Privacy Policy
Last updated: August 2026
1. Who We Are
URoasted (“we”, “our”, or “the Service”) is an anonymous-first roast generator that lets you create and share playful insults with friends, on the web and via our mobile app. This Privacy Policy explains what information we collect, how we use it, who we share it with, and your rights. “Anonymous-first” means you never have to create an account to use URoasted — signing in is optional and only unlocks extra features like a public profile, following, and email notifications.
2. Information We Collect
Anonymous device ID
The first time you visit, we set a random identifier in a cookie (device_id). It is not linked to your real identity on its own, is stored for up to 2 years, and is the key we use to attribute the roasts you create, your follows/blocks/reactions, and to apply rate limits and spam prevention. Nearly everything below is organized around this ID rather than a traditional account.
Account information (only if you sign in)
Signing in is optional. If you choose to, you can sign in with Google or with a one-time code sent to your email, both handled by our authentication provider, Supabase. We do not store your email address in our own database — it lives only in Supabase’s authentication system and is looked up from there when we need it (for example, to send you a notification email). Signing in links your existing anonymous activity on that device to your account, and lets you sign in on more than one device under the same account.
Content you create
- Roast text: receiver and sender names, roast lines, button text, titles, and tags.
- Photos and voice notes you attach to a roast, and profile avatars — stored with our storage provider, Cloudflare R2.
- Profile details, if you set them: display name, username, and bio.
- Comments you post on roasts, including any @mentions.
Content others create about you
If someone sends you a roast with an interactive widget (a quiz, rating, calendar pick, guessing game, etc.), your response to it is emailed directly to the person who created the roast so they can see it. We don’t use these responses for anything else.
Usage & analytics
We record when a roast is viewed (once per device per roast per hour) so creators can see basic stats about their own roasts — total views, a daily views chart, and their best-performing roasts. This view data is tied to the anonymous device ID, not shared with other users, and only ever shown in aggregate to the roast’s own creator. We also use Vercel Analytics for basic, privacy-respecting site traffic metrics, and Sentry for error monitoring (see Section 6).
Automatically collected
Our hosting and infrastructure providers (Vercel, Cloudflare) automatically log standard request information such as IP address, as most web services do, for security and abuse prevention. Our own application code does not read, store, or log your IP address in our database.
3. How We Use Information
- To create, store, and display the roasts and profiles you make.
- To power features you opt into: following, comments, notifications, and your personal analytics dashboard.
- To moderate content for harmful material (see Section 4).
- To prevent spam and abuse via rate limiting and bot checks.
- To send you email notifications you haven’t opted out of (Section 5).
- To improve and maintain the Service.
4. Content & Image Moderation
We run automated checks on content before it’s published:
- Text(roast lines, comments, titles, and similar fields) is screened by OpenAI’s Moderation API for things like hate speech, sexual content involving minors, threats, and self-harm content.
- Voice notesare transcribed via OpenAI’s Whisper so the spoken content can go through the same text moderation check as above.
- Photos are screened by an on-device/server-side image classifier (based on the open-source nsfwjs model) for explicit content. Images that are flagged are deleted immediately and never published.
If a check fails to run for any reason, we block the content rather than risk letting something harmful through. We also let users report content directly (roasts, comments, or profiles) — see the Terms of Service for how reports are reviewed.
5. Email Notifications
If you’re signed in, we can send you an email when someone follows you, comments on your roast, mentions you, tags you as a roast’s receiver, or when one of your roasts hits a view milestone. Some activity (someone flaming your roast, a follower watching it, or a receiver opening it) only shows up as an in-app notification, never an email. Every notification email includes a one-click unsubscribe link, and you can also turn email notifications off entirely from your profile settings at any time.
6. Third-Party Services
We use the following providers to run the Service, each governed by their own privacy policy:
- Supabase — our database and authentication infrastructure.
- Cloudflare R2 — storage for uploaded photos, voice notes, and avatars.
- Cloudflare Turnstile — a bot/spam check run when you create a roast; it does not track you across other sites.
- Google — powers “Sign in with Google”, if you choose to use it.
- OpenAI — automated text moderation and voice-note transcription (moderation only; we do not use your content to train anyone’s models).
- Anthropic and OpenAI — power our optional AI “Magic Roast” writing assistant, if you use it (limited to 5 requests per hour per device).
- GIPHY — powers in-app GIF search; your search terms are sent to GIPHY to fetch results.
- Resend — sends the notification emails described in Section 5.
- Sentry — error monitoring, so we can detect and fix bugs. We do not configure Sentry to intentionally collect your IP address or other personal information.
- Vercel — hosting and basic site analytics.
- Inngest — background job processing (e.g. queuing notification emails).
- Google Fonts — typeface delivery.
7. Cookies
We use a small number of cookies: the device_idcookie described in Section 2, and, if you sign in, session cookies managed by Supabase so you stay signed in between visits. We don’t use advertising or cross-site tracking cookies.
8. Public vs Unlisted vs Private Roasts
When you create a roast you choose its visibility. Public roasts appear in the Wall of Shame feed and are indexable by search engines. Unlisted roasts are only accessible by the share link. Private roasts (when available) require sign-in to access.
9. Age Requirement
URoasted is intended for users aged 13 and older. We do not knowingly collect information from children under 13, and we do not currently ask for or verify age at sign-up. If you believe a child under 13 has used the Service and provided us information, please contact us and we will delete it.
10. Data Retention
Roasts, comments, and profile data are retained until you delete them, your account is deleted, or we remove them for policy violations. A photo flagged by our moderation check is deleted immediately and never published. Rate-limit and abuse- report records are kept only as long as needed for spam prevention and moderation review.
11. Your Rights & Choices
- You can delete individual roasts and comments yourself, at any time, from within the app.
- You can turn off email notifications from your profile settings, or via the unsubscribe link in any notification email.
- You can block other users, which also removes any follow relationship between you.
- You can request that we delete your data by emailing us (Section 14). Include your device ID, username, and/or the roast links you want removed.
12. Children’s Privacy
URoasted is not directed at children under 13, and we ask that anyone under that age not use the Service. See Section 9 for how we handle this.
13. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify users of material changes by posting the new policy on this page with an updated date.
14. Contact
Questions about this policy, or want your data deleted? Email contact@uroasted.com.