Privacy Policy
Rosetta Lens Privacy Policy
Last updated: 11 October 2026
This Privacy Policy explains how the Rosetta Lens mobile app for iOS and Android (the "App") handles your information. Rosetta Lens helps you read ancient inscriptions (such as Egyptian hieroglyphs, ancient Greek and cuneiform) from photos you take.
The App is operated by [LEGAL ENTITY NAME] (ABN [ABN]), trading as ethosec, of Queensland, Australia ("we", "us", "our").
Summary at a glance
- Your photos stay on your phone by default. Readings are made on your device by on-device models. On the Free and [MIDDLE PLAN NAME] plans, photos are never uploaded.
- Cloud reading is optional, Pro-only and per photo. If you are on the Pro plan and choose a cloud reading for a photo, that photo and a few related details are sent securely to our server and on to xAI's Grok API (USA) to produce the reading. We do not store your photo. The finished reading text is kept for up to 10 minutes and then deleted.
- No account, no name, no email. The App does not ask you to sign up. On the Free and [MIDDLE PLAN NAME] plans, your reading counts stay on your phone. We use a purchase or install identifier only to count cloud readings and track reading-pack and trip-pass balances.
- No ads, no third-party analytics or tracking SDKs, and we do not sell your information or share it for cross-context behavioural (targeted) advertising.
- Location is optional. You can add a location hint to improve a reading. GPS is used only if you turn it on and grant permission.
- Payments are handled by Apple or Google. We receive purchase status, never your card or payment details.
- You have rights to access, correct and delete your information, and to complain to a regulator. Contact us at [CONTACT EMAIL].
Contents
- Who we are
- Information we handle
- How cloud reading works
- How and why we use information
- Permissions on your device
- Who we share information with
- International transfers
- How long we keep information
- Security
- Your choices and controls
- Your rights and how to make a request
- Australia
- European Economic Area and United Kingdom
- United States
- Canada
- New Zealand
- Children
- Future model training
- Changes to this policy
- Contact us
1. Who we are
Rosetta Lens is provided by [LEGAL ENTITY NAME] (ABN [ABN]), trading as ethosec, an Australian business based in Queensland and run by Brent Roberts.
- Email: [CONTACT EMAIL]
- Post: [POSTAL ADDRESS]
For the purposes of the EU and UK General Data Protection Regulation (GDPR), we are the controller of the personal data described in this policy that leaves your device. Under the Australian Privacy Act 1988 we are the entity responsible for that personal information.
2. Information we handle
Information that stays on your device
This information is created and stored only on your phone. We do not receive it unless you use cloud reading (see section 3).
- Photos you take or choose from your photo library, and the readings produced by the on-device models.
- Reading history: a history of your readings, stored locally in the App.
- Reading counters: on the Free and [MIDDLE PLAN NAME] plans, the count of readings you have used is kept only on your phone; we never receive it. On iOS this may be stored in the iOS Keychain, which can persist if you delete and reinstall the App.
- Location hint (optional): if you add a country, region or site, or allow GPS, it may be used on your device to improve the reading.
Information we receive
| What | When | Why |
|---|---|---|
| Purchase or install identifier: currently a beta token; later, the Apple App Store original transaction ID or Google Play purchase token | When you use the App's plan features | To recognise your plan and count readings |
| Cloud-reading usage and balances: the number of cloud readings used against the Pro monthly allowance, and reading-pack and trip-pass balances. Free and [MIDDLE PLAN NAME] reading counts are not sent to us | When you use cloud reading or buy a pack or pass | To apply plan limits and balances |
| Purchase status from Apple or Google (for example, which plan or pack was bought and whether it is active) | When you buy or restore a purchase | To give you what you paid for |
| Cloud reading request (Pro plan only, only when you choose it for a photo): the photo, the script you chose, the optional location hint (country/region/site, and GPS coordinates only if you enabled GPS), and the on-device reading text | Each time you request a cloud reading | To produce the cloud reading |
| Cloud reading result: the finished reading text | After a cloud reading | So the App can retrieve it if your connection drops (kept up to 10 minutes) |
| Technical and security data: IP address and request metadata (for example, time, request path, status) processed by Cloudflare; AI gateway logs of time, model, token counts, cost, status and duration | When the App contacts our server | Security, abuse prevention, reliability and cost control |
What we do not collect: your name, email address, phone number, contacts, payment card details, advertising identifiers, or browsing activity in other apps or websites. The App has no account or sign-up.
A note on photos: inscriptions rarely contain personal information, but a photo can capture people, faces, or other details in the background. Please avoid including people in photos you send for cloud reading.
3. How cloud reading works
Cloud reading is available only on the Pro plan and happens only when you choose it for a particular photo. Nothing is uploaded automatically.
- The App sends the photo, chosen script, optional location hint and on-device reading text over an encrypted (HTTPS) connection to our server at api.rosettalens.net, which runs on Cloudflare Workers.
- Our server forwards the request to xAI's Grok API (in the USA), which produces the reading.
- We do not store your photo. It is handled in memory only to pass the request to xAI.
- Cloudflare AI Gateway records metadata only (time, model, token counts, cost, status and duration). It does not log the photo or the content of the request or response.
- The finished reading text is held on our server for up to 10 minutes so the App can collect it if your connection drops. It is then deleted.
xAI processes the request as our service provider, in line with its API terms and data policy. See xAI's privacy policy: https://x.ai/legal/privacy-policy. Any retention by xAI is governed by xAI's API data policy. We do not use your photos or readings to train our own models.
4. How and why we use information
We use information only for these purposes:
| Purpose | Information used | GDPR lawful basis |
|---|---|---|
| Producing cloud readings you request | Cloud reading request and result | Performance of our contract with you |
| Recognising your plan, counting readings and applying pack and trip-pass balances | Purchase or install identifier, usage counts and balances, purchase status | Performance of our contract with you |
| Using precise (GPS) location to improve a reading | GPS coordinates (only if you enable it) | Your consent, which you can withdraw at any time |
| Using a typed location hint (country/region/site) to improve a reading | Location hint | Performance of our contract with you (you choose to provide it) |
| Keeping the service secure, preventing abuse and fraud, rate limiting, and managing reliability and costs | IP address, request metadata, gateway metadata, identifier and usage counts | Our legitimate interests in protecting the service and its users |
| Complying with law, resolving disputes and responding to lawful requests | Any of the above, as needed | Compliance with legal obligations; legitimate interests |
| Answering your emails and privacy requests | What you send us | Legitimate interests; legal obligations (for rights requests) |
We do not use your information for advertising, profiling, or automated decisions that have legal or similarly significant effects on you.
Where we rely on legitimate interests, we have balanced our interests against your rights. You can ask us for more detail and you can object (see section 11).
5. Permissions on your device
- Camera: to take photos of inscriptions.
- Photo library: to choose existing photos to read.
- Location (optional): to add a GPS-based location hint. The App works without it.
You can grant or withdraw these permissions at any time in your phone's settings. If you refuse a permission, only the feature that needs it will be unavailable.
6. Who we share information with
We do not sell your personal information and we do not share it for cross-context behavioural advertising. We disclose information only to the service providers we need to run the App:
| Provider | Role | Location |
|---|---|---|
| Cloudflare, Inc. | Hosts our server (Workers) and AI Gateway; provides network security (TLS, web application firewall, rate limiting) and processes request metadata such as IP address | USA and global network |
| xAI | Provides the Grok API that produces cloud readings | USA |
| Apple | App distribution and in-app purchases (App Store) | USA and global |
| App distribution and in-app purchases (Google Play) | USA and global |
Apple and Google handle payments under their own privacy policies; we receive purchase status, not payment details. If you have opted in at the operating-system level, Apple or Google may also provide us with aggregated app performance and crash statistics under their own terms.
We may also disclose information if required by law, to protect rights, safety or security, or as part of a sale or restructure of our business (in which case this policy will continue to apply to your information or you will be notified).
7. International transfers
We are based in Australia, but our service providers process information in the United States and in other countries where Cloudflare operates. This means your information may be transferred outside Australia, the EEA, the UK, Canada or New Zealand.
When we transfer information, we take reasonable steps to make sure it is protected, including by using providers that commit by contract to protect it. For transfers from the EEA or UK, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses, the UK International Data Transfer Addendum, or the EU–US Data Privacy Framework (and its UK Extension) where the provider is certified. You can contact us for more information about these safeguards.
8. How long we keep information
| Information | Where | How long |
|---|---|---|
| Photos (on-device reading) | Your phone | Until you delete them; we never receive them |
| Photo sent for cloud reading | Our server (in memory) | Not stored; discarded once passed to xAI. Any retention by xAI is per xAI's API data policy |
| Cloud reading result (reading text) | Our server | Up to 10 minutes, then deleted |
| Reading history | Your phone | Until you delete it in the App or uninstall the App |
| Free and [MIDDLE PLAN NAME] reading counters | Your phone only (iOS Keychain on iOS) | Until you uninstall the App; on iOS it may persist after reinstall until the device is reset |
| Purchase or install identifier, cloud-reading usage and pack/trip-pass balances | Our server | While your plan, packs or passes can still be used, then deleted within 13 months of your last activity (reading packs expire 12 months after purchase) |
| AI Gateway metadata logs (no request or response content) | Cloudflare | Up to 30 days, then deleted |
| Security and request logs (including IP address) | Cloudflare | Per Cloudflare's retention for our plan: security events and traffic analytics up to 31 days; server (Worker) logs up to 7 days |
| Emails and privacy requests | Our email | 2 years after the request is closed, or longer if needed for legal reasons |
9. Security
We protect information using measures that include:
- encryption in transit (TLS/HTTPS) for all communication between the App and our server;
- keeping secrets and API keys on the server, never in the App;
- rate limiting and a web application firewall (WAF) to prevent abuse;
- collecting as little as possible and deleting cloud reading results quickly.
No system is perfectly secure. If a data breach is likely to cause serious harm, we will notify affected people and regulators as required by law, including under Australia's Notifiable Data Breaches scheme.
10. Your choices and controls
- Stay fully on-device: don't use cloud reading. On the Free and [MIDDLE PLAN NAME] plans, photos are never uploaded.
- Location: leave the location hint blank and keep GPS off, or turn off location permission in your phone's settings.
- Reading history: delete readings in the App, or uninstall the App to remove locally stored data.
- Permissions: change camera, photo and location access in your phone's settings at any time.
11. Your rights and how to make a request
Depending on where you live, you may have the right to:
- access the personal information we hold about you, and receive a copy (including in a portable format);
- correct inaccurate information;
- delete your information;
- object to or restrict certain processing, including processing based on legitimate interests;
- withdraw consent at any time (for example, for GPS location), without affecting earlier processing;
- complain to a privacy regulator (see the regional sections below).
How to make a request: email [CONTACT EMAIL] with the subject "Privacy request" and tell us what you would like us to do.
Verification: because the App has no accounts, we hold very little that identifies you. To find your records and confirm they are yours, we may ask for your App identifier (shown in the App at [IN-APP LOCATION OF IDENTIFIER, e.g. Settings > About]) or details from your App Store or Google Play purchase receipt. We will use this only to handle your request. If we cannot reasonably verify the request, we will tell you why.
Timing: we aim to respond within 30 days, and within any shorter or different period required by your local law (for example, one month under the GDPR, extendable in some cases, or 45 days under California law, extendable once by a further 45 days). We do not charge a fee unless the law allows it for requests that are clearly unfounded or excessive.
Please note: deleting your purchase identifier and usage records may mean we can no longer recognise remaining pack or trip-pass balances. Apple and Google hold your purchase records under their own policies.
You may use an authorised agent where the law allows; we may ask for proof of their authority and may ask you to verify your identity directly.
12. Australia
We handle personal information in line with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).
- Anonymity (APP 2): you can use the App without giving us your name or contact details.
- Cross-border disclosure (APP 8): we disclose personal information to overseas recipients, mainly in the United States (Cloudflare and xAI) and in other countries where Cloudflare, Apple and Google operate. Before doing so, we take reasonable steps to ensure those recipients handle it consistently with the APPs, including through their contractual terms.
- Access and correction (APPs 12 and 13): see section 11.
- Complaints: please contact us first at [CONTACT EMAIL]. We will acknowledge your complaint and aim to respond within 30 days. If you are not satisfied, you can complain to the Office of the Australian Information Commissioner (OAIC): https://www.oaic.gov.au, phone 1300 363 992.
13. European Economic Area and United Kingdom
If you are in the EEA or the UK, the GDPR or UK GDPR applies to our processing of your personal data.
- Controller: [LEGAL ENTITY NAME], contact details in section 1.
- Lawful bases: see the table in section 4. In summary: contract for cloud readings and plan management; legitimate interests for security and abuse prevention; consent for GPS location.
- Your rights: access, rectification, erasure, restriction, data portability, objection, and withdrawal of consent (see section 11). We do not make decisions about you based solely on automated processing that have legal or similarly significant effects.
- International transfers: see section 7.
- Representative: [EU REPRESENTATIVE NAME AND CONTACT DETAILS, IF APPOINTED UNDER ARTICLE 27 GDPR] / [UK REPRESENTATIVE NAME AND CONTACT DETAILS, IF APPOINTED UNDER ARTICLE 27 UK GDPR].
- Complaints: you have the right to lodge a complaint with a supervisory authority, in particular in the country where you live or work or where an alleged infringement took place. EEA authorities are listed at https://edpb.europa.eu/about-edpb/about-edpb/members_en. In the UK, contact the Information Commissioner's Office (ICO): https://ico.org.uk.
Providing information for cloud reading is necessary to deliver that feature; if you do not provide it, you can still use on-device readings.
14. United States
California (CCPA/CPRA)
This section applies to California residents to the extent the California Consumer Privacy Act, as amended by the California Privacy Rights Act, applies to us.
Notice at Collection. In the past 12 months we have collected the following categories of personal information, for the purposes in section 4, and keep them for the periods in section 8:
| CCPA category | Examples | Source | Disclosed for a business purpose to |
|---|---|---|---|
| Identifiers | Purchase or install identifier; IP address | You and your device; Apple or Google | Cloudflare; Apple or Google |
| Commercial information | Purchase status, plan, pack and trip-pass balances, cloud-reading counts | You; Apple or Google | Cloudflare |
| Internet or other electronic network activity | Request and gateway metadata | Your device | Cloudflare |
| Geolocation data | Optional location hint; precise GPS location only if you enable it | You and your device | Cloudflare; xAI |
| Audio, electronic, visual or similar information | Photos sent for cloud reading (Pro only) | You | Cloudflare; xAI |
| Sensitive personal information | Precise geolocation (only if you enable GPS) | Your device | Cloudflare; xAI |
We do not collect sensitive personal information for the purpose of inferring characteristics about you, and we use it only for purposes permitted by law (providing the reading you asked for).
No sale or sharing. We do not sell personal information and do not share it for cross-context behavioural advertising, and have not done so in the past 12 months. We have no actual knowledge of selling or sharing the personal information of consumers under 16.
Your rights. You have the right to know what personal information we collect, use and disclose; to access a copy; to delete it; to correct it; and to limit the use of sensitive personal information (we already limit it to permitted purposes). Because we do not sell or share personal information, there is nothing to opt out of. To make a request, see section 11. You may use an authorised agent.
Non-discrimination. We will not discriminate against you for exercising your privacy rights, for example by denying you the service or charging a different price.
Other US states
Residents of states with comprehensive privacy laws, including Virginia, Colorado, Connecticut, Utah, Texas and Oregon (and other states with similar laws), may have rights, where those laws apply to us, to:
- confirm whether we process their personal data and access it;
- correct inaccuracies;
- delete their personal data;
- obtain a portable copy;
- opt out of the sale of personal data, targeted advertising, and profiling with legal or similarly significant effects (we do none of these);
- give or withdraw consent for processing sensitive data. We process precise geolocation only if you choose to enable GPS.
To make a request, see section 11. Appeals: if we decline your request, you can appeal by replying to our decision with the subject "Privacy appeal". We will respond within the period required by your state's law. If you are not satisfied with the outcome, you may contact your state Attorney General.
Children (COPPA)
See section 17.
15. Canada
We handle personal information in line with the Personal Information Protection and Electronic Documents Act (PIPEDA). By choosing to use cloud reading or the location hint, you consent to the processing described in this policy, including processing in the United States, where it may be accessible to authorities under local law. You can withdraw consent at any time by not using those features. You can access and correct your information (see section 11) and complain to the Office of the Privacy Commissioner of Canada: https://www.priv.gc.ca.
16. New Zealand
We handle personal information in line with the Privacy Act 2020 and its Information Privacy Principles, including the rules on sending information overseas (IPP 12). You can access and correct your information (see section 11). If you are not satisfied with our response, you can complain to the Office of the Privacy Commissioner: https://www.privacy.org.nz.
17. Children
Rosetta Lens is a general-audience app. It is not directed at children under 13 (or under 16 in the EEA and UK, or the relevant age in your country), and we do not knowingly collect personal information from them. This is consistent with the US Children's Online Privacy Protection Act (COPPA). If you believe a child has provided personal information through the App, contact us at [CONTACT EMAIL] and we will delete it.
18. Future model training
We do not currently offer, and do not carry out, any use of your photos to train models. If we ever offer the option to share photos to help improve our models, it will be a separate, explicit opt-in. It will be off by default, and we will update this policy before it starts.
19. Changes to this policy
We may update this policy from time to time, for example when we change the App or when the law changes. We will post the new version at this page and change the "Last updated" date. If a change is significant, we will also tell you in the App or through the app store listing before it takes effect, and where the law requires it, ask for your consent.
20. Contact us
For any privacy question, request or complaint:
- Email: [CONTACT EMAIL]
- Post: [LEGAL ENTITY NAME], [POSTAL ADDRESS], Queensland, Australia