Privacy Policy
This page covers rogueon.ai, the marketing site you are reading now, and the Rogue app at app.rogueon.ai. The site collects almost nothing. The app keeps what it needs to run your account and your projects, described below.
Last updated September 18, 2026
The short version
This site does not track you. There is no analytics, no advertising pixel, no third-party script of any kind, and no cookie. We do not build a profile of you, and we have nothing to sell or share about you.
The app is different because it has accounts. It keeps your name and email, what you ask Rogue to build, and a record of how much your account uses. We do not sell any of it, we show no ads, and we share it only with the services that run the app, listed below.
What stays in your browser
One thing, and it never leaves your device: your light or dark theme choice, saved under the key rogue-themein your browser's local storage. It exists so the page does not flash the wrong colours when you come back. Clearing your browser data removes it.
What you type in the prompt box
The box on the home page runs nothing here. This site has no server-side API of its own. Your text stays in your browser until you submit it, and submitting sends it to the Rogue app at app.rogueon.ai as part of the request. Until you press send, nobody receives it.
Because the text travels as part of the address, it can appear in ordinary web server logs. Treat the prompt box the way you would treat any address bar, and do not paste passwords, keys, or personal documents into it.
What our host sees
The site is served by Vercel. Like any web host, Vercel processes the technical data your browser sends with each request, such as your IP address, the page you asked for, and your user agent. That processing is what makes serving a page possible, and it is governed by Vercel's own privacy terms.
Fonts and images
Typefaces are served from this domain, not fetched from a font network while you browse. Every image and video on the page is served from this domain too. The page's content security policy blocks connections to anywhere else, so the site cannot quietly load a third-party asset.
Your Rogue account
When you sign in to the app we store your name, your email address and when your account was created. If you sign in with Google we also store the address of your Google profile picture and whether Google confirmed your email. If you use a password, we store only a one-way hash of it. Sign-in codes we send by email are stored hashed and expire after five minutes.
Signing in with Google
We ask Google only for your basic profile and your email address (the openid, email and profile permissions). We use them to create your account and to recognise you when you come back, and for nothing else. We cannot read your Gmail, Drive, contacts or calendar. The tokens Google returns are stored encrypted. Rogue's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Staying signed in
A cookie named __Host-rogue.session_token keeps you signed in for up to 30 days. It can only be read by app.rogueon.ai and is never available to scripts on the page. For each session we record the IP address and the browser that started it, and we count sign-in attempts per IP address, so we can stop abuse. Signing out ends the session.
What you ask Rogue to build
Your prompts, the files you attach, the conversation and the pages and code Rogue produces are stored so your projects keep working and you can come back to them. Every page Rogue builds has its own public address, and anyone who has the link can open it, so do not put anything in a page that you would not show the people you send it to.
AI processing
To answer you, Rogue sends your prompt and the context it needs to AI model providers through the Vercel AI Gateway, and image requests to fal. Each request carries an opaque identifier derived from your account, never your name or email, so a provider can apply its safety rules to your usage alone. The providers process the request to return a result, under their own terms.
Usage records
For every request we record which model ran, which provider served it, how many tokens it used, what it cost us, when it happened and which project it belongs to, linked to your account. You can see your own usage in the app, under Preferences, Account. The Rogue team uses these records to understand costs, to set fair limits and to stop abuse.
Measurement in the app
The app uses Vercel Web Analytics and Speed Insights to count page views and to measure how fast pages load. They do not set cookies.
Who processes data for the app
- Vercel: hosting, file storage, measurement and the AI Gateway.
- Neon: the database that holds accounts and usage records, in the United States.
- AgentMail: sends sign-in codes by email.
- Google: only if you choose to sign in with Google.
- AI model providers reached through the Vercel AI Gateway, and fal for images.
- Boat: the isolated machines where Rogue builds your projects.
- Perplexity: web search, when you ask Rogue to research something.
- GitHub: only if you connect it to save your code to your own repositories.
Most of these services process data in the United States.
How long we keep it
Account data, projects and usage records stay while your account exists. Sessions end after 30 days without use, and sign-in codes after five minutes. The database is backed up daily and each backup is kept for 14 days, so data you ask us to delete leaves the backups within two weeks.
Links that leave
Links to our X profile and to other sites take you to services with their own privacy practices. Once you follow one, this policy no longer applies.
Children
Rogue is not directed at children under 13, and we do not knowingly create accounts for them. If you believe a child has an account, write to us and we will delete it.
Your rights
Brazilian data protection law (LGPD) and the GDPR give you rights over personal data held about you, including access, correction, portability and deletion. This site holds no personal data. For the app, write to us from the email on your account and we will answer within 15 days.
Changes
When what we collect changes, this page changes first and the date at the top moves with it.
Contact
Questions about this policy go to caio@rogueon.ai.