RoLearn · Trust & Security

How we protect your data

Brands trust RoLearn with the performance of high-value activations. This page lays out, plainly, how that data is protected: encrypted, isolated to your workspace, minimised by design, and backed up off-site.
Encrypted in transit and at rest
Isolated to your workspace
Direct PII blocked at ingest
Off-site, recoverable backups
Our approach

The safest data is the data we never collect

RoLearn measures activations without ever needing to know who your players are.

Most of our protection comes before any of the technical controls: we designed the product to hold as little sensitive data as possible. We measure real behaviour inside your experience, then reduce it to the numbers you actually use, and we actively reject personal data at the door. Everything below builds on that foundation.

Three commitments
Your activation data is yours alone and never mixed with another customer's. We collect pseudonymous platform identifiers and country, never player emails, names, or precise location. And we tell you honestly what is measured, what is modelled, and what we cannot see, on this page and in every number in the product.
Data protection

Encrypted, everywhere it rests and moves

Encrypted at rest

Your database runs on Amazon RDS with AWS KMS encryption on the volumes, snapshots, and every backup copy. Data on disk is unreadable without the managed keys.

Encrypted in transit

Traffic to RoLearn is served over TLS 1.2 and 1.3. Connections between our services and the database run over SSL. Nothing moves in the clear.

Backed up and recoverable

The database keeps point-in-time recovery with a 35-day window and automatic cross-region backup copies. On top of that, we take our own encrypted daily backups to independent off-site storage, versioned and access-restricted. We rehearse restores so recovery is a practised procedure, not a hope.

Tenant isolation

Your data is yours. Full stop.

No other customer can see your activations, and you can't see theirs.

Every customer is a separate workspace. Every request is scoped to your workspace on the server, from an identity we derive from your session, never from anything your browser could tamper with. A request for data outside your workspace does not return an error that confirms it exists: it returns nothing.

Proven, not just intended
Isolation is enforced on every request and backed by an automated regression suite that actively attempts cross-customer access against our core endpoints and asserts it is denied. That suite runs against every change, so isolation can't quietly regress.

The one place we show cross-market comparison, competitive benchmarks, is built entirely from publicly observable Roblox data and our own curated industry index. It never draws on another customer's private telemetry.

Player data

What we collect, and what we don't

We collectWe never collect
Pseudonymous platform IDs and session IDsPlayer emails, real names, or phone numbers
In-experience behaviour: sessions, playtime, purchases, eventsIP addresses on the telemetry path
Country, at country level onlyCity or precise location

An automated guard inspects every incoming event and rejects anything that looks like direct personal data, email addresses, government IDs, card numbers, before it is ever stored. Raw events are aggregated into daily summaries and then purged on a rolling retention window; the long-lived data is counts, not people. If a brand needs a specific player's records removed, an authenticated erasure endpoint deletes them.

Said plainly
Player identifiers are pseudonymous, not anonymous: they map to a Roblox account, so we treat them as personal data and protect them accordingly. RoLearn is a processor here; your brand and Roblox remain the parties that know who a player is.
Accounts & access

Getting into your workspace

Login security

Passwords are stored only as bcrypt hashes, never in readable form, and new accounts verify their email before they can sign in. Sessions use short-lived tokens that rotate and can be revoked centrally, so access can be cut immediately.

Roles and permissions

Team members hold roles, owner, admin, editor, viewer, and every action is checked against that role on the server. Access keys are stored as hashes, shown once, and scoped so a data-ingest key can never read data back out.

Abuse and monitoring

Sensitive endpoints are rate-limited per account and per address, and the platform is under continuous error monitoring so we see problems as they happen, with player data kept out of those logs.

Infrastructure

Built on ground others already certify

Your data lives on Amazon Web Services, whose infrastructure maintains SOC 2 Type II and ISO 27001 certification. That covers the datacentres, the physical security, and the managed database service underneath us. We build on that foundation rather than reinventing it.

LayerWhat protects it
EdgeCloudflare in front of everything: TLS, DDoS protection, and a firewall. Our servers accept traffic only through Cloudflare.
DatabaseAmazon RDS, KMS-encrypted, reachable only from our application servers by an IP allowlist.
ReleasesEvery deploy is immutable and health-checked, with automatic rollback if anything looks wrong.
RecoveryPoint-in-time recovery plus independent off-site backups, with rehearsed restores.
Compliance

Where we are, and where we're going

We would rather tell you the truth about our maturity than imply a certification we don't hold. Here is exactly where things stand.

Today
  • Infrastructure on SOC 2 Type II and ISO 27001 certified AWS.
  • Encryption in transit and at rest.
  • Per-customer isolation, tested continuously.
  • Data minimization and an erasure endpoint.
On our roadmap
  • RoLearn's own SOC 2 Type II audit.
  • Independent penetration test.
  • Enterprise SSO / SAML and multi-factor authentication.
The legal detail
Our Data Processing Agreement, Privacy Policy, and Sub-processors list are all published and cover how we handle data as your processor.

Have a security question?

We answer them in plain language, and we don't hide the gaps.

Security teams evaluating RoLearn can request our detailed security overview and complete a security questionnaire under NDA. Your RoLearn contact is the fastest route.

1 / 9
Use ← → to move