Rofiant
PlatformCompany
PricingDocsDownload
Log inSign Up
Rofiant

An AI agent for your files, local by default.

© 2026 Rofiant. All rights reserved.

Platform

  • Pricing
  • Chat
  • Agents

Resources

  • Documentation
  • API Reference
  • Changelog
  • Status

Company

  • About
  • Careers
  • Security
  • Contact

Legal

  • Terms of Service
  • Privacy Policy

Privacy Policy

Last updated July 5, 2026

01

Introduction

This Privacy Policy describes how Rofiant ("Rofiant," "we," "us," or "our") collects, uses, stores, shares, and protects personal information when you visit rofiant.ca, use our web application, APIs, dashboards, or related services (collectively, the "Services").

We wrote this policy to match what our platform actually does. If you do not agree with this policy, do not use the Services.

This policy applies to visitors, registered users, agency administrators, billing contacts, and anyone who submits information through our contact or careers forms.

02

Who Controls Your Data

Rofiant is the data controller for personal information processed through the Services, except where we process data solely on behalf of a customer organization under a separate data processing agreement. In those cases, the customer organization is the controller and Rofiant acts as a processor.

03

Information We Collect

We collect the categories of information below depending on how you use the Services:

  • Account information: name, email address, hashed password, authentication tokens, multi-factor authentication enrollment status, organization or agency membership, role assignments, and SSO identifiers when your organization uses single sign-on.
  • Platform content: chat messages, prompts, agent instructions, workflow inputs and outputs, API requests and responses, knowledge base entries, and metadata associated with those records (timestamps, model identifiers, token counts).
  • Screen and file data: documents, PDFs, files, and on-screen content Rofiant accesses on your machine to complete tasks, including extracted text and indexing metadata.
  • Audio data: voice recordings or audio files you submit for transcription or voice AI features, plus generated transcripts and summaries.
  • Usage and diagnostic data: feature interactions, page views (when analytics cookies are accepted), session identifiers, IP address, browser type, device information, error reports, stack traces, and performance logs.
  • Billing information: subscription plan, payment status, invoice history, and limited payment metadata processed by our payment provider. We do not store full payment card numbers on our servers.
  • Communications: messages you send through contact forms, support requests, careers notifications, and email correspondence with our team.
  • Security and fraud-prevention signals: bot verification results from Cloudflare Turnstile, rate-limit counters, and audit log entries for administrative actions.

We do not intentionally collect sensitive categories of personal information unless you choose to include them in content you submit to the platform. You are responsible for the data you upload, prompt, or transmit through the Services.

04

How We Collect Information

We collect information in three ways:

  • Directly from you when you register, configure an account, submit content, upload files, complete forms, or contact us.
  • Automatically when you use the Services, including through cookies, server logs, application telemetry, and error monitoring tools.
  • From third parties when you authenticate through OAuth or SSO providers, when your organization provisions access through SCIM, or when our payment processor sends billing event webhooks.
05

How We Use Information

We use personal information only for legitimate business purposes connected to the Services, including to:

  • Create and manage accounts, authenticate users, deliver chat, voice, document, agent, and workflow features, and respond to API requests.
  • Detect abuse, enforce rate limits, verify form submissions, investigate security incidents, and protect the integrity of the platform.
  • Provide customer support, troubleshoot errors, and respond to your requests.
  • Process subscriptions, send billing notices, and manage payment-related records.
  • Monitor reliability, analyze aggregated usage patterns, and improve product performance. We do not use customer content to train generalized AI models unless you explicitly opt in under a separate written agreement.
  • Meet legal obligations, respond to lawful requests, and enforce our Terms of Service.
  • Send service announcements, security alerts, product updates, and administrative messages.

We do not sell personal information. We do not share personal information with third parties for their independent marketing purposes.

06

Legal Bases for Processing

If you are located in the European Economic Area, the United Kingdom, or another jurisdiction that requires a legal basis for processing, we rely on the following bases:

  • Performance of a contract when processing is necessary to provide the Services you requested.
  • Legitimate interests when we secure the platform, prevent fraud, improve reliability, and communicate about the Services, balanced against your rights.
  • Consent when you accept analytics cookies, subscribe to optional communications, or otherwise opt in to a specific processing activity.
  • Compliance with legal obligations when we must retain, disclose, or process information under applicable law.
07

AI Processing

Several Rofiant features send user content to third-party AI inference providers to generate responses, summaries, transcriptions, or workflow outputs. Today we use Groq for model inference. When you submit a prompt, document, or audio file, the relevant content and necessary metadata are transmitted to that provider for processing.

AI providers process data under their own terms and privacy policies. We configure our integrations to support our contractual commitments, but you should assume that content sent for inference leaves our direct execution environment for the duration of processing.

AI outputs may be inaccurate, incomplete, or inappropriate. Do not submit export-controlled, classified, attorney-client privileged, or other regulated data to the Services unless your organization has approved that use under its own compliance review.

08

Service Providers

We use the following categories of subprocessors and infrastructure providers to operate the Services:

  • SupabaseAuthentication, PostgreSQL database, file storage, and row-level security for application data.
  • GroqAI inference for chat, voice, document, and workflow features.
  • PostHogProduct analytics when you accept analytics cookies. Page views and usage events are not captured for analytics before consent.
  • SentryError monitoring, performance tracing, and limited session replay for debugging production issues.
  • CreemSubscription billing, checkout, and payment event processing.
  • ResendTransactional email delivery for account, billing, and notification messages.
  • UpstashRedis-backed rate limiting and abuse prevention.
  • CloudflareTurnstile bot verification on public forms such as contact and signup flows.
  • VercelApplication hosting and edge delivery for the Rofiant web platform.

Each provider processes data under its own privacy policy and, where applicable, a data processing agreement. We limit the information we share to what is reasonably necessary for each provider to perform its function.

09

When We Disclose Information

We may disclose personal information in the following circumstances:

  • To service providers listed in this policy who process data on our behalf under contractual confidentiality and security obligations.
  • To comply with applicable law, regulation, legal process, or enforceable governmental request.
  • To protect the rights, property, or safety of Rofiant, our users, or the public, including to investigate suspected fraud, abuse, or security incidents.
  • With your direction or consent, including when you connect third-party integrations approved by your organization.
  • In connection with a merger, acquisition, financing, reorganization, or sale of assets, subject to confidentiality obligations and notice where required by law.

We do not disclose customer content to third parties for advertising or unrelated commercial purposes.

10

International Data Transfers

Rofiant operates from Canada and uses service providers that may process data in Canada, the United States, and other countries where they maintain facilities.

When we transfer personal information across borders, we rely on appropriate safeguards where required, including contractual clauses, provider security commitments, and organizational access controls. If you need information about transfer mechanisms for your jurisdiction, contact us at privacy@rofiant.ca.

11

Data Retention

We retain personal information only as long as necessary for the purposes described in this policy:

  • Account and profile data remain while your account is active.
  • Platform content remains until you delete it, your administrator removes it, or your account is deleted, subject to backup retention described below.
  • Security, audit, and diagnostic logs are retained for a limited period appropriate to investigation and compliance needs. Aggregated or de-identified analytics may be kept longer.
  • Billing and tax records are retained as required by applicable accounting and tax laws.
  • We may retain information longer when required by law, to resolve disputes, or to enforce our agreements.

When you delete your account or submit a verified deletion request, we delete or de-identify personal information within 30 days except where retention is legally required or where encrypted backups expire on their normal cycle.

12

Security

We apply administrative, technical, and organizational measures designed to protect personal information, including:

  • Encryption in transit using TLS and encryption at rest through our infrastructure providers.
  • Role-based access controls, least-privilege policies for production systems, and multi-factor authentication for administrative access.
  • Logging, alerting, and error monitoring to detect anomalous activity.
  • Managed cloud infrastructure with vendor security programs and independent audits performed by those vendors.
  • An incident response process to investigate and notify affected parties when required by law.

No online service can guarantee absolute security. You are responsible for maintaining the confidentiality of your credentials and for configuring organization-level controls appropriate to your data classification requirements.

13

Your Privacy Rights

Depending on your location, you may have some or all of the following rights:

  • Request access to the personal information we hold about you.
  • Request correction of inaccurate or incomplete information.
  • Request deletion of personal information, subject to legal exceptions.
  • Request a portable copy of certain information associated with your account.
  • Request restriction of processing in specific circumstances under applicable law.
  • Withdraw consent where processing is based on consent, without affecting prior lawful processing.
  • Lodge a complaint with a supervisory authority. Canadian residents may contact the Office of the Privacy Commissioner of Canada. Quebec residents may also contact the Commission d'accès à l'information du Québec.

To exercise these rights, email privacy@rofiant.ca with enough detail for us to verify your identity and locate your account. We respond within 30 days unless applicable law permits an extension.

14

Cookies and Similar Technologies

We use cookies and similar storage technologies for the following purposes:

  • Essential cookies and local storage entries required for authentication, session continuity, security, and remembering your cookie preference.
  • A consent record stored in local storage and a cookie so we can honor your analytics preference across sessions.
  • Analytics cookies and event capture through PostHog only after you click Accept on our cookie banner. If you decline, analytics capture remains disabled by default.

You can change your browser settings to block cookies, but some features may not function without essential cookies. Our cookie banner lets you accept or decline analytics cookies at any time on first visit.

15

Children

Users under 18 may create accounts in limited minor mode. For those accounts, Rofiant does not collect or retain name, age, chat history, uploads, analytics events, or usage records beyond the email and credentials required to operate the account. If you believe a child under 13 has provided us personal information, contact privacy@rofiant.ca and we will delete it.

16

Automated Processing

Our AI features generate outputs using automated processing. We do not use automated decision-making that produces legal or similarly significant effects about you without human review unless your organization explicitly configures such a workflow outside our default product behavior.

17

Changes to This Policy

We may update this Privacy Policy to reflect product changes, legal requirements, or provider updates. We will revise the date at the top of this page when we make material changes. Continued use of the Services after an update means you accept the revised policy.

18

Contact

Privacy questions, rights requests, or complaints: privacy@rofiant.ca. Security incidents: security@rofiant.ca.