1. Introduction
Rosely Private Limited ("Rosely", "we", "us", or "our") is the data controller for personal data processed through Rosely.ai ("Platform", "Service").
This Privacy Policy explains how we collect, use, store, share, and protect your personal data when you use our Service. We are committed to processing your data responsibly and in compliance with applicable data protection laws, including the General Data Protection Regulation (GDPR) where applicable.
By accessing or using Rosely.ai, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with our data practices, please do not use the Service.
2. Data We Collect
2.1 Data You Provide to Us
- Email address
- Username
- Password (stored in hashed form only)
- Date of birth
- Payment data (processed and stored by third-party payment processors; we do not store full payment details on our servers)
- Support messages and communications
- Chat messages you send to AI companions
2.2 Data Collected Automatically
- IP address
- Browser type and version
- Operating system
- Device information
- Usage data (pages visited, features used, interaction patterns)
- Cookies and similar tracking technologies
- Referral URL
2.3 Service-Generated Data
- AI memory data (encrypted at rest and in transit)
- Preference data derived from your interactions
- AI-generated content (text, images, and video produced during your sessions)
3. Legal Bases for Processing
We process your personal data on the following legal bases (where GDPR applies):
- Performance of a Contract: Processing necessary to provide the Service, manage your account, process payments, and deliver AI companion features.
- Legitimate Interests: Processing necessary for fraud prevention, security, service improvement, and analytics, where our interests do not override your fundamental rights and freedoms.
- Consent: Processing based on your explicit consent (e.g., marketing communications and non-essential cookies). You may withdraw consent at any time.
- Legal Obligation: Processing necessary to comply with applicable legal requirements.
4. How We Use Your Data
We use the personal data we collect for the following purposes:
- Providing, operating, and maintaining the Service
- Creating and managing your account
- Processing payments and subscriptions
- Powering AI companion features, including conversation, memory, and personalized interactions
- Personalizing your experience and improving the Service
- Communicating with you about your account, support requests, and service updates
- Detecting, preventing, and addressing fraud, abuse, and security issues
- Complying with legal obligations
- Sending marketing communications (only with your explicit consent; you may opt out at any time)
5. Data Sharing
We do NOT sell your personal data to third parties. We may share your data with the following categories of recipients, strictly as necessary:
- Payment Processors (for processing subscription and one-time payments)
- Cloud Infrastructure providers (for hosting, storage, and computing services)
- Email Services (for transactional and service-related email communications)
- Analytics: Privacy-focused analytics tools only
- Legal Authorities: When required by applicable law or to protect our legal rights
- Professional Advisors: Legal, accounting, and other professional advisors as necessary
6. International Transfers
Your personal data may be transferred to and processed in countries outside the European Economic Area (EEA), including the United States (for AWS cloud infrastructure). When such transfers occur, we ensure appropriate safeguards are in place, including:
- European Commission adequacy decisions
- Standard Contractual Clauses (SCCs) approved by the European Commission
- Data Processing Agreements (DPAs) with all service providers
7. Data Retention
We retain your personal data only for as long as necessary to fulfill the purposes described in this Privacy Policy, unless a longer retention period is required by law:
- Account Data: Retained for the duration of your account plus 12 months after account deletion.
- Payment Records: Retained as required by applicable tax and financial laws.
- Conversations and AI Memory: Retained for the duration of your account. Deleted within 30 days of account deletion (unless legally required to retain longer).
- Server Logs: Retained for up to 12 months.
- Marketing Consent Records: Retained for the duration of consent validity plus 3 years.
8. Your Rights
Depending on your location and applicable law, you may have the following rights regarding your personal data:
- Right of Access
- Right to Rectification
- Right to Erasure (“Right to be Forgotten”)
- Right to Restrict Processing
- Right to Data Portability
- Right to Object
- Right to Withdraw Consent
- To exercise any of these rights, please contact us at support@rosely.ai. We will respond to your request within 30 days. You also have the right to lodge a complaint with your local data protection authority.
9. Your Rights Under CCPA
If you are a California resident, you have the right to know what data we collect, request deletion, and opt-out of sales (though we do not sell data).
To exercise your CCPA rights, please contact us at support@rosely.ai
10. Children’s Privacy
Rosely.ai is not intended for use by anyone under the age of 18. We do not knowingly collect personal data from individuals under 18 years of age. If we become aware that we have collected personal data from a person under 18, we will take immediate steps to delete that data and terminate the associated account.
11. Security Measures
We implement robust technical and organizational measures to protect your personal data, including encryption in transit and at rest, access controls, and regular security audits.
12. Changes to This Policy
We may update this Privacy Policy from time to time. For material changes, we will notify you via email or a prominent notice on the Service at least 30 days before the changes take effect.
13. Contact Information
- For any questions or concerns about this Privacy Policy, please contact us at: Rosely Private Limited
- Email: privacy@rosely.ai
- Website: https://rosely.ai