Privacy Policy
How we handle your data at Rool.
Effective date: September 16, 2026
Company: Lightpost One Ltd (trading as Rool)
Location: Dublin, Ireland
Contact: contact@rool.dev
Lightpost One builds Rool, a platform and developer toolkit built around private collaborative virtual machines ("Rool Machines") for working with structured data, files, and AI-powered tools.
We aim to be straightforward and respectful about privacy. We do not sell personal data, there are no ads in Rool, and we never use your content to train AI models. We use data only to operate, secure, support, and improve the Rool service.
This policy explains what we collect, how we use it, and your rights.
1. Who we are
Lightpost One Ltd is the operator of Rool.
We are the data controller for your account data and for the operation of the Rool service.
If you use Rool through your employer or another organisation, that organisation decides how the content in its Machines is handled, and its privacy policy applies to that content. We handle it only as the organisation instructs us.
2. Data we collect
Account data
When you create an account, we collect:
- Name
- Email address
- Authentication information (tokens or IDs from your auth provider)
- Billing or subscription information (if applicable)
Service data (your Rool Machines)
This includes the content you create or upload while using Rool, such as:
- Objects, relations, and metadata
- Files and media
- Prompts and interaction history with AI features
- User storage and preferences
- Collaboration data (members, roles, activity)
Usage and technical data
Collected automatically when the service is used:
- IP address
- Device/browser information
- Timestamps
- API requests and feature usage
- Performance metrics and error logs
3. How we use data
We use data to:
- Provide and operate the Rool service
- Authenticate users
- Store and synchronize Rool Machines
- Enable collaboration features
- Execute AI operations you request
- Maintain reliability and security
- Provide support
- Understand how Rool is used, so we can find problems and improve the product
We do not:
- Use your content to train AI models
- Sell personal data
- Use data for advertising
- Track users across unrelated websites
4. AI processing, support, and product improvement
When you use AI features (such as prompts, placeholders, search, or generation), relevant content and context are processed to provide the requested functionality. Section 5 lists which providers process it.
No model training
We do not use your content to train or otherwise improve AI models. This applies to your files, messages, conversations, and everything else stored in your Rool Machines. It applies to the models we run ourselves and to the third-party providers in section 5, and to every plan, including the free one.
Support and quality assurance
We use usage and technical data to monitor reliability, detect abuse, and understand how features are used.
When you ask us for support, when we investigate a security incident, or when we diagnose a fault in the service, such as a failed, malformed, or incorrect AI response, we may need to access the data in your Machine. We do so only as far as that purpose requires, and where feasible we work with aggregated or de-identified data instead.
5. Data sharing
Rool is built on infrastructure and services we do not run ourselves. Each provider below does one job for us and receives only the data that job needs.
Providers that run Rool
These providers are part of running Rool, so they are involved whenever you use it:
- Hetzner (Finland) hosts Rool's servers and storage.
- Google Cloud hosts part of Rool's servers and storage in Google's Finland region (europe-north1), and handles sign-in.
- Verda (Finland) hosts the GPU servers our own AI models run on. Those models handle everything the optional services below do not, including safety review and email your machine sends, and process your messages, the conversation so far, images you attach, and the text of files the AI reads.
- Stripe handles payments. It receives your billing details when you buy a plan or credits.
- Resend handles email: the email Rool sends you, and the email your machine sends and receives.
Optional providers
These providers each power a specific feature and are only involved when you use it. Requests are sent from Rool's servers under Rool's account. The provider receives no name, email address, or other account details, and cannot tie a request to you. You can turn each of them off in the app under Settings, Data and Privacy:
- TensorX (Ireland) is a backup for when Rool's own models are unavailable or busy. It then receives what our own models would have: your messages, the conversation so far, images you attach, and the text of files the AI reads.
- Google Cloud AI (Vertex AI) generates and edits images. It receives the description of the image you ask for, and the image you ask to edit.
- Brave Software (Brave Search) provides web, image, and video search. It receives the search query, written by you or by the AI on your behalf.
- SerpApi provides Google Scholar search. It receives the search query.
- Jina AI (Jina Reader) lets the AI read web pages. It receives the address of the page to open.
We may also share data with professional advisors or authorities where required by law.
These providers are bound by data-processing agreements that hold them to protection equal to this policy, including a prohibition on retaining your data or using it for training. Where a provider processes data outside the EU/EEA, the safeguards in section 6 (Data location) apply.
6. Data location
Your machines, files, conversations, and account data are stored in the European Union (Finland). Sign-in records, payment records, and email delivery logs are held by Google, Stripe, and Resend respectively and may be stored outside the EU/EEA.
Where processing or storage occurs outside the EU/EEA, we use appropriate safeguards such as Standard Contractual Clauses or equivalent protections.
7. Retention
We retain data only as long as necessary:
- Account data: while your account exists
- Rool Machine data: until you delete it
- Logs: limited retention for operational and security purposes
Deleting a Rool Machine removes its data from active systems. Backups expire automatically after a limited period.
8. Your rights (GDPR)
If you are located in the EU/EEA, you have the right to:
- Access your data
- Correct inaccuracies
- Export your data
- Delete your data
- Restrict or object to certain processing
Your files are yours to take at any time: download them from your Machine, or ask the AI to package them in whatever form you need.
To exercise your rights, contact: contact@rool.dev
You may also lodge a complaint with the Irish Data Protection Commission.
9. Security
We use industry-standard safeguards, including:
- Encryption in transit (HTTPS/TLS)
- Access controls
- Secure infrastructure
- Monitoring and updates
No system is perfectly secure, but we work to protect your data using best practices.
10. Children
Rool is a general-purpose productivity and developer platform and is not directed to children under 16.
We do not knowingly collect personal data from children. If we become aware that a child has created an account or provided personal data, we will take steps to delete the information.
If you believe this has occurred, please contact contact@rool.dev.
11. Changes
We may update this policy as the service evolves. We will notify users of material changes.
12. Contact
Questions or requests:
contact@rool.dev
Lightpost One Ltd
Dublin, Ireland