Trust Center
SECURITY, PRIVACY AND DISCLOSURE
ROLearn processes public game metrics, workspace account data and, for SDK customers, pseudonymous player telemetry. This page states what we actually do with it today, in plain terms, with a link to the binding document behind each commitment. We hold no third-party security certification, and we say so rather than implying one. Everything below is verifiable against our Privacy Policy, Data Processing Agreement and sub-processor list.
Security practices
These are the controls described in section 6 of our Privacy Policy. The full cookie inventory is in the Cookie Policy.
- Encryption in transit
- All traffic between your device and our servers is encrypted over HTTPS using TLS 1.2 or 1.3. Database connections are encrypted as well.
- Credential handling
- Account passwords are hashed with bcrypt. We never store or transmit a password in a recoverable form.
- Session security
- Web sessions are held in HttpOnly cookies (rolearn_access, rolearn_refresh) that JavaScript cannot read, alongside a readable rolearn_csrf cookie used only for double-submit cross-site-request-forgery protection. Mobile tokens live in the device secure keystore.
- Short-lived signed tokens
- Authentication uses short-lived, cryptographically signed JSON Web Tokens rather than long-lived shared secrets.
- Customer data exports
- SDK data exports are encrypted before delivery to the destination storage you configure.
- Data minimisation in the SDK
- The telemetry SDK rejects direct identifiers and does not request precise location, so player data reaches us pseudonymous by construction.
Data protection and your rights
Processor terms. For player telemetry sent through the SDK we act as a processor on the customer's documented instructions. The terms are in our Data Processing Agreement, with the enterprise-specific commitments in Enterprise Terms.
Retention. Usage and activity data is purged after 30 days. SDK player telemetry is retained for a default of 30 days and is configurable per customer. Public game metrics keep hourly resolution for about 3 days, then roll up into daily summaries, with per-platform snapshots kept around 90 days. Account data is kept for the life of the account. Full table in Privacy Policy section 7.
Deletion is self-serve. You can delete your own account and its associated data from your profile settings at any time, without opening a ticket. Deletion requests sent by email are actioned within 30 days. Individual SDK players can be erased on request through the customer's own erasure endpoint.
Export. SDK customers can have event data exported to storage they control, encrypted before delivery.
Rights. Under the EU and UK GDPR, the California CCPA and CPRA, and Vietnam's PDPD you may access, correct, delete, port and restrict processing of your personal data, object to processing based on legitimate interest, and withdraw consent. We respond within 30 days. We do not sell or share personal information as those terms are defined under the CCPA and CPRA, and we do not use it for cross-context behavioural advertising. See Privacy Policy section 8.
Rights requests and privacy questions go to [email protected]. The controller of record is HUBERT.STUDIO LLC, 9B Phung Khac Khoan, Sai Gon ward, Ho Chi Minh City, Vietnam.
Sub-processors
We publish every third party that processes data on our behalf. The list currently names 19 sub-processors, of which 19 may process personal data, each with its purpose, the data categories involved and its country of processing. Enterprise and SDK customers can subscribe to advance notice of additions under the DPA.
Responsible disclosure
If you believe you have found a security issue in ROLearn, report it to [email protected]. Include enough detail to reproduce the issue. Please give us a reasonable window to remediate before disclosing publicly, and do not access, modify or delete data belonging to anyone other than yourself while testing.
Our machine-readable contact is published per RFC 9116 at /.well-known/security.txt.
We do not currently run a paid bug bounty. We will acknowledge receipt and keep you informed of the fix.
Certifications
ROLearn does not hold a SOC 2, ISO 27001, HIPAA or PCI attestation, and we do not claim alignment with one as a substitute. If your procurement process needs a specific control answered, write to [email protected] and we will answer it directly rather than point at a badge.