Privacy policy

Last updated 20 August 2026. This policy describes the hosted service at openroom.app. Self-hosted deployments are operated by whoever runs them.

Who this covers

OpenRoom is used by tutors (hosts) who sign in, and by participants who join a live session without an account. A tutor may also issue a learner a link to that learner’s own records. That link is not an account.

What we collect

Host accounts

When you sign in with Google we store your Google subject id, email, and display name, plus the decks, folders, spaces, memberships, presentation contexts, and compact session notes you create. Personal API tokens are stored as SHA-256 hashes; the raw token is shown once.

Live sessions

Each live session holds the session agenda, a server-generated participant id, a join timestamp, and — depending on identity mode — a session-local handle or the display name the tutor wrote on the context. It also holds the current ballot per participant per question and the recomputed aggregate. Participants are never asked for a name, email, or password.

Learner access links

A tutor can mint a link that reaches one context’s learner-visible records. We store a SHA-256 of the token, a visible prefix, and creation, expiry, and revocation timestamps. The raw token is shown once and cannot be read back.

What we do not collect

How we use the data

Host data is used to provide the product: save decks, start sessions, share a space, and recover recent host controls. Live session data is used only to run that session and to show aggregate results. Learner links are used only to show that context’s learner-visible records.

When an MCP client or ChatGPT plugin connects, OpenRoom receives an OAuth access token or personal API token for the signed-in host and uses it to run the same tutoring actions the browser can run. OpenRoom does not proxy or bill model tokens.

How long we keep it

Sharing

We do not sell personal data. Hosts share a space with people they invite. A leaked learner link reaches exactly one context. A leaked roster invite reaches exactly one session. Google receives the OAuth sign-in for hosts. Stock photographs stay hosted by Pixabay and are embedded by URL.

Contact

Questions about this policy: use the documentation at openroom.app/docs or the support contact on the OpenAI plugin listing.