Privacy policy

Public data.
Clear boundaries.

RoTrail is a local-first Chrome extension for selected public Roblox profile changes. Optional website account linking is separate from Roblox and is used for RoTrail entitlements and payments.

Effective 30 August 2026. Applies to the RoTrail website and the Chrome extension.

Summary: RoTrail helps you monitor selected public Roblox profile and limited-item changes. The website may use Google sign-in, Firebase, Cloudflare, and Dodo Payments for account linking, subscription access, security, and support. RoTrail does not receive Google or Roblox passwords.

1. Who operates RoTrail

RoTrail is operated by the owner of rotrail.net. The privacy contact is [email protected]. If the service is operated through a company or registered business, the operator's legal name and postal address must be added to this section before public launch or before relying on this policy as a complete legal notice.

2. What this policy covers

This policy covers the RoTrail website, the public demo, the RoTrail Chrome extension, the RoTrail account-linking Worker, and optional paid checkout. It does not cover Roblox, Google, Firebase, Cloudflare, Dodo Payments, roproxy.com, ff-roproxy.com, or Rolimons; those providers have their own terms and privacy notices.

3. Information handled by the extension

The core monitoring workflow stores data in Chrome extension storage on the device where RoTrail is installed. Depending on what you use, this includes selected Roblox user IDs and names, watched limited-item IDs and names, comparison snapshots, public-data category health, settings, notification state, cached item catalogue data, and recent activity history. History is retained locally for up to 12 hours on Free, 3 days on Plus, or 7 days on Pro, subject to the extension's storage cap.

The extension also keeps a non-exportable device key in browser-managed IndexedDB and derives a short install identifier from its public half. If you link an account, it stores the RoTrail access key and a cached entitlement assertion locally. The access key is a RoTrail credential, not a Roblox credential. A local 13+ confirmation flag is stored to keep background monitoring disabled until the user accepts the age requirement.

4. Public Roblox and item data

When you choose to watch a profile or item and grant the relevant optional host access, the extension requests only data needed for that feature. It may include public names, descriptions, display names, follower and following counts, friends, groups, public outfit information, public inventory categories, public account status, and limited-item catalogue or resale values. It does not request Roblox passwords, browser cookies, private messages, security codes, or private inventory.

Profile requests are routed through roproxy.com and, when needed, ff-roproxy.com rather than sent directly to Roblox. Those independent proxy operators can receive your IP address, user agent, requested endpoint, and the Roblox profile identifier in the request. That can reveal which public profiles you are checking. Item catalogue requests go to rolimons.com; the catalogue request can reveal your IP address, but the extension does not send Rolimons your private watchlist.

RoTrail cannot and should not bypass Roblox privacy settings. Public availability is not permission to harass, stalk, threaten, dox, or infer sensitive private activity. You control which profiles and items you watch and can remove them at any time.

5. Optional account linking

If you choose Google sign-in on the dashboard or pricing page, Firebase Authentication verifies your session. RoTrail's account service receives and uses a Firebase user identifier, email address, and display name to link the account, issue or revoke a RoTrail access key, provide support, and apply the selected entitlement. The browser's Firebase client may retain authentication state using its own browser storage. RoTrail does not receive your Google password.

The dashboard uses a generated local fallback avatar and does not send a Google profile-image URL to the extension or store it as part of RoTrail account linking. Firestore is used as a dashboard-readable mirror of entitlement status; clients may read only their own user document, while entitlement writes are performed by the verified backend.

6. RoTrail backend records

The Cloudflare Worker and its D1 database may handle a one-way hash of an extension access key, the linked Firebase user ID, key creation and expiry times, the bounded install identifiers used for device caps, server-backed daily quota counters, subscription records, provider status, and webhook processing identifiers. The raw extension key is generated for the browser and is not stored in the database. The backend uses signed, short-lived entitlement assertions so a locally edited tier cannot grant paid access.

Cloudflare may also process request metadata such as IP address, user agent, URL, timing, and security or abuse signals when delivering and protecting the site and Worker. Application errors are recorded without intentionally logging request bodies or access keys. Operational retention is partly controlled by Cloudflare's configuration and terms.

7. Payments

When checkout is enabled, Dodo Payments processes the transaction as the payment provider. RoTrail may receive the purchaser email, product or plan, subscription identifier, payment or subscription status, billing-period dates, and webhook information needed to grant, revoke, troubleshoot, or defend the service. RoTrail does not ask you to email a complete card number and does not store complete payment-card details.

8. Website storage, fonts, and no advertising sale

The website stores a local 13+ confirmation in localStorage. The account pages may use Firebase's browser-managed authentication and its browser client for dashboard reads. The public pages do not intentionally use advertising trackers or sell personal information for cross-context behavioral advertising. The site loads interface fonts from Google Fonts, so a page visit can cause requests to Google-hosted font domains. Firebase, Google sign-in, Cloudflare, and payment pages can also make their own requests under their own policies.

9. Why information is used

Depending on your location and the activity involved, the relevant legal basis may include performance of a contract, steps taken at your request, legitimate interests in security and service operation, consent for optional features, or compliance with a legal obligation. Local law and the exact facts control; this policy is not legal advice.

Chrome Web Store data-use statement

RoTrail's use of information received from Chrome APIs will adhere to the Chrome Web Store User Data Policy, including its Limited Use requirements. RoTrail uses that information only to provide, secure, and improve the disclosed public-data monitoring and optional account and entitlement features. RoTrail does not sell it, use it for personalized advertising, transfer it to data brokers, or use it to determine creditworthiness. Information is shared only with providers needed for the features, security and abuse prevention, legal compliance, or account and payment operations described in this policy.

10. Recipients and international processing

Information may be processed by the service providers named above: Cloudflare for hosting, Worker execution, D1, rate limiting, and security; Google and Firebase for sign-in, fonts, and Firestore; Dodo Payments for checkout; and the public-data proxy or catalogue providers selected by the extension. These providers may process information outside your country. Where applicable, the operator should use the transfer safeguards required by local law and the provider's current contractual terms.

11. Retention and deletion

Local extension data remains on your browser profile until you remove it, uninstall the extension, or use Delete all RoTrail data. That action also clears local alarms, cached state, and extension notifications; it does not by itself erase backend records held for an account, a payment, a support request, or security purposes. You can revoke a key in the account flow or ask support to remove optional account data.

Backend keys expire after their stated lifetime and are removed by scheduled cleanup after expiry. Inactive install-cap records are cleaned after the configured inactivity period. Daily quota records are kept only for the short operational window needed to enforce the quota. Webhook event records are retained for up to 90 days under the current cleanup job. Subscription, payment, tax, fraud, security, and support records may be retained longer where required or reasonably necessary. Cloudflare and Google retain provider-side data under their own policies and settings.

12. Your choices and rights

Where applicable law grants them, you may request access to, correction of, deletion of, restriction of, or portability of personal information, object to particular processing, withdraw consent for an optional feature, or complain to your local data-protection authority. California residents may also have rights to know, correct, delete, and opt out of sale or sharing; RoTrail does not intentionally sell or share information for cross-context behavioral advertising.

Email [email protected] with the request and enough information to verify the relevant account. Do not send passwords, payment-card numbers, Firebase identity tokens, or extension keys. We may need limited verification to protect another person's account. Where GDPR-style timelines apply, requests are generally answered within one month unless a lawful extension or exception applies.

13. Automated decisions and appeals

RoTrail automatically applies plan limits, daily quotas, device caps, abuse rate limits, key expiry, and entitlement status. These controls protect the service and determine feature availability. They are not intended to make decisions with legal or similarly significant effects. If a control blocks legitimate use, contact support with the account email and a description of the issue; do not send the key itself.

14. Security and incident contact

RoTrail limits browser permissions, keeps the main monitoring data local, hashes backend keys, verifies signed webhook messages, and uses short-lived signed entitlement assertions. No internet service is perfectly secure. If you believe a key, account, or personal information has been exposed, email [email protected] promptly and do not include the secret in the message. Responsible security reports may be sent to the same address.

15. Age requirement

RoTrail is for people aged 13 or older only. We do not knowingly direct the service to children under 13 or knowingly collect their personal information. If we learn that information was collected from someone under 13, we will take reasonable steps to delete it. The 13+ rule does not override a higher age threshold or consent rule in the user's location.

16. Changes and contact

Material changes will be posted on this page with a new effective date. Questions, deletion requests, privacy objections, data-protection requests, or responsible security reports belong at [email protected]. Please do not send Roblox credentials, Google credentials, payment-card details, Firebase tokens, or RoTrail access keys.