Privacy
What we collect and how we use it.
This page covers forms, the AI assistant, analytics, service providers, and deletion requests.
01 — Privacy notice
Data used by this site.
- 01
Who we are
This site is operated by Zaydream Media, operating as Robota, in Austin, Texas. We decide what this site collects and why, so we are the controller of that data. Privacy and deletion requests go to the address at the end of this page.
- 02
Contact by email
When website submissions are disabled, Contact and Audit open a draft in your email app. Opening the draft or copying our address does not submit a form to Robota. You choose what to include and send the email yourself.
- 03
Form submissions
When enabled, the project form collects a work email, company, process description, approximate frequency, tools involved, desired result, optional timing, and follow-up consent. The SEO audit form collects a website URL, email, optional company, and consent. Both forms also use a hidden field and form-load timestamp to screen automated submissions.
- 04
Email delivery
Form submissions, and transcripts you choose to send, are delivered by Resend, an email provider that processes them in the United States. Resend receives the fields you filled in and the address you gave us, inside the message we build from them. It receives nothing else from this site. When a production form shows success, the configured mail provider has accepted the request. That does not guarantee delivery, reading, assignment, or a reply. Rejected requests, unavailable providers, and ambiguous timeouts return an error and are not retried automatically.
- 05
AI assistant
The anonymous assistant conversation is retained for up to 24 hours. The browser sends one new message at a time; the application maintains the conversation history. For eligible messages, the application sends the new message and relevant recent conversation to the configured AI provider, which chooses a response from a limited catalog written by Robota. That provider is Google's Gemini API. We use its free tier, and on that tier Google may use what you type here to improve its products, so please do not put confidential details in this assistant. Some security-related, abusive, or unrelated messages are answered locally. Do not send passwords, credentials, secrets, or sensitive personal information. The assistant never sends a transcript to our team automatically. To request follow-up, you must review the visible transcript, choose the send option, provide an email address, and consent. Deleting the session removes the active server session and browser cookie, but it cannot cancel a provider request already in progress.
- 06
Abuse prevention
BotID checks public forms, assistant sessions and messages, and transcript requests before the application calls an AI or mail provider. Requests stop if that check is unavailable. BotID processing, retention, and deployed settings depend on the provider and deployment configuration. Public forms, assistant turns, and transcript handoffs use minute and 24-hour abuse quotas. Rate-limit checks use the IP address your request comes from. Before storage, the application converts the address into a one-way identifier; raw IP addresses are not written to application logs, events, or Redis keys. Anonymous session and idempotency records expire no later than 24 hours. IP-derived quota keys expire no later than 24 hours.
- 07
Operational logs
Operational logs record when a request happened, which route handled it, how long it took, and whether a provider returned an error. They do not include prompts, replies, form text, email addresses, or full IP addresses. Log retention follows our hosting provider's settings; ask us for the current details.
- 08
Analytics
The site uses Vercel Analytics and Speed Insights. Their provider settings, cookie behavior, and retention period depend on the deployed configuration.
- 09
Service providers
The configured AI provider processes assistant messages. Resend, in the United States, processes form submissions and transcripts you choose to send. Form content is not stored in the application session store. Provider and inbox retention, deletion, and incident response depend on the deployed services and operating procedures.
Privacy and deletion requests
Email privacy or deletion requests to hello@robota.sh. Deleting an anonymous assistant session does not remove a transcript already accepted by the mail provider. We may need to verify the requester's identity before completing a deletion. Provider and inbox deletion follow the procedures for those services.