⚠️ DRAFT — NOT LEGAL ADVICE. This document was drafted as a starting point and MUST be reviewed, corrected and approved by a qualified solicitor / data protection specialist before use. It is likely incomplete and may be wrong in places.
rolo — Privacy Policy
Draft date: 2026-07-11 · Effective date: [EFFECTIVE DATE]
This policy explains what personal information rolo collects, why we collect it, who we share it with, and the rights you and your child have. We have tried to write it plainly. If anything is unclear, please contact us — details are at the end.
A note on the AIR relationship. rolo is built on a companion/friend service provided by AIR ([AIR LEGAL ENTITY]). rolo and AIR handle different parts of your child's data (see section 5). Whether AIR acts as our processor, or whether rolo and AIR are joint controllers, is still being determined. [LEGAL REVIEW NEEDED: resolve controller/processor status and put a Data Processing Agreement or joint-controller arrangement in place before publishing.]
1. Who we are
rolo is a service provided by [COMPANY LEGAL NAME] ("rolo", "we", "us", "our"), a company registered in England & Wales with company number [COMPANY NUMBER], whose registered address is [REGISTERED ADDRESS].
We are the data controller for the personal data described in this policy (subject to the open question about AIR, above).
- ICO registration number: [ICO REGISTRATION NUMBER]
- Data protection / privacy contact: [DPO / PRIVACY CONTACT EMAIL]
- General support: [SUPPORT EMAIL]
[LEGAL REVIEW NEEDED: confirm whether a formal DPO is required under UK GDPR Art 37, and name them if so.]
2. What rolo is, in a sentence
rolo is a calm companion-chat app for autistic children. A parent or guardian holds the account. The child talks to a friendly AI companion, and the grown-up can always read along and is alerted when something needs them. rolo is designed around a promise we call "watched over, never watched".
3. Who this policy is for
- The account holder — a parent or legal guardian (an adult). You sign up, you consent on your child's behalf, and this policy is addressed to you.
- The child — your child never has a login. We hold some information about your child, described below. There is a plain-language explanation for children in our safeguarding document.
- Observers — other adults you invite to read along (e.g. a second parent, grandparent or carer). See section 8.
4. The data split — how rolo is designed
rolo deliberately keeps the child's identity separate from the child's friendship with the companion.
- rolo holds the identity layer. Who you are, who your child is, your consent, which devices are trusted, and the alerts we send you.
- AIR holds the friendship. The actual chats, the companion's memory of your child, and a short "brief" that helps the companion respond kindly.
We send AIR the minimum it needs to work: your child's first name, a coarse age band (for example "6–8"), and the brief. We never send AIR your child's exact age, and we never send AIR your identity as the parent.
5. What personal data we collect, and where it lives
The table below shows what is held on the rolo side and what is held on the AIR side.
5a. Data held by rolo (the identity layer)
| Data | Why we hold it |
|---|---|
| Parent/guardian email address | To create and secure your account, sign you in, and contact you. |
| Parent/guardian password (stored only as a secure hash) | To protect your account. We never store your password in readable form. |
| Parent/guardian name and stated relationship to the child | To personalise the account and record who is responsible for it. |
| Child's real first name | To pair a device to the right child and personalise the experience. |
| Child's exact age | To decide safety settings and derive the age band we send to AIR. The exact age stays on the rolo side. |
| Consent ledger | A record of the consents you have given, when, and for what — so we can prove we have a lawful basis. |
| Device trust records | Which devices are paired, to which child, and when — enforcing "one child per device". |
| Inbound alerts | Signals from AIR that something in a chat needs your attention, so we can notify you. |
| Overseer/observer records | Who else you have invited to read along, their email, and their (read-only) role. |
| Purge receipts | A record that an erasure happened, kept as proof the right to be forgotten was honoured. |
| Billing information | Enough to manage your £15/month subscription. Card details are handled by our payment provider — see section 12. |
| Technical/usage data | Basic logs and local storage needed to run the app securely (see section 15 on cookies). |
5b. Data held by AIR (the friendship layer)
| Data | Notes |
|---|---|
| Child's first name | Sent by rolo. |
| Child's age band (e.g. "6–8") | Coarse band only — never the exact age. |
| The distilled brief | A coarse age band, a voice register, short "things they love / things to step around" notes, and a care level. |
| The chats | The messages between the child and the companion. |
| The companion's memory of the child | Built up over time to make the companion feel consistent and kind. |
[LEGAL REVIEW NEEDED: confirm exactly what AIR stores, for how long, and where — and reflect AIR's own privacy terms here. rolo's description of AIR-side data must match AIR's contractual reality.]
6. Your child's data, specifically
Because rolo is used by and for children, we take particular care:
- The child has no account, no password, and no independent login. All access flows through you.
- We practise data minimisation: AIR is told a first name, an age band, and the brief — nothing more about your child's identity.
- High-privacy defaults are on from the start.
- You can read every chat, and you can erase everything at any time (section 10).
This design is intended to support the ICO's Age Appropriate Design Code (the "Children's Code") — see section 14.
7. Special-category data (health / disability)
rolo is made for autistic children, and the brief may include a care level and signals related to mood. Information that reveals a child's autism, disability or health is special-category data under UK GDPR Article 9, which has extra protection.
[LEGAL REVIEW NEEDED: identify the Article 9 condition (likely Art 9(2)(a) explicit consent, and/or another condition) and the matching DPA 2018 Schedule 1 condition; document the additional safeguards and, where required, an Appropriate Policy Document.]
8. Overseers and observers — sharing your child's data with other adults
rolo lets you invite other adults to help watch over your child:
- One owner (usually you) has full control.
- Read-only observers — a second parent, grandparent or carer — can read the chats and receive alerts, but cannot change anything.
Please understand: when you invite an observer, you are sharing your child's chats and alerts with another adult. Only invite people you trust and who have a proper caring role in the child's life. You are responsible for who you invite. You can remove an observer at any time; when you do, their access ends.
[LEGAL REVIEW NEEDED: confirm the lawful basis and Children's-Code position for sharing a child's data with invited observers, and whether both parents' consent is needed in shared-custody situations.]
9. Purposes and lawful bases
Under UK GDPR we must have a lawful basis for each use of your data. Our current mapping is below. This mapping needs legal confirmation.
| What we do | Lawful basis (proposed) |
|---|---|
| Create and run your account; provide the service | Contract (UK GDPR Art 6(1)(b)) |
| Process your child's personal data to provide the companion | Consent of the parent/guardian (Art 6(1)(a)), given on the child's behalf |
| Process special-category data about the child (autism, care level, mood) | Explicit consent (Art 9(2)(a)) [LEGAL REVIEW NEEDED: confirm] |
| Keep you and your child safe (oversight, alerts, ending a chat for safety) | Legitimate interests (Art 6(1)(f)) — child safety — and/or consent [LEGAL REVIEW NEEDED] |
| Take payment for the subscription | Contract (Art 6(1)(b)) |
| Meet legal and record-keeping duties (e.g. the consent ledger, purge receipts) | Legal obligation (Art 6(1)(c)) and/or legitimate interests |
Note: the UK digital age of consent is 13. rolo's model relies on parental consent rather than the child consenting for themselves. [LEGAL REVIEW NEEDED: confirm how age of consent interacts with a service where the parent always holds the account and the child is typically under 13.]
You can withdraw consent at any time (section 10). Withdrawing consent may mean we can no longer provide the service.
10. Your rights, and your child's rights
You can exercise these rights on your own behalf and on behalf of your child:
- Access — ask for a copy of the personal data we hold.
- Rectification — ask us to correct anything inaccurate.
- Erasure ("right to be forgotten") — ask us to delete the data. In rolo, removing a child erases both sides — the rolo record and AIR's memory of the child — and we record a purge receipt as proof.
- Portability — ask for a copy of certain data in a machine-readable form. [LEGAL REVIEW NEEDED: confirm what portable data can practically be exported, including from AIR.]
- Restriction — ask us to pause certain processing.
- Objection — object to processing based on legitimate interests.
- Rights around automated decisions — the companion is an AI system. [LEGAL REVIEW NEEDED: assess whether any processing amounts to solely automated decision-making with legal/similarly significant effects under Art 22, and what safeguards apply.]
To exercise any right, contact [DPO / PRIVACY CONTACT EMAIL]. We will respond within one month, as required by law.
11. How long we keep your data (retention)
We keep personal data only as long as we need it:
- Account and identity data — for as long as your account is open, and a short period afterwards.
- Consent ledger and purge receipts — kept as legal records for a defined period even after erasure of the underlying data.
- Alerts — [retention period to be set].
- AIR-side data — governed by AIR's retention and by our erasure process.
[LEGAL REVIEW NEEDED: agree a concrete retention schedule for every category above and state the exact periods here.]
12. Payments
Your subscription is £15/month (inc. VAT) for the whole family. Card payments are handled by our payment provider, [PAYMENT PROVIDER], who acts as a separate controller/processor for card data. We do not store full card numbers. [LEGAL REVIEW NEEDED: name the provider, confirm the arrangement, and link their terms.]
13. Security
We protect your data with appropriate technical and organisational measures, including storing passwords only as secure hashes, restricting staff access, and encrypting data in transit. No system is perfectly secure, but we take our duty to your family seriously.
[LEGAL REVIEW NEEDED: document the actual security measures, staff access controls, and breach-notification process (72-hour ICO notification duty).]
14. Children's Code (Age Appropriate Design Code)
The Children's Code is a statutory code that services likely to be accessed by children must follow. rolo's design already supports several of its standards — data minimisation, high-privacy defaults, the identity/friendship data split, and easy erasure.
However, formal conformance against all 15 standards must be assessed by a specialist before we can claim to conform. [LEGAL REVIEW NEEDED: complete a full Children's Code conformance assessment.]
15. Cookies and local storage
rolo uses cookies and local storage on your device to keep you signed in, remember trusted devices, and run the service securely. [LEGAL REVIEW NEEDED: complete a cookie/local-storage audit, list each item with its purpose and lifespan, and confirm PECR consent requirements. Update this section from that audit.]
16. International transfers
We aim to process personal data in the UK. Some data may be processed elsewhere — in particular, AIR's processing location must be confirmed. If any personal data is transferred outside the UK, we will use a valid transfer mechanism (such as the IDTA or the UK Addendum to the EU SCCs, or reliance on adequacy).
[LEGAL REVIEW NEEDED: establish where rolo and AIR store/process data, and put valid transfer mechanisms in place if data leaves the UK.]
17. How to complain
If you are unhappy with how we handle your data, please contact us first at [DPO / PRIVACY CONTACT EMAIL] so we can try to put it right.
You also have the right to complain to the UK regulator, the Information Commissioner's Office (ICO) — ico.org.uk, helpline 0303 123 1113.
18. Changes to this policy
We may update this policy. If we make important changes, we will tell you. The "effective date" at the top shows the current version.
19. Contact
- Privacy / data protection: [DPO / PRIVACY CONTACT EMAIL]
- Support: [SUPPORT EMAIL]
- Post: [COMPANY LEGAL NAME], [REGISTERED ADDRESS]
This is a non-lawyer draft and not legal advice. It must be reviewed and approved before use.