Privacy Policy

What we collect, why we collect it, who can see it, and how to get it back or get rid of it.

Version 2026-09-11 · StonkLab Inc.

RoomRiff is operated by StonkLab Inc. (company number 1768908-0, registered at 20829 77A Avenue, Unit 414, Langley Township, BC V2Y 0Y5, Canada). StonkLab Inc. is the data controller for the personal data described here. Contact us at contact@stonklab.com.

1. The short version

A dating profile is personal by definition, and some of what we ask is sensitive. So:

  • We only collect what the app actually uses. Every field beyond your name, date of birth, gender and who you are interested in is optional.
  • We do not sell your data, and we do not run advertising or third-party analytics.
  • Your profile is visible to other signed-in members who match your filters. It is not public and is not indexed by search engines — the one exception is a first-name-and-city mention on our homepage, which is off unless you switch it on.
  • You can download or permanently delete everything, yourself, from your profile page.

2. What we collect

Account

DataWhy
Email addressTo sign you in, and to contact you about your account.
PasswordStored only as a bcrypt hash. We never store, and cannot recover, your actual password.
Date and version of the terms you acceptedTo evidence consent, as data protection law requires.

Profile

Required: display name, date of birth, gender, and who you are interested in. Your date of birth is never shown to anyone — other members see only your age.

Optional: photos, bio, location, languages, education, profession, hobbies, travel preferences, exercise, how you spend weekdays and weekends, and your answers to profile prompts.

Sensitive data

Some optional fields count as sensitive personal information under Canadian privacy law — and would be special category data under the GDPR, which is the standard we have chosen to hold ourselves to: who you are interested in (which can reveal sexual orientation), religion, ethnicity, diet, drinking, smoking and drug use, and your position on children.

We process these only with your explicit consent, which we ask for separately at sign-up. You can decline and still use RoomRiff — you simply leave those fields blank. Every one of them offers a “Prefer not to say” option. You can clear them at any time from your profile, and you can withdraw consent by deleting them or by deleting your account.

Activity

DataWhy
Likes and passesTo create matches and to stop showing you the same person twice.
MatchesSo the two of you can message.
MessagesTo deliver them. Stored in plain text — see “Messages” below.
Blocks and reportsFor safety, and to keep blocked people apart.

Technical

  • A session cookie. A single roomriff_session cookie holding a random session token. It is httpOnly, so scripts cannot read it. We store only a SHA-256 hash of the token, never the token itself.
  • Analytics cookies. We use Google Analytics to understand how people find and move through RoomRiff — how many visitors arrive, which pages they open, roughly where in the world they are. It sets cookies beginning _ga and sends Google your IP address, your browser and device type, and the page you are on.
  • What Google is not told. We strip identifiers out of the page address before it is sent, so a page like a specific conversation is reported to Google as /matches/[id] rather than the real one. Google is never sent your name, your email address, your photos, your messages, or anything that says which particular person you were looking at or talking to. We do not send query strings at all.
  • A campaign cookie, if you arrived from one of our adverts. When a link you followed to RoomRiff carries campaign tags in its address (the utm_ parameters an advertising platform adds), we store those tags in a single rr_attr cookie for 30 days. It records which advert brought you — a campaign name, a creative name, and which page you landed on — and nothing about you. It is httpOnly, so scripts cannot read it, and it is never sent to anyone outside RoomRiff.
  • Why we keep it. When you create an account, we record which campaign brought you alongside that step, so we can tell which adverts bring people who actually go on to use RoomRiff. If you arrived without campaign tags — by typing the address, or from an ordinary link — this cookie is never set at all.
  • There is no advertising on RoomRiff, and we do not use these cookies to build an advertising profile of you or to follow you to other sites.
  • Server logs. Our web server records the IP address, timestamp, requested URL and browser user-agent of each request. These are ordinary security and diagnostic logs — we use them to investigate abuse, debug faults and detect attacks, not to build a profile of you. They are automatically deleted after 30 days, and they are not combined with your account data.
  • Failed sign-in attempts to our server itself. Our firewall records the IP addresses of attempts to log into the server over SSH, so that repeat offenders can be blocked. These concern administrators and attackers rather than members, and are kept for 30 days.

3. Messages are not end-to-end encrypted

Messages are transmitted over HTTPS and stored in our database in plain text. That means they are protected in transit and by our access controls, but we are technically able to read them, and we may do so where it is necessary to investigate a report or comply with a legal obligation. Please do not send anything through RoomRiff that you would not want a support person to be able to read.

4. Who can see your data

  • Other members see your profile only if they match your filters and you match theirs. They see your age, never your date of birth, and never your email address.
  • Your matches can read your full profile, including your prompt answers, and the messages you send them.
  • Visitors to our homepage — but only if you switch this on. There is an off-by-default setting on your profile that lets us mention your first name and city in a “recently joined” line on the public homepage. Never your photo, age, full name, or a link to your profile, and never an exact time. Leave it off and you are never mentioned; turn it off later and you stop being mentioned.
  • Google, for analytics only, and only the limited technical information described under “Technical” above — never your profile, messages or matches.
  • Nobody else. We do not sell or rent your data, and we do not share it with advertisers or data brokers.

5. Where your data is processed

RoomRiff is offered in Canada, the United States, India and the Philippines. StonkLab Inc. is a Canadian federal corporation, but the app runs on a server in St. Louis, United States, rented from Contabo. If you are in Canada, India or the Philippines, your data is therefore stored outside your country and is subject to the laws of the United States, including lawful access requests by US courts and authorities. We think you should know that before you sign up, which is why it is written here rather than buried.

If you are in Canada, PIPEDA treats a transfer to a supplier who processes data on our behalf as a use rather than a disclosure, permitted without separate consent provided we stay accountable for the data.

If you are in India, the Digital Personal Data Protection Act 2023 permits transfers abroad except to countries the Central Government has restricted by notification. No such restriction applies to the United States at the time of writing. If that changes we will move your data or stop serving India, and we will tell you before we do either.

If you are in the Philippines, the Data Privacy Act of 2012 works the same way it does for Canada above rather than India’s: we stay accountable for your data wherever it is processed, and use contracts and other reasonable means to keep it protected to a comparable standard when it leaves the country.

The safeguards behind all three are the same:

  • A written data processing agreement with Contabo that binds them to process data only on our instructions, keep it confidential, and maintain defined security measures.
  • Contabo has no application-level access. They provide the machine; the database is not reachable from the public internet, administrative access is by SSH key only, and all traffic to the site is encrypted with TLS.
  • StonkLab Inc. remains accountable to you regardless. Using a supplier does not move our responsibility onto them. If something goes wrong with your data, your route of complaint is to us, and then to the regulators named in section 7.

Beyond that hosting we use two sub-processors:

  • Google, for the analytics described above. Google processes that limited technical data on its own infrastructure, under its own terms, which may involve transfers to the United States and elsewhere.

We do not send your profile, your photos, your messages or your matches to any third party.

Third parties your browser contacts

Giphy. If you open the GIF picker in a chat, the GIF images are loaded directly from Giphy by your browser. Your IP address is therefore visible to Giphy, and their privacy policy applies to that request. GIF searches are proxied through our server, so Giphy does not receive your search terms tied to your IP. If you never open the GIF picker, your browser never contacts Giphy.

Google Analytics. Loaded on every page, so your browser contacts Google on each visit. What is and is not sent is set out under “Technical” above.

6. How long we keep it

  • While your account exists, we keep your profile and messages so the app works.
  • Unmatching closes a match rather than deleting it, so the two of you are not immediately shown to each other again. The messages become inaccessible to both of you.
  • Deleting your account permanently removes your profile, photos, prompt answers, likes, passes, matches and messages. This is immediate and cannot be undone.
  • Reports you made about others are deleted along with your account. We have chosen full erasure over retaining safety records about a departed member, because keeping data on someone who has left needs a justification we do not currently have — there is no moderation review process for it to feed. If that changes, we will update this policy and say so.

7. Your rights

Depending on where you live, you have the right to access, correct, delete, restrict or object to our use of your data, to withdraw consent, and to receive your data in a portable format. Two of these are built into the app and need no request:

  • Access and portability — download everything we hold as a JSON file from your profile page.
  • Erasure — delete your account permanently from your profile page.

For anything else, email contact@stonklab.com. We aim to respond within 30 days, as PIPEDA requires.

If you are unhappy with our response you may complain to a regulator: the Office of the Privacy Commissioner of Canada, the Information and Privacy Commissioner for British Columbia, the Data Protection Board of India if you are in India, the National Privacy Commission if you are in the Philippines, or — if you are in the United States — the attorney general of your state.

Raising a grievance (India)

Under India’s Digital Personal Data Protection Act 2023 you have the right to a readily available means of grievance redressal. Email contact@stonklab.com with “Grievance” in the subject and we will respond within 30 days. That address reaches the person accountable for data protection at StonkLab Inc. directly — it is not a queue. If you are not satisfied with the outcome, you may then approach the Data Protection Board of India.

You may also nominate another person to exercise these rights on your behalf in the event of your death or incapacity, as the Act provides. Email us and we will record the nomination against your account.

Raising a grievance (Philippines)

If you are in the Philippines, email contact@stonklab.com with “Grievance” in the subject and we will respond within 30 days — the same commitment we make everywhere else in this policy. If you are not satisfied with the outcome, you may then approach the National Privacy Commission.

8. Security

Passwords are hashed with bcrypt. Session tokens are stored only as hashes. Traffic is served over HTTPS. Access to the server is restricted to key-based SSH on a firewalled host. No system is perfectly secure, and we will tell affected members without undue delay if a breach puts their data at risk.

9. Children

RoomRiff is strictly for people aged 18 and over. We verify your stated date of birth at sign-up and reject anyone under 18. If you believe a minor is using RoomRiff, email us immediately and we will remove the account.

10. Changes

If we make a material change we will ask you to accept the new version the next time you sign in. The version and date at the top of this page always reflect the current document.

See also our Terms of Service and Community Guidelines.