rateblox

Privacy Policy

Last updated: September 28, 2026

1. Data controller

This policy explains how Individual Entrepreneur Novitski Maksim Andrei (DUNS 933896898, 27 N. Tigranyan St., Arabkir, Yerevan, Armenia) processes personal data when you use Rateblox at rateblox.com. We act as the data controller. Contact us about privacy at ceo@mnapps.tech.

2. What we collect

  • Account data: email address and a securely hashed password (managed by our authentication provider).
  • Content you create: prompts, chat history, saved memory notes and the scripts and commands the Service generates for you.
  • Roblox Studio data: when you connect the plugin, the parts of your open place needed to do the job (selected objects, hierarchy, plugin logs).
  • Roblox Open Cloud keys: if you connect one, it is stored encrypted (AES-256-GCM) and used only for the actions you request.
  • Payment data: plan, payment status and billing history. Card details are handled by our payment provider and never reach our servers.
  • Technical data: IP address, browser and device information, and logs needed for security and troubleshooting.

3. Why we use it

  • To provide the Service — generate content and apply it to your place (performance of our contract with you).
  • To manage your account, credits and subscription, and to process payments (contract).
  • To keep the Service secure, prevent abuse and fraud, and fix errors (legitimate interests).
  • To answer your requests and send service emails such as receipts and important changes (contract).
  • To meet accounting, tax and other legal obligations (legal obligation).

We do not sell your personal data and do not use it for third-party advertising.

4. Who we share it with

We use trusted providers that process data on our behalf:

  • Supabase — database and authentication.
  • Cloudflare — hosting, content delivery and security.
  • Kie.ai and the AI model providers it routes to — to process your prompts and generate output.
  • Roblox Corporation — when you connect Roblox Studio or the Open Cloud API.
  • Our payment provider — to process payments.

Some providers are located outside Armenia. Where data is transferred internationally we rely on appropriate safeguards such as standard contractual clauses. We may also disclose data when required by law.

5. Cookies

We use only strictly necessary cookies to keep you signed in, and browser storage for small preferences. We do not use advertising or cross-site tracking cookies.

6. How long we keep it

We keep your data while your account is active. When you delete your account we delete or anonymise your personal data within 30 days, except records we must keep by law (for example, payment records for tax purposes).

7. Your rights

Depending on where you live, you may have the right to access, correct, delete or export your data, to restrict or object to processing, and to withdraw consent. To use these rights, email us from your account address — we reply within 30 days. You can also complain to your local data protection authority (in Armenia, the Personal Data Protection Agency).

8. Security

We use encryption in transit, encrypted storage for secrets, access controls and row-level security in our database. No system is perfectly secure, but we work to protect your data and will notify you of breaches as required by law.

9. Children

The Service is not intended for children under 13, and we do not knowingly collect their data. Users under 16 may use the Service only with parental consent. If you believe a child has given us personal data, contact us and we will delete it.

10. Changes

We will post updates on this page and notify you by email about material changes. See also our Terms of Service.

11. Contact

Individual Entrepreneur Novitski Maksim Andrei

DUNS: 933896898

Address: 27 N. Tigranyan St., Arabkir, Yerevan, Armenia

Email: ceo@mnapps.tech

Phone: +374 77 119403