Privacy Policy
1. Who we are
RoMacro ("we," "us," "our") is a desktop application (Windows and macOS) and cloud service for creating and sharing input macros. It is operated by Virage Studio, a sole proprietorship registered in Québec, Canada (NEQ: 2282248550).
Privacy officer: the person responsible for the protection of personal information at Virage Studio, reachable at privacy@getromacro.com. A postal address is available on request.
2. What we collect
When you create an account
- Email address: required so you can log in and we can send security notices.
- Display name: chosen by you. Can be a pseudonym.
- Password: stored only as an irreversible PBKDF2 hash. We never see, store, or log the original password.
When you use the app
- Macros you create: titles, descriptions, tags, and the macro body (the recorded sequence of actions).
- Engagement: likes, downloads, when a macro was opened.
- Forum posts: the threads and replies you write, which are public, the images you attach to them (public with their message, and taken down when it is deleted; images you added but never sent are deleted within a day), the earlier text of a message you edit (kept as its edit history, which only you and the moderators can see; everyone else sees that it was edited), and reports you file about other posts.
- Community macro usage: the first time you download a macro someone else published (with your plan at that moment), and how long each run of it lasts, from Start to Stop. This lets creators see how their macros are used; it's never tied to what you do outside RoMacro.
- Device identifier: a random number RoMacro creates on each computer, sent when you open a paid or run-only macro, to limit how many computers one account uses them on.
- Free trials: when you use a paid macro's free trial, how much of it you've used (the app checks in every 30 seconds while the macro's screen is open or it's running), the computer's device identifier and your linked Roblox account ID if any, so each person gets one trial.
- AI Assistant conversations: what you send the AI Assistant (your message, the macro it goes with, and the names of any macros you attach for reference) and what it answers, including its reasoning. We keep them so we can fix problems and make the assistant better, and only the RoMacro team can read them. Pictures you attach are not kept, only the fact that there was one.
- Sign-in timestamps: the time of your last login.
- API logs: including your IP address, used to detect abuse and debug errors. Retained for 30 days, then deleted.
If you link a Roblox account
- Your Roblox user ID and username: to show which Roblox account is linked, and to check game passes you sell or buy.
- A Roblox access token, stored encrypted. It lets us check which game passes you own, and nothing else. We never see your Roblox password. You can unlink in the app at any time, which deletes it, and you can also revoke RoMacro's access in your Roblox settings.
- Purchases: which paid macros your account unlocked, and the Roblox account and game pass that proved each purchase.
If you opt in to the newsletter
- Your email address, and the fact you opted in, plus the date and the exact wording you agreed to, so we can show when and to what you consented.
Signing up asks you outright, with “Yes, email me” and “No thanks” and neither answer pre-selected; you can’t finish creating the account without choosing one. Accepting the Terms does not opt you in, and neither does simply having an account.
If you buy a paid plan, anti-spam law treats the purchase itself as consent to hear from us about the product for 24 months, and we do add paying customers to the list on that basis, unless you have told us not to. A “No thanks” at signup, switching the toggle off in the app, or an unsubscribe link is final: a purchase never overrides it.
You can turn it off at any time in Settings in the app, or with the unsubscribe link in any newsletter we send. We stop sending within 10 days at the latest, and usually immediately.
Turning it off does not stop service emails: password resets, verification codes, receipts, and notices about your plan. Those aren't marketing and we send them to run your account.
What we do not collect
- Tracking cookies, ad pixels, or third-party analytics.
- Anything you type outside RoMacro.
- Anything inside macros you keep private: the macros saved in My Macros are stored in our database with access restricted to your account and are never shown to other users. If RoMacro can't reach our server when it saves, it keeps that save on your computer until it can send it.
3. Why we collect it
| Data | Purpose | Legal basis |
|---|---|---|
| Email + password | Identify you, let you log in | Performance of contract |
| Display name | Attribute your published macros | Performance of contract |
| Public macros | Show them to other users (the point of the service) | Performance of contract |
| Private macros | Store them under your account so you can access them when signed in | Performance of contract |
| Likes / downloads | Power the "Trending" and "Recent" feeds | Performance of contract |
| Linked Roblox account + purchases | Check game pass ownership so you can buy and sell paid macros | Performance of contract |
| Forum posts, images, edits and reports | Run the public forum and keep it safe | Performance of contract / legitimate interest |
| Macro usage (first download, run times) | Give creators statistics about how their macros are used | Legitimate interest |
| Device identifier | Limit how many computers one account uses paid and run-only macros on | Legitimate interest |
| Free trial usage | Count trial time and give each person one trial | Performance of contract / legitimate interest |
| AI Assistant conversations | Fix problems with the assistant and improve its answers | Legitimate interest |
| IP + sign-in logs | Rate limiting, abuse prevention, debugging | Legitimate interest |
| Newsletter opt-in (+ date and wording) | Send you RoMacro updates, and evidence the consent was given | Consent, withdrawable at any time |
4. How long we keep it
| Data | Retention |
|---|---|
| Active account data | As long as your account exists |
| Macros | Until you delete them or close your account. A deleted macro stays in Recently deleted for 30 days so you can restore it, and each saved macro keeps up to 30 earlier versions. |
| API logs (incl. IP) | 30 days, rolling |
| AI Assistant conversations | 90 days, rolling, or until you close your account |
| Database backups | 14 days, rolling |
| Newsletter consent record | While your account exists, including after you unsubscribe, so we can show when you opted in and when you opted out |
| Closed account data | Hard-deleted within 30 days of account closure |
5. Who we share it with
We use these third parties to operate the service:
| Provider | Purpose | Location | Their privacy policy |
|---|---|---|---|
| Fly.io | Hosting the API and database | United States (Virginia) | fly.io/legal/privacy-policy |
| GitHub | Hosting installer downloads and auto-updates | United States | docs.github.com/site-policy |
| Z.ai (Zhipu AI) | Powers the AI Vision block and, for some requests, the AI Assistant (GLM models). Only what you actively submit is transmitted: the text you send to the assistant, the macro you ask it to edit, or the screenshot an AI Vision block captures. | China | docs.z.ai/legal-agreement/privacy-policy |
| Anthropic | Powers the AI Assistant (Claude models). Only what you actively submit is transmitted: the text you send to the assistant, the macro you ask it to edit, and any image you attach. | United States | anthropic.com/legal/privacy |
| Stripe | Processing card payments for paid plans and macros bought by card | United States | stripe.com/privacy |
| Resend | Delivering account emails (verification and password-reset codes) and, if you opted in, the newsletter | United States | resend.com/legal/privacy-policy |
Z.ai and Anthropic process your input to generate a response, and both state that they do not use API traffic to train their models. AI features are optional and only send data when you actively use them, and only to the provider we route that request to. We choose which provider answers each AI Assistant request.
About Z.ai: Z.ai is a company based in China. Chinese law (including the National Intelligence Law) can require companies there to cooperate with government requests regardless of where servers sit or what a contract says. We don't send your account details, and we ask you not to put personal information into AI prompts, but you should know this before using the AI features, and you can use RoMacro fully without them.
Resend receives your email address and the message being sent to you. For the newsletter, it also keeps your subscribed/unsubscribed status so that an unsubscribe from the email link takes effect immediately.
International transfers: Your data is processed and stored in the United States, and AI requests you actively make are processed in China (Z.ai) or in the United States (Anthropic), depending on which provider answers them. By using RoMacro, you consent to these transfers. Data protection laws in those countries may not be equivalent to those where you live.
6. AI features
RoMacro includes optional AI features: the AI Assistant (a chatbot that turns your request into macro blocks) and the AI Vision block. These are powered by Anthropic's Claude models and Z.ai's GLM models, all routed through our own server (see the table in section 5).
- It is an AI, not a human. Responses are generated automatically and can be wrong or incomplete. Always review AI-generated blocks before running them.
- What is sent: only what you actively submit, the message you type, the macro you ask it to edit, and any screenshot or image you attach. We do not send your other macros or account details.
- What we keep: a copy of each AI Assistant conversation (your messages, the macro sent with them, and the answers) for 90 days, so the RoMacro team can see what went wrong when an answer is bad and make the assistant better. Pictures are not kept. AI Vision questions and screenshots are not kept either.
- Minor safety: because RoMacro is used by a broad audience, every AI request carries our own child-safety instructions on top of the provider's content policies, accounts are restricted to users 13 and older, and an in-app "Report" button flags inappropriate responses (routed to
safety@getromacro.com). - You can simply not use the AI features. Nothing is sent to an AI provider unless you do.
7. Your rights
You can at any time:
- Access: request a copy of everything we have on you.
- Correct: fix inaccurate information.
- Delete: close your account; we hard-delete your data within 30 days.
- Withdraw consent: same as deleting the account.
- Object or restrict processing of your data for specific purposes.
To exercise any of these, email privacy@getromacro.com. We will respond within 30 days.
If you believe your rights are not being respected, you can file a complaint with the Commission d'accès à l'information (CAI), the authority that oversees our privacy practices, at cai.gouv.qc.ca.
8. Local data on your computer
The desktop app stores one file locally:
- On Windows,
%APPDATA%\RoMacro\auth.dat: your encrypted authentication token. Encryption uses Windows DPAPI scoped to your Windows user account. The file never leaves your machine. - On macOS,
~/Library/Application Support/RoMacro/auth.dat: the same token, encrypted with a key kept in your login Keychain. The file never leaves your machine.
Uninstalling RoMacro does not remove this file automatically. Delete it manually if you want to wipe local state.
9. Children
RoMacro is not intended for users under 13 years of age. We do not knowingly collect personal information from anyone under 13, consistent with the U.S. Children's Online Privacy Protection Act (COPPA). Account creation requires confirming you are 13 or older. If you are 13–17, you need permission from a parent or legal guardian to use the service.
If you are a parent or guardian and believe a child under 13 has created an account, contact privacy@getromacro.com and we will delete the account and data immediately.
10. Security
- Passwords are hashed with PBKDF2 (ASP.NET Core Identity standard).
- All client-server communication uses HTTPS / TLS 1.2+.
- JWT signing keys are stored as encrypted Fly.io secrets, not in source code.
- Database access requires authentication; backups are encrypted.
We are not a Fortune 500. If there is a security breach involving your personal information, we will notify you within 72 hours of becoming aware of it.
11. Changes to this policy
We will update this page when our data practices change. The "Last updated" date at the top of this page reflects the most recent revision, and we may also point out significant changes in the app.
12. Contact
- Privacy:
privacy@getromacro.com - AI safety reports:
safety@getromacro.com - Support:
support@getromacro.com - Postal mail: available on request via the email addresses above
