Roidio

Legal

Privacy Policy

How Roidio collects, uses, shares, protects, and retains personal data for users worldwide.

Effective date: July 2, 2026

Hanif Developments (002647287-X) operates Roidio. This Privacy Policy explains how we collect, use, disclose, retain, and protect personal data when you use our website, applications, subscriptions, trials, support channels, and related services.

We are based in Malaysia and make the service available worldwide. Depending on where you live, local privacy rights may also apply.

1. Who Is Responsible for Your Personal Data

Hanif Developments is responsible for personal data we process for our own service operations, account administration, billing, analytics, marketing, security, and support.

You can contact us at [email protected] or by post at P/35 Block B, Jalan SS 7/26, SS7, 47301 Petaling Jaya, Selangor, Malaysia.

2. Personal Data We Collect

We collect personal data that you provide directly, data generated through your use of the service, and data received from third-party services you choose to connect to Roidio.

  • Account data, such as name, email address, password authentication data, organization or team details, role, settings, and profile information.
  • Authentication data from Google Auth, such as email address, name, profile image, OAuth subject identifier, and sign-in metadata.
  • Billing data handled through Stripe, such as checkout details, subscription status, invoice history, payment method metadata, tax details, fraud signals, and transaction identifiers.
  • Usage and device data, such as IP address, browser, device type, pages viewed, events, referral URLs, approximate location, session data, cookies, pixels, and similar technologies.
  • Brand Context data, such as business name, industry, target audience, brand voice, product and service descriptions, tone guidelines, and other brand knowledge you enter or import to configure AI agents.
  • Knowledge connector content, such as the text content of Google Drive documents and Notion pages you explicitly select and sync to use as AI context within the service.
  • Connected account credentials, such as encrypted OAuth tokens and API keys for third-party platforms you link to Roidio, including LinkedIn, Meta (WhatsApp Business, Instagram, Facebook), Google Drive, Notion, WordPress, and MCP servers.
  • Agent run data, such as inputs, task parameters, step outputs, tool call records, approval requests, AI-generated content, error logs, and credit usage associated with AI agent executions.
  • Social media post data, such as platform targets, draft post content, publishing status, and scheduling or approval records for posts created or queued through the service.
  • Advertising research data, such as ad creatives, audience signals, and campaign information retrieved from Meta Ads Library, TikTok Ads Library, and Google Ads via Apify for research and analysis features.
  • Media and image files, such as image ad creatives generated or uploaded through the service and stored in Cloudflare R2 object storage.
  • WhatsApp conversation data, such as the phone numbers and message content of customer contacts who interact with your WhatsApp Business account via the WhatsApp auto-reply agent feature.
  • Customer content, such as prompts, uploaded materials, creative assets, generated outputs, saved workflows, notes, and other materials submitted to the service.
  • Support and communications data, such as messages, requests, feedback, survey responses, and email metadata.
  • Marketing and advertising data, such as campaign interactions, conversion events, audience or attribution signals, and ad measurement data where legally permitted.

3. How We Use Personal Data

We use personal data to operate, secure, improve, and market the service, and to comply with legal obligations.

  • Provide accounts, dashboards, subscriptions, trials, AI features, analytics, support, and team workflows.
  • Process payments, invoices, subscription changes, credit top-ups, cancellations, renewals, fraud prevention, and tax or accounting records.
  • Authenticate users, protect accounts, monitor security, prevent abuse, detect bots via Cloudflare Turnstile, troubleshoot errors, and enforce our Terms.
  • Run AI agents on your behalf, including blog drafting, social media repurposing, WhatsApp auto-reply, and image ad generation, using Brand Context, connected account data, and knowledge connector content as AI context.
  • Retrieve and process content from connected knowledge sources (Google Drive, Notion) you authorize, for use as context in AI features.
  • Process incoming WhatsApp messages from your customers and generate automated replies using your Brand Context, in accordance with your agent configuration.
  • Retrieve advertising research data from Meta Ads Library, TikTok Ads Library, and Google Ads on your behalf for ad intelligence features.
  • Store image ad creatives and other generated media files in Cloudflare R2 for display and download within the service.
  • Analyze product usage, measure performance, improve features, and understand how users interact with the service.
  • Send service messages, security notices, billing notices, product updates, and marketing communications where permitted via Elastic Email.
  • Measure, attribute, and improve advertising through Google Ads, Meta Ads, TikTok Ads, and related analytics tools.
  • Comply with legal, regulatory, tax, accounting, dispute, and enforcement obligations.

5. Cookies, Analytics, and Advertising Technologies

We and our providers may use cookies, pixels, SDKs, local storage, Cloudflare Turnstile, and similar technologies to keep you signed in, secure the service, remember preferences, analyze usage, detect abuse, measure advertising, and understand conversions.

Google Analytics may collect and process usage data from our website or application. Google Ads, Meta Ads, and TikTok Ads may process event, device, cookie, conversion, and attribution data for advertising measurement and campaign optimization where enabled and legally permitted.

6. AI Processing

When you use AI-assisted features, prompts, Brand Context, knowledge connector content, connected account data, uploaded materials, creative assets, generated outputs, metadata, and related usage information may be processed by Anthropic (Claude AI) and NanoBanana AI to provide, secure, monitor, and support those features.

Anthropic (Claude AI) is used for blog drafting, social media repurposing, WhatsApp auto-reply, ad analysis, and general AI agent capabilities. NanoBanana AI is used for image ad generation features.

Do not submit sensitive personal data, regulated data, confidential third-party data, or data you are not authorized to process unless the product expressly supports that use and you have all required rights, notices, and consents.

7. How We Share Personal Data

We may share personal data with service providers and business partners that help us operate the service, including Stripe, Anthropic (Claude AI), NanoBanana AI, Apify, Google (Auth, Analytics, Ads, Drive, Search Console), Meta (WhatsApp Business, Ads), LinkedIn, TikTok Ads, Cloudflare (R2 Storage, Turnstile), Elastic Email, Notion.

We may also share personal data with professional advisers, authorities, courts, regulators, payment processors, security providers, or transaction counterparties where necessary for legal, security, corporate, or compliance purposes.

We do not sell personal data. We do not share personal data with third parties for their own direct marketing without your consent.

8. Connected Accounts and Third-Party Integrations

Roidio allows you to connect third-party platforms to power AI agents and workflows. When you connect an account, we store the credentials or OAuth tokens required to act on your behalf, encrypted at rest using industry-standard encryption.

The following integrations are available and involve storing or processing data from those platforms:

  • WordPress — API credentials or MCP server details stored to enable the WordPress Blog Agent to create and publish draft posts.
  • LinkedIn — OAuth token stored to enable queuing and publishing of approved social media posts.
  • Meta (Instagram, Facebook) — OAuth token stored for social post publishing and Meta Ads Library research.
  • WhatsApp Business — OAuth token and webhook configuration stored to enable the WhatsApp auto-reply agent. Incoming customer messages and AI-generated replies are stored to track conversation history and avoid duplicate replies.
  • Google Drive — OAuth token stored to allow you to select and sync Google Drive documents as knowledge sources for AI context.
  • Notion — OAuth token stored to allow you to select and sync Notion pages as knowledge sources for AI context.
  • MCP servers — Credentials or endpoint URLs you provide to connect custom MCP-compatible tool servers.
  • You may disconnect any connected account at any time from the Connections page in your dashboard. Disconnecting revokes our access and removes stored credentials. Conversation history and synced knowledge content may be retained for a limited period before deletion, unless you request immediate deletion (see Section 14).

9. WhatsApp Business — Customer Message Processing

If you activate the WhatsApp auto-reply agent, Roidio will receive and process incoming WhatsApp messages sent to your connected WhatsApp Business number via the Meta Cloud API webhook.

We store the sender's phone number, message content, message identifiers, conversation context, and AI-generated reply content to operate the auto-reply feature, track conversation history, and prevent duplicate responses.

Messages from your WhatsApp customers are processed by Anthropic (Claude AI) together with your Brand Context to generate replies. Message content is not used to train AI models.

You are responsible for ensuring that your use of the WhatsApp auto-reply feature complies with applicable privacy laws, WhatsApp Business Policy, and any notice or consent obligations owed to the individuals whose messages are processed. You should disclose to your customers that their messages may be handled by an automated AI system.

You may request deletion of stored WhatsApp conversation data by following the process in Section 14.

10. International Transfers

Because Roidio is available worldwide and uses global cloud, payment, analytics, advertising, authentication, AI, and storage providers, personal data may be processed in Malaysia and other countries, including the United States, where our providers operate.

Where required, we use appropriate safeguards such as contractual protections, data processing terms, vendor assessments, consent, or other mechanisms recognized by applicable data protection laws.

11. Retention

We retain personal data for as long as needed to provide the service, maintain accounts, process subscriptions, comply with legal obligations, resolve disputes, enforce agreements, maintain security, and keep business records.

Typical retention periods by data type: account data is kept while the account is active and for a reasonable period after closure; billing and tax records are kept as required by applicable law (typically 7 years); security and access logs are kept for a limited operational period; support messages are kept while needed for service and recordkeeping; agent run data and AI outputs are retained while your account is active; synced knowledge connector content is retained until you disconnect the source or delete your account; WhatsApp conversation data is retained while your account is active; media files in Cloudflare R2 are retained while your account is active; and deleted account data is removed or anonymized within 90 days unless longer retention is legally required.

12. Security

We use reasonable technical and organizational measures designed to protect personal data against unauthorized access, loss, misuse, alteration, or disclosure. These include encryption at rest for connected account credentials, encrypted transport (TLS), access controls, and bot protection via Cloudflare Turnstile on public-facing forms. No online service can guarantee absolute security.

If you believe your account or data has been compromised, contact us immediately at [email protected].

13. Your Privacy Rights

Depending on your location, you may have rights to access, correct, delete, restrict, object to, or receive a copy of your personal data, and to withdraw consent where processing is based on consent.

To exercise privacy rights, contact [email protected]. We may need to verify your identity before responding. We will respond within the timeframe required by applicable law.

14. Data Deletion and Account Closure

You have the right to request deletion of your personal data. We provide the following options:

  • Delete specific data — You may request deletion of specific data categories (such as WhatsApp conversation history, synced knowledge connector content, agent run data, or media files) by emailing [email protected] with the subject line "Data Deletion Request". Please specify the data you want deleted and the account email address.
  • Close your account and delete all data — To permanently close your account and request deletion of all associated personal data, email [email protected] with the subject line "Account Closure and Data Deletion". We will verify your identity, terminate your subscription (if active), and initiate deletion of your account data.
  • Disconnect connected accounts — You may revoke Roidio's access to any connected third-party account (LinkedIn, Meta, Google Drive, Notion, WhatsApp, WordPress) at any time from the Connections page in your dashboard. This removes stored credentials immediately. Residual data such as synced knowledge content or conversation history will be queued for deletion.
  • We will action deletion requests within 30 days of verified identity confirmation. Certain data may be retained beyond this period where required by applicable law (for example, billing records for tax compliance), where data is part of an ongoing dispute or legal obligation, or where immediate technical deletion is not feasible, in which case the data will be securely isolated and deleted as soon as practicable.
  • Note that deletion is irreversible. Deleting your account will permanently remove access to your subscription, agents, brand context, run history, and all associated data. Credit balances are forfeited on account closure except where required by law.

15. Children

The service is intended for business and professional users and is not directed to children. Do not use the service if you are not legally able to form a binding agreement or if your use would require parental consent that has not been provided.

16. Marketing Communications

We may send product updates, newsletters, offers, and service-related communications via Elastic Email. You can unsubscribe from marketing emails using the unsubscribe link in any email or by contacting [email protected]. We may still send transactional or security messages regardless of marketing preferences.

17. Changes to This Policy

We may update this Privacy Policy from time to time. If changes are material, we will take reasonable steps to notify users, such as updating the effective date, posting a notice, or sending account email where appropriate. Continued use of the service after changes become effective means you accept the updated Policy.

18. Contact

For privacy questions, data access requests, or deletion requests, contact Hanif Developments at [email protected] or by post at P/35 Block B, Jalan SS 7/26, SS7, 47301 Petaling Jaya, Selangor, Malaysia.