Privacy policy
What we collect, why, who helps us process it, and how to use your rights. Your project source never leaves your machine.
Who we are
ROTEX is operated by its operator (“we”, “us”).
Contact us through the requests page.
We are the controller of the personal data described here. This policy covers the website, your account, the ROTEX desktop app and the Studio plugin.
The short version
- Your project source code stays on your machine. We never upload it.
- We collect what we need to run your account and take payment, and nothing to advertise to you.
- No advertising trackers, no analytics cookies and no selling of your data, ever.
- You can see, export, correct or delete your data. Most of it you can delete yourself from Settings.
What we collect, why, and our lawful basis
| Data | Why | Lawful basis | How long |
|---|---|---|---|
| Account: email address and a hashed password (never the password itself) | To create your account, sign you in and send service emails | Contract | Until you delete your account |
| Age band (13-17 or 18+). Never your date of birth | To apply the right rules for younger users and for purchases | Legal obligation; legitimate interests | Until you delete your account |
| Record of accepting the Terms and Privacy Policy: date, versions, marketing choice | To show what you agreed to and when | Legal obligation; legitimate interests | Until you delete your account |
| Marketing preference | To email you about releases, only if you opted in | Consent (withdraw any time) | Until you opt out or delete your account |
| Billing: name, billing address, tax ID, and card details held by the payment provider | To take payment, issue invoices and meet tax law | Contract; legal obligation | As long as tax law requires, usually 6-10 years |
| Requests you file (withdrawal, refund, privacy, deletion) and messages you send | To act on them and show that we did | Legal obligation; legitimate interests | Up to 6 years after the request is closed |
| Service data from the app: package names and symbols you look up | To resolve documentation and library lookups | Contract | Cached lookups are not tied to your identity |
| Technical logs: IP address, browser, pages requested, errors | To run, secure and debug the site | Legitimate interests | Up to 30 days in our hosting provider's logs |
“Contract” means we need the data to provide what you signed up for. “Legitimate interests” means we have a reason that does not override your rights. You can object to it (see your rights).
We don't make decisions about you by automated means that have legal or similarly significant effects.
Who processes it for us
We use these service providers, under contracts that let them use your data only to provide their service to us:
- Neon: account sign-in and our database.
- Cloudflare: hosting the website and API, their logs, and file storage.
- Our payment provider: taking payments, calculating tax and issuing receipts, once paid plans are live. We never see or store your full card number.
- An email delivery provider: sign-in emails and acknowledgements of your requests.
We share data with others only if the law requires it, to protect people's safety or our legal rights, or as part of a sale or reorganisation of ROTEX under the same protections. We do not sell or rent personal data, or share it for targeted advertising.
International transfers
Our providers may process data outside the UK and the EEA, including in the United States. When they do, the transfer is covered by an adequacy decision (such as the UK-US data bridge or the EU-US Data Privacy Framework) or by standard contractual clauses and the UK addendum. Ask us for a copy of the safeguards.
Your rights
Depending on where you live, you have the right to:
- get a copy of your data and have it sent to you in a portable format;
- have inaccurate data corrected;
- have your data deleted;
- object to, or ask us to restrict, how we use it;
- withdraw consent at any time, where we rely on it;
- if you are in California or a similar US state, know what we collect and not be discriminated against for using your rights. We don't sell or share personal data as those laws define it.
How to ask: one place for everything, the requests page. You can also delete your account yourself in Settings. We reply within one month and may ask you to confirm your identity first. It is free, unless a request is clearly unfounded or excessive.
Children and younger users
ROTEX is not for children under 13. Sign-up asks when you were born. For anyone under 13, no account is created and nothing they entered is kept. The only trace is a cookie that lasts one day and says the check stopped them. We never store dates of birth, only whether an account holder is 13-17 or 18+.
Users aged 13-17 can use the Free plan. A paid plan for them must be bought by a parent or guardian. We don't send marketing to users under 18 unless they opted in. We don't profile them, and we have no advertising trackers.
If you think a child under 13 has given us personal data, tell us on the requests page and we will delete it.
Security
Data is encrypted in transit. Our database uses row-level security, so each account can reach only its own records. Passwords are stored only as hashes. No system is perfectly secure. If a breach puts your data at risk, we will tell you and the regulator as the law requires.
Complaints
Please come to us first, and we will try to fix it. You also have the right to complain to a data protection regulator. In the UK that is the Information Commissioner's Office (ico.org.uk, 0303 123 1113). In the EU it is the authority in the country where you live or work.
Changes to this policy
When this policy changes, the version and date at the top change too. If a change is significant, we tell account holders by email or on the site before it applies.