The full policy

Privacy Policy

What Robin collects, who processes it, how long it is kept, and how to have it removed.

Last updated: September 26, 2026

1. Who we are

Robin is a product of Zamora Design LLC, a design studio based in San Francisco, California.

For questions about this policy, or about information we hold, write to privacy@zamora.design. For anything else, hello@zamora.design.

Anyone can sign up for Robin and create a workspace.

2. Who this policy covers

Studio users hold a Robin account and run calls with it. Call participants are the clients and guests who join those calls without an account, and most of what follows matters most to them.

Where a studio uses Robin on its own clients' information, that studio decides what is collected and why, and we act on its instructions. Studios needing a data processing agreement can request one at privacy@zamora.design.

3. What we collect

From a call

  • A written transcript: speaker labels, spoken text, and timestamps.
  • Annotated screen frames. When a participant marks up a shared screen, Robin captures that single frame as an image. A maximum of twelve are retained per call, and individual frames are attached to the tickets they relate to.
  • Participant details where supplied on joining: name, business name, and email address.
  • Call metadata: duration, date, an internal call number, and the participant's rating of the call if given.
  • Tickets and comments created during or after the call.

We do not store call audio. Audio is processed live and is never written to disk or object storage.

From a voice note

On a review, a client can record a voice note of up to two minutes. The audio is sent to Deepgram to be written down, and Robin never saves it. Only the written transcript is kept, like a typed comment: the studio sees it on the review, and it may become tickets. Voice notes are available on Pro and Studio workspaces.

From studio accounts

Account and authentication details are handled by Clerk, including name, email address, and organization membership. We store preferences, notification settings, and usage counts against the account.

If a studio buys a paid plan, payment is handled by Stripe. Card details are entered on Stripe's own page and never reach Robin. We keep a Stripe customer reference, the plan, the number of seats, and billing dates such as when a trial ends.

From the website

Our marketing pages use Vercel Web Analytics in its default configuration. It sets no cookies. Visitors are identified by a hash derived from the incoming request, which is discarded after twenty-four hours, and no IP address is stored. It records the page viewed, the referrer, approximate location at city level, browser, operating system, and device type, and reports them in aggregate only.

People who write to us through the contact form give us their email address and whatever they choose to tell us about their studio.

4. How we use it

To run the call and produce its output: the transcript, the tickets, and the summary email sent to participants afterwards.

To operate and support the product, including investigating faults.

To reply to people who asked to be contacted, such as through the contact form.

To understand whether Robin decodes client feedback correctly, by comparing what Robin filed against what a person subsequently changed. This uses ticket content, not audio and not personal details.

We do not sell personal information. We do not use call content for advertising.

5. Service providers

Robin depends on the following providers, each receiving only what its function requires. All are hosted in the United States.

ProviderFunctionReceives
LiveKitReal-time audio and screen-share transportLive audio and video during the call
DeepgramSpeech to text, and text to speech for Robin's voiceLive call audio, in both directions, and the audio of a voice note
Google (Gemini API)Understanding what was said and deciding what to fileThe text of the call as transcribed, and a picture of your screen on the turns where you ask Robin to look. On a review, the text of comments and voice note transcripts
OpenAI (gpt-5.4-mini, reached through LiveKit Inference)Backup model, used only on a turn where Gemini fails or is too slow to answerFor that turn, the same as Google: the text of the call as transcribed, and a picture of your screen if you asked Robin to look
SupabaseDatabase and file storage, hosted in Northern Virginia (US East)Transcripts, images, tickets, account records
ClerkAuthenticationStudio user identity
StripePayments and billing, for paid plans onlyBilling name, email and address, tax ID if given, card details, and subscription and invoice history. Card details go straight to Stripe; Robin never sees or stores the card number
ResendEmail: summaries, notifications, and product updatesRecipient addresses and summary content
SlackOptional notificationsCall notifications, only where a studio connects it
VercelApplication hosting and analyticsWeb requests
RailwayCall worker hostingCall processing

Use of call content by Deepgram

Deepgram turns the call audio into text and Robin's replies back into speech, so it handles the voice on both sides of every call. It also writes down voice notes left on a review.

Deepgram's only training route is a voluntary programme with a per-request opt-out, which is not on by default. Robin sends the opt-out on every request. Deepgram states that opted-out data is kept only as long as processing needs, and that it does not sell or redistribute customer data. That is their published policy rather than an audited finding.

Use of call content by Google

Robin uses Google's Gemini API. Content sent to it may be used to develop Google's products and services, and human reviewers may read it.

What Google receives: the text of the call as transcribed, and a picture of your screen on the turns where you ask Robin to look. Not the call audio, and nothing on any other turn. On a review, it receives the text of each comment and voice note transcript, to turn it into tickets. Never the audio of a voice note.

The screens you mark up are separate. They are attached to the ticket they belong to, go to the studio you are working with, and are not sent to any AI model.

Use of call content by OpenAI

When Gemini fails or is too slow on a turn, a backup model from OpenAI answers that turn instead, so the call does not go silent. That turn's content then goes to OpenAI rather than Google. Robin reaches OpenAI through LiveKit, the service that carries the call, not through an OpenAI account of our own. We have not independently confirmed how long OpenAI keeps that content or whether it may be used for training.

6. How long we keep it

Call records are retained until the studio that owns them deletes them. There is no automatic expiry.

When a studio deletes a call or a ticket, it is immediately hidden from every surface, including public-facing ones such as the rating page and the transcript export, and is then permanently destroyed by a scheduled purge fourteen days later.

Account records are retained for the life of the account. Contact requests, including waitlist signups made before Robin opened, are retained until we act on them or you ask us to remove them.

7. Where data is held and transferred

Robin's infrastructure is hosted in the United States, and the database is in Northern Virginia (US East). If you are located outside the United States, including in the European Economic Area or the United Kingdom, information about you is transferred to and processed in the United States. Studios operating under EU or UK data protection law that require a transfer mechanism or a data processing agreement should write to privacy@zamora.design before running a call.

8. Access and separation

Each studio's calls, tickets and transcripts are separated by account, enforced on the server. One studio cannot see another's.

The screens you mark up are held in private file storage rather than in the database rows, and are never publicly addressable. A link to one is issued only to someone already entitled to see it, and expires within minutes.

Administrators at Zamora Design can access records for support and troubleshooting.

9. Your rights

Anyone whose information appears in a Robin call may ask us for a copy of it, ask us to correct it, or ask us to delete it. Write to privacy@zamora.design and we will respond.

Where a studio controls the record, we will act on your request and inform that studio, or refer you to them and tell you that we have done so.

Depending on where you live, you may have further rights, including in California under the CCPA and in the European Economic Area and United Kingdom under the GDPR. Those rights can include access, correction, deletion, portability, objection, and the right to complain to a supervisory authority. Write to us and we will honour them.

10. Security

Access to Robin requires authentication, and two-factor authentication is required on Robin accounts. Records are separated by account and access is enforced server-side.

We hold no security certification. Robin has not been through a SOC 2 or ISO audit or an independent penetration test. We would rather say so than imply otherwise.

11. Consent on calls

Participants see a notice before joining, stating that the session is transcribed by Robin, an AI project manager, and that a summary follows. Joining indicates agreement to it and to this policy. Anyone who does not agree should not join, and should say so to the studio.

12. Children

Robin is a business product and is not directed at anyone under 18.

13. Changes

We will post changes here and update the date at the top, and we will email account holders when anything material changes.