Privacy policy
What data Routines collects, why, and what never leaves your machine.
Draft — not legal advice
What we collect
Account data — name, email, and the profile details you choose to provide during onboarding.
Commerce data — orders, subscriptions, licences and payment references. Card details are handled by the payment processor and never reach Routines servers.
Execution telemetry — which tool ran, in which host application and version, how long it took, and whether it succeeded. Element counts where a tool reports them.
Web analytics — pages viewed, searches performed, and referring source.
What we never collect
Model content. The Hub does not transmit geometry, parameter values, drawing data, or file contents to Routines or to tool developers. Error messages are truncated and scrubbed on the machine before they are sent.
What developers see
Aggregate figures for their own tools: active subscribers, execution counts, success rates, host versions in use. Developers do not receive customer contact details, model data, or individual usage timelines.
Marketing cookies
Advertising and analytics pixels load only after you accept marketing cookies. Declining leaves the site fully functional; first-party analytics continues without cross-site identifiers.
Where the data is, and who else touches it
Routines runs on managed infrastructure rather than its own machines, so the honest answer to "where is my data" names other companies. These are the sub-processors, what each of them holds, and the region it holds it in. An engineering practice's own client contracts usually force this question, and a policy that does not answer it is a policy their procurement team sends back.
| Sub-processor | What it processes | Region | | --- | --- | --- | | Supabase | The database: accounts, orders, licences, telemetry, support threads | EU (Frankfurt) | | Cloudflare R2 | Tool packages and the source archives developers upload | EU | | Paymob | Card payments. Card numbers never reach Routines; we hold a reference | Egypt | | Resend | Transactional email — sign-in links, receipts, decisions | EU |
Execution telemetry does not leave that set. It is written from the Hub straight to the database and is not forwarded to an analytics vendor.
A data processing agreement is available on request and takes about a day. Ask through support, or through the address on the terms page.
Social media accounts we connect
Routines publishes its own marketing posts through its own accounts on Facebook, Instagram, Threads, TikTok, LinkedIn, YouTube and Reddit. Only Routines staff connect accounts, and only accounts that belong to Routines. No customer or developer account is ever connected, and nothing a customer does on the marketplace is posted anywhere.
YouTube. Routines uses the YouTube API Services to upload videos to the Routines channel and to read that channel's public statistics (subscribers, views, likes and comments on its own videos). By using the Routines YouTube features you agree to the YouTube Terms of Service, and Google's handling of the data is covered by the Google Privacy Policy. Access can be revoked at any time from the Google security settings page.
TikTok. Routines uses TikTok's Login Kit and Content Posting API to post videos and photos to the Routines TikTok account and to read that account's profile and the statistics of its own posts, under TikTok's Terms of Service and Privacy Policy. Access can be revoked from TikTok under Settings → Security → Manage app permissions.
What is stored. The sign-in tokens each platform issues (kept on the server only, never sent to a browser), the account's name, handle and picture, the posts Routines published and their public numbers. Nothing is shared with anyone outside Routines or sold. Disconnecting an account in Routines deletes its tokens and account details straight away. Records of published posts and their numbers are deleted on request through support.
How long we keep it
Execution telemetry and web analytics are kept for 180 days and then deleted. Source archives a developer uploaded and did not submit are purged after 90 days; submitted ones are kept while the version they belong to is published, because a customer running a tool has a right to know what was reviewed. Orders, invoices and payout records are kept for seven years, which is what accounting rules require and is the one category closing an account does not remove.
Your rights
You can export your account data or close your account from Settings. Closing an account revokes licences, cancels active subscriptions and removes your public profile. We retain only anonymized transaction and fraud-prevention records where accounting, legal or security obligations require it. Company owners and developers with live listings must transfer ownership or contact support before closure.