1. Who is responsible for your data
RoomBoxPaper is operated by Muhsin Efe Tarım, who is the data controller for the processing described in this notice. Questions and requests may be sent to [email protected].
2. Data we process
- Identity and account data: verified email address, authentication-provider identifiers, room username, and basic profile information supplied through Auth0 or Google sign-in. RoomBoxPaper does not receive your Google password.
- Your content: room structure, text, drafts, photos, audio, video, links, titles, and other material you choose to create or upload.
- Sharing and access data: visibility choices, invitation and guest-access records, and actions needed to provide public or restricted access.
- Technical and security data: session records, request and error information, IP address and similar records created by the service and its infrastructure providers.
- Communications: messages and supporting information you send when requesting help, deletion, or another privacy right.
We collect this data directly from you through account and support forms and the content you create or upload; from authentication providers such as Auth0 and, when selected, Google; and automatically through session cookies, server logs and infrastructure providers while you use the service.
3. Why we process data
We process data only as needed to:
- create and authenticate accounts and provide rooms;
- store, display, organize, share and recover user content;
- operate invitations and the visibility choices you select;
- protect accounts, investigate abuse and keep the service secure;
- answer requests and comply with applicable law; and
- improve reliability without using advertising profiles.
Depending on the activity and applicable law, processing is based on performance of the service agreement, legal obligations, legitimate interests in operating and securing the service, or consent where consent is specifically required. Privacy information is not a blanket consent to unrelated processing.
4. Public and restricted content
RoomBoxPaper provides visibility controls. Material marked for everyone may be viewed by people who are not signed in and may be copied or shared by them. Material limited to you or approved guests is served through restricted access controls. You should not publish personal data belonging to another person unless you have a lawful reason and their permission where required.
5. Service providers and international transfers
RoomBoxPaper relies on carefully selected providers to operate the service: Auth0/Okta for authentication, Google Identity when you choose Google sign-in, Render for application and database hosting, and Cloudflare for network and media-storage services. When the domain's forwarding aliases are enabled, Cloudflare Email Routing routes messages sent to those aliases. Messages sent to the published support and privacy address are ultimately received and stored through Google/Gmail regardless of the sign-in method you use. If transactional account email through Resend is enabled, Resend will also be used to deliver those messages. These providers process data on RoomBoxPaper's instructions or under their own legal duties.
Because these providers operate internationally, data may be stored in or accessed from countries outside Türkiye. We use the contractual and technical protections made available by these providers and are reviewing the additional transfer formalities required by Turkish data-protection law as part of the service's early-stage compliance work. Law-enforcement or public authorities may receive data only where disclosure is legally required.
RoomBoxPaper does not sell personal data and currently does not use it for third-party advertising or behavioural advertising.
6. Cookies and sessions
The service currently uses cookies and similar storage that are necessary for sign-in, security, invitation handling and requested preferences. It does not currently place advertising or optional analytics cookies. If optional tracking is introduced, this notice and the consent controls will be updated before those tools are used where consent is required.
7. Retention and deletion
Account and room data are generally kept while the account is active or as needed to provide the service. Items moved to RoomBoxPaper's Trash have a 90-day recovery window. Web sessions expire after 30 days of inactivity and no later than 90 days after creation. Invitations normally expire after two days.
When an account-deletion request is submitted, the account and room are immediately made inaccessible and hidden. For 15 calendar days from the request date, the account owner may cancel the request and restore access. At the end of the 15th day, the permanent deletion process begins for application data, media held in RoomBoxPaper's private storage, and the linked Auth0 identity. Completing the technical deletion steps may take a limited amount of processing time, but the account and room remain unavailable during that process.
The room username stays reserved for a total of 30 days from the original request date. If deletion is cancelled during the 15-day recovery period, the username remains with the restored account. Otherwise, it may become available for another account after the 30-day reservation ends.
We may retain narrowly limited records for longer when a legal obligation requires it or when they are reasonably needed for security, fraud prevention, or an active dispute. Technical backups may also retain isolated copies until they are overwritten or deleted under the backup schedule. Those copies are not available for ordinary use, and an account deletion remains applicable if a backup must be restored.
8. Your choices and rights
Subject to applicable law, you may ask whether and how your data is processed; learn its purposes, whether it is used consistently with those purposes, and recipients in Türkiye or abroad; request access, correction, deletion or destruction when the legal conditions are met; ask that correction or deletion be notified to recipients; object to an adverse result produced solely through automated analysis; or claim compensation for damage caused by unlawful processing. Where processing relies on consent, you may withdraw that consent for future processing. Requests should be sent to [email protected]. Account owners should write from the email address already registered with the service. Other applicants should contact that address first for the applicable written or secure electronic submission method and identity or authority documents. Identity verification may be required before a request is completed. Requests under Türkiye's data-protection law will be answered as soon as possible and no later than 30 days, normally without charge except for a fee permitted by the official tariff where responding creates an additional cost.
Sealed parts are normally immutable and cannot be edited or deleted through ordinary product controls. In an exceptional case involving sensitive personal data, another person's personal data, copyright, or a legal request, you may ask support to review removal of the specifically identified part. The request is assessed narrowly and does not automatically remove the part or make sealed writing editable.
9. Age information and younger users
RoomBoxPaper is a general-audience service and is not designed to profile or advertise to children. During the friend alpha we do not request a date of birth or operate an age or guardian-verification flow. A parent, guardian, or other legal representative who believes the service contains information about a person they represent may contact us to request review or deletion under applicable law.
10. Security and changes
We use technical and organizational measures intended to protect data, including encrypted connections, restricted media storage and protected server-side sessions. No online service can promise absolute security. If this notice changes materially, the updated version and effective date will be published here and additional notice will be provided where required.