Privacy Policy
Last updated: 22 July 2026
This policy explains what personal data OJ Labs Ltd, trading as RoboStudio ("RoboStudio", "we", "us"), collects when you use the service, why we collect it, and what rights you have over it. For UK and EU data protection law, OJ Labs Ltd is the data controller. Our registered details and contact address are at the bottom of this page.
What we collect
- Account data — your name, email address, profile image and authentication state, managed on our behalf by our sign-in provider Clerk. We never receive or store your password.
- Billing data — your subscription plan and its status. Payments are processed by Clerk Billing and its payment processor; card details never reach our servers and we do not store them.
- Project and workspace data — the robot models, meshes, world configurations, code and other files you create or upload. Projects in the browser are stored locally on your device; cloud-instance workspaces are stored on encrypted AWS EFS volumes.
- Instance metadata — for each cloud instance, its identifier, owner, distribution, state, plan, add-ons, compute profile and last-seen timestamp, so we can run and bill the service accurately.
- Operational event logs — records of significant actions on the service (for example an instance starting, suspending or failing). These include the acting account's identifier and the IP address the request came from. We use them to operate the service, investigate faults, and detect and prevent abuse.
- Server and platform logs — our hosting and infrastructure providers generate their own request logs, which include IP addresses, and retain them under their own policies.
- Usage analytics — cookieless page analytics and performance measurement via Vercel. There are no advertising trackers, no cross-site tracking, and we do not sell personal data.
Why we use it, and our lawful basis
- To provide the service you signed up for — account data, project and workspace data, and instance metadata. Lawful basis: performance of a contract.
- To take payment and prevent billing errors — subscription and credit usage data. Lawful basis: performance of a contract.
- To keep the platform secure and available — event logs including IP addresses, used for fault diagnosis, rate limiting and abuse prevention. Lawful basis: legitimate interests (running a secure, working service), balanced against your interest in not being monitored beyond what that requires.
- To understand aggregate usage — cookieless analytics. Lawful basis: legitimate interests. Because this analytics does not use cookies or similar device storage, no consent banner is required.
- To meet legal obligations — for example retaining records needed for tax and accounting. Lawful basis: legal obligation.
Who processes your data for us
We use the following processors. Each is bound by a data processing agreement and may only act on our instructions.
- Clerk — authentication, account management and subscription billing.
- Vercel — hosting for the website and API, plus cookieless analytics.
- Amazon Web Services (AWS) — cloud robot instances (Fargate) and workspace file storage (EFS), in the United States.
- Supabase — the managed PostgreSQL database holding instance metadata and event logs.
- Cloudflare — DNS for per-instance hostnames, which processes instance identifiers and instance IP addresses.
International transfers
Our processors are based in, or process data in, the United States. Where personal data leaves the UK or European Economic Area, transfers are made under the safeguards permitted by UK and EU data protection law — the UK International Data Transfer Agreement or Addendum, the European Commission's Standard Contractual Clauses, or the EU–US and UK–US Data Privacy Framework where the provider is certified.
How long we keep it
- Account data — for as long as your account exists.
- Cloud workspaces — until you delete the instance, or until reclaim. If an instance runs out of credit it is suspended; if credits are not restored, a suspended, idle instance and its workspace are permanently deleted after the reclaim period, currently 7 days from suspension. Deleted workspaces are not recoverable.
- Instance metadata and operational event logs — kept for as long as your account exists, because they underpin billing accuracy and abuse investigation. They are deleted when your account is deleted (see below). We are moving to a shorter fixed retention window for event logs; until that ships, this is what actually happens, and we would rather say so than describe a schedule we do not yet enforce.
- Provider logs — retained by Clerk, Vercel, AWS, Supabase and Cloudflare under their own retention policies.
Cookies and similar technologies
We use only strictly necessary cookies — the session cookies Clerk sets to keep you signed in and to protect against cross-site request forgery. We use no advertising, profiling or cross-site tracking cookies, and our analytics is cookieless. That is why you are not asked for cookie consent. If that ever changes, we will ask for your consent before setting any non-essential cookie. See our Cookie Policy.
Your rights
Under UK and EU data protection law you have the right to access a copy of your personal data, to have inaccurate data corrected, to have your data erased, to restrict or object to certain processing, and to receive your data in a portable format.
How to exercise them today: use our contact form from the address on your account. We will respond within one month, as the law requires. Account deletion, data export and erasure are currently handled by us on request rather than by a button in the app; when self-service versions ship we will update this page. Deleting your account removes your account record, your instance metadata and the associated event logs, and permanently destroys your cloud workspaces.
Security
Access to production systems is restricted to the operator. Workspace volumes are encrypted at rest by AWS, and traffic to the service is encrypted in transit. Cloud instances give you shell access to a container running on our infrastructure — treat anything you store in a workspace as you would any remote development machine, and do not store credentials or personal data there that you would not want held on a shared platform.
Data breaches
If a personal data breach occurs that is likely to result in a risk to your rights and freedoms, we will report it to the Information Commissioner's Office within 72 hours of becoming aware of it, and will tell you directly without undue delay where the law requires it.
Children
The service is not intended for children. You must be at least 16 years old to create an account. If you believe a child has created an account, contact us and we will delete it.
Complaints
If you are unhappy with how we handle your data, please contact us first so we can put it right. You also have the right to complain to a supervisory authority: in the UK, the Information Commissioner's Office (ico.org.uk); in the EEA, the data protection authority in the country where you live or work.
Changes
We will update this page when our practices change and revise the "Last updated" date above.
Contact
For data protection enquiries, use our contact form.
RoboStudio is a trading name of OJ Labs Ltd, a company registered in United Kingdom (company number 17348346), registered office: 19 Rosebery Street, Liverpool, L8 2TN. No VAT is charged.