the project context the plugin reads from your open Studio project — such as your script source, the instance tree, project and place names, and recent Studio output. This content, and the code the Service generates in response, is stored as part of your chat history so you can refer back to it. As described in section 4, your instructions and project context are sent to third-party AI providers to generate responses.

    Usage and technical data

    We collect data about how you use the Service — for example which model you used, credits consumed, and metadata about each generation (such as token counts, outcome, and timing) used to operate, secure, and improve the Service. Our hosting providers also automatically collect technical data such as IP address, browser and device information, and access logs as part of running the Service securely.

  3. 3. How and why we use your data

    We use personal data for the following purposes, on the following legal bases under the GDPR:

    • To provide the Service — authenticate you, generate and sync code, and maintain your chat history. Legal basis: performance of our contract with you.
    • To handle payments and subscriptions — process payments through Stripe, manage renewals, credits, and cancellations. Legal basis: performance of our contract, and compliance with our legal obligations for accounting.
    • To secure, maintain, and improve the Service — prevent abuse and fraud, debug, monitor reliability, and understand aggregate usage. Legal basis: our legitimate interests in running a secure and functional service.
    • To communicate with you — respond to support requests and send essential service messages. Legal basis: performance of our contract and our legitimate interests.
    • To comply with the law — for example keeping accounting records. Legal basis: compliance with a legal obligation.

    We do not sell your personal data, and we do not use your prompts or code to train our own AI models. We do not show third-party advertising in the Service.

  4. 4. AI processing of your prompts and code

    To generate responses, the Service sends your instructions together with the project context described above to AI model providers, routed through OpenRouter. The providers process this input to produce the requested output and return it to us. The handling and retention of data by these providers is governed by their own terms and privacy policies. We send only what is needed to generate a useful response, and we do not use your content to train our own models. Please avoid including sensitive personal data or secrets (such as private keys or credentials) in your prompts or project, since that content will be transmitted to these providers to produce output.

  5. 5. Who we share data with (sub-processors)

    We share personal data with service providers who process it on our behalf to run the Service, and only what each provider needs. They fall into two groups:

    • Authentication, payment, and cloud hosting providers — used to sign you in, process payments and subscriptions, host the Service, and store your account and chat data.
    • AI providers — OpenRouter and the AI model providers it routes to — used to process your prompts and project context and generate output, as described above.

    We may also disclose data if required by law, to protect our rights or the safety of others, or in connection with a business transfer such as a merger or acquisition, in which case we will inform you.

  6. 6. Cookies and local storage

    We use cookies that are strictly necessary to operate the Service — in particular, authentication cookies set by Clerk to keep you signed in. We also store some preferences and your chat threads locally in your browser (local storage), such as your theme and selected model, so the dashboard works as expected. We do not use advertising cookies or third-party advertising trackers.

  7. 7. International data transfers

    Some of our sub-processors are located outside the EU/EEA, including in the United States. Where personal data is transferred outside the EU/EEA, we rely on appropriate safeguards recognised under the GDPR — such as the European Commission’s Standard Contractual Clauses or an adequacy decision — so that your data continues to be protected. You can contact us for more information about the safeguards in place.

  8. 8. How long we keep your data

    We keep personal data for as long as it is needed for the purposes described in this policy. In general:

    • Account, content, and usage data are kept while your account is active. If you delete your chats they are removed from our active systems, and if you close your account we delete or anonymise your data within a reasonable period, except where we must keep it for the reasons below.
    • Billing and transaction records are kept for as long as required by Swedish accounting law (currently seven years).
    • We may retain limited data for longer where necessary to comply with the law, resolve disputes, or enforce our agreements.
  9. 9. Your rights

    Under the GDPR, you have the right to:

    • access the personal data we hold about you and receive a copy of it;
    • have inaccurate data corrected and incomplete data completed;
    • have your data erased in certain circumstances;
    • restrict or object to certain processing, including processing based on our legitimate interests;
    • receive certain data in a portable, machine-readable format; and
    • withdraw consent where we rely on it, without affecting processing already carried out.

    To exercise any of these rights, contact us using the contact details at the end of this policy. You also have the right to lodge a complaint with your local data-protection authority. In Sweden this is the Swedish Authority for Privacy Protection (Integritetsskyddsmyndigheten, IMY, imy.se).

  10. 10. Children

    The Service is not directed to children under the age of 13, and we do not knowingly collect personal data from children under 13. If you are under 18, you may use the Service only with the consent and involvement of a parent or guardian. If you believe a child has provided us with personal data without the appropriate consent, please contact us and we will take appropriate steps to delete it.

  11. 11. Security

    Protecting your data matters to us, and we work to keep it secure using technical and organisational measures such as encryption of data in transit (HTTPS) and access controls on our systems. We continually work to safeguard it; however, no method of transmission or storage over the internet is ever completely secure, so we cannot guarantee absolute security.

  12. 12. Changes to this policy

    We may update this Privacy Policy from time to time. If we make a material change, we will take reasonable steps to notify you, for example by posting the updated policy with a new date or notifying you through the Service. The “last updated” date at the top shows when this policy was last revised.

  13. 13. How to contact us

    For any questions about this policy or to exercise your rights, contact us by email at privacy@rocortex.gg.