join our discord server for updates ->

privacy policy

Effective: December 30th, 2025

rotheme (“we”, “us”, “our”) is committed to protecting your privacy. This Privacy Policy explains what data we collect, how we use it, and the rights you have in relation to your data. By using rotheme's services, you agree to the practices described below.


1. Information we collect

When you create a rotheme account using Roblox OAuth, we collect personal information, including but not limited to:

  • Your Roblox username and nickname
  • Your Roblox user ID
  • Your avatar/banner image
  • Your current Roblox profile bio
  • Session data, such as IP address and User-Agent

We also collect limited, non-personal information via cookies and local storage to:

  • Maintain your login session
  • Save local preferences (e.g., dismissed messages, theme settings)

In addition:

  • We use a cloud instance of Umami to collect anonymous, aggregated analytics (e.g., page views). No sensitive data is stored.
  • This Umami instance is currently not controlled by rotheme, and as such you are subject to Umami's Privacy Policy.

2. How we use your data

We use your information to:

  • Authenticate you and allow access to your account
  • Enable theme creation, sharing, and marketplace functionality
  • Provide essential site and extension features
  • Improve rotheme through basic, non-personal analytics

We do not sell, rent, or share your personal data with third parties, except as required by law or to operate core services (e.g. Cloudflare).


3. Cookies and local storage

We use essential cookies and local storage for:

  • Remembering your login session
  • Saving dismissed popups

We do not use advertising or tracking cookies.


4. Extension communication

The rotheme Extension communicates with the rotheme website to:

  • Verify extension installation
  • Retrieve your currently equipped theme
  • Save new theme data locally to your browser

The extension does not track browsing history or collect unrelated site data.

Note


5. Data retention

We retain account data until one of the following occurs:

  • You request deletion of your account
  • Your account remains inactive for 3 years, after which it may be permanently deleted
  • Retention is required by law or for legitimate security purposes

You may request deletion of your account at any time.


6. Data hosting and security

rotheme services are hosted in the EU and protected with industry-standard security measures (e.g. TLS, restricted access).

Cloudflare provides DDoS protection and caching. As part of normal operation, they may temporarily process your IP address.


7. Your rights

Depending on your location, you may have the right to:

  • Access the data we hold about you
  • Request correction or deletion of your data
  • Withdraw consent for data use where applicable
  • File a complaint with your local data protection authority

To exercise your rights, contact: [email protected]

privacy policy - rotheme