Privacy Policy
Version dated 19 August 2026
This Policy explains what personal data the rombik service collects, for what purpose and on what legal basis it processes the data, with whom it is shared, and what rights the user (data subject) has. The data controller is the person listed in the “Contacts” section (“we”). Processing is carried out under the Law of Ukraine “On Personal Data Protection”.
1. Data we process
Account: email, name (if any), sign-in provider (Google/GitHub or magic link).
Usage: history of generated charts and exports, purchases and payments, API keys (stored as a hash).
Your code: if you are signed in, the TEXT OF THE CODE you turn into a chart is stored on our server — otherwise history, state restore, short chart links and re-downloading an export you already paid for could not work. Render settings are stored alongside the code.
If you are not signed in, your code is NOT stored on the server: it is transmitted, processed to build the chart and not retained. The Telegram bot does not store code either — only anonymised metadata (language, format, chat) for plan accounting.
Technical data: IP address and User-Agent — for security, abuse prevention and analytics.
We do NOT collect sensitive data and do NOT store payment card details — they are processed by the acquiring bank on its side.
2. Purpose
Providing the service, crediting and accounting for payments, support, security, legal compliance and product improvement.
3. Legal basis
Processing is based on: performance of the contract (public offer), the data subject’s consent, our legal obligations, and our legitimate interests (security, abuse prevention).
4. Third parties (processors)
plata by mono (JSC Universal Bank, Monobank) — payment processing and sending payment receipts.
Paddle.com Market Limited (“Paddle”) — processing of international payments as Merchant of Record: accepting payment, issuing invoices and receipts, assessing taxes. Processes data outside Ukraine.
Google and GitHub — authentication (OAuth sign-in), if you use it.
Resend — sending service emails (sign-in, receipts).
Cloudflare, Inc. — CDN and attack protection (traffic passes through the Cloudflare network).
Hosting provider (cloud infrastructure) — hosting the service.
Some processors may process data outside Ukraine with an adequate level of protection. We do not sell personal data and do not share it for advertising.
5. Cookies
We use only strictly necessary cookies — the authentication session (to keep you signed in) and Cloudflare protection cookies. No advertising or tracking cookies; we run web analytics with our own anonymised server-side logs (no third-party trackers).
6. Retention and deletion
Data is kept while the account exists and as required by law (including payment records). After account deletion the data is erased or anonymised, except what we are legally required to retain.
Code and charts: we keep the last 50 builds per user in history — older ones are evicted automatically. The exception is charts you created a short link for: they are kept until you delete them, otherwise the link would stop working. The recipe of a paid export (so you can download the file again) is kept if it does not exceed 256 KB.
Technical logs (requests, IP, User-Agent) are kept for 30 days and then deleted automatically.
7. Data subject rights
You have the right to: know the sources, location and purpose of processing; access your data; request its correction, update, deletion or anonymisation; withdraw consent; object to processing.
To exercise these rights, write to the contact address below — we will respond within the period set by law (up to 30 days).
You also have the right to lodge a complaint with the Ukrainian Parliament Commissioner for Human Rights.
Contacts
- Data controller:
- Nadiia Odarchuk, Individual Entrepreneur (FOP)
- Email:
- [email protected]