Roomy Guide: what's sent, what isn't

Draft — 28 September 2026. Planned for after launch.

Roomy Guide is not part of the launch build — it is coming later. Nothing on this page is sent today. It describes how Guide is designed to work once it launches, when the local core — scanning, every view, duplicates, applications, snapshots, and the local "what is this?" knowledge base — will keep working without it.
Roomy Guide explains unfamiliar items, summarizes what changed, and helps you decide what deserves a closer look.

What Roomy Guide will do

Guide is a cloud-assisted add-on, planned as an optional paid extra once it launches. It is not a general chatbot, and it never talks about anything other than the item or scan you asked about:

A free-form ask (POST /v1/guide/ask) is also available for a question about the current scan. Every one of these four calls consumes exactly one "ask" against your quota, on success only.

Exactly what gets sent

Before the first request, the app shows you this exact JSON in a consent preview — not a paraphrase of it. Guide only ever receives the metadata below for the item(s) involved, never a raw file, a directory listing, or your whole file tree. By default, names and paths are off: name and path_hint are sent as null unless you explicitly allow them for that request. When a path is allowed, Roomy redacts your Windows user name to <user> first.

A real GuideItem, with names and paths at their default (off), as sent to POST /v1/guide/explain:

{
  "item": {
    "kind": "folder",
    "name": null,
    "path_hint": null,
    "extension": null,
    "size_bytes": 4831838208,
    "file_count": 2140,
    "modified_days": 3,
    "parent_category": "browser-cache",
    "app_id": null,
    "children": [
      { "name": null, "kind": "file", "size_bytes": 812004352 },
      { "name": null, "kind": "file", "size_bytes": 603512832 }
    ]
  },
  "question": "What is this and is it safe to review?"
}

The same item with names and paths explicitly allowed for that one request looks like this instead — note the redacted user name:

{
  "item": {
    "kind": "folder",
    "name": "Cache_Data",
    "path_hint": "C:\\Users\\<user>\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Cache",
    "extension": null,
    "size_bytes": 4831838208,
    "file_count": 2140,
    "modified_days": 3,
    "parent_category": "browser-cache",
    "app_id": null,
    "children": [
      { "name": "data_3", "kind": "file", "size_bytes": 812004352 },
      { "name": "data_1", "kind": "file", "size_bytes": 603512832 }
    ]
  },
  "question": "What is this and is it safe to review?"
}

The response back is structured the same way every time — a title, a 1–3 sentence summary, a recommendation, a confidence level, evidence, caveats, and next steps. Nothing free-form is ever presented as more certain than that structure allows.

What's sent (by default)

  • Item kind (file/folder)
  • Extension
  • Size in bytes
  • File count (for folders)
  • Modified age, in days
  • Parent category from the local knowledge base (e.g. browser-cache)
  • Application identifier, if known
  • Up to 12 largest children's sizes (names off by default)
  • Your typed question

What's never sent

  • File contents — ever, regardless of settings
  • Your whole file tree or file list
  • Names or paths, unless you explicitly allow them for that request
  • Your real Windows user name (always redacted to <user> when paths are on)
  • Anything about items you didn't select or ask about

Provider and retention

Quotas, in plain words

Guide usage is counted in asks — one ask per Guide request that succeeds. You never see a token count or a per-request cost; the app shows something like "12 of 25 asks left this period" with the date it resets. Server defaults: a subscription gets 300 asks/month (reset on the calendar month), and a trial gets 25 asks total over 14 days. When your quota runs out, Guide stops answering rather than quietly billing more — the free local core keeps working either way. Per-device request rate is also limited (10/minute by default) to prevent runaway use, and the whole service has a hard monthly cost ceiling; if that ceiling is reached, Guide returns "unavailable right now" rather than overspending.

Uncertainty and safety principles

Full privacy policy → · Back to the Guide overview →