Privacy Policy
Last updated · October 6, 2026
Roseau is an AI assistant for recording, reflecting, and acting on personal context. This page explains what we process, why, where it lives, and how you can export or delete it.
Data we process
If you use the app, we may process:
- Account email and user ID (Supabase Auth, often via Google Sign-In).
- Timeline records you create, including photos you attach.
- Chat messages and assistant replies.
- Services you create, and their parameters.
- Memory: summaries (MemCells), a structured understanding (LivingProfile), and — when those features are on — style profiles.
- Insights Tab publications: weekly organize and judgment blocks derived from sources you allow. They are not MemCells; they stay until you reset memory or delete your account.
- Records you import — export files you hand in from other services (for example Douban, Letterboxd, or Goodreads). The file is read in memory to extract records and is not stored. Files Roseau cannot yet read item by item are noted by name only; files that look like passwords or configuration are rejected and not saved. Ratings and short notes in imported records can shape your viewing and reading taste. An import is not a connection.
- Apps you add — when you connect an app Roseau doesn't officially support, you give its name and your own API key. Roseau reads that app's public documentation to draft how to read your records, and you confirm which hosts the key will be sent to before anything is read. The key is stored in an encrypted vault on our servers; after you enter it, the AI model, logs, and the app never see it. Roseau only reads your records there (it never changes or deletes them) and only sends the key to the hosts you confirmed. What it reads is handled like imported records: searchable context, each pull can be withdrawn, and it does not by itself change the structured understanding. If those records carry your own ratings, reviews, saved items or highlights of books, films or articles, they also inform your taste profiles (ratings and reviews as what you like; saves and highlights only as what you found useful). You can turn that off per app on its connection page, and it then stops applying to records already pulled in.
- Files you share in chat — when you pick a file in chat (other than an image), it is uploaded to our server and read in memory to pull out its text; the original file is not stored. That text is given to the AI model to answer you, and it is kept with that conversation (as part of your chat history, which you can delete) so you can ask follow-up questions. Values that look like passwords, keys or tokens are masked before the text reaches the AI model or your chat history. A file shared in chat is not an import: Roseau does not extract facts about you from it or add it to memory. If the file is one of the record exports Roseau recognizes, Roseau may ask whether you also want to import it; nothing is imported unless you confirm.
- Push metadata and an APNs device token, if you enable notifications.
- Short-lived voice audio for transcription (not kept as a long-term recording).
- Location only if you grant When In Use permission.
Optional connections are off until you connect them:
- Google Gmail — tokens, sender/subject/time, and bounded body/snippet text for briefs, memory, and reading signals. Not a full mailbox copy.
- Google Calendar — event fields for reminders and context. Events are plans, not proof something happened.
- Notion, RSS, Trakt — authorized workspace, feeds, or watch data; Trakt writes only after you confirm.
- Apple Health — on-device recent aggregates only. Raw samples are not uploaded and not written into memory cells.
- Apple Music — on-device MusicKit. A small recently-played title/artist set may be sent as service input.
- WeChat — messages you send Roseau there are processed as chat (same assistant and memory path as in the app). Not a mail/calendar history source; cannot use your Google credentials.
Disconnecting stops new access. Summaries already in memory stay until you reset memory or delete your account.
If you connect Gmail or Calendar, Roseau’s use of that Google user data follows the Google API Services User Data Policy, including Limited Use. We use it for briefs, reminders, memory you can inspect, and assistant replies — not to serve ads, sell it, or train generalized models.
Sending email waits for your confirmation. In the app, a calendar event you clearly asked to create or edit can be written in that turn when the fields are complete. Background suggestions, events with invitees, Trakt writes, and Apple Music library writes still wait. Some Notion edits you clearly ask for in the app can run in that turn.
Website waitlist
If you submit the waitlist form on this site, a Cloudflare Worker stores your email, timestamp, IP address, and user-agent in Cloudflare KV so we can contact you and limit abuse. We then send one confirmation email from Zac at Roseau (zac@roseau.app) via Resend.
Website analytics
When you visit this site, Cloudflare Web Analytics records aggregate visits, pages, referrers, countries, and load performance. It does not use cookies or local storage, and we do not use it to identify you or to advertise. Campaign tags in the URL are not stored. Aggregates stay on Cloudflare’s network. This is separate from the waitlist form.
Where data lives
- On your iPhone — local timeline, settings, HealthKit / MusicKit if connected.
- On Roseau’s backend — Supabase in the United States. Transport uses TLS.
- At Google / Notion / Trakt / publishers — originals stay with those services.
Authorized Gmail and Calendar content is processed on Roseau’s servers (bounded excerpts plus summaries), not “read on-device and discarded.” We do not keep a dump of your entire mailbox.
AI processing
Current production routing: Cloudflare AI Gateway to Anthropic (chat / higher-stakes reasoning) and DeepSeek (lower-cost background roles); Cloudflare Workers AI for embeddings and voice transcription.
Morning email briefs, cold-start understanding, and memory extraction do use corresponding email or calendar text. Payloads are not always stripped of originals.
We do not train Roseau’s own models on your content. That is the default for every account, not an opt-out. We configure and contractually require providers not to train on your prompts and outputs where those controls exist.
There is no switch that turns AI off, globally or per record. Chat still uses what you type in that turn. To clear what Roseau has learned, reset memory or delete your account.
What we do not do
- Sell your personal data, or share it for cross-context behavioral advertising.
- Use advertising SDKs, advertising identifiers, or session-replay analytics in the iOS app, or sell ads against your content.
- Collect card numbers (Pro is billed by Apple).
Retention
While your account is active, unless you delete the item or the account: chat, records, memory, profile, Insights Tab publications, services, and attached photos.
Imported records stay until you withdraw that import batch, reset memory, or delete your account. Imports you never confirm are discarded after 7 days.
Keys for apps you add are kept until you disconnect that app or delete your account. Records brought in from them follow the same rules as imported records; disconnecting keeps records already brought in.
Memory reset clears understanding, imported records, and Insights Tab publications, then queues a rebuild. It does not delete your account, chats, records, or the calendar-week preference. In-app account deletion removes cloud account data when it succeeds. Cloud export (and deletion if the in-app path fails) via privacy@roseau.app; we aim to respond within 30 days.
Your rights
- Export local records from Privacy & Data in the app.
- Request a cloud export by email.
- Delete your account in the app.
- Disconnect integrations; withdraw an import batch; reset memory.
Children
The app is not directed at children under 16.
Contact
Privacy: privacy@roseau.app.
General: hello@roseau.app.
During the beta, hello@ and privacy@ may be routed through Cloudflare Email Routing (receive/forward only). Waitlist confirmation is sent from zac@roseau.app via Resend.
Subprocessors
- Supabase — database, functions, auth, storage (US).
- Cloudflare — DNS, website, Web Analytics, email routing, waitlist KV, AI Gateway, Workers AI.
- Resend — waitlist confirmation from zac@roseau.app.
- Anthropic and DeepSeek — model inference via the gateway.
- Apple APNs and StoreKit; Google; Notion; Trakt; Tavily / Jina Reader; E2B when those features run.