MyRoshi

Privacy Policy

Last updated: 22 August 2026

This policy explains what MyRoshi collects and how it is handled, whether you use the MyRoshi mobile app (iOS or Android) or the website. MyRoshi is operated by Saravanakumar D, an individual sole proprietor (“we”, “us”), based in India — the data controller under the EU/UK GDPR and the Data Fiduciaryunder India’s Digital Personal Data Protection Act, 2023. Privacy contact: admin@myroshi.com.

The short version

Your practice content is stored encrypted under a key that only you hold — we never keep a copy of that key, so the archive on our servers cannot be opened by us, or by anyone who steals it. To write you a talk your teacher must read what you wrote, so your key travels with that request, is used in memory, and is discarded. We never see your card details. We don’t sell your data, show ads, or track you across other apps. We collect the minimum needed to run the Service.

What we collect

  • Account: your email address (via Sign in with Google, Sign in with Apple, or an email-and-password account) and basic account status. We do not store your name, even when the sign-in provider offers it. If you use Apple’s “Hide My Email”, we only ever see the relay address.
  • Payment: purchases are made through Apple’s App Store or Google Play and managed with RevenueCat. We receive only a subscription status and transaction identifiers — we never receive or store your card details.
  • Your practice content (spoken/typed reflections, journals, and generated talks): stored encrypted in a per-user vault (AES-256-GCM). The key is held on your device and sent with each request so your teacher can read and answer you; it is used in memory and never written to our storage. We cannot read the vault at rest.
  • Voice recordings: a recording you make is uploaded, held in memory only, transcribed, and then deleted — it is not written to our server’s disk and the temporary copy is removed after processing.
  • Device data: a push-notification token (so your phone can be told a talk is ready) and basic device identifiers used by our subscription and diagnostics tools.
  • Usage and diagnostics: which features are used and when (analytics via PostHog) and crash/performance reports (via Sentry), associated with your account ID so we can fix what breaks for you. These never include the content of your practice — no reflections, no talks, not even their titles.

How your reflection is processed

To generate a talk, your reflection is transcribed and sent, together with reference texts, to our AI processors for that single generation: speech recognition and drafting run on Microsoft Azure, talk writing on Anthropic models, and the voice is synthesized on our own servers (with Modal as backup infrastructure). Your words are used only to produce your talk and are not used to train models. The resulting talk is returned to you and stored encrypted.

Your reflections, and what is never done with them

MyRoshi provides free-form text areas for personal reflection. We treat all journal entries as unstructured user content. We do not solicit, require, or categorize structured sensitive information regarding your health, religious beliefs, or philosophical practices — there is no field that asks, and nothing you write is sorted into such a category.

Your reflections are read by your teacher — an AI — for one purpose: to answer them. No human being reads them. We do not mine them for advertising, we never sell or share them, and nothing you write is used to train any model. Your teacher does keep notes on your practice between sessions, so that the teaching builds rather than starting over each time; those notes serve you and no one else, and they are stored under your key like everything else.

Your practice is stored encrypted under a key only you hold, and we never keep a copy of it — so the stored archive cannot be opened by us, or by anyone who takes it. If you lose your key, it cannot be recovered. The section below sets out exactly what that does and does not protect.

What the encryption does, and what it does not do

We would rather be exact about this than flattering. Your practice is encrypted at rest with AES-256-GCM, under a key that is generated on your device and that we never store. What sits on our disks is therefore unreadable to us, to anyone who steals a backup, and to anyone who compels us to hand one over — we have nothing to hand over but ciphertext.

What it is not is end-to-end encryption, and we will not call it that. Your teacher has to read what you wrote in order to answer it — that is the entire product — so your key is sent with your request, held in memory for as long as it takes to serve you, and then discarded. For the moments in which your talk is being composed, our servers can see your words. No product that answers you can honestly claim otherwise, and any app that promises you both a thinking teacher and end-to-end encryption is telling you a story.

The practical consequence is the one that matters to you: no human being reads your practice, nothing you write is shown to another user or sold to anyone, the stored archive cannot be opened by us — and if you lose your key, neither can you. We cannot reset it. There is no recovery. Back it up.

Why we use your data

  • To provide and secure the Service and your account.
  • To manage your subscription (via the app stores and RevenueCat).
  • To understand usage, fix crashes, and improve the Service.
  • To notify you when your talk is ready, if you allow notifications.
  • To contact you about your account, billing, or important changes.

Who we share with (processors)

  • Apple / Google — sign-in and mobile app purchases.
  • RevenueCat — subscription management for the mobile app.
  • Microsoft Azure — speech transcription and part of talk generation.
  • Anthropic — talk writing.
  • Modal — backup voice-synthesis infrastructure.
  • Railway — application hosting.
  • Cloudflare — website delivery and security.
  • Sentry — crash and performance reports.
  • PostHog — product analytics.

We do not sell your personal data, and we do not share it with data brokers or advertising networks.

International transfers

The Service runs on infrastructure in the United States (hosting, AI processing) and India (voice synthesis), with global providers that may process data outside your country, including in the United States and the EU. Where required, transfers rely on appropriate safeguards.

Retention

Encrypted practice content is kept until you delete it or close your account — deleting a talk in the app erases it from our servers. Temporary audio is deleted right after processing. Feedback you send the developer is kept while your account exists and is erased with it. Analytics and crash data are retained on our providers’ standard schedules. Billing records are retained by the stores as required for tax and accounting.

Your rights

Depending on where you live (including under the EU/UK GDPR and India’s Digital Personal Data Protection Act, 2023), you may have rights to access, correct, delete, or export your personal data, and to object to certain processing. To exercise them, email admin@myroshi.com. Note that because your practice content is encrypted with your own key, we can delete it but cannot read or reproduce it. If you lose your key, your content is unrecoverable — by design.

If you are in India (DPDP Act, 2023)

MyRoshi is operated from India, so the Digital Personal Data Protection Act, 2023 applies to us. In its terms we are the Data Fiduciary and you are the Data Principal. The companies listed under Who we share with are Data Processors, engaged under contract and acting only on our instructions.

What we rely on. We process your data on your consent, given when you create an account and use the Service, and limited to what each purpose needs. You may withdraw that consent at any time, and it is as easy to withdraw as it was to give: erase your practice and keep the account at Delete your data, or close the account entirely at Delete your account. Both take effect immediately. Where we must keep something afterwards, it is listed on those pages and nowhere else.

Your rights under the Act are to obtain a summary of the personal data we hold and how we process it; to have it corrected, completed, updated or erased; to nominate someone to exercise these rights if you die or become incapacitated; and to a grievance procedure, below. One honest limit applies to all of them: your practice content is sealed under a key we do not keep, so we can delete it but cannot read, correct or produce a copy of what is stored.

Grievance Officer

If you have a question or complaint about how we handle your data, write to Saravanakumar D, Grievance Officer, at admin@myroshi.com with “Grievance” in the subject. We aim to acknowledge within 3 working days and to resolve within 30 days. MyRoshi is run by one person; that is who will read it and who will answer.

If we do not answer, or you are not satisfied with the answer, you may complain to the Data Protection Board of India. Complaining to us first is not required, but it is usually faster.

If something goes wrong

If a personal data breach occurs, we will notify the Data Protection Board of India and every affected person, without waiting to judge whether the breach was serious — the Act sets no threshold, and neither do we. The notice will say what happened, what data was involved, what we are doing about it, and what you can do. Because practice content is encrypted with your own key, a breach of our servers would expose ciphertext we cannot read ourselves; we would still tell you.

Cookies and on-device storage

The website uses a strictly necessary cookie to keep you signed in; the mobile app keeps its session and your encryption key in your device’s secure storage. Our infrastructure providers may set cookies needed for security. We do not use advertising cookies, and the app contains no advertising or cross-app tracking SDKs.

Children

The Service is for adults. It is not intended for anyone under 18, and we do not knowingly collect data from anyone under 18. Under India’s Digital Personal Data Protection Act, 2023 — the law we operate under — a child is anyone under 18, and their data may only be processed with verifiable parental consent. We have deliberately not built a way to obtain that consent, because we do not think this app is the right place for a minor to bring what it invites them to bring. If we learn that we hold data belonging to someone under 18, we delete it. Our reasons are set out in why MyRoshi is for adults.

Changes

We may update this policy; material changes will be posted here with a new “last updated” date.


HomeTermsRefundsContact