Last updated: 5 July 2026. Version: 2026-07-05-v1
This Privacy Policy describes how personal data is processed within the Roro Vision service, in accordance with Regulation (EU) 2016/679 (GDPR) and the French Data Protection Act No. 78-17 of 6 January 1978, as amended.
The data controller is Alexandre Khalifé, a sole trader operating under the trade name "Roro Vision", SIREN 989 113 352 (Créteil Trade and Companies Register), whose registered office is at 29 Boulevard Henri Ruel, 94120 Fontenay-sous-Bois, France.
For any question regarding your data or to exercise your rights: support@roro.vision. Phone: +33 7 82 03 85 21.
In accordance with Article 6(1) of the GDPR, processing is based, depending on the purpose, on:
The service neither solicits nor requires health data. However, as part of general-purpose use (for example reading a medication dosage), a user may voluntarily provide information that may fall within Article 9 of the GDPR (special categories of data). Such information is processed solely to answer the user's specific request.
We use the following processors, which act only on our documented instructions:
| Processor | Role | Location / transfer | Transfer safeguard |
|---|---|---|---|
| Google (Gemini / Cloud / Vertex AI) | Generative AI (session photos and transcription) | EU regions available; inference may occur outside the EU | EU-US Data Privacy Framework (DPF) and Standard Contractual Clauses (SCC) |
| LiveKit Cloud | Real-time audio/video infrastructure | Regional pinning possible; observability outside the EU | DPF, Standard Contractual Clauses (SCC) and UK IDTA |
| AssemblyAI | Voice transcription (speech-to-text) of the user's speech during sessions | EU endpoint (Dublin); company based in the United States | Standard Contractual Clauses (SCC) and AssemblyAI DPA |
| Supabase | Database, storage and authentication | EU region (Frankfurt) | Standard Contractual Clauses (SCC) |
| Fly.io | Backend and worker hosting | EU region (Paris) | EU-US Data Privacy Framework (DPF) |
| RevenueCat | Subscription and purchase management | United States infrastructure | Standard Contractual Clauses (SCC) |
| Sentry | Error monitoring | EU residency option | DPF and Standard Contractual Clauses (SCC) |
| PostHog | Usage analytics (can be enabled / disabled) | PostHog Cloud EU (Frankfurt) | Standard Contractual Clauses (SCC) |
To measure the effectiveness of our advertising campaigns, the application embeds the SDK of Meta Platforms Ireland Limited (Merrion Road, Dublin 4, Ireland). Unlike the processors above, Meta acts as a separate data controller for this measurement. The data processed is limited:
This measurement is enabled by default and can be disabled at any time via the app's analytics setting (the same setting as usage analytics). The first technical events (install, first app launch) may however be sent before that choice is expressed. Transfers to the United States are governed by the EU-US Data Privacy Framework and Standard Contractual Clauses (SCC). More information: Meta Privacy Policy.
The roro.vision website, a presentation page that directs visitors to the App Store and Google Play Store, additionally embeds the Meta pixel. It sets a cookie (_fbp) and sends Meta the page view as well as clicks on the download buttons, as an expression of interest: no download is recorded at this stage, since the actual install is measured only on the application side. No directly identifying data (name, email address, phone) is sent to Meta from the website. You can limit this processing through your browser's cookie settings and your Meta ad preferences.
Where processing involves a transfer to a third country, it is governed by the appropriate safeguards under Articles 44 to 49 of the GDPR: Standard Contractual Clauses adopted by the European Commission (Article 46) and, where applicable, a processor's participation in the EU-US Data Privacy Framework (adequacy decision).
Account deletion is preceded by a 30-day cooling-off period during which the account can be reactivated.
Under Articles 15 to 21 of the GDPR, you have the following rights:
To exercise these rights, contact support@roro.vision.
The role of Data Protection Officer is held by the director of Roro Vision, who can be reached at support@roro.vision.
Under Article 77 of the GDPR, you have the right to lodge a complaint with a supervisory authority. In France, the competent authority is the Commission nationale de l'informatique et des libertés (CNIL). cnil.fr.
The service is not intended for children under 15. In France, consent to data processing in the context of online services requires a minimum age of 15 (Article 8 of the French Data Protection Act).
At launch, data is hosted in the European Union (single region). Any transfers to processors located outside the EU are governed in accordance with section 7.
The Roro Vision mobile application does not use cookies. Usage within the application is measured using PostHog (by means of a tracking identifier) and technical errors are collected via Sentry. Audience measurement can be disabled in the application settings. The roro.vision website, however, sets an advertising-measurement cookie (Meta pixel, _fbp cookie) described in section 6; this cookie can be controlled through your browser settings.
This policy may be updated. Users are informed of significant changes within the application.
Applicable official references.