Back

Privacy Policy

Version 1.2 · Effective 11 September 2026

The short version

We keep your email, your goals and tasks, and your conversations with the guide. Your messages are sent to Anthropic so the guide can answer, and they are stored in a database in India. Nobody reads them for fun, we do not sell them, and they are not used to train AI models. There are no trackers and no advertising. Delete your account and it is all gone the same second.

1. Who is responsible

Roshii is run by one person, not a company. That person is the data controller for everything described here and can be reached at hello@roshii.io.

2. What we collect

Only what the app needs to work. There is nothing collected in the background.

  • Your account. Email address, a hashed password (never the password itself), the display name you choose, and the time zone your browser reports, which is what decides when your day rolls over.
  • What you are working on. Goals, tasks, deadlines, whether you completed or skipped each one, the notes you write when you check in, and your streak.
  • Your conversations. Every message you send the guide and every reply, along with a short summary written at the end of each day and a running description of how you tend to work, which the guide uses to sound like it remembers you.
  • Your onboarding answers. What you told us in the opening questions.

Roshii does not ask for your real name, your address, your phone number, your location, or any payment details, and there is nowhere to enter them. It does not read your contacts, calendar, or files.

3. The sensitive part, said plainly

People tell an accountability guide about their health, their moods, their work, and their worst days. Anything you type into the chat is stored, including that. If a message looks like you are struggling badly, the app flags it so the guide answers with support instead of coaching, and that flag is stored on the message. It is used to keep a hard day out of the long term description of how you work, and for nothing else. No human is notified, and no human reads it.

We would rather you knew that than found it out later. If there is something you would not want stored, do not type it.

4. Why we are allowed to hold it

We process your account details and your goals, tasks and messages to give you the service you asked for, which is the performance of our agreement with you. Where what you write reveals something about your health, we rely on your explicit consent, given by the second tick box at signup, which asks about exactly that and nothing else. You can withdraw that consent at any time by clearing your chat history or deleting your account. We keep a small amount of technical information, such as rate limit counts, because we have a legitimate interest in the service not being abused.

5. Who else sees it

Three companies process data on our behalf, and no one else. We do not sell your data, share it for advertising, or hand it to anyone for their own purposes.

  • Anthropic PBC (United States) runs the model behind the guide. Your message, your recent conversation, your goals and tasks, and the description of how you work are sent to Anthropic each time the guide replies or generates a plan. Under Anthropic's commercial terms this is not used to train their models.
  • Supabase hosts the database. Everything above is stored there, on servers in Mumbai, India.
  • Render hosts the app itself, on servers in Singapore. Its logs record requests and errors.

We may also disclose data if the law genuinely requires it, or to protect someone from serious harm. If that ever happens we will tell you unless we are forbidden from doing so.

6. Where your data goes

Because of the above, your data leaves the country you are in. It is stored in India, processed in Singapore, and sent to the United States for the guide to answer. If you are in the UK or the European Economic Area, that is an international transfer, and we rely on the standard contractual clauses in our providers' terms to make it lawful. If you are not comfortable with your data being handled in those places, Roshii is not for you.

7. Cookies

One cookie: a session cookie that keeps you signed in. It is HTTP only, sent only over HTTPS, and it lasts thirty days. It is strictly necessary for the app to work, which is why there is no cookie banner. There are no analytics cookies, no advertising cookies, no tracking pixels, and no third party scripts or fonts on any page.

8. How long we keep it

Your account data, tasks, goals, messages and summaries are kept for as long as your account exists, because the guide's memory is the product. There is no automatic expiry today. When you delete your account, all of it is deleted immediately from the live database, with no recovery period and no archived copy held by us. Provider backups may hold a copy for a short period before they roll over.

Clearing your chat history from the chat screen deletes those messages the same way.

9. Your rights

You can see everything Roshii holds about you inside the app: your tasks, your goals, your streak, your report, and your conversation. Beyond that you have the right to ask for a copy of your data, to have it corrected, to have it deleted, to restrict or object to what we do with it, and to withdraw consent. Depending on where you live these rights come from the UK or EU GDPR, from California law, or from local law, and we apply them to everybody rather than checking where you are first.

Deletion is a button in Settings and takes effect at once. For anything else, write to hello@roshii.io and we will answer within thirty days. We will never charge you for asking, and we will never treat you differently for having asked. If you are unhappy with how we handled it, you can complain to your local data protection authority. The two sections below spell this out for the UK and Europe, and for the United States.

10. If you are in the UK or Europe

The UK and EU GDPR apply to you, and this section says how.

  • Controller. The individual operator of Roshii, reachable at hello@roshii.io. Roshii is run by one person and not by a company, so there is no registered office to name.
  • Legal bases. Article 6(1)(b), performance of our contract with you, for your account, goals, tasks and messages. Article 6(1)(f), our legitimate interest in the service not being abused, for rate limiting and error logs. Article 9(2)(a), your explicit consent, for anything you write that reveals your health, given by the second tick box at signup, which is separate from your acceptance of the terms.
  • Withdrawing consent. Clear your chat history, or delete your account. Both take effect immediately. Withdrawing does not undo processing that already happened, and it does not affect your account details, which we hold under the contract.
  • Your rights. Access, rectification, erasure, restriction, objection, portability, and withdrawal of consent. Erasure is a button in Settings. For the rest, write to hello@roshii.io and we will answer within one month.
  • Automated decision-making. Roshii generates task suggestions, plans, and a description of how you tend to work. None of it produces a legal effect or anything similarly significant for you, so Article 22 does not apply. No decision about you is made by the app that you cannot simply ignore.
  • Transfers. Your data goes to India, Singapore, and the United States. None of those has a UK or EU adequacy decision covering this arrangement, so we rely on the standard contractual clauses in our providers' terms, together with the technical measures in section 13 below.
  • Complaints. Your national supervisory authority, or the Information Commissioner's Office in the UK. Please try us first.

We have not yet appointed an Article 27 representative in the EU or the UK, because Roshii is a closed beta with no general availability there. If that changes, one will be appointed and named here before it does.

11. If you are in the United States

HIPAA does not apply to Roshii. We are not a healthcare provider, a health plan, or a business associate of one. What you tell Roshii does not carry the protections that medical records carry, which is another reason not to type anything into it you would not want stored.

We do not sell your personal information, and we do not share it for cross-context behavioural advertising. We never have. There is no advertising in Roshii, no analytics, and no third party trackers, so there is nothing to opt out of and no Global Privacy Control signal for us to act on. If that ever changes, we will say so here first and give you a way to opt out before it starts.

Under California law, and under the comparable laws of Colorado, Connecticut, Virginia, Texas, Oregon, Montana and other states, you have the right to know what we collect, to get a copy of it, to correct it, and to have it deleted. The categories we collect are listed in section 2, why we collect them in section 4, and who receives them in section 5. We collect sensitive personal information, because what you write to the guide can reveal your health. We use it only to provide the service you asked for, never to infer characteristics about you for anyone else's purposes, and you consented to that separately at signup.

Exercise any of these by writing to hello@roshii.io, or delete everything yourself from Settings. We will not charge you, will not make the service worse for you, and will not ask you a second time to talk you out of it. If you want an authorised agent to act for you, send us their written permission. We may ask you to confirm the request from your account's email address, which is the only way we can tell it is you.

12. Consumer health data

This section is for people in Washington State, under the My Health My Data Act, and in Nevada, and it applies to everybody else too because it is easier to keep one promise than two.

  • What we collect. What you write to the guide, which may describe your physical or mental health, your moods, your sleep, your habits, or your treatment. Plus the flag the app sets on a message that appears to describe a crisis.
  • Why. Only to give you the service: so the guide can reply, so it remembers what you told it, and so a hard day is kept out of the long term description of how you work. Nothing else.
  • Who gets it. Anthropic, Supabase, and Render, as processors acting on our instructions and named in section 5. Nobody else. We do not sell consumer health data, and we will not, which under Washington law would require your separate written authorisation that we will never ask for.
  • Your rights. To know what we hold, to get a copy, and to have it deleted, including from our processors. Deleting your account does all of it at once. Write to hello@roshii.io if you would rather we did it, and we will confirm when it is done.
  • No inferences. We do not use what you write to infer a diagnosis, to score you, or to build a profile for anybody outside the app.

13. How it is protected

Passwords are stored as salted hashes and cannot be read back. Traffic runs over HTTPS, with HSTS and a content security policy set. Every page that touches your data requires you to be signed in, forms carry cross site request forgery tokens, and every request reads your data by the identity in your session rather than by anything the browser sends. The database is reachable only by the app.

No system is perfectly secure, and we will not pretend otherwise. If a breach happens that puts you at risk, we will tell you and the relevant regulator without undue delay, and within seventy two hours where the law requires it.

14. Children

Roshii is for people 18 and over. We do not knowingly collect anything from a child. If we learn that a minor has an account we will delete it and everything in it. If you are a parent or guardian and think that has happened, write to hello@roshii.io.

15. Changes

If this policy changes, the version and date at the top change with it, and we will tell you in the app or by email before anything material takes effect.

Questions, requests, or complaints: hello@roshii.io. A real person answers.