Privacy policy
Roomeo holds some genuinely sensitive things: what you owe, what you have paid, and, if you own the home, what you still owe the bank. This policy explains exactly what we collect, who can see it, where it is kept, and what happens when you leave. It is written to be read, not skimmed past.
1. Who we are
Roomeo is operated by Savvi Corp Technologies (ABN 79 627 343 425), a registered Australian business based in Brisbane, Queensland. In this policy, “we”, “us” and “our” mean Savvi Corp Technologies, and “Roomeo” means the Roomeo mobile app, the Roomeo website at roomeo.savvicorp.com.au, and the services behind them.
We are bound by the Privacy Act 1988 (Cth) and the Australian Privacy Principles. This policy tells you how we handle personal information, and how to reach us if you are unhappy with it.
getintouch@savvicorp.com.au. Write to us first if something in this policy concerns you. Section 16 explains what happens next if we do not resolve it.
2. The short version
The rest of this document is the detail. This is the honest summary of it.
- We collect the information you type into Roomeo, and very little else.
- We never ask for, and cannot accept, your bank logins or card numbers. Roomeo records money that moves elsewhere. It does not move money itself.
- We run no analytics, no advertising, no tracking, no crash reporting and no session recording, in the app or on the website. We do not build a profile of you and we do not sell or rent personal information to anyone. The one exception is the spam check on the website’s two forms, which section 14 describes in full.
- If you own the home, your mortgage balance, equity, property value and payoff projection are yours alone. Your housemates cannot see them. This is enforced by the software, not by a setting you have to find.
- Your account data lives in Australia. A small number of overseas services support billing, app updates, notifications and the website, and they are listed in section 8.
- Deleting your account removes your identity from Roomeo. It does not delete the shared financial record, because that record also belongs to the people you lived with. Section 11 explains this properly.
3. What we collect
Almost everything Roomeo holds is information you or the people in your household entered on purpose. The categories are:
Your name, your email address, and your password. Your name matters more than it might seem: it is the name printed on any room agreement you sign, so it should be your real full name. We also record whether you have verified your email address, and your chosen app language if you set one.
If you choose to add one, we store it. You can take it with the camera or pick it from your photo library, and it is shown to the other people in your home so they can tell who is who on the roster. If you sign in with Google, we copy the profile photo on that Google account across at sign-up. It is optional, you can remove it at any time, and Roomeo works normally without one.
The home’s name, and optionally its street address, suburb, and state or territory. Rooms and their default rent. Who lives there, in what role, from when, and on what rent and bond terms.
Rent charges and rent history, shared bills and expenses and how they were split, bond amounts and end-of-stay bond settlements, payments recorded against any of those, and any note someone wrote alongside them.
If someone attaches a photo or a PDF of a receipt to a bill, we store that file. Those are the only file types Roomeo accepts for a bill. There is no document upload and no identity document upload.
The full text of any agreement created in Roomeo, including house rules and any extra clauses that were written into it, plus both parties’ names as typed, the date and time each person signed, the fact that each person consented to sign electronically, and a cryptographic fingerprint of the document.
If you own the home and choose to enter them: your loan balance, interest rate, term, repayment amount and frequency, the property’s value, and your offset arrangement. Also any repayment you mark as made, and any private note you attach to a late rent charge.
The invite codes you generate. If you choose to send an invitation by email rather than reading out the code, we store the address you sent it to. If the code was spoken or scanned as a QR code, which is the usual case, no address is stored.
The credentials that keep you signed in, and any password reset or email verification link you request. These are stored only as one-way hashes, never in a form we could read back or reuse.
If you turn on notifications, your device gives us a push token, and we store it with the kind of device it came from so we can send the notification to the right place. It is issued by Apple or Google for this app on this device, it is not an advertising identifier, and it cannot be used to identify you anywhere else. Turning notifications off, signing out of that device, or deleting your account removes it.
If you buy a subscription or an agreement credit, we store the identifiers our billing provider returns: which product, which store, the transaction reference, and when the entitlement runs to. We never receive your card number, and we never receive your billing address.
4. What we do not collect
This section is as important as the one above, because most apps of this kind do collect these things. We do not.
- No bank logins, account numbers, BSBs or card numbers. Roomeo does not connect to your bank and has no way to.
- No analytics, product telemetry, crash reporting, session recording, heatmaps or A/B testing tools. There is no such software in the app or on the website. The website’s spam check, in section 14, is the only third-party script that runs on any page, and what it measures is whether you are a robot.
- No advertising identifiers, no advertising networks, and no tracking of you across other apps or websites. The app’s iOS privacy manifest declares no tracking.
- No location data. Roomeo asks for no location permission and includes no mapping or address lookup service.
- No advertising IDs or installation IDs. The only device identifier we hold is the push token described in section 3, which exists so a notification can reach your phone and does nothing else.
- No contacts and no microphone.
- No date of birth, no phone number, no government identifiers. Roomeo does not verify anyone’s identity and does not hold identity documents.
Two technical notes, for completeness. Our servers read the IP address of an incoming request in order to throttle abuse, such as repeated failed sign-ins or invite-code guessing. That address is held in memory for the length of the throttling window and is never written to our database and never written to our logs. The app also tells our servers which app version it is, so that we can stop an outdated build from using a feature it does not understand. That version information is not stored either.
The app does ask for four permissions, and it is worth being exact about what each one is for, because a permission prompt tells you what could be accessed rather than what is. Every one of them is optional, each is requested at the moment you first use the feature rather than up front, and declining any of them leaves the rest of Roomeo working normally:
Three things, and nothing else: scanning a house invite QR code, photographing a receipt to attach to a bill, and taking a profile photo. The camera is opened only when you tap one of those actions. Roomeo does not record video and has no background access.
So you can pick an existing photo instead of taking a new one, for a receipt or a profile photo. Roomeo reads the single image you choose. It does not scan, index or read the rest of your library.
So Roomeo can write your rent and bill due dates into your calendar as real events, if you turn that on. This one writes rather than reads: we do not look at your existing events, and nothing from your calendar is sent to us or stored by us.
So we can tell you rent is due, a payment landed, or an agreement needs your attention while the app is closed. See the push token entry in section 3, and section 13 for what we send.
Face ID or Touch ID, if you switch on the app lock, is handled entirely by your phone. Roomeo is told only whether the check passed. We never receive your fingerprint or your face data, and neither does anyone else.
5. How we use your information
We use the information described above to do the things Roomeo exists to do, and for nothing else:
- To run your household’s records: work out what is due and when, apply payments to charges, track bond, split shared expenses, and keep the history that both sides can refer back to.
- To produce the documents you ask for, such as a payment record or an owner statement, and to let a third party confirm that a document you gave them is genuine.
- To create, deliver and store room agreements, and to keep the signed record of them.
- To calculate the mortgage offset and payoff projections shown to owners, from the figures the owner entered.
- To send you transactional email: verifying your address, resetting your password, confirming an email change, and telling you about things that happened in your household, such as an invitation or an agreement being offered.
- To manage subscriptions and the one-off agreement credit, and to know which features your household has access to.
- To keep the service secure and working: throttling abuse, diagnosing errors, and keeping backups.
- To answer you when you contact us.
We do not sell, rent or trade personal information. We do not use your household’s financial records to market anything to you, and we do not send marketing email unless you have separately asked us to, such as by joining the mailing list on our website.
6. The line between an owner and their housemates
Roomeo is used by people who live together, so the most important privacy question is not what we can see. It is what each other can see.
If you own the home, the financial details of the property itself are yours alone. Your loan balance, your interest rate, your repayments, the property’s value, your equity, your payoff projection, and any private note you attach to a late rent charge are never sent to a housemate’s app. They are not greyed out or hidden behind a setting. They are not on your housemates’ side of the service at all, and the software refuses any request for them that does not come from an owner of that home.
If you live in someone else’s home, what your host can see is your side of the shared record: what you owe, what you have paid or flagged as paid, and your history in that home. Your host can keep private notes about a late payment that you will not see. We tell you that here because you should know it, and the app tells you too.
In a shared house with no owner, there is no owner-only view, because there is no owner. Everyone sees the same shared record.
One consequence worth stating plainly: if a home has more than one owner, all of them are inside that boundary. Someone who accepts a co-owner invitation can see the home’s loan and equity figures. Only send a co-owner invitation to someone you intend to give that access to.
7. Household records belong to more than one person
A payment is a record of two people: the one who paid and the one who was paid. A signed agreement is a record of both signatories. This shapes how Roomeo behaves, and it is the reason for several things in this policy that might otherwise look odd.
- What you enter about a shared charge is visible to the other people that charge concerns.
- When you move out, or are removed, your own payment history and your own signed agreements stay readable to you under Past homes. Your history is often the closest thing you have to a rental reference, so we do not take it away from you.
- Equally, your former housemates keep their copy of the same records, because those records are theirs too.
- When you delete your account, the shared financial record survives, with your identity removed from it. Section 11 sets this out in full.
8. Who else touches your information
We use a small number of service providers to run Roomeo. They process information on our instructions, for the purposes listed below, and for nothing else. We do not disclose personal information to anyone else except where this policy says so or the law requires it.
Hosts the Roomeo database. This is where your account, your household and its financial records live. The database runs in Sydney.
Runs our servers, stores receipt files and profile photos, holds our backups, and keeps our application logs. All in the Azure Australia East region, in Sydney.
Delivers our transactional email. Configured so that message content and logs are held in the Australian data geography, and configured with open and click tracking switched off, so no one learns whether you opened an email from us.
Manages subscriptions and entitlements. It receives your Roomeo account identifier and, for a subscription, the identifier of the home the subscription is for. It does not receive your name, your email address, or any figure from your household’s records. RevenueCat is based in the United States.
Distributes the app and processes every in-app purchase. Apple is the merchant for those purchases. Your payment details go to Apple and never to us. We receive only the fact of a purchase and its transaction reference.
Builds the app, delivers over-the-air updates to it, and carries our push notifications. An installed app contacts Expo’s servers to ask whether an update is available, which necessarily discloses the device’s IP address and platform to Expo. If you turn notifications on, Expo also holds your push token and passes each notification to Apple or Google for delivery, so the text of that notification passes through Expo and appears on your lock screen. Because of that, no dollar amount ever goes into one. A push tells you that rent is due, or that someone sent or signed an agreement, and the amount is only ever shown inside the app once you have opened it. That is built into how the messages are assembled rather than being a rule we remember to follow. What a push can contain is a person’s first name, the name of the home, and a date. Expo is based in the United States.
Hosts our source code and runs our automated deployment and backup jobs. Our nightly database backup is produced on GitHub’s infrastructure before being stored in Australia, which means a copy of the database passes through GitHub’s systems in the course of being backed up. GitHub is a Microsoft company based in the United States.
Hosts the roomeo.savvicorp.com.au website, including the contact and mailing list forms. It does not host the app or the database.
Tells people from bots on the website’s contact form and mailing list form. It runs on the two pages that carry those forms and nowhere else, and not at all in the mobile app. While you are on one of those pages your browser talks directly to Google, which discloses your IP address, your browser and how you moved through the page, and Google sets a cookie of its own to recognise the browser. When you press send we pass Google the resulting token along with your IP address, and Google answers with a score. We keep nothing from that exchange except the decision to accept or refuse the submission. Google is based in the United States and what it does with what it sees is governed by Google’s own privacy policy, which is linked beside both forms.
By using Roomeo you consent to these overseas disclosures. We take reasonable steps to use reputable providers, but we cannot control how an overseas provider is treated under the law of its own country, and Australian Privacy Principle 8.2 means we are not always accountable for their acts once information is disclosed to them.
We may also disclose personal information where we are required or permitted to by law, for example in response to a court order, or where it is reasonably necessary to prevent a serious threat to someone’s life, health or safety. If our business is ever sold or restructured, information may pass to the new owner, who would remain bound by this policy or one no less protective.
9. Document verification codes
When you export a payment record or an owner statement, Roomeo can register it and print a short verification code on it. Anyone holding that code can ask us to confirm the document is genuine and unaltered. That is what makes the document useful as a reference.
Anyone who has the code can see the name on the document, the home it refers to, the period it covers and the total amount. That is the point of a verification code, but it means you should treat a registered document, and its code, as something you have chosen to be able to share.
The check reveals nothing else. It never exposes a loan balance, a valuation, an interest rate, or anyone else’s records.
10. How we protect your information
What we actually do, described without exaggeration:
- Passwords are stored only as an argon2id hash. We cannot read your password, and neither can anyone who obtains our database.
- Sign-in sessions use short-lived access tokens and a longer-lived refresh token that is stored only as a one-way hash. Refresh tokens rotate every time they are used, and if an old one is ever replayed we treat that as theft and revoke the entire chain.
- On your device, those credentials are kept in the operating system’s secure storage, the iOS Keychain or the Android Keystore, and are marked so they are not carried into an encrypted cloud backup and cannot be restored onto a different device.
- Changing your password or resetting it signs you out everywhere and cancels any outstanding reset or verification link.
- Password reset and email verification links are single use, expire after 45 minutes, and are stored only as a hash, so the link in your inbox is the only copy that exists.
- Traffic between the app and our servers, and between our servers and the database, is encrypted in transit. Receipts and profile photos are held in private storage containers that are not reachable from the public internet. There is no shareable link to one, not even a short-lived one: when you open a receipt, the file is streamed to you through the app after we have checked that you are in that household, so a receipt cannot leak by a URL being forwarded.
- Who can read what is enforced on the server, on every request, before any data is loaded. It is not enforced by hiding things in the app.
- That enforcement is covered by an automated test suite that fails the build if any housemate-facing response is capable of carrying an owner-private figure.
- Sign-ins, password resets, invite redemptions and account changes are rate limited.
- Our application logs record which request was made and whether it failed. They deliberately never record what was in the request, any money figure, any email address, or any IP address.
What we do not claim: our database and file storage sit on major cloud platforms that encrypt stored data as a platform default, but we have not configured customer-managed encryption keys, and we do not separately encrypt individual fields. We do not offer multi-factor authentication yet. Invite codes for a housemate are short, readable codes, protected by being single use, by expiring, and by a limit on failed attempts rather than by length.
No service can promise perfect security, and we will not pretend otherwise. Keep your password to yourself and use a different one from your other accounts.
11. How long we keep things, and what deletion means
You can delete your account at any time from the You screen in the app. It asks for your password first, because it cannot be undone.
Deleting your account ends any current tenancy in Roomeo that day, signs you out on every device, and permanently removes your identity: your name is replaced with “Former housemate”, your email address is replaced with a dead address that can never receive mail, your password is destroyed, and any invitation we ever sent to your email address has that address erased from it.
Deletion is de-identification, not erasure of the household ledger. Payments, charges, bond records and signed agreements remain, because they are also the records of the people you lived with, and removing them would take someone else’s history with them.
A signed agreement is the one place your name persists after deletion. A signed document cannot be rewritten after the fact without destroying the thing that makes it evidence, so agreements keep the names that were on them when they were signed.
If you are the primary owner of a home that is still active, you will be asked to transfer ownership or remove the home before you can delete your account. Deleting one person’s account should never destroy an entire household’s records.
Kept for five years after a home is removed, following the Australian convention for keeping financial records. After that they can be purged.
Kept for 30 days. Something you deleted can survive in a backup until those backups age out.
The record that we sent you a notification is deleted 30 days after it settles. It never contains your email address or the message body.
Kept for 30 days.
A message you send through our contact form, and your address if you join our mailing list, are handled by email and kept only as long as we need them to deal with your enquiry. They are not added to any database.
12. Getting at your information, and correcting it
You can change your name, your email address and your app language yourself, in the app. You can export your own payment history for a home as a PDF or a spreadsheet from the You screen, and that export is never withheld from you for any reason, including an unpaid subscription.
For anything broader, write to getintouch@savvicorp.com.au and ask. You have the right under the Australian Privacy Principles to ask for access to the personal information we hold about you, and to ask us to correct it if it is wrong. We will respond within 30 days. We do not charge for making a request. If we refuse, we will tell you why in writing.
There is one limit worth being upfront about. We may not be able to change a figure in a shared household record on your say-so alone, because that record is also somebody else’s, and altering it would rewrite their history as well. Where that happens we will tell you, and we can note your disagreement.
13. Email from us
Roomeo notifies people by email and, if you allow it, by push notification to your phone. There is no SMS. You can turn push notifications off for individual kinds of update, or entirely, in your notification settings or in your phone’s own settings, and email is covered below.
Most of what we send is transactional: verifying your address, resetting your password, an invitation to join a home, or an agreement being offered, signed or ended. These are part of the service and you cannot currently switch them off individually, though deleting your account stops them entirely.
We do not send marketing email unless you asked for it, and anything we do send of that kind will have an unsubscribe link.
14. The Roomeo website
roomeo.savvicorp.com.au is a brochure site. It has no login and no account.
- We set no cookies of our own, and run no analytics, no tag manager and no tracking pixel. The only cookie in play is Google’s, set by the spam check described below, and it is there to tell people from bots rather than to follow you anywhere.
- Your browser’s local session storage is used for one thing only: remembering whether you switched the page to dark mode. It never leaves your browser.
- The offset calculator runs entirely in your browser. The loan amount, rate and rent you type into it are never sent to us.
- If you use the contact form or join the mailing list, we receive what you typed so we can reply or add you to the list.
- Both of those forms are protected by Google reCAPTCHA, so it loads on the home page and the contact page and on no other page. It watches how the page is used in order to judge whether you are a person, and when you press send it gives us a score. We use that score to accept or refuse the submission and we learn nothing else about you from it. Section 8 sets out what Google receives.
- If that check ever refuses a genuine message, the page shows you our email address instead. Writing to us directly always works, and nothing checks you on the way.
- Our typefaces are served from our own site rather than fetched from a font service, so visiting a page that carries no form means your browser contacts nobody but us. The spam check on the two form pages is the only third party your browser ever talks to on our site.
- Our hosting provider keeps its own standard server logs, which we do not control.
15. Children
Roomeo is for adults. Our terms of service require you to be at least 18, because using Roomeo involves entering into arrangements about money and accommodation. We do not knowingly collect personal information from anyone under 18. If you believe a child has an account, tell us and we will remove it.
16. If something goes wrong
If a data breach occurs that is likely to result in serious harm to you, we will assess it and, where the Notifiable Data Breaches scheme requires it, notify you and the Office of the Australian Information Commissioner as soon as practicable.
If you think we have mishandled your personal information, write to getintouch@savvicorp.com.au. Tell us what happened and what you would like us to do about it. We will acknowledge you within 5 business days and give you a considered answer within 30 days.
If our answer does not satisfy you, you can take the complaint to the Office of the Australian Information Commissioner at oaic.gov.au, or by phone on 1300 363 992. You do not need our permission to do that.
17. Changes to this policy
We will update this policy when what we do changes. The version number and effective date at the top of this page tell you which revision you are reading, and every revision is published here and in the app at the same time.
If a change materially affects how we handle your personal information, we will tell you in the app or by email before it takes effect, rather than quietly editing this page.
18. Contact us
Questions, requests and complaints about privacy all go to the same place, and a person reads them.
Savvi Corp Technologies, ABN 79 627 343 425