Last updated September 16, 2026
Privacy Policy
This policy explains what we collect when you use myroomplanner, why we collect it, who we share it with, and the choices you have. It is written to be read, not skimmed past.
Scope and definitions
This policy covers www.myroomplanner.io and the planner, dashboard and gallery it serves (together, the Services). Personal data means any information that relates to, describes or could be used to identify you, directly or indirectly. "We" and "us" mean myroomplanner, the operator of the Services.
It does not cover data we hold about employees, contractors or job applicants, and it does not cover other sites we link to.
What we collect
Account details. When you sign in with Google, Apple or an email link, we receive your email address, your name and, if your provider offers it, a profile picture. We use these to run your account.
What you make. Floor plans, 3D rooms, renders and any 3D models you upload are stored so you can come back to them. Renders include the view you sent and the picture that came back, plus the words you typed.
Sign-in and request records. Each time you sign in we record the time, your IP address, an approximate location derived from it, and your browser type. We also keep a log of requests to our servers. Screenshots you take never leave your browser.
Payments. Stripe collects and stores your card details when you buy a plan. We receive confirmation of what you bought, your subscription status and your billing history, never the card itself.
Messages. If you write to us, we keep the correspondence so we can answer and refer back to it.
How and why we use it
- To run the planner and keep your rooms, renders and models in your account (performance of our contract with you).
- To bill you and manage your plan, including plans included with ArchitectGPT (contract and legal obligation).
- To generate renders, which means sending the view and your description to our AI model provider (contract).
- To show public renders in the idea gallery, unless you keep yours private (our legitimate interest in showing what the product makes, which you can switch off).
- To keep the service safe, enforce plan limits, prevent fraud and respond to payment disputes (legitimate interest and legal obligation).
- To fix problems and improve the service (legitimate interest).
- To send you messages about your account. We do not send marketing email unless you ask for it (contract, and consent for anything else).
Payment disputes
If you or your card issuer open a chargeback or dispute, we may disclose the records above, including your IP address, browser type, sign-in times, account activity and billing history, to our payment processor, the card network and your issuing bank as evidence in responding to the dispute. Disclosure in that context is limited to what the dispute needs.
Who we share it with
We use a small number of providers to run the service, each of which processes only what it needs: Google Firebase for sign-in, Neon for the database, Cloudflare for image and model storage, fal.ai for AI rendering, Vercel for hosting and page-view analytics, and Stripe for payments. If you have an ArchitectGPT plan, we check your subscription status with ArchitectGPT to apply it here.
The view and the words you send for a render go to fal.ai only to produce that render. We do not use your rooms, renders or models to train AI models, and we have not authorised our provider to do so.
We do not sell your personal data, and we do not share it for cross-context behavioural advertising. Beyond the providers above, we share personal data only with your consent, when the law or a valid legal request requires it (where permitted, we will tell you about such a request), to protect our rights or the safety of others, or as part of a sale or merger of the business, in which case this policy continues to apply.
Public renders
Finished renders can appear in our public idea gallery, with a generic title and without your name. On Pro and Premium you can keep every render private from your account settings. Private renders never appear in the gallery, on hub pages or in search listings.
Cookies, local storage and signals
We use your browser's local storage to keep the room you are working on and your sign-in session. We use Vercel Analytics to count page views and see which pages are used. It sets no cookies, stores no IP addresses and does not identify you across sites. We do not use advertising cookies or web beacons. Third-party providers such as Stripe set cookies on their own pages during checkout. Because we do not track you across sites, we treat Do Not Track and Global Privacy Control signals as already honoured.
Security
We take reasonable measures to protect your data, including encryption in transit and at rest with our providers, access controls, and regular review of who can reach what. No method of transmission or storage is entirely secure, so we cannot promise absolute security. Keep access to the email account you sign in with safe, since it is the key to your account. If we learn of a breach affecting your personal data, we will tell you and the authorities as the law requires.
How long we keep it
Your account and what you make stay as long as your account exists. Sign-in and request records are kept for twenty-four months, a period chosen to cover the window in which a payment can be disputed under card network rules, and are then deleted or anonymised. When you delete a room, render or model it is removed from your account, and copies in backups clear on their own schedule. When you close your account we delete or anonymise your data within thirty days, except where we must keep records for tax, dispute or legal reasons.
Where data lives
Our providers store data in the United States and may process it elsewhere. Where the law requires, transfers are protected by standard contractual safeguards.
Your rights
You can see and change your rooms, renders and models from your dashboard, and keep renders private from your account. Depending on where you live you may also have the right to know what personal data we hold about you, to correct it, to receive a copy, to have it deleted, to object to or restrict how we use it, and not to be treated differently for exercising these rights. Residents of California have these rights under the CCPA and CPRA; residents of the EU and UK have them under the GDPR, along with the right to complain to a supervisory authority.
To exercise a right, write to us using the contact details on this site from the email address on your account, or through an authorised agent with written permission. We will confirm your identity and respond within thirty days, or within forty-five days where California law applies, and tell you if we need longer.
Children
The Services are not directed at children under thirteen, and we do not knowingly collect data from them. If you believe a child under thirteen has given us data, contact us and we will delete it. Users under eighteen need a parent or guardian to agree to our Terms, and where the law requires parental consent for a minor's data, we will ask for it before collecting or using that data.
Other sites
The Services link to sites we do not run, such as Stripe's checkout and ArchitectGPT. Those sites have their own privacy policies, and anything you share with them is governed by those policies, not this one.
Changes and contact
We may update this policy. The date at the top shows the latest version. For material changes we give notice on the site or by email before they take effect, and continuing to use the Services after that means you accept the updated policy. Questions about your data can be sent through the contact details on this site.