Trust & Security

What protects your data.

Roox runs on your website and talks to your visitors, so trust isn't optional — it's built into every layer. Here's exactly how we handle data, in plain terms. No claims we can't back.

Encryption

All data is encrypted in transit (TLS) and at rest. The widget script loads over HTTPS only.

Per-site isolation

Each site's brain, conversations, and leads are isolated by siteId. One customer's data is never visible to another, and the agent only answers from the site it's installed on.

We don't train models on your data

Your conversations and content are never used to train any model — not ours, and not our LLM provider's (Anthropic, via the zero-retention API path). We don't sell or share your data.

The benchmark network

You contribute anonymized aggregate patterns (medians, quartiles, theme frequencies) to a cross-site benchmark so you can see how you convert vs sites like yours. Never raw conversations, never identifying data, never used to train models. Cross-site auto-learning is on the roadmap, not live today.

What the install script does

~22KB, loaded with `defer` so it never blocks your page render. It runs in a Shadow DOM, so it can't touch or be touched by your CSS. No session recording, no cursor tracking, no third-party cookies. Remove it any time by deleting one line.

Subprocessors

Vercel (hosting), Neon (database), Anthropic (LLM), Resend (transactional email), Stripe (payments, only if you connect it). We keep this list current; a DPA is available on request.

Retention & deletion

You own your data. Request export or deletion any time at armando@rooxai.com and we'll action it.

Compliance status

We run on SOC 2 infrastructure (Vercel/AWS). Our own SOC 2 audit is in progress — we'll publish the report here when it completes. We do not currently claim a completed SOC 2 Type II audit, because we don't have one yet. We'd rather tell you that than imply otherwise.

Questions? armando@rooxai.com · Privacy