Legal
Privacy Policy
Last updated: September 4, 2026
1. Overview
This Privacy Policy explains how ROK (the "Service") collects, uses, stores, and shares your information when you use the chat assistant, whether as a guest or with an account. "We," "us," and "our" refer to the operators of ROK. By using the Service, you agree to the practices described here.
ROK is designed to be privacy-conscious: your chats and settings live on your own device by default, and only limited information is transmitted to our servers and the AI providers that power the Service.
2. Information We Collect
We collect the following categories of information:
- Account information: If you sign up with Google, we receive your name, email address, and profile picture through Google OAuth. If you sign up with an email address and password, we receive your email address and a display name derived from it. Your password is never seen by ROK — it is sent directly to our authentication provider (Supabase Auth), which stores it in hashed form. We store the identifiers needed to recognize you on return visits, including your Google account identifier and Supabase user id.
- Chat content: The prompts you send, the responses we generate, and any text you paste into the chat.
- Uncensored-model audit logs: When you use an uncensored or adult-content model (such as "ROK Hermes Spicy"), we additionally log the text of each prompt you send together with the email address of the account that sent it. This is done so that prohibited or unlawful use of that model can be attributed to an account and addressed; see Sections 3, 8, and 9.
- Uploaded content: Files and images you attach to a conversation. These are stored in a temporary workspace on our servers so the AI models and tools can process them.
- Generated content: Text, images, code, and artifacts the Service produces for you, which appear in your conversation history.
- Share data: When you create a share link for a conversation, we store a frozen copy of that conversation on our servers so the link can be served publicly.
- Settings and preferences: Your model selection and other preferences. These are stored locally on your device (see Section 6).
- Technical data: Cookies and session tokens for authentication, and standard server logs that include request metadata and error identifiers ("ref" codes). Server logs may include your IP address.
3. How We Use Your Information
We use the information we collect to:
- Operate and provide the Service, including generating AI responses and running tools (code execution, file handling, web search, image generation).
- Authenticate your account through Google OAuth and keep you signed in.
- Process file and image uploads so the AI can read them.
- Store and serve shared conversations that you choose to publish.
- Maintain, debug, and improve the Service — including investigating errors using the reference IDs attached to failed requests.
- Enforce our Terms of Service and protect the Service from abuse.
- Monitor prompts sent to uncensored or adult-content models (such as "ROK Hermes Spicy") for compliance with our Terms and applicable law, and investigate potential violations.
4. Where Your Data Is Stored
Your chat history, settings, and artifacts are stored on your own device in your browser's IndexedDB and local storage. They are not uploaded to our servers unless you actively share a conversation or attach a file.
Content you share (via share links) and files you upload are stored on our backend servers so the Service can function. Backend storage currently uses a small SQLite database and a sandboxed workspace directory on the server.
Authentication data is stored in a signed session cookie managed by Auth.js and validated by our servers on each request.
Account records (email, display name, profile picture, and authentication identifiers) are stored in a managed PostgreSQL database provided by Supabase, so we can recognize you across devices and sign-in methods. Email/password credentials are stored by Supabase Auth, and verification codes are held by Supabase Auth until used or expired.
5. Google Sign-In and Third-Party AI Providers
Sign-in is provided by Google through OAuth 2.0. When you sign in with Google, you are subject to Google's own privacy policy and terms, which govern how Google handles your credentials. We only receive the profile information Google shares with us (see Section 2).
Authentication infrastructure — including email/password credentials, one-time verification codes, and the managed database that stores account records — is provided by Supabase (supabase.com). Verification emails are delivered through Supabase's email service and contain only a one-time code. Your use of these services is subject to their respective terms and privacy policies.
To generate responses, your prompts and uploaded content are transmitted to third-party AI providers that host the models ROK uses (for example, hosted Ollama models, the Puter platform, and the model and image-generation providers that power signed-in features). These providers process your content solely to generate the response. We do not sell your data, and we do not use your content to train our own models.
Your use of these third-party services is also subject to their respective terms and privacy policies.
These providers process your content to generate a response on our behalf. We require that they not use your content to train their own models where such controls are available to us; however, we do not control these providers' infrastructure directly, and their retention and logging practices are governed by their own terms and privacy policies, which we encourage you to review. We are not responsible for the data practices of third-party providers once your content has been transmitted to them for processing.
We do not collect or store any age attestation or age-verification data. Access to uncensored modes of the Service (such as "ROK Hermes Spicy") is subject only to the age requirements in our Terms of Service; we do not record or verify your age.
6. Cookies and Local Storage
We use the following browser storage:
- Session cookies: A signed JWT session cookie that keeps you signed in.
- Local storage: Your settings and preferences, a small anonymous counter that paces how often guests are shown sign-up prompts, and an anonymous device id (a random UUID) used to key guests' daily usage limits. These stay in your browser; the anonymous device id is also sent to our servers so guest usage can be metered per device rather than per shared network address.
- IndexedDB: Your conversation history, which never leaves your device unless you share it.
7. Public Sharing
When you share a conversation, we create a public link that anyone with the link can view. Shared conversations use unguessable cryptographic IDs rather than your personal information. If you mark a share as "logged-in users only," the viewer must sign in to view it.
You can revoke a share link at any time, after which it immediately stops working. Before sharing, consider that the content of a shared conversation becomes accessible to whoever receives the link.
8. Data Retention
Conversation history and settings stay on your device until you delete them or clear your browser data.
Uploaded files are retained in the backend workspace while needed to serve your conversation, and are cleaned up as the Service manages its storage.
Share records remain stored until you revoke them, the share is removed, or we delete the underlying data.
Server logs, including error reference IDs, are retained for a limited period for debugging and security purposes, then deleted.
Uncensored-model audit logs (prompt text paired with the sending account's email — described in Section 2) are retained on our servers for a limited period so that violations of our Terms on those models can be investigated, then deleted.
Auth data: Authentication records and one-time verification codes are held by our authentication provider (Supabase Auth). Codes are invalidated on use or expiry; account records in the managed database are retained until you delete your account or request deletion.
9. Illegal Content and Reporting
We do not monitor conversations in real time. However, if we become aware of content generated or shared through the Service that we reasonably believe depicts child sexual abuse material (CSAM), facilitates violence, or otherwise violates applicable law, we may remove that content, suspend the associated account, and report it to the National Center for Missing & Exploited Children (NCMEC) or other relevant law enforcement or regulatory authorities, as required or permitted by law. We may disclose account and technical information (such as IP address or account identifiers) as part of such a report. Prompts sent through uncensored models (such as "ROK Hermes Spicy") are logged together with the account email (see Sections 2 and 8) — specifically so prohibited content of this kind can be attributed to an account and acted on.
10. Your Choices and Deletion
You can delete individual chats, or all chats, from the Service at any time — this removes them from your device's storage.
You can revoke any share link you have created at any time.
You can sign out at any time. Signing out does not delete your locally stored chats.
You can delete your account at any time from Settings. This removes your ROK account record and linked identities from the managed database, revokes your session, and clears your local data on this device. The underlying credential held by our authentication provider is not removed by in-app account deletion, so signing in again will create a fresh account record.
To request deletion of other data stored on our servers (such as shared conversations or uploaded files), contact us at [email protected], and we will process your request within a reasonable timeframe.
11. Children's Privacy
The standard Service is not directed to children under 13, and we do not knowingly collect personal information from children under 13.
Uncensored models, "Spicy" personality variants, and any mode of the Service capable of producing explicit, adult, or unfiltered content are not directed to, and may not be accessed by, anyone under 18 years of age. The Service does not verify age and stores no age-verification data. If we become aware that a user under 18 has accessed an uncensored mode, or that a user under 13 has provided us with personal information, we will take steps to restrict that access and delete the associated data. If you believe this has occurred, please contact us so we can investigate.
12. Security
We use industry-standard measures to protect data in transit (HTTPS/TLS) and to restrict access to the servers that store shared conversations and uploads. Session tokens are signed and cannot be forged. No method of transmission or storage is completely secure, however, so we cannot guarantee absolute security.
13. Changes to This Policy
We may update this Privacy Policy from time to time. When we do, we will revise the "Last Updated" date at the top of this page. Material changes will be communicated through the Service where practicable. Continued use of the Service after changes take effect constitutes your acceptance of the updated policy.
14. Contact
Questions, concerns, or deletion requests can be directed to us at [email protected]. We aim to respond promptly.
This Privacy Policy is provided for transparency. Nothing in it is intended to limit rights that cannot be limited under applicable law.