Rotly Privacy Policy
Version 1.2. Effective [publish date].
Rotly ("Rotly", "we", "us") is an app that turns a scene you type into a short animated clip starring our cast of characters. This policy explains what personal data we collect, why, who we share it with, how long we keep it, and the rights and choices you have, wherever you live.
The data controller (the company responsible for your data) is [controller legal name], [address], Belgium. For any question about this policy or your data, contact [[email protected]].
The short version
- You must be 13 or older to use Rotly. We ask your date of birth once, check it, and store only the yes/no result, never the date itself.
- We collect the minimum the service needs: your account email, a random device identifier, the scenes you write, the clips we generate for you, your subscription status, and basic in-app usage events. We do not even store your name.
- We do not collect your photos, contacts, or precise location. We show no ads, we use no third-party advertising or tracking SDKs, and we do not sell your personal data or share it for behavioural advertising.
- To generate a clip we send the scene text and dialogue you write to our generation provider (fal.ai) and the AI model partners it routes to, which can involve processing outside your country (see "International data transfers"). We never send them your name or email, and we do not use your content to train AI models.
- You can delete your account from inside the app at any time (Account > Delete account).
Who this policy covers
This policy applies to the Rotly mobile app and any web version we operate. It does not cover the separate services you sign in with (Google, Apple) or the app stores you download from (Apple App Store, Google Play), each of which has its own privacy policy.
Age requirement (13+)
Rotly is intended for people aged 13 and over and is not directed to children under 13. Before you can sign in, the app asks for your date of birth and refuses access if you are under 13. For data minimisation we store only the outcome of that check (verified or blocked) on your device, never your date of birth.
Some regions set a higher age of digital consent (up to 16 in parts of the EEA). Where local law requires it, you must meet that higher age, or have a parent or guardian consent on your behalf, to use the service.
If you believe a child under the applicable age has given us personal data, contact [[email protected]] and we will delete it.
What we collect and why
We only collect what the feature you use needs.
| Data | What it is | Why we process it | Legal basis (EEA/UK) | Kept until |
|---|---|---|---|---|
| Account data | Email address, the technical identifier your sign-in provider gives us, and a record of your consent (timestamp and policy version). We do not store your name, even when your sign-in provider offers it | Create and secure your account, restore it on a new device, respond to your requests | Contract; legal obligation (consent records) | Account deletion |
| Device identifier | A random identifier the app generates and stores on your device (not your name, not an advertising ID) | Apply free and subscription clip limits, link your subscription, group usage events | Contract; legitimate interests (abuse prevention) | See "Deleting your account" |
| Content you create | Scene text and dialogue, chosen characters and format, and the clips generated from them | Produce and deliver your clips | Contract | Account deletion (see below) |
| Subscription status | Whether a subscription is active, and the store events needed to grant or revoke it | Provide what you paid for | Contract | Account deletion |
| Usage events | In-app events such as screens opened, format and characters chosen, the length (a number, never the text) of a scene, and purchase or share taps, keyed to your device identifier | Understand how the app is used, fix problems, prevent abuse | Consent (given at sign-up); legitimate interests for abuse prevention | See "How long we keep it" |
| Technical data | IP address and basic request data when the app talks to our server | Rate limiting, security, and keeping the service running | Legitimate interests | Short-lived technical logs |
| Support messages | Whatever you send us by email | Answer you | Legitimate interests; contract | As long as needed for the request |
What we do not collect. We do not access your photos or camera roll, your contacts, or your precise location. We do not use third-party advertising or analytics SDKs, we do not track you across other companies' apps or websites, and we never see your card number: payment runs entirely through Apple or Google.
Content, clips, and AI
To make your clip, we send the scene text and dialogue you wrote, and the characters and format you chose, to our AI generation provider (fal.ai). fal.ai routes parts of the work to the AI model partners behind the features: currently Kling (by Kuaishou) for video, and ElevenLabs and MiniMax for character voices. This is the only purpose your content is shared for. Our agreements require these providers to process your content only to provide the generation service to us. We do not use your content to train AI models.
Your prompts are screened automatically against a content filter before any generation starts; prompts that hit the filter are refused. This screening is automated, but it only blocks a single clip from being generated: it makes no decision with legal or similarly significant effects about you, and you can contact [[email protected]] if you believe a prompt was refused wrongly.
Finished clips are usually hosted on our server at a link that is not guessable but is not access-controlled: anyone you share a clip or its link with can view it. Some clips, previews and thumbnails are delivered directly from our generation provider's storage instead and are removed on its retention schedule. When you save a clip to your device or post it elsewhere, that copy is outside our control.
Legal bases (EEA, UK and similar laws)
Where the EU or UK GDPR (or a similar law) applies, we process personal data on these bases:
- Performance of a contract: creating your account, generating and delivering your clips, and providing your subscription.
- Legitimate interests: securing the service, preventing abuse of clip limits, and defending legal claims, in each case balanced against your rights.
- Consent: shown and recorded (with the policy version you saw) when you create your account; it covers the usage analytics described above. Where we rely on consent you can withdraw it at any time by contacting us or by deleting your account; withdrawing does not affect processing that already happened.
- Legal obligation: keeping records we are required to keep, such as consent records.
We do not use your data for automated decisions that produce legal or similarly significant effects on you, and we do not do profiling beyond the basic usage analytics described above.
Who we share data with
We use a small number of service providers ("processors") who handle data only on our documented instructions. We do not sell your personal data, and we do not share it for cross-context behavioural advertising.
| Provider | What they receive | Why | Where |
|---|---|---|---|
| fal.ai, which routes to its AI model partners: currently Kling (Kuaishou) for video and ElevenLabs and MiniMax for voices | The scene text and dialogue you write, and the chosen characters and format | To generate the video and voices for your clip | United States; model partners may process in the countries where they operate, which can include Singapore and China (see "International data transfers") |
| RevenueCat | Your random device identifier and subscription events | To manage and verify your subscription | United States |
| Google (Google Sign-In) | Your Google sign-in | To verify your identity when you choose Google | United States |
| Apple (Sign in with Apple, App Store billing) | Your Apple sign-in and App Store purchases | To verify your identity and process App Store subscriptions | United States |
| [Hosting provider] | The data in the table above, at rest on our server | To run the Rotly backend | [region] |
We never send fal.ai, its model partners, or RevenueCat your name or email.
We may also disclose data where the law requires it, to public authorities on a valid request, to protect our rights or users' safety, or as part of a merger, acquisition or asset sale, in which case this policy continues to apply to your data and we will notify you of any new controller.
International data transfers
We are based in Belgium. Several of our providers are in the United States, and the AI model partners behind clip generation may process the content you submit in the countries where they operate, which can include Singapore and China. Using Rotly therefore involves transferring personal data outside the EEA, the UK and Switzerland, including to countries without an adequacy decision.
Where required, we rely on the European Commission's Standard Contractual Clauses (with the UK Addendum or the Swiss amendments where applicable), or on an adequacy decision such as the EU-US Data Privacy Framework where the provider is certified. Remember that the only content that travels this far is what is needed to render your clip: your scene text and dialogue and your casting choices, never your name, email or device identifier. You can ask for more detail, including a copy of the relevant safeguards, at [[email protected]].
How long we keep it
- Account data: until you delete your account, then de-identified immediately (see below).
- Content you create: prompts and clip links are removed when you delete your account, and generated clip files are deleted from our server at that point. Copies delivered from our generation provider's storage are removed on its retention schedule.
- Usage events: kept in identifiable form (keyed to your device identifier) only while needed for analytics and abuse prevention; unlinked from your device at account deletion.
- Session tokens: we store only a hashed form, and they expire automatically.
- Technical logs: kept briefly for security and debugging, then deleted.
- De-identified records: see the next section.
Deleting your account
Open the app, go to Account > Delete account, and confirm. Deletion takes effect immediately and works like this:
- Your email and sign-in link are erased from the account record. The emptied record keeps only an internal record number and dates (created, deleted, and the consent timestamp and policy version we must keep for legal accountability): no name, no email, nothing that identifies you.
- Every sign-in session is revoked immediately.
- Your prompts, dialogue and clip links are erased, and generated clip files are deleted from our server. If a clip is being generated at that exact moment (renders take minutes and only one runs at a time), we erase what can safely be erased right away and mark the rest, which is erased when that render is next processed. Copies delivered from our generation provider's storage are removed on its retention schedule.
- De-identified operational records are retained: your device's usage counters (how many clips were generated, when), which stay keyed to the random device identifier stored on your device, so that free limits and our anti-abuse and cost controls keep working, and event counts with the device link removed. These records contain no name, no email and no content. We keep them because the law allows retention for these purposes; if the same device is used again they apply to it as a device, not to you as a person.
- Copies in short-lived technical logs and backups clear on their normal rotation cycle.
Deleting the app from your phone does not delete your account (and does not cancel a subscription); use the in-app deletion first. Subscriptions are cancelled in your App Store or Google Play settings.
Your rights
Depending on where you live, you have some or all of the rights below. All of them are free of charge. We may need to verify it is really you before acting (we do this using your signed-in account or the email address on the account), and we will respond within the time your law requires (one month under the GDPR, extendable where the law allows; 45 days under most US state laws).
- Access / to know: get a copy of the personal data we hold about you.
- Correction: fix inaccurate data.
- Deletion: use in-app deletion, or email us.
- Portability: receive the data you gave us in a machine-readable format.
- Restriction and objection: restrict processing, or object to processing based on legitimate interests, including at any time to any direct marketing (we currently send none).
- Withdraw consent: at any time, without affecting past processing.
- No discrimination: we will not treat you worse for exercising a right.
To exercise any right, email [[email protected]]. If you are not happy with our answer, you can complain to your local supervisory authority. In Belgium (our lead authority) this is the Data Protection Authority / Gegevensbeschermingsautoriteit / Autorite de protection des donnees, www.dataprotectionauthority.be. You may also have the right to ask a court for a remedy.
Country and region specifics
European Economic Area, United Kingdom and Switzerland
Everything above applies, including the GDPR legal bases and the transfer safeguards. UK users can complain to the ICO (ico.org.uk); Swiss users to the FDPIC. [If a UK representative is appointed: our UK representative is [name, address].]
United States (California and other state laws)
For the purposes of the California Consumer Privacy Act (CCPA/CPRA) and similar state laws (including those of Virginia, Colorado, Connecticut, Utah and Texas), in the last 12 months we have collected these categories of personal information: identifiers (email, device identifier, IP address), internet or network activity (in-app usage events), audio/visual and user content (the scenes you write and clips generated from them), and commercial information (subscription status). We collect them from you, automatically from your device and our servers, from your sign-in provider, and from the app store and our subscription manager (RevenueCat), for the purposes in the table above, and disclose them to the service providers listed above only for business purposes.
We do not sell personal information, we do not share it for cross-context behavioural advertising, we do not use or disclose sensitive personal information beyond what is necessary to provide the service, and we have no actual knowledge of selling or sharing the personal information of anyone under 16. Because we neither sell nor share personal information, there is nothing to opt out of (including via the Global Privacy Control), but the rights to know, delete, correct and not be discriminated against all apply: email [[email protected]]. You may use an authorised agent; we will verify the request with you directly. Retention periods per category are set out in the tables above.
Brazil (LGPD)
We process personal data on the legal bases of contract performance, legitimate interests and consent, as described above. You have the rights in Article 18 LGPD, including confirmation of processing, access, correction, anonymisation, deletion, portability, and information about sharing. Contact [[email protected]] (our contact for LGPD purposes). Complaints can be made to the ANPD.
Canada
We comply with PIPEDA and, for Quebec residents, Law 25. Your data may be processed outside Canada, in the countries described in the sharing and transfer sections above, with contractual protections. You may request access to and correction of your personal information, and withdraw consent subject to legal and contractual limits. The person in charge of personal information protection can be reached at [[email protected]]. Complaints can be made to the Office of the Privacy Commissioner of Canada or, in Quebec, the Commission d'acces a l'information.
Australia
We handle personal information in accordance with the Australian Privacy Principles. Your data is held and processed overseas, in the countries described in the sharing and transfer sections above. You may request access and correction at [[email protected]], and complain to us first and then to the OAIC (oaic.gov.au) if unresolved.
Everywhere else
Wherever you live, we apply the protections in this policy, and we honour access, correction and deletion requests sent to [[email protected]] to the extent your local law provides them.
Security
We restrict access to personal data, encrypt data in transit, store sign-in session tokens only in hashed form, keep your scene text out of analytics events, and screen prompts server-side rather than trusting the app. No system is perfectly secure, but we take technical and organisational measures appropriate to the risk, and if a breach ever creates a risk to you we will notify you and the competent authority as the law requires.
Changes to this policy
If we make a material change we will update the version and effective date above and, where appropriate, notify you in the app before the change takes effect. Continued use after a change means you accept the updated policy. Earlier versions are available on request.
Contact
[controller legal name] [address], Belgium Enterprise number: [BE 0xxx.xxx.xxx] [VAT BE 0xxx.xxx.xxx, if VAT-registered] [[email protected]]
This policy is written in English. If we provide translations for convenience, the English version prevails to the extent local law allows.