What happens to your room
Privacy Policy
Last updated 8 August 2026
You point a phone at a room and we turn it into a 3D model of that room. To do that we hold photographs of your home. This page says exactly what we collect, exactly where it goes, and exactly how to make all of it disappear — in the plainest terms we can manage, with the uncomfortable parts included.
1Who this is about
This policy covers the roomstudio iPhone capture app and the roomstudio web app (together, “the service”). The service is operated by Utkarsh Singh (“we”), an individual.
Questions, requests, and complaints: 23singhutkarsh@gmail.com.
2What a scan contains
A scan (we call it a capture) is the raw material for everything else. One capture contains:
- Photographs of the room. The app keeps a still frame roughly every 10 cm or 5° of camera movement, so a walk around a room produces a few hundred JPEG images. These are ordinary photographs of your home and are the most sensitive thing we hold.
- Depth measurements, on iPhone Pro models with a LiDAR sensor: a
256×192grid of distances, in metres, per frame, plus a per-pixel confidence value. - Camera motion. Position and orientation for each frame, lens parameters, and the direction of gravity. These describe where the phone was inside the room, not where the room is in the world.
- Room geometry. Detected wall, floor, and ceiling planes, and — on Pro devices — Apple RoomPlan’s model of the room: wall outlines, a floor polygon, doors and windows, and boxes around furniture with categories and dimensions.
- Device and app facts. The device model string (e.g.
iPhone17,1), iOS version, app version, whether the device has LiDAR, and a random identifier generated on first launch and stored in the iOS Keychain. That identifier is per-installation; it is not your Apple ID, your phone number, or any Apple-provided device ID. - Times. When the capture started and ended.
A capture does not contain your location. The app never requests location permission, and no GPS coordinates are read, stored, or transmitted. The camera positions in a capture are relative to wherever you happened to start scanning.
The app does not record audio. There is no microphone use anywhere in the capture path.
3Who you are to us
The capture app signs you in anonymously on first launch. That produces an opaque account identifier and nothing else — no email, no name, no profile. You can use the app this way indefinitely.
If you want to reach your rooms in a browser, you can attach Sign in with Apple to that same anonymous account, and then sign in on the web with Apple or with Google. Attaching a provider gives us whatever that provider releases to us — typically an email address, and a stable provider-specific identifier. With Apple you may choose to hide your email, in which case we receive only a relay address.
Your account identifier does not change when you attach a provider. The web app can only ever sign you in; it will not create a new account, precisely so that a browser sign-in can never orphan the rooms on your phone.
4Where it is stored
Captures are uploaded from the phone directly to Google Cloud Storage. Processing runs on Google Cloud Run in the asia-southeast1 (Singapore) region, and the buckets live in the same region. Records — your list of rooms, upload state, and conversations — are held in Google Cloud Firestore.
If you are not in Singapore, this means your data is transferred and processed outside your country. By using the service you understand that this transfer takes place. Google Cloud is engaged as a processor under its standard data processing terms.
5What leaves the system, and to whom
Two things go to a third party beyond our cloud provider. Both go to Anthropic, and they send very different amounts of your room, so we describe them separately.
a. Working out what your walls and floor are made of. To decide whether a floor reads as wood, tile, stone, carpet, or concrete, we send up to four small rectified crops of that surface — actual photographic image data from your room — to Anthropic’s API, and get back a one-word family and a confidence score. This happens at most once per surface per room, and the crops are close-ups of a wall or floor patch rather than views of the whole room. It is nonetheless the one place where pictures of your home are transmitted to a company that is not our cloud provider.
b. The conversation about your room. When you talk to the guest on a room’s page, what we send is text, not pictures: a derived list of what was found in the room (“bed”, “desk”, “two chairs”), approximate distances and sizes, and the messages you type. No image, depth map, or coordinate ever enters that request.
We do not sell your data, we do not share it with advertisers, and we do not authorise any processor to use your content to train models. Our processors handle it under their own published terms, which are theirs to change and yours to read.
Other Google services in the path — Firebase Authentication for sign-in, and Firebase Cloud Messaging if you allow notifications — see only account identifiers and delivery tokens, never room content.
Beyond this, we may disclose data if we are legally required to, or to protect the service or someone’s safety. If we are ever acquired, the data follows the service, and this policy follows it too until you are told otherwise.
6How long it is kept
- The raw scan — every photograph and depth frame you uploaded — is deleted automatically 24 hours after upload. A storage lifecycle rule enforces this; it is not a policy we have to remember to apply. This is the single most important retention fact on this page.
- The room we build from it is kept until you delete it — the 3D model, the surfaces, the inventory of what was found. This is the product; it persists so that your house is there when you come back.
- Failed scans — captures that could not be processed — are removed 90 days after they fail.
- Upload bookkeeping expires 7 days after the upload.
- Intermediate processing files kept to avoid recomputing your room are deleted after 180 days.
- Conversations are kept with the room they belong to, and go when it goes.
7Deleting everything
Open the account menu in the web app and choose Delete account. This is not a request queued for review; it runs immediately and removes:
- every room and everything built from it, in storage;
- any raw capture blobs still inside their 24-hour window;
- every record of yours — rooms, upload sessions, usage counters, and every conversation and message;
- the account itself, last.
Deletion runs storage first and the account last, deliberately: if it were interrupted, nothing would be stranded without a record pointing at it, and you would still be able to sign in and run it again. It is safe to run twice.
Deleting your account does not reach into your phone. The capture app will start over with a fresh anonymous account the next time you open it, and any captures still on the device are yours to delete by removing the app.
To delete a single room rather than everything, or to ask what we hold about you, write to 23singhutkarsh@gmail.com. Depending on where you live you may have rights to access, correct, export, or restrict the processing of your data, and to complain to a data protection authority; we will honour those requests through that address.
8People in your scans
If someone is in the room while you scan it, they will be photographed. This deserves a straight answer rather than a reassurance.
What the system does: it looks for people in every frame and excludes them from the room it builds. A detected person is never reconstructed as an object, never named in the inventory, never used as evidence of what a wall or floor looks like, and is disqualified from the crops described in §5a. In testing, a third of one wall’s measured colour turned out to be a person standing in front of it; that measurement is now excluded.
What we will not claim: that detection is perfect. It is a machine learning model, it will miss people, and the raw frames themselves always contain whoever was in the room until the 24-hour deletion in §6 removes them. Rooms processed before this behaviour shipped may still carry measurements taken from a person.
So: ask people to step out before you scan. The app asks you to do this too. It is the only method here that works every time.
If you scan a space that is not yours, or people who have not agreed to it, that is on you — see the Terms.
9Security
Everything travels over TLS. Rooms are scoped to the account that made them, and a request for someone else’s room is refused rather than filtered. Links to your 3D files are individually signed and expire after an hour. The keys our services use are held in Google Secret Manager, and each service runs with only the permissions it actually needs.
No system is immune. If we discover a breach affecting your data we will tell you and the relevant authority as required by law.
10What we do not do
The web app contains no analytics, no tracking pixels, no advertising technology, and no third-party scripts of any kind. It sets no cookies for tracking. Two small flags are stored in your browser’s local storage — whether you have any rooms yet, and whether you have already watched a particular room assemble — so the first screen and the reveal behave sensibly. Neither is sent anywhere, and clearing site data removes both.
11Children
The service is not directed at children under 13 (or the equivalent minimum age where you live), and we do not knowingly collect their data. If you believe a child has used the service, write to 23singhutkarsh@gmail.com and we will delete the account.
12Changes
If this policy changes in a way that materially affects what we collect or who receives it, we will say so in the app before the change takes effect. The date at the top always reflects the current version.