Back to Home

Privacy Policy

Last updated: 03.11.26

1. Introduction

Rebirth is operated from England. This Privacy Policy explains how Rebirth ("we", "us", or "the Service") collects, uses, and protects your personal information when you use our AI-powered Roblox game development platform. We are the data controller for the personal data we process through the Service.

2. Information We Collect

Account Information

When you create an account, we collect:

  • Email address - from your Google account for authentication
  • Name - your display name from Google
  • Profile picture - your avatar URL from Google

Roblox Account Information (Optional)

If you choose to connect your Roblox account, we collect:

  • Roblox User ID - your unique Roblox identifier
  • Roblox Username - your Roblox display name

Subscription and Payment Information

For paid features, we store:

  • Subscription status - your current plan (free, pro, etc.)
  • Subscription period - start and end dates of your billing cycle
  • Stripe identifiers - customer and subscription IDs for payment processing

Note: We do not store your credit card details. All payment information is securely handled by Stripe, our payment processor.

Usage Information

We track:

  • Credit balance - your available credits for AI features
  • Credit transactions - history of credit purchases and usage

AI Prompts and Conversation Data

When you use AI features, we collect and process:

  • Your prompts and messages - text you send to the AI assistant
  • AI responses - generated code and content from the AI
  • Conversation history - we store your chat history to maintain context across sessions

3. How We Use Your Information

We use your information to:

  • Provide and maintain the Service
  • Authenticate your identity and manage your account
  • Process payments and manage subscriptions
  • Connect the Roblox Studio plugin to your account
  • Track credit usage for AI features
  • Communicate with you about the Service
  • Improve and develop new features

4. Data Sharing

We share your information only with:

  • Stripe - for payment processing
  • Supabase - our database and authentication provider
  • AI service providers - to process your AI requests. We send your prompts, messages, studio context, and images to these providers to generate responses. These providers may process and temporarily store your data according to their own privacy policies.

Important: We store your conversation history securely in Supabase, our enterprise-grade database provider, for service functionality and context continuity. Supabase implements industry-standard security measures including encryption at rest and in transit, row-level security, and regular security audits. Your prompts and AI responses are stored securely by us, but are also transmitted to and processed by third-party AI service providers. We do not use your prompts to train AI models. However, these third-party providers may use your data for training purposes according to their own privacy policies, which we do not control.

We do not sell your personal information to third parties.

5. International Data Transfers

Your data may be transferred to and processed in countries outside the UK, including the United States, where our service providers (Supabase, Stripe, and AI service providers) are based. These transfers are protected by appropriate safeguards as required by UK data protection law, including standard contractual clauses and adequacy decisions where applicable. We maintain data processing agreements with our key service providers to ensure your data is handled in accordance with applicable data protection standards.

6. Data Security

We implement appropriate security measures to protect your information, including:

  • Encrypted data transmission (HTTPS)
  • Secure authentication through Google OAuth
  • Enterprise-grade database security via Supabase with encryption at rest and in transit
  • Row-level security on database tables
  • Regular security updates and audits

7. Data Retention

We retain your data for as long as your account is active. If you delete your account, we will delete your personal information within 30 days, except where we are required to retain it for legal or legitimate business purposes.

8. Legal Basis for Processing (UK GDPR)

We process your personal data under the following legal bases:

  • Contract performance - processing necessary to provide the Service you signed up for (account management, AI features, credit system)
  • Legitimate interest - we rely on legitimate interest for: (i) improving the Service based on usage patterns, (ii) monitoring for and preventing fraud, abuse, and security threats, and (iii) ensuring the stability and performance of the Service. We have assessed that these interests do not override your rights and freedoms
  • Legal obligation - where we are required to retain data by law (e.g., financial records)
  • Consent - where you have given explicit consent (e.g., connecting your Roblox account)

9. Your Rights Under UK GDPR

Under the UK General Data Protection Regulation, you have the following rights:

  • Right of access - request a copy of the personal data we hold about you
  • Right to rectification - request correction of inaccurate or incomplete data
  • Right to erasure - request deletion of your personal data
  • Right to restrict processing - request that we limit how we use your data
  • Right to data portability - request your data in a structured, machine-readable format
  • Right to object - object to processing based on legitimate interest
  • Right to withdraw consent - where processing is based on consent, you may withdraw it at any time

To exercise any of these rights, contact us at support@userebirth.com. We will respond within 30 days. You also have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk.

10. Cookies and Tracking

We use essential cookies for authentication and session management. We do not use tracking cookies for advertising purposes.

11. Children's Privacy

The Service is intended for users aged 13 and over. We do not knowingly collect personal information from children under 13. If you are aged 13 to 17, you should review these terms with a parent or guardian. If you believe we have collected information from a child under 13, please contact us.

12. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of any material changes by posting the new policy on this page with an updated date.

13. Contact Us

If you have questions about this Privacy Policy, or if you wish to exercise your rights under GDPR or other applicable data protection laws (including the right to access, correct, or delete your data), please contact us:

Email: support@userebirth.com

We are committed to resolving any privacy concerns you may have. We aim to respond to all data subject requests within 30 days.