This document was written in Bahasa Malaysia, which is the official and binding version. The Bahasa Malaysia version is the controlling version in the event of any conflict of interpretation with a translation, including this English one.
1. What we collect
Rojak collects the data required to operate the Service, plus basic usage data used to improve this site.
1.0 Third-party tools on this site
We use three third-party tools on our public pages:
Google Analytics, anonymous visit statistics: pages viewed, device type and country.
Microsoft Clarity, anonymous session recordings (mouse movement, scrolling, taps) so we can see where users get stuck. The images and videos you upload, and the results generated, are masked out of these recordings and are not sent to Microsoft.
TikTok Pixel, which measures the effectiveness of our advertising.
All three of these tools store cookies. You can block them using your browser settings or any ad blocker, and the Service will continue to work normally.
1.1 Account data
Email address, used as your account identifier and for transactional email (login links, credit pack receipts).
Password, stored as a salted scrypt hash. We never see your plaintext password.
IP address at registration, used to prevent abuse of the free credit grant. Stored in plaintext alongside your account record.
Credit balance and generation count, used to meter the Service.
1.2 Generation data
Uploaded character images, treated as biometric data (see Terms, section 5). Sent to fal.ai for processing. The source upload is deleted from our blob storage once the generation completes successfully.
Uploaded reference videos, sent to fal.ai for processing. The source upload is deleted from our blob storage once the generation completes successfully.
Generated output videos, stored in Vercel Blob (at publicly accessible URLs) in order to deliver them to you. You can delete your generations from the Studio interface.
Generation metadata, including timestamps, the fal.ai request ID and the credit cost. Stored in Vercel KV.
1.3 Payment data
Credit pack purchases are processed by Stripe. Stripe receives your card details directly, encrypted on their servers. We only see the Stripe customer ID, the pack purchased, the amount, and the verified email associated with the payment. We do not store card numbers.
1.4 Push notification data
If you enable push notifications, your browser gives us a push subscription token (a cryptographic endpoint, not personal identification). We store this against your account so we can tell you when a generation finishes. You can disable push notifications from your browser settings at any time, which invalidates that token.
1.5 Customer support data
If you type into the "Adik Rojak" support chat on this site, or contact us through our Telegram bot:
Your messages and the bot's replies, stored so our team can read the conversation, reply to you, and fix answers that were wrong. Your messages are sent to Google (Gemini) to generate a reply.
Your account email address, recorded alongside the conversation if you are logged in, so we know whose conversation it is and can reply to you. If you are not logged in, the conversation is stored anonymously.
Do not type card numbers, passwords or identity card numbers into that chat. We do not need them and the chat is not the place for that information.
1.6 Passport photo tool (/gambar-passport)
The passport photo cropper runs entirely inside your browser. Your photo is not sent anywhere to be cropped, resized or laid out on a 4R sheet. Only two things send your photo off your device, and both begin with an action you take yourself:
White background removal (RM9.90), your source photo is sent to fal.ai to have its background removed, and the result comes back to your browser. We do not store that photo.
“Email it to me”, your finished photo is sent as an attachment through Resend, our email provider. We do not store that photo; we keep only your email address and a timestamp, so we can rate-limit abuse and know how many people use this feature.
2. How long we keep your data
Account records, until you delete the account.
Source uploads (character images, reference videos), deleted once the generation completes (usually within 2 minutes).
Generated output videos, kept until you delete them, or until 90 days pass with no account activity.
Stripe payment records, kept for as long as Malaysian tax law requires records to be retained (currently 7 years).
Email addresses from the passport photo tool, kept until you ask us to delete them. Photos sent by email are not stored at all.
Server logs (IP, request URL), kept at Vercel for up to 30 days, then deleted automatically.
Support chat conversations, kept for up to 180 days, then deleted automatically.
3. Third-party processors
Rojak relies on the following processors. By using the Service, you consent to your data being shared with them for the stated purposes.
fal.ai (United States), AI motion sync generation. Uploaded images and videos are sent here for processing. Privacy.
Stripe (United States, with a Malaysian entity), payment processing. Privacy.
Resend (United States), transactional email (login links, receipts) and delivery of the passport photo when you ask us to email it to you. Privacy.
Cloudflare (United States), DNS and edge protection for rojak.app. Privacy.
Google (United States), Google Analytics: anonymous visit statistics on public pages. Privacy.
Google (United States), Gemini: generates support chat replies. The messages you type into the chat are sent here. Privacy.
Microsoft (United States), Clarity: anonymous session recordings. Your images and videos are masked out of the recordings and are not sent here. Privacy.
TikTok (Singapore / United States), TikTok Pixel: advertising measurement. Privacy.
4. Your rights under the PDPA (Malaysia)
Under Malaysia's Personal Data Protection Act 2010, you have the right to:
Access the personal data we hold about you, by emailing hello@rojak.app.
Correct inaccurate data, by updating your account or emailing us.
Delete all of your data using the "Delete account" button on the Account page. This removes your user record, generation history, blob output, IP record and push subscription token.
Withdraw consent for processing, which means closing your account.
Object to direct marketing, although we do not currently send direct marketing email.
5. Security
All connections to rojak.app use HTTPS. Passwords are stored as scrypt hashes with a per-user salt. Session cookies are HMAC-signed, HttpOnly, Secure and SameSite=Lax. Generated video URLs are unguessable but publicly accessible (blob identifiers of 30+ characters). Do not share a generation URL you want to keep private.
6. Cookies
We set one functional cookie, ms_session, which is the HMAC-signed login session. It is essential for the Service to function. We do not use tracking or advertising cookies of our own, and we do not embed third-party scripts that set cookies beyond the tools named in section 1.0.
7. Children
Rojak is for users aged 18 and over. We do not knowingly collect data from anyone under 18. If we find an account belonging to a child, the account and all its data will be deleted.
8. International transfers
Most of our processors are based in the United States (Vercel, fal.ai, Stripe, Resend, Cloudflare). When you use Rojak from outside the United States, your data is transferred to and processed in the United States. By using the Service, you consent to that transfer.
9. Changes to this Policy
Material changes will be announced by email. The "Last updated" date at the top of this page reflects the most recent revision.
10. Contact us
For privacy questions, complaints or data subject requests: hello@rojak.app
Operated by the Rojak Studio team (Malaysia). Contact: hello@rojak.app.