Privacy Policy

Last updated: August 12, 2026

This policy describes what data RoProfit collects, why, where it's stored, and what we don't touch. We try to keep it short and human-readable. If anything here is unclear, email privacy@roprofit.app and we'll fix it.

1. Who we are

RoProfit is a software tool that aggregates a Roblox creator's earnings into a single dashboard. We are not affiliated with, endorsed by, or sponsored by Roblox Corporation.

2. What data we collect

We collect six kinds of data:

  • RoProfit account identity: your email address and, when supplied by your sign-in provider, your display name and avatar. This account owns your workspace, billing status, and linked data sources.
  • Linked Roblox identity: your Roblox user id, username, display name, and avatar URL, received after you authorize RoProfit through Roblox OAuth. We also store the OAuth access and refresh tokens issued by Roblox so the connection can remain active between sessions.
  • Aggregated revenue and ad-spend totals: per-day, per-game totals reported by the RoProfit Desktop. We do not store individual transactions, individual buyers, or any payment details.
  • Desktop pairing metadata: a SHA-256 hash of the bearer token we issue to the desktop app, plus a device label and timestamps for issuance and last use. We never store the plaintext bearer token.
  • Successful sign-in activity: the date and time of a successful RoProfit sign-in and the RoProfit surface used (for example, desktop or the private founder console). We do not attach IP addresses, user agents, browser fingerprints, page views, or a browsing history to these records.
  • Customer-support conversations: messages you choose to send through the support chat, the page where you opened it, and a name or email address only when you provide them for human follow-up. Do not send passwords, Roblox cookies, access tokens, payment details, or other secrets in support chat.

3. What we don't collect

  • Your Roblox password.
  • Your .ROBLOSECURITY cookie or any other Roblox session cookies.
  • Per-transaction details, buyer identities, or payment-method information.
  • Marketing-grade analytics, advertising identifiers, or third-party trackers.

4. Why we collect it

We use the data above to authenticate your RoProfit account, maintain your linked Roblox data sources, provide the sync service, render your portfolio dashboard, manage billing access, and understand whether accounts can sign in successfully. For pricing decisions, the founder console uses broad, portfolio-wide 90-day revenue ranges; it does not display an individual customer's exact earnings beside their identity. We don't sell your data, share it with advertisers, or use it to train machine-learning models. Support messages are processed through the OpenAI API to draft answers; OpenAI does not use API inputs or outputs to train its models by default.

5. Where it's stored

Data is stored in a managed Postgres database hosted on Supabase (US region). The connection is TLS-encrypted. Row-level security limits access to the RoProfit application using a service-role credential held only by our server.

6. Who else sees it

  • Authorized RoProfit operations. The founder may access account identity, linked-account names, billing and access status, and recent successful sign-in timestamps for support and account administration. Pricing insight is presented as an aggregate distribution across customer workspaces rather than a user-level earnings report.
  • Supabase (database hosting). Bound by its own privacy policy and a data processing agreement.
  • Vercel (web hosting). Sees request metadata (IP, user-agent, requested URL) per normal HTTP serving; does not see your dashboard data.
  • Roblox. We call Roblox's OAuth and public APIs on your behalf at sign-in time. RoProfit Desktop calls Roblox APIs locally using your existing session inside the app.
  • NanoFox and OpenAI. NanoFox stores support conversations and optional contact details so RoProfit can answer and follow up. OpenAI processes the message and relevant approved RoProfit help content to draft an answer. These providers do not receive your Roblox password, Roblox session cookie, payment details, or private earnings data from the support widget.

7. How long we keep it

We retain your data for as long as your account is active. If you disconnect (Settings → Delete account), we purge your row from profiles, which cascade-deletes everything else (OAuth tokens, revenue rows, ad-spend rows, sync log, desktop tokens). We complete the purge within 90 days. Successful sign-in activity is retained for no more than 180 days and is deleted by an automated retention job.

Support conversations are kept while they are needed to answer the request, improve our help materials, and maintain a reasonable support record, and are deleted or anonymized within 12 months after resolution unless a longer period is required for security, fraud prevention, or law. You may request earlier deletion by emailing privacy@roprofit.app.

8. Your rights

  • You can export all your data from the Settings page.
  • You can delete your account from the Settings page at any time.
  • You can revoke RoProfit Desktop's access token without deleting your account.
  • Residents of the EU/UK/CA: you have additional rights under GDPR/UK GDPR/CCPA. Email privacy@roprofit.app and we'll honor any reasonable request within 30 days.

9. Children

RoProfit is intended for Roblox creators 13+ as defined by Roblox's own terms. We do not knowingly accept accounts from users under 13. If you believe a child has signed up, contact privacy@roprofit.app and we'll remove the account.

10. Changes

If we make material changes to this policy we'll update the "last updated" date and, for changes that affect what data we collect or share, give notice on the dashboard. Continued use of RoProfit after a change constitutes acceptance.

11. Contact

Privacy questions: privacy@roprofit.app. Security reports: security@roprofit.dev.

See also: Terms of Service · Security overview