Legal

Privacy Policy

Last Updated: December 31, 2025

Rock Smith is committed to protecting your privacy. Our hybrid desktop-cloud architecture keeps sensitive website data on your machine while providing powerful AI testing capabilities. We collect only what's necessary to deliver our service.

1. What We Collect

Account Information

Email, name, and profile photo for authentication and communication.

Billing Data

Processed securely by Stripe. We never store your complete credit card details.

Test Configuration

Flows, assertions, and settings you create. Your website's source code stays on your machine.

Analytics

Privacy-focused product analytics via PostHog. You can opt out in settings.

2. How We Use Your Data

  • Provide and improve the Rock Smith service
  • Process payments and manage subscriptions
  • Send important updates and provide support
  • Analyze usage patterns to improve features

3. Third-Party Services

We work with trusted partners to deliver our service:

Supabase

Database, authentication, and file storage

Stripe

Secure payment processing (PCI DSS Level 1)

PostHog

Privacy-focused product analytics

AI Providers

OpenAI/Google for test intelligence

We never sell your data. Third parties only receive data necessary to provide their services.

4. Your Rights

Under GDPR and CCPA, you have the right to:

  • Access your personal data
  • Correct inaccurate information
  • Delete your account and data
  • Export your data in portable formats
  • Object to certain processing
  • Opt out of analytics tracking

Email contact@rocksmith.ai with subject "Privacy Rights Request" to exercise your rights. We respond within 30 days.

5. Security & Retention

Security Measures

  • TLS encryption in transit, AES-256 at rest
  • Hybrid architecture: browser runs locally on your machine
  • One-time authentication tokens for secure connections
  • Row-level security policies for data isolation

Data Retention

  • Account data: Until you delete your account
  • Test results: Until you delete them
  • Billing records: 7 years (legal requirement)
  • PAYG credits: Expire 1 year from purchase

6. Cookies

We use essential cookies for authentication and optional analytics cookies (opt-out available). We don't use advertising or tracking cookies.

Rock Smith is a B2B platform not directed at children under 16.

7. Contact & Updates

For privacy questions, email contact@rocksmith.ai.

We'll notify you by email at least 30 days before any material changes to this policy take effect.

BY USING ROCK SMITH, YOU ACKNOWLEDGE THAT YOU HAVE READ THIS PRIVACY POLICY AND AGREE TO ITS TERMS. IF YOU DO NOT AGREE, PLEASE DO NOT USE THE SERVICE.