Legal

Privacy Policy

Last updated July 1, 2026

This policy explains how ROSE collects, uses, and protects data. ROSE (“ROSE,” “we,” or “us”) provides an AI assistant platform at poweredbyrose.com. It covers the account data of business owners who use ROSE and the customer contact details their assistant collects on their behalf. This version is effective July 1, 2026.

Two roles: controller and processor

The law treats the same information differently depending on who decides how it is used, so it helps to be plain about our two roles:

  • For a business owner’s own account data — the email and avatar from their Google sign-in — ROSE is the data controller.
  • For the customer contact details an owner’s assistant collects on their behalf — a customer’s name, requested time, phone number, and any notes — the business owner is the controller and ROSE acts as a processor, handling that data only on the owner’s instructions.

What we collect and why

  • Owner account. Your Google email and avatar, received through Google sign-in (Google OAuth), so we can create and secure your account.
  • Lead data. A customer’s name, requested time, phone number, and any optional notes — captured by the owner’s assistant and shown to the owner so they can follow up.
  • Chat messages. Text a visitor types to a Rose assistant is sent to our AI inference provider to generate a reply. It is used only to produce that response and is not used to train AI models.
  • Technical data. An IP address is processed transiently for bot protection and rate limiting (see sub-processors below).

What we don’t do

These are commitments, not aspirations:

  • Conversation messages are not stored in our database. The chat is stateless — we don’t keep a transcript.
  • Where we log automated-abuse signals, an IP address is stored only as a salted, one-way hash — never the raw IP — and no message content is stored.
  • We use no analytics, no tracking cookies, and no advertising technology.

Sub-processors

We rely on a few trusted providers that process data on our behalf under their own terms:

  • Supabase — database and authentication storage.
  • Google — owner sign-in.
  • Anthropic — AI inference for assistant replies.
  • Cloudflare Turnstile — bot protection (receives IP).
  • Upstash — rate limiting (uses IP transiently).
  • Email-delivery service — sends the owner a notification when their assistant captures a lead.

Cookies

We use only the essential Supabase authentication session cookie, which keeps an owner signed in. A temporary browser sessionStorage value briefly holds an in-progress setup across sign-in. There are no tracking or advertising cookies.

Data retention

Account and lead data are kept while the account is active. Owners can request deletion at any time.

How we protect data

Access to stored data is restricted by database-level security rules, so each business owner can reach only their own records. Data is transmitted over encrypted connections (HTTPS), and our secrets and keys are held in encrypted configuration, never in our code.

Your choices and requests

To request access to or deletion of your data, email support@poweredbyrose.com. For lead data that an owner controls, end customers should contact that business directly; owners can also reach us for help.

Children

ROSE is a business tool and is not directed to anyone under 18.

Changes to this policy

We may update this policy from time to time. The “last updated” date above always reflects the latest version.

Contact

Questions? Email support@poweredbyrose.com. Our mailing address is available on request.