Privacy Policy
This Privacy Policy explains how Anthony Pullano (“AnyRoom,” “we,” “us,” or “our”) collects, uses, and shares information when you use AnyRoom at anyroom.app and related services (the “Service”). By using the Service, you agree to this Policy.
1. Who this applies to
The Service has two kinds of people: hosts (professionals who create an account and set up branded waiting rooms) and visitors (people who open a host’s waiting-room link to join a meeting). This Policy covers both.
2. Information we collect
Information you give us (hosts)
- Account info: your name, email address, and a password (or, if you sign in with Google, Microsoft, or LinkedIn, a unique identifier and basic profile info from that provider).
- Profile & branding: your display name, bio, timezone, profile picture, logo, background images, and page styling.
- Meeting details: meeting titles, agendas, scheduled times, and the video-meeting link and any passcode you save. Meeting links and passcodes are encrypted at rest.
- Recipients: if you add a client’s name and email to send an invite or reminder, we store that to send those emails.
- Support & communications: anything you send us directly.
Information collected automatically
- Visitor data: when someone opens a waiting-room page, we log a one-way hashed (pseudonymized) IP address and a timestamp to power host “someone arrived” notifications and basic visit counts. We do not ask visitors for their name, and we do not store raw IP addresses.
- Device/log data: standard technical data such as browser type and pages accessed, used to operate and secure the Service.
- Cookies: see “Cookies” below.
Information from third parties
If you sign in with Google, Microsoft, or LinkedIn, we receive basic profile information (such as your name and email) to create your account. We do not receive your password for those services.
3. How we use information
- To provide, maintain, and operate the Service.
- To send transactional messages — account and confirmation emails, meeting invites and reminders, and host “client arrived” alerts (you can control arrival alerts in your settings).
- To send product updates, tips, and our newsletter, where permitted — you can opt out at any time (see “Your choices & rights”).
- To secure the Service, prevent abuse, debug, and improve features.
- To comply with law and enforce our Terms.
4. How we share information
We do not sell your personal information. We share it only as follows:
- Service providers (subprocessors) who run the Service on our behalf, under confidentiality obligations: Supabase (database & authentication), Vercel (hosting), Resend (email delivery), and Stripe (payment processing, once paid plans launch).
- Identity providers you choose to sign in with (Google, Microsoft, LinkedIn).
- Legal & safety: when required by law, subpoena, or to protect rights, safety, and the integrity of the Service.
- Business transfers: in a merger, acquisition, or sale of assets, subject to this Policy.
Video-meeting providers. AnyRoom is not affiliated with Zoom, Google Meet, Microsoft Teams, or any meeting provider. When you or a visitor clicks “Join,” you leave AnyRoom and enter that provider’s meeting; what happens there is governed by that provider’s own privacy policy and terms, not ours.
5. Cookies
We use only essential cookies: a session cookie to keep you signed in, and a short-lived cookie to remember that a visitor has passed a room’s password gate. We do not use advertising or cross-site tracking cookies.
6. Data retention
We keep account and content data for as long as your account is active. Visitor visit logs (hashed IP + timestamp) are retained for approximately 180 days, then deleted or further anonymized. When you delete your account, we delete or anonymize associated personal data within a reasonable period, except where we must retain it by law.
7. Security
We protect data with encryption in transit (HTTPS) and encryption at rest for sensitive fields like meeting links, passcodes, and passwords, plus access controls that keep the database reachable only through our authenticated backend. No method of transmission or storage is 100% secure, but we work to protect your information and will notify you of a material breach as required by law.
8. Your choices & rights
- Access, correct, or delete: you can edit most information in your dashboard, or email privacy@anyroom.app to request access, correction, or deletion.
- Marketing opt-out: every marketing email has an unsubscribe link; transactional messages will still be sent.
- California residents (CCPA/CPRA): you have rights to know, delete, and correct your personal information, and to not be discriminated against for exercising them. We do not sell or “share” personal information as those terms are defined by California law.
- EU/UK residents (GDPR/UK GDPR): where applicable, you have rights of access, rectification, erasure, restriction, portability, and objection. Our legal bases are performance of our contract with you, your consent (for example, marketing), and our legitimate interests in operating and securing the Service.
To exercise any right, contact privacy@anyroom.app.
9. Children
The Service is intended for users 18 and older. It is not directed to children, and we do not knowingly collect personal information from anyone under 18. If you believe a minor has provided us information, contact us and we’ll delete it.
10. International users
We operate in the United States and our providers process data in the United States. If you access the Service from outside the U.S., you understand your information will be processed in the U.S.
11. Changes to this Policy
We may update this Policy from time to time. We’ll change the “Last updated” date above and, for material changes, provide additional notice. Continued use after changes means you accept the updated Policy.
12. Contact
Anthony Pullano · privacy@anyroom.app