Rosetta Lens Privacy Policy

Last updated: 11 October 2026

This Privacy Policy explains how the Rosetta Lens mobile app for iOS and Android (the "App") handles your information. Rosetta Lens helps you read ancient inscriptions (such as Egyptian hieroglyphs, ancient Greek and cuneiform) from photos you take.

The App is operated by [LEGAL ENTITY NAME] (ABN [ABN]), trading as ethosec, of Queensland, Australia ("we", "us", "our").

Summary at a glance

Contents

  1. Who we are
  2. Information we handle
  3. How cloud reading works
  4. How and why we use information
  5. Permissions on your device
  6. Who we share information with
  7. International transfers
  8. How long we keep information
  9. Security
  10. Your choices and controls
  11. Your rights and how to make a request
  12. Australia
  13. European Economic Area and United Kingdom
  14. United States
  15. Canada
  16. New Zealand
  17. Children
  18. Future model training
  19. Changes to this policy
  20. Contact us

1. Who we are

Rosetta Lens is provided by [LEGAL ENTITY NAME] (ABN [ABN]), trading as ethosec, an Australian business based in Queensland and run by Brent Roberts.

For the purposes of the EU and UK General Data Protection Regulation (GDPR), we are the controller of the personal data described in this policy that leaves your device. Under the Australian Privacy Act 1988 we are the entity responsible for that personal information.

2. Information we handle

Information that stays on your device

This information is created and stored only on your phone. We do not receive it unless you use cloud reading (see section 3).

Information we receive

What When Why
Purchase or install identifier: currently a beta token; later, the Apple App Store original transaction ID or Google Play purchase token When you use the App's plan features To recognise your plan and count readings
Cloud-reading usage and balances: the number of cloud readings used against the Pro monthly allowance, and reading-pack and trip-pass balances. Free and [MIDDLE PLAN NAME] reading counts are not sent to us When you use cloud reading or buy a pack or pass To apply plan limits and balances
Purchase status from Apple or Google (for example, which plan or pack was bought and whether it is active) When you buy or restore a purchase To give you what you paid for
Cloud reading request (Pro plan only, only when you choose it for a photo): the photo, the script you chose, the optional location hint (country/region/site, and GPS coordinates only if you enabled GPS), and the on-device reading text Each time you request a cloud reading To produce the cloud reading
Cloud reading result: the finished reading text After a cloud reading So the App can retrieve it if your connection drops (kept up to 10 minutes)
Technical and security data: IP address and request metadata (for example, time, request path, status) processed by Cloudflare; AI gateway logs of time, model, token counts, cost, status and duration When the App contacts our server Security, abuse prevention, reliability and cost control

What we do not collect: your name, email address, phone number, contacts, payment card details, advertising identifiers, or browsing activity in other apps or websites. The App has no account or sign-up.

A note on photos: inscriptions rarely contain personal information, but a photo can capture people, faces, or other details in the background. Please avoid including people in photos you send for cloud reading.

3. How cloud reading works

Cloud reading is available only on the Pro plan and happens only when you choose it for a particular photo. Nothing is uploaded automatically.

  1. The App sends the photo, chosen script, optional location hint and on-device reading text over an encrypted (HTTPS) connection to our server at api.rosettalens.net, which runs on Cloudflare Workers.
  2. Our server forwards the request to xAI's Grok API (in the USA), which produces the reading.
  3. We do not store your photo. It is handled in memory only to pass the request to xAI.
  4. Cloudflare AI Gateway records metadata only (time, model, token counts, cost, status and duration). It does not log the photo or the content of the request or response.
  5. The finished reading text is held on our server for up to 10 minutes so the App can collect it if your connection drops. It is then deleted.

xAI processes the request as our service provider, in line with its API terms and data policy. See xAI's privacy policy: https://x.ai/legal/privacy-policy. Any retention by xAI is governed by xAI's API data policy. We do not use your photos or readings to train our own models.

4. How and why we use information

We use information only for these purposes:

Purpose Information used GDPR lawful basis
Producing cloud readings you request Cloud reading request and result Performance of our contract with you
Recognising your plan, counting readings and applying pack and trip-pass balances Purchase or install identifier, usage counts and balances, purchase status Performance of our contract with you
Using precise (GPS) location to improve a reading GPS coordinates (only if you enable it) Your consent, which you can withdraw at any time
Using a typed location hint (country/region/site) to improve a reading Location hint Performance of our contract with you (you choose to provide it)
Keeping the service secure, preventing abuse and fraud, rate limiting, and managing reliability and costs IP address, request metadata, gateway metadata, identifier and usage counts Our legitimate interests in protecting the service and its users
Complying with law, resolving disputes and responding to lawful requests Any of the above, as needed Compliance with legal obligations; legitimate interests
Answering your emails and privacy requests What you send us Legitimate interests; legal obligations (for rights requests)

We do not use your information for advertising, profiling, or automated decisions that have legal or similarly significant effects on you.

Where we rely on legitimate interests, we have balanced our interests against your rights. You can ask us for more detail and you can object (see section 11).

5. Permissions on your device

You can grant or withdraw these permissions at any time in your phone's settings. If you refuse a permission, only the feature that needs it will be unavailable.

6. Who we share information with

We do not sell your personal information and we do not share it for cross-context behavioural advertising. We disclose information only to the service providers we need to run the App:

Provider Role Location
Cloudflare, Inc. Hosts our server (Workers) and AI Gateway; provides network security (TLS, web application firewall, rate limiting) and processes request metadata such as IP address USA and global network
xAI Provides the Grok API that produces cloud readings USA
Apple App distribution and in-app purchases (App Store) USA and global
Google App distribution and in-app purchases (Google Play) USA and global

Apple and Google handle payments under their own privacy policies; we receive purchase status, not payment details. If you have opted in at the operating-system level, Apple or Google may also provide us with aggregated app performance and crash statistics under their own terms.

We may also disclose information if required by law, to protect rights, safety or security, or as part of a sale or restructure of our business (in which case this policy will continue to apply to your information or you will be notified).

7. International transfers

We are based in Australia, but our service providers process information in the United States and in other countries where Cloudflare operates. This means your information may be transferred outside Australia, the EEA, the UK, Canada or New Zealand.

When we transfer information, we take reasonable steps to make sure it is protected, including by using providers that commit by contract to protect it. For transfers from the EEA or UK, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses, the UK International Data Transfer Addendum, or the EU–US Data Privacy Framework (and its UK Extension) where the provider is certified. You can contact us for more information about these safeguards.

8. How long we keep information

Information Where How long
Photos (on-device reading) Your phone Until you delete them; we never receive them
Photo sent for cloud reading Our server (in memory) Not stored; discarded once passed to xAI. Any retention by xAI is per xAI's API data policy
Cloud reading result (reading text) Our server Up to 10 minutes, then deleted
Reading history Your phone Until you delete it in the App or uninstall the App
Free and [MIDDLE PLAN NAME] reading counters Your phone only (iOS Keychain on iOS) Until you uninstall the App; on iOS it may persist after reinstall until the device is reset
Purchase or install identifier, cloud-reading usage and pack/trip-pass balances Our server While your plan, packs or passes can still be used, then deleted within 13 months of your last activity (reading packs expire 12 months after purchase)
AI Gateway metadata logs (no request or response content) Cloudflare Up to 30 days, then deleted
Security and request logs (including IP address) Cloudflare Per Cloudflare's retention for our plan: security events and traffic analytics up to 31 days; server (Worker) logs up to 7 days
Emails and privacy requests Our email 2 years after the request is closed, or longer if needed for legal reasons

9. Security

We protect information using measures that include:

No system is perfectly secure. If a data breach is likely to cause serious harm, we will notify affected people and regulators as required by law, including under Australia's Notifiable Data Breaches scheme.

10. Your choices and controls

11. Your rights and how to make a request

Depending on where you live, you may have the right to:

How to make a request: email [CONTACT EMAIL] with the subject "Privacy request" and tell us what you would like us to do.

Verification: because the App has no accounts, we hold very little that identifies you. To find your records and confirm they are yours, we may ask for your App identifier (shown in the App at [IN-APP LOCATION OF IDENTIFIER, e.g. Settings > About]) or details from your App Store or Google Play purchase receipt. We will use this only to handle your request. If we cannot reasonably verify the request, we will tell you why.

Timing: we aim to respond within 30 days, and within any shorter or different period required by your local law (for example, one month under the GDPR, extendable in some cases, or 45 days under California law, extendable once by a further 45 days). We do not charge a fee unless the law allows it for requests that are clearly unfounded or excessive.

Please note: deleting your purchase identifier and usage records may mean we can no longer recognise remaining pack or trip-pass balances. Apple and Google hold your purchase records under their own policies.

You may use an authorised agent where the law allows; we may ask for proof of their authority and may ask you to verify your identity directly.

12. Australia

We handle personal information in line with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).

13. European Economic Area and United Kingdom

If you are in the EEA or the UK, the GDPR or UK GDPR applies to our processing of your personal data.

Providing information for cloud reading is necessary to deliver that feature; if you do not provide it, you can still use on-device readings.

14. United States

California (CCPA/CPRA)

This section applies to California residents to the extent the California Consumer Privacy Act, as amended by the California Privacy Rights Act, applies to us.

Notice at Collection. In the past 12 months we have collected the following categories of personal information, for the purposes in section 4, and keep them for the periods in section 8:

CCPA category Examples Source Disclosed for a business purpose to
Identifiers Purchase or install identifier; IP address You and your device; Apple or Google Cloudflare; Apple or Google
Commercial information Purchase status, plan, pack and trip-pass balances, cloud-reading counts You; Apple or Google Cloudflare
Internet or other electronic network activity Request and gateway metadata Your device Cloudflare
Geolocation data Optional location hint; precise GPS location only if you enable it You and your device Cloudflare; xAI
Audio, electronic, visual or similar information Photos sent for cloud reading (Pro only) You Cloudflare; xAI
Sensitive personal information Precise geolocation (only if you enable GPS) Your device Cloudflare; xAI

We do not collect sensitive personal information for the purpose of inferring characteristics about you, and we use it only for purposes permitted by law (providing the reading you asked for).

No sale or sharing. We do not sell personal information and do not share it for cross-context behavioural advertising, and have not done so in the past 12 months. We have no actual knowledge of selling or sharing the personal information of consumers under 16.

Your rights. You have the right to know what personal information we collect, use and disclose; to access a copy; to delete it; to correct it; and to limit the use of sensitive personal information (we already limit it to permitted purposes). Because we do not sell or share personal information, there is nothing to opt out of. To make a request, see section 11. You may use an authorised agent.

Non-discrimination. We will not discriminate against you for exercising your privacy rights, for example by denying you the service or charging a different price.

Other US states

Residents of states with comprehensive privacy laws, including Virginia, Colorado, Connecticut, Utah, Texas and Oregon (and other states with similar laws), may have rights, where those laws apply to us, to:

To make a request, see section 11. Appeals: if we decline your request, you can appeal by replying to our decision with the subject "Privacy appeal". We will respond within the period required by your state's law. If you are not satisfied with the outcome, you may contact your state Attorney General.

Children (COPPA)

See section 17.

15. Canada

We handle personal information in line with the Personal Information Protection and Electronic Documents Act (PIPEDA). By choosing to use cloud reading or the location hint, you consent to the processing described in this policy, including processing in the United States, where it may be accessible to authorities under local law. You can withdraw consent at any time by not using those features. You can access and correct your information (see section 11) and complain to the Office of the Privacy Commissioner of Canada: https://www.priv.gc.ca.

16. New Zealand

We handle personal information in line with the Privacy Act 2020 and its Information Privacy Principles, including the rules on sending information overseas (IPP 12). You can access and correct your information (see section 11). If you are not satisfied with our response, you can complain to the Office of the Privacy Commissioner: https://www.privacy.org.nz.

17. Children

Rosetta Lens is a general-audience app. It is not directed at children under 13 (or under 16 in the EEA and UK, or the relevant age in your country), and we do not knowingly collect personal information from them. This is consistent with the US Children's Online Privacy Protection Act (COPPA). If you believe a child has provided personal information through the App, contact us at [CONTACT EMAIL] and we will delete it.

18. Future model training

We do not currently offer, and do not carry out, any use of your photos to train models. If we ever offer the option to share photos to help improve our models, it will be a separate, explicit opt-in. It will be off by default, and we will update this policy before it starts.

19. Changes to this policy

We may update this policy from time to time, for example when we change the App or when the law changes. We will post the new version at this page and change the "Last updated" date. If a change is significant, we will also tell you in the App or through the app store listing before it takes effect, and where the law requires it, ask for your consent.

20. Contact us

For any privacy question, request or complaint: