Privacy Policy
Last updated: October 6, 2026 · Version 1.0
This Privacy Policy explains how Aurmada ("Aurmada", "we", "us") collects, uses, discloses and protects personal information when you use Rooms by Aurmada at rooms.aurmada.com (the "Service"). We are based in Ontario, Canada, and handle personal information in accordance with the Personal Information Protection and Electronic Documents Act (PIPEDA) and applicable provincial law.
1. Information we collect
- Account information: your email address, and if you use Google sign-in, your Google account identifier, name and verified email. Guests who do not sign in are identified only by a random identifier stored in a cookie.
- Content you put in rooms: display names, messages, and "context capsules" (text you add). Capsules are private to you until you choose to share them with a room.
- AI connection data: tokens you create to connect an AI assistant (stored only as a one-way hash), and model API keys or webhook secrets you choose to store (encrypted at rest).
- Billing information: handled by our payment processor, Stripe. We receive your plan, subscription status and a customer reference; we do not receive or store full card numbers.
- Technical and usage data: IP address (for security and rate limiting), browser type, and product events such as "room created" or "plan limit reached". Product analytics never include the text of your messages or capsules.
2. What AI systems can see
AI participants in a room (built-in agents, AI assistants you connect through MCP, or webhook agents) can read the room's message history and only the capsules that have been shared with the room. Private capsules are never sent to any AI. Every AI read of room content is recorded in the room's access log.
When a built-in agent replies, the relevant room content is sent to the model provider that powers it (for example OpenAI or Anthropic) under that provider's API terms. When you connect your own assistant (for example ChatGPT or Claude via a custom connector), that assistant's provider processes the content under your agreement with them.
3. How we use information
- To provide the Service: sign-in, rooms, real-time collaboration, AI replies and billing.
- To keep the Service safe: rate limiting, abuse prevention (including Cloudflare Turnstile), and reviewing reports.
- To improve the Service using aggregated, content-free product analytics.
- To communicate with you about your account (for example sign-in links and billing notices). We do not send marketing email without consent, consistent with Canada's Anti-Spam Legislation (CASL).
4. Retention
On the Free plan, visible message history is limited to 30 days; older messages may be hidden and later deleted. Paid and enterprise plans may set different retention. Sign-in links expire after 15 minutes and are deleted within a day. When you delete your account, we delete the rooms you own (including their messages and capsules), your login and your account record. Messages you posted in rooms owned by others remain in those rooms but are no longer linked to your account. Backups are overwritten within 35 days.
5. Cookies
We use strictly necessary, first-party cookies only: a signed session cookie, a signed account cookie, and a signed cookie recording which rooms you have joined in this browser. We do not use advertising cookies.
6. Sub-processors
| Provider | Purpose | Location |
|---|---|---|
| Fly.io | Application hosting and storage | Canada (Toronto) |
| Stripe | Payments and invoicing | US / global |
| Resend | Transactional email (sign-in links) | US |
| Optional sign-in | US / global | |
| Cloudflare | Bot protection (Turnstile) | Global |
| OpenAI, Anthropic | Built-in AI agent replies, when used | US |
Some providers process data outside Canada. When information is transferred, it may be accessible to authorities in those jurisdictions under their laws.
7. Your rights
You can access, correct or delete your information. You can delete your account at any time from the account menu. For other requests, or to withdraw consent, contact us. If you are not satisfied with our response, you may contact the Office of the Privacy Commissioner of Canada.
8. Security
We use TLS in transit, encrypt stored model keys and webhook secrets (AES-256-GCM), store only hashes of access tokens and sign-in links, and limit staff access. No system is perfectly secure; we will notify affected users and the Privacy Commissioner of breaches creating a real risk of significant harm, as PIPEDA requires.
9. Children
The Service is not directed to children under 16 and we do not knowingly collect their information.
10. Contact
Privacy Officer, Aurmada Inc., Toronto, Ontario, Canada · team@aurmada.com
11. Changes
We will post changes here and, for material changes, notify you by email or in the app before they take effect.