Roleplay Privacy Policy
Last updated: 5 October 2026
This policy explains what personal data Sergiu Moloman ("we") handles for Roleplay, why, and what you can do about it. Our address is Str. Ștefan cel Mare 202, Chișinău, Republic of Moldova. Contact: support@useroleplay.app.
Who this covers, and who is in charge of your data
- Website visitors (useroleplay.app). We decide how this data is used, so we are the controller.
- Demo visitors (people who try the product without an account). We are the controller.
- Users invited by their company. Your employer (our customer) decides how Roleplay is used and is the controller of your practice data. We process it for them, on their instructions. For questions or requests about that data, contact your employer first; we will help them. We are the controller only for running sign-in, security and our own product analytics.
- People who sign up without an invitation. Signing in without an invitation creates your own workspace on a free trial. You are then the owner of that workspace and the customer for it.
- Buyers. When a team buys a plan, Paddle handles the purchase (see "Payments").
What we collect
Website visitors
- A random ID made for each page view (not stored in your browser), the page language, the campaign tag or
refin the link, and the referring site's host name. The landing page sends this without cookies to our web app, which passes it to our server and, when analytics is on, to PostHog. - Your IP address is seen by our hosting provider (Vercel), which hosts the landing page and the web app, and by Google, because the landing page loads Google Fonts.
Demo visitors
- A random demo token in a cookie (
demo, 30 days from your first visit). We store only a hash of it. - What you build and practise: the website you give us, the text we read from it, the text of any documents you upload (we keep the extracted text and the file name, not the file), the practice customer we create, call recordings, transcripts and scores.
- For usage limits: a keyed hash of your IP address (never the address itself), kept about 24 hours.
- For the bot check before you build a demo: Cloudflare's bot-check script runs in your browser on that page, so Cloudflare receives your IP address and the browser signals its check uses. Our server also sends Cloudflare the check's token and your IP address.
- If you send us feedback: your message, the page you were on and, from a call's results, which call it is about. If you use "Talk to us", also the email you type.
- If you later sign in, the practice customers and calls you made as a demo visitor move into your workspace. There, the people who can open your calls (see "Who we share it with") can see them like any other call.
Users with an account
- Account details: email, name, sign-in IDs, workspace, role, department, who invited you, when you joined and when you were last seen.
- Preferences: language, time zone, reminder settings, call languages, and any call-language requests (with the note you add).
- Company content your team adds: websites and the text read from them, the text extracted from uploaded documents and their file names (the files themselves are not kept), scenarios, tracks and assignments.
- Practice calls: a recording of the call (your microphone and the AI customer, mixed together), a line-by-line transcript, scores, written feedback, quoted moments, XP and streaks, and in-call coaching marks.
- Team activity about you: assignments and due dates, and when a manager marked that they talked with you or sent you a reminder.
- Feedback you send us: your message, your email, the page, and the call it is about if you send it from a call's results.
- Sign-in: our sign-in provider (WorkOS) receives your email, name, IP address and browser user agent. It emails you sign-in codes and invitations and holds your workspace membership. If you sign in with Google or your company's own login, that provider passes your profile (such as name and email) to WorkOS.
Payments
- Plans are sold by Paddle (Paddle.com Market Ltd), our reseller and Merchant of Record. Paddle collects your payment details, billing name and address, and tax details, and handles them as an independent controller under its own privacy notice.
- We never see or store your full card number.
- Paddle tells us what we need to run your plan: the subscription's status, plan, number of seats, billing period, and which workspace it is for.
We do not store passwords.
Cookies
We use only first-party cookies needed to run the service:
sessionkeeps you signed in. It ends after 30 days without a visit.signin-flowprotects the sign-in step. It lasts 10 minutes.demoholds your demo. It lasts 30 days.
There are no advertising or analytics cookies. Two third-party scripts can load in the web app: Cloudflare's bot check on the demo build page, and Paddle's checkout when you choose to buy a plan.
Analytics
We may use PostHog for product analytics. It is sent from our server, not from your browser.
- Events (such as "call started" or "call scored") are tied to a pseudonymous ID: a hash of the demo token, or your sign-in user ID, plus your workspace ID. When a demo visitor signs in, we link the two IDs so they count as one person.
- Events can include the company website a practice customer was built from, and call scores.
- Landing page views carry only the random per-view ID described above, with no person profile.
- We do not send your IP address, email or name, and location lookup is switched off.
- Data goes to PostHog's EU host.
Why we use it, and our legal bases
| Purpose | Legal basis | |---|---| | Providing the service to our customer and their users | Contract with the customer; for invited users we act on the customer's instructions | | Sign-in, security, abuse prevention, usage limits, bot checks | Legitimate interests in keeping the service safe | | Running the demo for demo visitors | Legitimate interests (responding to your request to try the product) | | Cookieless page-view counts and product analytics | Legitimate interests in understanding and improving the product | | Reminder emails to users | On the customer's instructions; you can unsubscribe from each email | | Answering feedback and support | Legitimate interests | | Selling plans and taking payment (through Paddle) | Contract and legal obligation |
How long we keep it
- Call recordings: deleted automatically 30 days after the call, by a cleanup that runs about once a day. Copies may remain in our hosting provider's backups for a limited time after that.
- Calls waiting to be delivered: at the end of a call, our voice agent saves the call's report (including its transcript) on its server's disk until our API has it, normally within seconds. If the API can't be reached, the report and the recording wait there for up to about 24 hours and are then dropped.
- Usage-limit records (demo): about 24 hours. They are cleared when the next demo activity happens, so they can last longer when the demo is quiet.
- Database backups: taken every 6 hours and kept for about 7 days.
- Everything else (accounts, company content, transcripts, scores, feedback, demo data): kept until it is deleted. Nothing in this group is deleted automatically.
- Taking someone off a team ends their access at once, but their calls and scores stay in the workspace.
- A workspace's owner can ask us to erase the whole team's data, or the data of someone already taken off the team. Write to support@useroleplay.app and we run it.
- After an erasure we keep only the erased people's email addresses and sign-in IDs, marked as removed, so an old invitation can't bring them back into the team by mistake. The owner can still invite them again.
- For customers, we also delete data at the end of the contract as set out in our Terms of Service.
- Demo data can no longer be reached once the 30-day cookie expires. You can ask us to delete it.
- Payment records: Paddle keeps them under its own privacy notice.
- Host logs: our hosting providers keep service logs for a limited period. These logs include the lines the AI customer says during calls.
Who we share it with
We use these service providers to run Roleplay:
- Railway: hosting for our API, voice agent and call server, and the storage for all product data.
- Vercel: hosting for the landing page and the web app.
- OpenAI: AI processing: reading company content, building practice customers, the live voice conversation, in-call coaching and scoring. It receives no user ID or email.
- WorkOS: sign-in, workspaces and invitations.
- Google: "Sign in with Google" (through WorkOS), and fonts on the landing page.
- Cloudflare: the bot check on demo builds.
- Paddle: selling plans and taking payment, as Merchant of Record.
- When switched on: PostHog (product analytics), Resend (reminder emails), Telegram (alerts to our team, including feedback messages with the sender's email, and error reports), an off-site backup store, and an alternative AI provider for scoring.
We do not sell personal data.
Inside a customer's workspace:
- The owner can open every call, with its recording, transcript and scores.
- A manager can open the calls of the people in the departments they belong to, and any call behind a moment assigned to one of those people.
- A rep sees their own calls. When a rep is assigned a moment from a call, they can open the whole call, including its recording, transcript and scores, even if it is a colleague's.
International transfers
Our main servers run in Europe: Railway in its europe-west4 region, and Vercel runs our web app's server code in Frankfurt, while its global network handles each visitor's connection at the nearest location. Some providers, such as OpenAI and WorkOS, may process data outside Europe. We are based in the Republic of Moldova. Where personal data moves from the EEA, UK or Switzerland to us or to providers outside those areas, we use the European Commission's Standard Contractual Clauses or another transfer mechanism the law allows.
Your rights
Depending on where you live, you can ask to access, correct, delete or export your data, object to or restrict how we use it, and complain to your data protection authority.
- Invited users: please contact your employer first, since they control your practice data. We will help them answer you, for example by erasing your data on their instruction.
- Everyone else: email support@useroleplay.app. We will reply within one month. We may ask you to confirm your identity. For demo data, we can only find it if you still have the demo cookie or tell us the website you used.
- Payment data: contact Paddle, or ask us and we will pass your request on.
Children
Roleplay is a business tool and is not meant for anyone under 18.
Changes
We will post changes here and update the date above. For significant changes we will tell customers by email.
Contact
Sergiu Moloman, Str. Ștefan cel Mare 202, Chișinău, Republic of Moldova, support@useroleplay.app.