Effective date: 28 August 2026
Last updated: 28 August 2026
This policy explains how Rosie AI (“Rosie”, “we”, “us”) collects, uses, stores, and shares personal information. Rosie is a family assistant at https://rosieai.xyz. The parent or guardian who creates the household is the account holder. Children use the service only through a profile that parent has created.
This policy covers the website, the web app (including when you add Rosie to a phone Home Screen), and related emails or notifications. It is written for families in Australia and for households who use Rosie from elsewhere. It is not legal advice.
If you do not agree with this policy, do not create an account or let a child use Rosie.
Rosie AI is operated from Australia. For privacy questions, access requests, deletion requests, or complaints, email hello@rosieai.xyz.
Parents and guardians. The adult who signs up is responsible for the household, including every child profile, co-parent they invite, and how Rosie is used.
Co-parents. A parent may invite another adult to share the household. That person can see and help supervise the same family wallet, profiles, and parent tools.
Children. Rosie is meant for families. We do not treat a child as a separate adult customer. A child profile belongs to the parent’s household. A parent may optionally link a child’s email so the child can sign in on their own device. That login stays on the existing child profile. It does not create a new household or a separate adult account.
If you are a child, ask a parent before using Rosie.
We collect what we need to run a supervised family assistant, take prepaid payments, and let parents review and control use.
We do not store full card numbers. Stripe processes cards.
New households can start with a small amount of free credit and no card. If you later buy credit or turn on auto-reload, Stripe handles that payment.
We do not use children’s profiles to serve third-party advertising.
We use personal information to:
We do not sell personal information. We do not sell children’s data. We do not use personal information to advertise other companies’ products to children.
Rosie is a parent-guided service. A parent must create the household before a child can use it.
We collect a child profile’s name, age, PIN hash, chats, images, memories (held for parent approval when taken from a child’s chat), optional login email, and usage so the parent can supervise the household.
Parents can:
We do not require a child to provide more information than the product needs. We do not sell children’s data. We do not use children’s data for third-party marketing.
This policy describes what we do. It is not a certification under the US Children’s Online Privacy Protection Act (COPPA) or any other children’s privacy scheme. If you need a formal COPPA programme (verifiable parental consent records, designated US operator, and so on), that is a separate piece of work.
If you believe we have a child’s information without a parent’s authority, email hello@rosieai.xyz and we will look into it.
We share information with the companies that actually run parts of Rosie. They are only allowed to use it to provide their service to us.
| Who | What they do | What they typically receive |
|---|---|---|
| Sign-in provider | Sign-in and sessions for parents, co-parents, and optional child email logins | Name, email, authentication identifiers, session cookies |
| Stripe | Prepaid credit payments and refunds | Payment details, email, purchase amounts, payment status |
| xAI | Grok 4.6 chat replies, image generation, automated safety checks, and web search | Prompts, name, age, approved memories, recent chat, images, and questions sent to search |
| Hosting provider | Hosts the website and app | Technical request data and logs |
| File storage provider | Stores uploaded and generated image files | Image files and the identifiers needed to fetch them |
We may also share information:
We do not sell personal information to data brokers.
Overseas disclosure: our sign-in, hosting, file storage, payment (Stripe), and AI (xAI) providers are typically based in the United States. If you use Rosie from Australia, that is an overseas disclosure of personal information. We use these providers because the product cannot run without sign-in, hosting, payments, and the Grok model.
We use cookies and similar technology that are needed to sign in, keep you signed in, and run the site. Our sign-in provider sets session cookies for that purpose.
You can block cookies in your browser. If you block essential cookies, sign-in and the app may not work.
Optional browser notifications use the browser’s own permission prompt. You can turn those off in the browser or in parent settings.
We keep household, profile, chat, image, memory, ledger, and alert records while the household account is open, so parents can review and control the service.
If a parent wipes a child’s history, we remove that child’s chats, memories, and image records from the app, and we delete the image files from our file storage. Wipe does not remove the child profile, usage records, safety alerts, or the credit ledger.
If a parent deletes a child profile, we remove that profile and its chats, memories, and image records from the app, and we delete the image files from our file storage. If the child had their own email login, that sign-in account may still exist until it is deleted with the sign-in provider.
If the household owner deletes household data under Parent → Account, we remove the family’s data from Rosie, including image files in storage. Payment records stay with Stripe. The Stripe customer is not deleted. Sign-in accounts may still exist until they are deleted with the sign-in provider.
We may keep limited records (for example, payment records, safety incidents, or deletion confirmations) where we need them for billing, security, or the law.
Stripe and our sign-in provider keep their own records under their policies.
We use industry-standard measures appropriate to a family app, including hashed PINs, authenticated sessions, and access limited to people who operate the service.
No method of transmission or storage is completely secure. Do not put highly sensitive information into chats (passwords, full medical records, or a child’s precise location on a regular basis) unless you understand it will be stored and sent to our AI provider.
You can ask us to:
Email hello@rosieai.xyz. We may need to verify that you are the parent or account holder before we act on a request about a child.
If you are in Australia and you are not satisfied with our response, you can complain to the Office of the Australian Information Commissioner: https://www.oaic.gov.au.
If you are in the European Economic Area or the United Kingdom, you may also have rights to object, restrict processing, or complain to your local regulator. Rosie is run from Australia; contact us first at hello@rosieai.xyz.
Credits are prepaid. They are consumed as the household chats and generates images. They are not a subscription.
Payment card data is processed by Stripe. Their privacy policy is at https://stripe.com/privacy. Refunds, if any, are handled through Stripe.
Chat prompts, relevant context (including the child’s display name, age, and approved memories), and images needed for a reply or a safety check are sent to xAI so Grok can generate a response or an image. We may also send a question to web search through xAI. That processing usually happens outside Australia.
Do not treat Rosie as a source of professional medical, legal, or school-enrolment advice. Parents remain responsible for how children use the assistant.
Rosie may generate or display links to other sites. Their privacy practices are their own. This policy does not cover them.
We may update this policy. The “Last updated” date at the top will change. If a change is material, we will post the new policy on this page and, where it is reasonable, email the account holder.
Continued use after an update means the updated policy applies.
Rosie AI
Email: hello@rosieai.xyz
Website: https://rosieai.xyz
Related pages: Terms of use.
Questions: hello@rosieai.xyz