Privacy Policy
RoylonAI is operated by RoylonAI (“we”, “us”, “our”). This policy explains how we collect, use, and protect your data.
Data Hosting
All data is hosted in Switzerland on Infomaniak infrastructure (Geneva and Winterthur data centres). Infomaniak is an ISO 27001:2022-certified ethical-cloud provider. Swiss law applies to your data end to end.
What We Collect
- Account data: Email address, name (provided at registration)
- Documents: Files you upload for analysis (stored encrypted at rest)
- Queries: Questions you ask about your documents
- Usage data: Query counts, storage used, feature usage (for billing and quotas)
- Technical data: IP address, browser type (for security and rate limiting)
What We Do NOT Collect
- We do not use your documents or queries to train AI models
- We do not share your data with third parties, except the sub-processors listed below (none of which are marketing or data-broker services)
- We do not sell your data
Your Rights (GDPR / nFADP)
You have the right to:
- Access your personal data
- Rectify inaccurate data
- Delete your account and all associated data (GDPR Right to Erasure)
- Export your data in machine-readable format
- Object to processing
To exercise these rights, contact us at privacy@roylon.ai.
Data Retention
- Documents: Retained until you delete them or your account is deleted
- Queries: Deleted at the end of the service’s query retention period, or of the period agreed in your organisation’s contract, and never kept longer than ten years
- Audit trail: The record of actions taken in your account is kept as compliance evidence for ten years from the end of the financial year, under the Swiss Code of Obligations (Art. 958f). The IP address in each record is removed after 90 days, and when you delete your account, its records are unlinked from you
- Account data: Retained until account deletion
- Technical logs: Request logs are deleted after 31 days, performance metrics after 30 days and request traces after 14 days; operational event records after 90 days by default. Two kinds of event record are kept past that period, linked to your organisation’s account and unlinked from it when the account is deleted: the record of a deletion that could not complete, so the deletion can be finished, and the record of an audit record that could not be delivered, so the gap in the audit trail stays visible
Backups keep a copy for seven days after the next successful backup run, then it is gone from them too.
Sub-processors
| Provider | Purpose | Location |
|---|---|---|
| Infomaniak | Cloud hosting and transactional email | Switzerland |
| Cloudflare | DNS, CDN, and marketing-site edge | USA (GDPR DPA + EU-US Data Privacy Framework participant) |
| Zitadel | Identity and access management | Switzerland |
| Stripe | Payment processing and tax calculation (VAT / GST) | USA (GDPR DPA + EU-US Data Privacy Framework participant) |
Cookies
We use a minimal set of cookies:
- Session cookie: Authentication (HttpOnly, Secure)
- ryl_referral: Partner referral attribution (30 days, first-party)
__cf_bm: Cloudflare bot-management cookie (30 minutes, first-party). Set automatically for visitors traversing our edge to distinguish legitimate traffic from automated abuse. No user identification or behavioural tracking.- Stripe payment cookies:
__stripe_midand__stripe_sidare set by Stripe during checkout and in the billing portal. Strictly necessary for fraud prevention; not used for advertising or cross-site tracking.
We do not use third-party tracking cookies or analytics.
Contact
For privacy inquiries: privacy@roylon.ai
RoylonAI, Switzerland