Privacy Policy
Last Modified: March 18, 2026
We are committed to safeguarding the privacy of our users. This Privacy Policy sets out how Roify, a product of Frowse LLC d/b/a Probs ("we," "us," "our," "the Company"), collects, uses, stores, shares, and protects your personal information when you use the Roify service ("the Service"). By using the Service and agreeing to this policy, you consent to our practices as described herein.
Roify is an AI-powered ROI estimation tool that processes user-submitted content through third-party artificial intelligence providers. This involves transmitting your content to third-party services. Please read this policy carefully to understand how your information is handled.
Consent: By creating an account, submitting content for analysis, or otherwise using the Service, you expressly and affirmatively consent to the collection, use, storage, processing, sharing, and international transfer of your personal information as described in this Privacy Policy, including the transmission of your content to third-party AI/LLM providers. If the Service presents a consent checkbox during registration or at any other point, that checkbox may be pre-checked to indicate your acceptance of this Privacy Policy and our Terms of Service; by completing your registration or continuing to use the Service, you confirm your consent regardless of whether the checkbox was manually checked or pre-checked. If you do not consent to these practices, you must not use the Service.
(1) What Information Do We Collect?
We collect, store, process, and use the following categories of personal and non-personal information:
(a) Account Information
- Email address (required for registration)
- Password hash (if you choose password authentication; stored as bcrypt hash, never in plaintext)
- Name (optional)
- Role/job title (optional)
- Hourly rate and currency (optional; used for value calculations)
- AI subscription cost and billing period (optional; used for net ROI calculations)
- Account creation and last login timestamps
- Email verification status
(b) User-Submitted Content
- Full text of content you submit for analysis, including AI conversations, emails, documents, notes, prompts, and responses ("Input Content")
- Content type classification (chat, email, doc, notes, other)
- SHA-256 cryptographic hash of your input (for deduplication and integrity verification)
- Analysis options you select (providers, aggregation method, hourly rate overrides, detail level)
(c) Generated Reports and Outputs
- Full ROI report data in structured JSON format, including task decompositions, time estimates (P10/P50/P90), value calculations, confidence scores, executive summaries, and recommendations
- Model fingerprints identifying which AI models generated the estimates
- AI processing costs incurred for your analyses
- Summary text of generated reports
(d) Calibration and Feedback Data
- Your baseline time estimates (P10/P50/P90 ranges)
- Your "with AI" time estimates
- Your hourly rate and value override inputs
- Accuracy and usefulness ratings (1-5 scale)
- Free-text feedback notes
(e) Technical and Device Information
- IP address
- Browser type, version, and user agent string
- Operating system
- Referral source
- Page views and navigation patterns
- Request timestamps
(f) Tracking and Rate Limiting Data
- Browser fingerprint cookie (
rl_fp): a 32-character hexadecimal identifier stored as an HTTP cookie with a 1-year expiration, used for rate limiting
- IP-based rate limiting records
- Per-user and per-email (SHA-256 hashed) rate limiting records
- Session cookies (PHPSESSID) for maintaining login state
(g) Billing and Payment Information
- Stripe customer ID and subscription ID
- Subscription plan, status, and billing period dates
- Payment event data received via Stripe webhooks (stored as full JSON payloads)
- Usage event records (analysis count, token usage) for billing reconciliation
Note: We do not directly collect or store credit card numbers, bank account details, or other payment instruments. All payment processing is handled by Stripe, Inc.
(h) Share Link Data
- Public share link identifiers
- Redaction level selected (none, standard, strict)
- View counts for shared reports
(i) Administrative and Audit Data
- Admin access logs (IP address, user agent, access path, success/failure)
- LLM usage records (provider, model, token counts, cost, latency, success/error status)
- Stripe webhook event logs
(2) Cookies and Tracking Technologies
We use the following cookies and tracking mechanisms:
| Cookie/Mechanism |
Purpose |
Duration |
Type |
PHPSESSID |
Session management and authentication |
Browser session |
Essential |
rl_fp |
Rate limiting fingerprint to prevent abuse |
1 year |
Essential |
Both cookies are set with HttpOnly and SameSite=Lax attributes. The Secure flag is enabled in production environments.
We do not currently use third-party analytics services (such as Google Analytics, Hotjar, or similar) on the Roify platform. If this changes, this policy will be updated accordingly.
Most browsers allow you to reject all cookies. However, blocking essential cookies will prevent you from using the Service.
(3) How We Use Your Information
We use the information we collect for the following purposes:
- (a) Service Operation: To operate, maintain, and provide the core functionality of the Service, including user authentication, ROI analysis, report generation, and account management;
- (b) AI Processing: To transmit your Input Content to third-party AI/LLM providers for task decomposition, time estimation, and report generation;
- (c) Billing and Payments: To process subscriptions, track usage against plan limits, and manage billing through Stripe;
- (d) Security and Abuse Prevention: To enforce rate limits, detect and prevent abuse, fraud, and unauthorized access, and to maintain the security and integrity of the Service;
- (e) Service Improvement: To calibrate and improve estimation accuracy using aggregated feedback data, refine algorithms, and enhance the user experience;
- (f) Communications: To send you transactional emails (magic links, password resets, billing notifications) and, if you have opted in, marketing communications;
- (g) Legal Compliance: To comply with applicable laws, regulations, legal processes, or governmental requests;
- (h) Aggregated Analytics: To generate anonymized, aggregated statistics about Service usage, estimation patterns, and benchmarks (which cannot be used to identify individual users); and
- (i) Share Links: To make reports publicly available when you choose to create share links, at the redaction level you select.
(4) Third-Party Data Sharing
We share your information with the following categories of third parties:
(a) AI/LLM Providers
This is the most significant data sharing in the Service. When you submit content for ROI analysis, your full Input Content is transmitted to one or more third-party artificial intelligence and large language model ("AI/LLM") providers via their APIs. Current providers include, but are not limited to:
- OpenAI (OpenAI, L.L.C.) — Privacy policy: openai.com/privacy
- Anthropic (Anthropic, PBC) — Privacy policy: anthropic.com/privacy
- OpenAI-compatible endpoints (self-hosted or third-party) — As configured by the Service operator
We reserve the right to add, remove, or change AI/LLM providers at any time without prior notice. Future providers may include, without limitation, Google (Gemini), Meta (Llama), Mistral AI, Cohere, Amazon (Bedrock), Microsoft (Azure OpenAI), or any other AI/LLM provider. When new providers are added, your Input Content may be transmitted to those providers under their respective terms and privacy policies. We will update this list periodically but are not obligated to do so before using a new provider.
Your Input Content is transmitted in full, without redaction or PII filtering, to these providers. Each provider has its own terms of service, data retention policies, and privacy practices. We strongly encourage you to review their policies. We are not responsible for how these providers handle, store, process, train on, or retain your data once transmitted. We do not control and make no representations about: (i) how providers use data received via their APIs; (ii) whether providers retain your data after processing; (iii) whether providers use your data for model training or improvement; or (iv) the jurisdictions in which providers process or store your data.
Data transmitted to AI providers includes: your full input text, system prompts (which may reference your hourly rate and role), task segment metadata, and any other information contained in your submission.
(b) Payment Processor
Stripe, Inc. handles all payment processing. We share your email address, name, user ID, and organization ID with Stripe. Stripe may collect additional information directly from you during the checkout process. Stripe's privacy policy is available at stripe.com/privacy.
(c) Other Disclosures
We may also disclose your personal information:
- (i) to the extent required by law, regulation, or legal process;
- (ii) in connection with any legal proceedings or prospective legal proceedings;
- (iii) to establish, exercise, or defend our legal rights (including providing information for fraud prevention);
- (iv) to the purchaser (or prospective purchaser) of any business or asset which we are (or are contemplating) selling; and
- (v) to our employees, officers, agents, contractors, and service providers insofar as reasonably necessary for the purposes set out in this policy.
(5) Data Retention
We retain your information as follows:
| Data Category |
Retention Period |
| Account information |
Indefinite (until account deletion, if requested) |
| User-submitted Input Content |
Indefinite (stored with job records) |
| ROI Reports |
Indefinite |
| Calibration feedback |
Indefinite |
| Usage events |
Indefinite |
| LLM usage logs |
Indefinite |
| Stripe webhook payloads |
Indefinite |
| Rate limiting records |
Variable (subject to periodic cleanup) |
| Magic link / reset tokens |
30 minutes / 1 hour (auto-expire), records retained |
| Session data |
Duration of browser session |
Fingerprint cookie (rl_fp) |
1 year (browser-side) |
Important: Data transmitted to third-party AI providers (including, but not limited to, OpenAI, Anthropic, and any future providers) is subject to those providers' own retention policies, which we do not control. Please review their respective privacy policies for details on how they retain and use API-submitted data.
Aggregated, anonymized, or de-identified data may be retained and used indefinitely regardless of account status.
(6) International Data Transfers and Geographic Restrictions
Information we collect may be stored, processed, and transferred between any of the countries in which we or our third-party providers operate. This includes transfers to the United States and any other jurisdiction where our AI providers maintain infrastructure.
Your Input Content may be processed by AI providers in data centers located outside your home jurisdiction. By using the Service, you expressly consent to such transfers of personal information.
Personal information submitted for publication via share links will be published on the internet and may be available worldwide. We cannot prevent the use or misuse of such information by others.
Geographic Restrictions and Local Law Compliance
The Service is designed for and directed to users in the United States. We do not represent or warrant that the Service or any part of it is appropriate, available, or compliant with laws in any particular jurisdiction outside the United States.
If you access the Service from outside the United States, you do so at your own risk and are solely responsible for compliance with all applicable local, national, and international laws, regulations, and data protection requirements. In particular:
- (a) European Economic Area (EEA), United Kingdom, and Switzerland: The Service is not directed to users in the EEA, UK, or Switzerland. We do not claim compliance with the General Data Protection Regulation (GDPR), the UK GDPR, or the Swiss Federal Act on Data Protection (FADP). We have not appointed an EU/UK representative. We do not provide Standard Contractual Clauses (SCCs) or other transfer mechanisms required under EU/UK data protection law. If you are located in these jurisdictions, you acknowledge that your use of the Service may not be compliant with local data protection laws, and you assume all risk associated with such use. We reserve the right to restrict access from these jurisdictions at any time.
- (b) Jurisdictions Requiring Explicit Opt-In Consent: If you are in a jurisdiction that requires explicit, affirmative, un-pre-checked opt-in consent for data processing (including transmission to third parties), your use of the Service constitutes your explicit consent to all data processing described in this Privacy Policy and our Terms of Service. If your local law does not recognize consent-by-use, you must not use the Service.
- (c) Jurisdictions Prohibiting International Data Transfers: If your jurisdiction restricts or prohibits the transfer of personal data to the United States or to third-party AI providers, you must not use the Service. We are unable to guarantee that data will remain within any particular jurisdiction.
- (d) Jurisdictions Requiring Data Localization: We do not offer data residency or data localization options. All data is processed and stored in the United States (and potentially in any jurisdiction where our AI providers operate). If your jurisdiction requires data localization, you must not use the Service.
- (e) General Backstop: If any provision of this Privacy Policy or our Terms of Service conflicts with, is prohibited by, or would be unenforceable under the laws of your jurisdiction, you must not use the Service. Your continued use constitutes a representation and warranty that your use is lawful in your jurisdiction and does not violate any applicable local, national, or international law or regulation.
We disclaim all liability for any claims, damages, or penalties arising from your use of the Service in violation of your local laws. You agree to indemnify and hold us harmless from any regulatory action, fine, penalty, or claim arising from your use of the Service in a jurisdiction where such use is unlawful or non-compliant.
(7) Security of Your Personal Information
We implement the following security measures:
- (a) Encryption in transit: HTTPS enforcement with HSTS headers for all sensitive operations;
- (b) Password security: Bcrypt hashing with cost factor 12;
- (c) Token security: SHA-256 hashing of magic link and password reset tokens;
- (d) CSRF protection: Token-based cross-site request forgery prevention;
- (e) Security headers: X-Content-Type-Options, X-Frame-Options, Referrer-Policy, and Content-Security-Policy headers;
- (f) Secure cookies: HttpOnly, Secure (in production), and SameSite attributes on all cookies;
- (g) Rate limiting: IP-based, fingerprint-based, and user-based rate limiting to prevent brute-force attacks; and
- (h) Input validation: Prepared SQL statements (PDO) to prevent injection attacks.
However, we do not guarantee the security of your data. Data transmission over the internet is inherently insecure, and we cannot guarantee the security of data sent over the internet. Our security practices may change without notice. You are responsible for keeping your password and account credentials confidential.
(8) Your Rights
Depending on your jurisdiction, you may have certain rights regarding your personal information as described below. We will respond to verifiable requests within the timeframes required by applicable law.
(a) General Rights (All Users)
- Access: You may request a copy of the personal information we hold about you. Provision of such information may be subject to a reasonable fee to cover administrative costs.
- Correction: You may update your account information (name, role, hourly rate, currency) through the Service's settings interface, or request corrections by contacting us.
- Deletion: You may request deletion of your account and associated data by contacting us at the email address below. Please note that: (i) deletion may not be immediate and may take up to 90 days to process; (ii) aggregated, anonymized, or de-identified data derived from your information may be retained indefinitely; (iii) data already transmitted to third-party AI/LLM providers cannot be recalled or deleted by us — you must contact those providers directly; (iv) data required for legal compliance, fraud prevention, or legitimate business purposes (including billing records) may be retained as required by law; (v) backups may retain your data for a limited period after deletion; and (vi) content licensed to us under the Terms of Service may continue to be used in accordance with those terms.
- Objection/Restriction: You may object to certain processing activities by contacting us. However, objecting to essential processing (such as AI/LLM transmission, which is the core function of the Service) may prevent you from using the Service. We cannot offer the Service without transmitting your content to AI providers.
- Portability: You may request your data in a structured, commonly used, machine-readable format (such as JSON) where technically feasible.
(b) California Residents (CCPA/CPRA)
If you are a California resident, you have the following additional rights under the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA):
- Right to Know: You have the right to request that we disclose the categories and specific pieces of personal information we have collected about you, the categories of sources from which the information was collected, the business or commercial purposes for collecting the information, and the categories of third parties with whom we share the information.
- Right to Delete: You have the right to request deletion of your personal information, subject to the exceptions noted above and those permitted under CCPA.
- Right to Correct: You have the right to request correction of inaccurate personal information.
- Right to Opt-Out of Sale/Sharing: We do not "sell" personal information as defined under CCPA. However, transmitting your Input Content to third-party AI/LLM providers for processing constitutes a "business purpose" disclosure, not a sale. We do not sell personal information for monetary consideration.
- Right to Limit Use of Sensitive Information: To the extent we process sensitive personal information (as defined under CCPA), we use it only for the purposes permitted under CCPA.
- Non-Discrimination: We will not discriminate against you for exercising any of your CCPA rights.
To submit a CCPA request, contact us at legal@probsai.com with the subject line "CCPA Request." We will verify your identity before processing your request. You may designate an authorized agent to make a request on your behalf.
(c) Other U.S. State Privacy Rights
Residents of Virginia (VCDPA), Colorado (CPA), Connecticut (CTDPA), Utah (UCPA), Texas (TDPSA), Oregon (OCPA), Montana (MCDPA), and other states with consumer privacy laws may have similar rights to access, correct, delete, and port their personal information. We will honor verifiable requests from residents of these states in accordance with applicable law. Contact us at legal@probsai.com to exercise your rights.
(d) Limitations on Rights
We may withhold personal information to the extent permitted by law. In particular:
- We cannot recall, delete, or modify data already transmitted to third-party AI/LLM providers. You must contact those providers directly regarding their data handling.
- We may retain information necessary for legal compliance, fraud prevention, enforcing our Terms, or completing transactions.
- De-identified or aggregated data is not subject to individual rights requests.
- We may charge a reasonable fee or refuse manifestly unfounded or excessive requests.
To exercise any of these rights, please contact us at legal@probsai.com. We will respond within the timeframe required by applicable law (typically 45 days, with extensions as permitted).
(9) Children's Privacy
The Service is not intended for use by anyone under the age of 18. We do not knowingly collect personal information from children under 18. If you are a parent or guardian and believe your child has provided us with personal information, please contact us immediately and we will take steps to delete such information.
(10) Third-Party Websites and Services
The Service may contain links to other websites and services, including those of our AI providers and payment processor. We are not responsible for the privacy policies or practices of third-party websites or services. We encourage you to read the privacy policies of every website and service you interact with.
(11) Do Not Track Signals
The Service does not currently respond to "Do Not Track" (DNT) signals sent by web browsers. This is because the cookies and tracking mechanisms we use are essential for the operation and security of the Service (session management and rate limiting).
(12) Policy Amendments
We may update this Privacy Policy from time to time by posting a new version on the Service. You should check this page regularly to ensure you are informed of any changes. Continued use of the Service constitutes acceptance of any changes, additions, or deletions. Any new version immediately supersedes all previous privacy policies.
We may, in our sole discretion and without guarantee of notification, also notify you of changes to this Privacy Policy by email.
(13) Severability
If a provision of this Privacy Policy is determined by any court or other competent authority to be unlawful and/or unenforceable, the other provisions will continue in effect. If any unlawful and/or unenforceable provision would be lawful or enforceable if part of it were deleted, that part will be deemed to be deleted, and the rest of the provision will continue in effect.
(14) Contact
If you have any questions about this Privacy Policy, our data practices, or our treatment of your personal information, please contact us:
- Email: legal@probsai.com
- Mail: Frowse LLC d/b/a Probs, 606 Baltimore Ave Unit 207, #587, Baltimore, Maryland 21204