Back to Home

Privacy Policy

Last updated: June 2026

Overview

RooxAI ("we," "our," or "us") respects your privacy. This policy explains how we collect, use, and protect personal data when you visit rooxai.com, sign up for the Roox product, or interact with the Roox widget on a customer's site.

Information We Collect

  • Contact information: name, email, and company name when you sign up, install Roox, or contact us.
  • Account information: siteId, widget configuration, and account usage metrics.
  • rooxai.com usage data: pages visited, time on site, browser type, device information.
  • Data generated by the Roox widget when installed on a customer site: visitor conversations with Roox and leads captured. We process this data on the customer's behalf (see "When Roox is installed on customer sites").

How We Use It

  • Operate the Service and deliver Roox to the customer.
  • Respond to inquiries and send operational communications (OTP codes, lead alerts, usage digests).
  • Improve the Service and site experience.
  • Comply with applicable legal obligations.

When Roox Is Installed on Customer Sites

When a customer installs Roox on their website, the customer acts as the data controller for personal data of their visitors, and RooxAI acts as a data processor. RooxAI uses this data only to operate the Service for that customer, does not sell it, does not use it to train AI models outside the customer's scope, and retains it only for as long as reasonably needed for its purpose.

Google Calendar Integration & Google User Data

Roox offers an optional Google Calendar integration so the agent can propose open time slots and book meetings on your calendar when a visitor wants to talk to you. You authorize the connection explicitly through Google's consent (OAuth) flow, and you can revoke it at any time.

When you connect your Google account, we request only these permissions (scopes), each for a narrow purpose:

  • View calendar availability (calendar.freebusy): we read only your busy/free windows to propose open slots. We do not read event titles, attendees, or any event details.
  • Create events (calendar.events): we create the meeting event a visitor books through Roox and invite that visitor. We use this permission only to create those meetings.
  • Basic identity (openid, email): to know which Google account is connected and display it back to you.

Storage and security: we store Google refresh tokens encrypted at rest; access tokens are short-lived. We do not store the contents of your calendar events.

What we do NOT do with your Google data: we do not sell it, do not use it for advertising, do not use it to train artificial-intelligence or machine-learning models, and do not allow humans to read it except (a) with your explicit consent, (b) for security or to comply with the law, or (c) in aggregated, anonymized form for internal operations.

Retention and deletion: you can disconnect Google Calendar from the Integrations section of your dashboard at any time; doing so revokes the tokens with Google and deletes the stored credentials. You may also email armando@rooxai.com to request deletion.

Roox's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Sharing and Transfers

We share data only with vendors who help us run the Service technically (hosting, AI infrastructure, transactional email, payments). These vendors only access data as needed to provide their service and under confidentiality obligations. We do not sell personal data.

Security

We implement reasonable technical and organizational measures to protect data against unauthorized access, alteration, or disclosure. However, no method of transmission over the internet is 100% secure.

Cookies and Telemetry

We use essential cookies so the site and dashboard work (session, authentication). We use anonymous analytics to understand site usage. You can control cookies from your browser settings.

Your Rights

You have the right to:

  • Access the personal data we hold about you.
  • Request correction of inaccurate data.
  • Request deletion of your data when it is no longer needed.
  • Object to processing for a specific purpose.

To exercise these rights, contact us at armando@rooxai.com.

Changes

We may update this policy from time to time. We will notify you by posting the new version on this page and updating the "Last updated" date.

Contact

For questions about this policy, contact us at armando@rooxai.com.