Legal
Privacy Notice
What we collect, why we have it, who else can see it, how long we keep it, and how to make us delete it. The cookie notice is part of this page.
1. Who is responsible
The person or company that decides how your data is used is called the controller. Under Article 13(1)(a) of the GDPR we have to name them here.
The controller is a private individual living in Vilnius, Lithuania, who runs Roomly as a non-commercial personal project rather than through a registered company. There is no legal person behind the site. The full identity and postal address are set out under Who operates Roomly, and are supplied in full to any supervisory authority that asks.
Write to teisine@roomly.com for anything on this page, including any request under Articles 15 to 22. A person reads that address, and Article 12(2) means we cannot make you go through an automated tool instead.
Roomly has no Data Protection Officer. One is only required under Article 37 of the GDPR where the core activity involves large scale regular monitoring or large scale processing of special category data. Roomly is one person with a small user base and does no monitoring, so the threshold is not met. If that changes, this section changes with it.
2. What we collect
Everything below comes from you. We do not buy data, we do not scrape it and we do not build profiles about you from anywhere else.
| What | Where it is stored | Who can see it |
|---|---|---|
| Email address and password | Firebase Authentication | You and us. The password is stored by Google in hashed form and we never see it. |
| First name and last name from the sign up form | Cloud Firestore, in your private account record | You and us only. This record is not readable by other users. |
| Your Google account name, email and picture, if you sign in with Google | Firebase Authentication and your private account record | You and us. |
| Profile: display name, age, occupation, city, budget, move in date, bio, lifestyle tags, prompt answers, and your structured answers about how you live: whether you have a room or are looking for one, smoking, pets, tidiness, guests, sleep rhythm, languages you speak, and your minimum stay | Cloud Firestore, in the public profile record | Every signed in and email verified Roomly user. |
| Your discover filters: budget range, age range, districts, move-in window, and the no-smokers and no-pets conditions | Cloud Firestore, in your private preferences record | You and us only. Other users never see what you filter by. |
| Up to 6 photos | Cloudinary. Your profile record holds the links. | Every signed in and email verified Roomly user. Anyone who has the direct image link, because the links are public URLs. |
| Who you liked and who you passed on | Cloud Firestore | You and us. The person you liked can see that a like exists, which is how matching works. Passes are visible only to you. |
| Your matches and your messages | Cloud Firestore | The two people in the match. Messages are stored as readable text, so we can read them if we have to. See section 6 of the Terms. |
| How many profiles you swiped through | Cloud Firestore, in your private account record | You and us. A counter, nothing more. |
| Reports you send us, and our decisions | Our email, and our own records | Us. The person reported gets a statement of reasons, which does not name you unless the law requires it. |
| Technical logs: IP address, browser, time of request | Google, as part of hosting and sign in | Google and us. We do not analyse these and we have no analytics product installed. |
3. What is public
Your profile is visible to every person who signs up and verifies an email address. Signing up is automatic. No human at Roomly approves anyone. Treat your profile as public.
Your photos are worth a separate warning. They are served from Cloudinary as ordinary public URLs. Anyone who has the link can open the photo without signing in to Roomly at all. Do not upload a photo you would mind a stranger seeing.
Your email address is never on your profile. Neither is the first and last name you typed at sign up. Only the display name you chose for your profile is shown.
4. Why, and on what legal basis
- To give you an account and run the matching and messaging service
- Because we have an agreement with you. GDPR Article 6(1)(b).
- To keep people safe: handling reports, moderating content, blocking abuse, stopping fake accounts
- Our legitimate interest, and other users' legitimate interest in not being harassed or defrauded. GDPR Article 6(1)(f).
- To keep a record of reports we received and decisions we made
- A legal obligation under the Digital Services Act, plus our legitimate interest in being able to show what we did. GDPR Article 6(1)(c) and 6(1)(f).
- To answer an authority, a court order or a removal order
- A legal obligation. GDPR Article 6(1)(c).
We do not rely on consent for anything, because there is nothing here you would have to consent to. There is no advertising, no analytics, no tracking and no profiling for marketing.
5. Sensitive information
Some information gets extra protection under Article 9 of the GDPR: health, religion, political opinions, trade union membership, ethnic origin, sex life and sexual orientation.
We do not ask for any of it. There is no field for it.
But your bio and your prompt answers are free text, and people do write things like "I go to church on Sundays", "I am gay and looking for a queer friendly flat" or "I have a chronic illness so I need quiet". If you write it, it is published to every Roomly user, and the legal basis is Article 9(2)(e): information you have deliberately made public yourself.
Please think about this before you type. You do not have to explain yourself to find a flatmate.
6. Who else is involved
We are a small operation and we build on other people's services. These companies process data on our instructions.
Google, through Firebase
Sign in, the database and the web hosting. This is where your account, your profile, your likes and your messages actually live, and it is where the server logs are.
Cloudinary
Your profile photos. Uploads go straight from your browser to Cloudinary, so Cloudinary also sees your IP address at that moment.
Aruodas.lt
The five rental cards on the home page load their photographs directly from Aruodas's image server. Your browser therefore contacts Aruodas when you view the home page, and Aruodas sees your IP address. We do not send them anything else about you.
We do not sell your data. We do not share it for advertising. Nobody gets a copy of the database.
We will hand over data if a Lithuanian court or a competent authority orders us to. If that happens we will tell you unless we are legally barred from doing so.
Our fonts and the photo cropping library are stored on our own server. There is no request to Google Fonts and none to a content delivery network.
7. Data outside the EU
Some of the companies above are outside the European Union, or may store data outside it.
When this is settled, this section will name each transfer, the country, and the safeguard we rely on, which will normally be the European Commission's standard contractual clauses or an adequacy decision.
8. Cookies and local storage
Roomly sets no advertising cookies, no analytics cookies and no tracking cookies. There is no cookie banner because there is nothing here that needs your consent.
What we do use is your browser's own storage, on your device, for things the site cannot work without.
| Name | What it is for | How long |
|---|---|---|
roomly-theme | Whether you chose the light or dark theme. | Until you clear your browser storage. |
darkMode | The older name for the same setting. Kept so people who set it before still get their theme. | Until you clear your browser storage. |
roomly-lang | Whether you chose English or Lithuanian. | Until you clear your browser storage. |
roomly-last-seen-... | The last time you opened a given conversation, so we can show an unread dot. | Until you clear your browser storage. |
openProfileTab | Tells the app to open the profile tab after you click Edit Profile. Session storage. | Until you close the tab. |
| Firebase sign in tokens | Keeps you signed in between visits. Set by the Firebase SDK in local storage and IndexedDB. | Until you sign out or clear your browser storage. |
All of these are strictly necessary for a service you asked for. Under the Lithuanian Law on Electronic Communications, which implements the ePrivacy Directive, storage of that kind does not need consent. The exact article number is one of the things a lawyer should confirm before launch.
You can clear them at any time in your browser settings. If you clear the sign in tokens you will be signed out.
9. How long we keep things
- Your account and profile: until you ask us to delete them.
- Your photos: removed from your profile when you delete them, and removed from the image host within 30 days.
- Likes, passes and matches: for as long as your account exists.
- Messages: for as long as the match exists. If one person leaves, the other person's copy of the conversation stays until we delete it as part of the account deletion.
- Reports and moderation decisions: up to three years after the decision. We need to be able to show what we did and why, and to spot repeat behaviour.
- Server logs held by Google: on Google's own schedule, which is short. We do not keep our own copy.
10. Deleting your account
Email teisine@roomly.com from the address on your account and say you want your account deleted. We will confirm and finish within 30 days.
Three honest points about how this works today.
- The delete button is on your profile tab. It removes your account, your public profile, every like and pass you have made, and every conversation you are in, and it signs you out. Email still works if you would rather ask, and we treat that as a formal erasure request under Article 17 of the GDPR.
- Photos take longer than everything else. Your photos live with Cloudinary. Because of how the upload is set up, deleting a file there needs a signed request that we can only make by hand from our own side. So your photos disappear from your profile straight away, and are purged from Cloudinary within 30 days. Until they are purged, someone who saved the direct image link earlier could still open the file. We are changing the upload so this becomes automatic.
- Some records are locked against deletion by design. Likes, passes, matches and messages cannot be deleted from the app, by anyone, including you. That was done so a like cannot be quietly retargeted after a match was built on it. It means erasing them is a manual database operation for us. We do it, but it is a job, not a click.
If someone you matched with keeps a copy of your messages by taking a screenshot, we cannot reach that. Nobody can.
11. Your rights
Under the GDPR you can ask us to:
- tell you what we hold about you, and give you a copy;
- correct anything that is wrong;
- delete your data;
- restrict what we do with it while a dispute is open;
- give you your data in a portable file, or send it to another service. The Download button under App settings on your profile tab produces this file immediately; email works too if you would rather ask;
- stop processing that we based on our legitimate interests, by objecting to it.
Write to teisine@roomly.com. We answer within one month. If a request is complicated we can take up to two months more, and we will tell you if that happens.
We may ask you to prove the request comes from you. Writing from the email address on your account is normally enough.
This is free. If a request is clearly excessive or repeated we may charge a reasonable fee or refuse, and we will explain why.
12. How to complain
Tell us first if you can. teisine@roomly.com.
You can also complain to the Lithuanian data protection authority at any time, and you do not have to talk to us first.
Valstybinė duomenų apsaugos inspekcija (State Data Protection Inspectorate)
L. Sapiegos g. 17, 10312 Vilnius, Lithuania
ada@ada.lt
vdai.lrv.lt
If you live in another EU country you can complain to the authority there instead.
13. Automated decisions
Roomly sorts the profiles you see. That is a sorting order, not a decision about you, and it produces no legal effect and nothing similarly significant. So Article 22 of the GDPR does not apply.
No account is suspended or closed by software. A person decides, every time. See section 7 of the Terms.
14. Children
Roomly is for people aged 18 and over. We do not knowingly collect anything from anyone younger. The database rules refuse a profile age under 18. If you think a child has an account here, tell us at labas@roomly.com and we will close it and delete the data.
15. Security
Sign in and passwords are handled by Google, not by us, so we never see or store a password. The site is served over HTTPS only. Access to the database is controlled by rules that stop one user reading another user's private records.
No system is perfectly safe. If a breach happens that puts you at risk, we will tell the data protection authority within 72 hours and tell you as well where the law requires it.
16. Changes
We will update this page when what we do changes. The date at the top always says when. If a change matters we will email you.
Version 1.0. Last updated 12 August 2026. The Lithuanian version is at privacy.lt.html.