Privacy Policy

Last updated: 29 August 2026

This document was written in Bahasa Malaysia, which is the official and binding version. The Bahasa Malaysia version is the controlling version in the event of any conflict of interpretation with a translation, including this English one.

1. What we collect

Rojak collects the data required to operate the Service, plus basic usage data used to improve this site.

1.0 Third-party tools on this site

We use three third-party tools on our public pages:

All three of these tools store cookies. You can block them using your browser settings or any ad blocker, and the Service will continue to work normally.

1.1 Account data

1.2 Generation data

1.3 Payment data

Credit pack purchases are processed by Stripe. Stripe receives your card details directly, encrypted on their servers. We only see the Stripe customer ID, the pack purchased, the amount, and the verified email associated with the payment. We do not store card numbers.

1.4 Push notification data

If you enable push notifications, your browser gives us a push subscription token (a cryptographic endpoint, not personal identification). We store this against your account so we can tell you when a generation finishes. You can disable push notifications from your browser settings at any time, which invalidates that token.

1.5 Customer support data

If you type into the "Adik Rojak" support chat on this site, or contact us through our Telegram bot:

1.6 Passport photo tool (/gambar-passport)

The passport photo cropper runs entirely inside your browser. Your photo is not sent anywhere to be cropped, resized or laid out on a 4R sheet. Only two things send your photo off your device, and both begin with an action you take yourself:

2. How long we keep your data

3. Third-party processors

Rojak relies on the following processors. By using the Service, you consent to your data being shared with them for the stated purposes.

4. Your rights under the PDPA (Malaysia)

Under Malaysia's Personal Data Protection Act 2010, you have the right to:

5. Security

All connections to rojak.app use HTTPS. Passwords are stored as scrypt hashes with a per-user salt. Session cookies are HMAC-signed, HttpOnly, Secure and SameSite=Lax. Generated video URLs are unguessable but publicly accessible (blob identifiers of 30+ characters). Do not share a generation URL you want to keep private.

6. Cookies

We set one functional cookie, ms_session, which is the HMAC-signed login session. It is essential for the Service to function. We do not use tracking or advertising cookies of our own, and we do not embed third-party scripts that set cookies beyond the tools named in section 1.0.

7. Children

Rojak is for users aged 18 and over. We do not knowingly collect data from anyone under 18. If we find an account belonging to a child, the account and all its data will be deleted.

8. International transfers

Most of our processors are based in the United States (Vercel, fal.ai, Stripe, Resend, Cloudflare). When you use Rojak from outside the United States, your data is transferred to and processed in the United States. By using the Service, you consent to that transfer.

9. Changes to this Policy

Material changes will be announced by email. The "Last updated" date at the top of this page reflects the most recent revision.

10. Contact us

For privacy questions, complaints or data subject requests: hello@rojak.app

Operated by the Rojak Studio team (Malaysia). Contact: hello@rojak.app.