Terms

Privacy Policy

Last updated 31 August 2026

The short version: Your data is yours. We never sell it and never use it to train AI models. It's encrypted and isolated to your account, and you can export or delete everything in one tap. We're based in the UK and store your data in the UK.

1. Who we are

Room is operated by Slowlane AI, its founding team in the United Kingdom (UK company registration in progress). For UK data-protection law (UK GDPR and the Data Protection Act 2018), we are the "controller" of your personal data. Contact: info@slowlane.ai.

2. The data we collect and why

We practise data minimisation — we collect the least we need.

Account

Your email address and an account identifier. Sign-in is handled by Amazon Cognito; we never store your plaintext password. Basis: our contract with you.

Content you capture

Documents, photos, PDFs, notes and voice notes you add. We store the encrypted original plus details our AI extracts (a title, summary, key facts). If you mark a capture sensitive, Room never reads its contents — only the file and a label you choose are stored. Basis: our contract; explicit consent where it contains special-category data.

Connected sources (you choose)

You authorise each connection yourself and can disconnect at any time, which deletes the data pulled from it. Basis: your consent (explicit consent for health data).

Google user data — Limited Use. Room's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. In plain terms: Google user data is used only to provide the user-facing features described above; it is never sold, never used for advertising, never used to determine creditworthiness or for lending, and never used to train AI/ML models — neither generalised models nor our own. Humans do not read it except with your explicit consent for a specific purpose, for security investigations, where the law requires — or where it appears in an answer covered by the beta answer-quality review described under “Security & usage” below, which we will close off from connected-source content before public launch.

Security & usage

A per-user, PII-free activity log (actions, never content), rate/cost counters, and standard server logs. For public actions (e.g. the waitlist) we store a hashed IP, never the raw IP. Basis: our legitimate interest in a secure, sustainable service.

Beta answer-quality review. During the private beta, the questions you ask Room and the answers it gives are stored and may be read by the founding team to find and fix bad answers. A small nightly sample is also re-scored automatically by the same AI service that answered it (AWS Bedrock, EU region — a service that does not train on this data); only a pass/fail mark is kept from that scoring, never new copies of your content. Because an answer can quote your own connected data (for example an email fact you asked about), this review can expose that content to us — we tell you here rather than pretend otherwise. This log is deleted with your account, and before public launch it will either exclude connected-source content or become strictly opt-in. Basis: our legitimate interest in making the product work during the beta, balanced by this disclosure and deletion with your account.

We do not use third-party advertising or tracking, and do not build advertising profiles.

This website counts its own page views without cookies: one number per day, page and referring site. No IP address, device or identifier is stored, and a browser that sends Do Not Track or Global Privacy Control is not counted at all.

3. Special-category (health) data

Health data gets extra protection. We process Apple Health / wearable summaries only with your explicit consent (given via the in-app consent screen), and you can withdraw it anytime by disconnecting. Documents you mark sensitive are never read by the AI.

4. How we use AI

Most answers are computed without any AI model — deterministic engines read your own record. When a model is needed, the relevant data is sent to our AI processor (AWS Bedrock running Anthropic's Claude), in the UK/EU region, only to perform that task. It is not used to train models and not retained by the provider for their own purposes. Two hard rules are enforced in code, not policy: your health numbers never enter a model prompt (answers are computed first; your numbers are added to the reply afterwards), and sensitive-marked documents are never sent to the AI. One derived fact does reach the model so its suggestions respect your day: whether you have already exercised or meditated today — a yes/no and the kind of activity, never a duration, count or heart measurement.

5. Who we share with

We do not sell your data. We use service providers who process it on our behalf, under contract:

ProviderPurposeLocation
Amazon Web ServicesHosting, database, encrypted file storage, authentication, AI (Bedrock)UK / EU
Google, Microsoft, Apple, GitHub, Todoist, Oura, Hevy, Strava, Last.fm, RescueTimeOnly the source you choose to connectPer provider
Meta (WhatsApp Business)Only if you link WhatsApp capture — inbound messages you send usPer provider
Apple / Google push servicesOnly if you enable notifications — the reminder text shown on your lock screen (a task line may include an email subject)Per provider

We may disclose data if required by law or to protect users' safety.

6. Where it's stored

Your data is stored in the UK (AWS London). AI processing occurs in the UK/EU. Any transfer outside the UK relies on appropriate safeguards.

7. How long we keep it

While your account is active. Disconnect a source → its data is deleted. Delete a capture → it and its file are deleted. Email-derived facts expire after 21 days on their own. Delete your account → all your data — database rows and stored files — is permanently and automatically deleted, and we verify the cascade reaches every table with an automated test.

8. How we protect it

9. Your rights

Under UK GDPR you can access, correct, erase, export, restrict or object to processing, and withdraw consent — most directly in the app (export, delete, disconnect). Contact info@slowlane.ai. You can also complain to the UK Information Commissioner's Office.

10. Children

Room is for adults 18+. We do not knowingly collect data from under-18s.

11. Changes

We may update this policy and will notify you of material changes.

Room · built in the UK · Home · Terms · info@slowlane.ai