Privacy Policy

Last updated: April 2025

1. Data Controller

Genius Room (“we”, “us”, “our”) is the data controller responsible for your personal data. We process personal data in compliance with applicable privacy laws, including the GDPR where applicable.

Contact: privacy@genius-room.app

2. Data We Collect

  • Account data: email address, name (provided during signup)
  • Usage data: session logs, mode usage counts (consulta, debate, hardcore)
  • Payment data: processed exclusively by Stripe — we never store card details
  • Technical data: IP address, browser type, and device information collected automatically

3. Legal Basis for Processing

  • Contract performance: to provide the service you signed up for
  • Legitimate interests: security, fraud prevention, and service improvement
  • Legal obligation: billing and tax compliance
  • Consent: analytics cookies (where applicable)

4. AI-Generated Content

Genius Room uses artificial intelligence to generate responses based on publicly documented ideas, writings, and interviews of the represented individuals. Your conversation inputs are sent to Anthropic’s API for processing. We do not use your conversations to train AI models. Anthropic’s data processing is governed by their own privacy policy and data processing agreement.

Genius Room is an educational simulation. No affiliation exists with any represented individual or their estates.

5. Data Retention

  • Account data: retained while your account is active and for 2 years after deletion
  • Usage counters: retained for the current calendar year plus 12 months
  • Billing records: retained for 5 years to comply with applicable tax and accounting law

6. Data Transfers

We use the following sub-processors, all of which provide adequate safeguards for international data transfers:

  • Supabase (database & auth) — EU region
  • Vercel (hosting) — EU region where available
  • Stripe (payments) — Standard Contractual Clauses
  • Anthropic (AI inference) — Standard Contractual Clauses

7. Your Rights

Depending on your location, you may have the right to:

  • Access your personal data
  • Rectify inaccurate data
  • Erasure (“right to be forgotten”)
  • Restriction of processing
  • Data portability
  • Object to processing
  • Lodge a complaint with your local data protection authority

To exercise any right, email hello@thegeniusroom.app. We respond within 30 days.

8. Your Data Rights (GDPR)

If you are located in the European Economic Area or United Kingdom, you have the following specific rights under GDPR:

  • Right to deletion: You may request the deletion of all your personal data at any time. Email hello@thegeniusroom.app with the subject line “Data Deletion Request”. All data — including your profile, usage history, and conversation data — will be permanently deleted within 30 days.
  • Right to data portability: You may request an export of your personal data at any time. Email hello@thegeniusroom.app with the subject line “Data Export Request”. We will provide your data in a machine-readable format within 30 days.

9. Changes to This Policy

We may update this policy. Material changes will be notified by email or a prominent notice in the app at least 14 days before they take effect.