Back to home

Privacy Policy

Last Updated: November 7, 2025

Welcome to RollApp. We're committed to protecting your privacy and being transparent about how we handle your data. This Privacy Policy explains what information we collect, how we use it, and your rights regarding your personal data.

🇨🇭

Built on Swiss Privacy Standards

RollApp is headquartered in Zurich, Switzerland, and we operate under Swiss data protection laws—some of the strongest privacy regulations in the world. Your data is stored in Swiss data centers and protected by the Federal Act on Data Protection (FADP).

Switzerland is not part of the EU or the "14 Eyes" surveillance alliance, providing an additional layer of privacy protection for your personal data.

By using RollApp, you agree to the collection and use of information in accordance with this policy.

1. Information We Collect

1.1 Information You Provide to Us

Account Information

  • Email address
  • Name
  • Password (stored as a cryptographic hash, never in plain text)
  • Payment information (processed through our payment provider)
  • Profile settings and preferences

Photos and Videos

  • Digital media files you upload or sync to RollApp
  • Metadata associated with your media (EXIF data, timestamps, location data if embedded)
  • Albums, tags, and organizational information you create

Communications

  • Support requests and correspondence
  • Feedback and survey responses
  • Communications preferences

1.2 Information We Collect Automatically

Usage Data

  • Pages visited and features used
  • Time spent on the service
  • Device information (type, operating system, browser)
  • IP address and general location data
  • Referring URLs and search terms

Technical Data

  • Log files and error reports
  • Performance metrics
  • Session information
  • Cookies and similar tracking technologies

1.3 Information from Third-Party Sources

When you connect external services (Google Photos, iCloud, Dropbox, etc.), we collect:

  • Access tokens to sync your media
  • Basic profile information from connected services
  • Media files and metadata from connected accounts

2. How We Use Your Information

We use your information for the following purposes:

2.1 Provide and Improve Our Service

  • Store and sync your photos and videos
  • Enable search, organization, and sharing features
  • Process your uploads and downloads
  • Maintain and improve service performance
  • Develop new features and functionality

2.2 Security and Protection

  • Verify your identity and authenticate access
  • Detect and prevent fraud, abuse, and security incidents
  • Comply with legal obligations
  • Enforce our Terms of Service

2.3 Communications

  • Send service-related notifications
  • Respond to your requests and support inquiries
  • Send marketing communications (with your consent)
  • Conduct surveys and gather feedback

2.4 AI and Machine Learning Features

  • Facial recognition for photo organization (processed locally on your device or in encrypted form)
  • Content recognition for search functionality
  • Automatic categorization and memory creation
  • Duplicate detection

Important: We use zero-knowledge encryption. Your photos are encrypted on your device before upload, and we cannot access the unencrypted content. AI processing happens either locally on your device or on encrypted data that we cannot view.

3. How We Share Your Information

We do not sell your personal information.

We may share your data in the following limited circumstances:

3.1 Service Providers

We work with third-party companies to provide:

  • Cloud storage infrastructure
  • Payment processing
  • Customer support tools
  • Analytics and performance monitoring
  • Email delivery services

These providers are contractually obligated to protect your data and use it only for the services they provide to us.

3.2 Legal Requirements

We may disclose information if required to:

  • Comply with applicable laws, regulations, or legal processes
  • Respond to government requests or court orders
  • Protect our rights, property, or safety
  • Prevent fraud or security threats

Note: Due to our zero-knowledge encryption, we cannot decrypt your photos even if compelled by legal process. We can only provide encrypted data and account metadata.

3.3 Business Transfers

If RollApp is involved in a merger, acquisition, or sale of assets, your information may be transferred. We will notify you before your data becomes subject to a different privacy policy.

3.4 With Your Consent

We may share information for other purposes with your explicit consent.

4. Data Security

4.1 Encryption

End-to-End Encryption

  • All photos and videos are encrypted on your device using AES-256 encryption
  • Encryption keys are derived from your password and never leave your device
  • We cannot access your unencrypted photos or videos

In Transit

All data transmitted between your device and our servers uses TLS 1.3 encryption

At Rest

  • Encrypted data is stored on secure servers
  • Database encryption for account information
  • Regular security audits and penetration testing

4.2 Access Controls

  • Multi-factor authentication available
  • Role-based access controls for our team
  • Regular access reviews and credential rotation
  • Employee background checks and security training

4.3 Monitoring and Incident Response

  • 24/7 security monitoring
  • Automated threat detection
  • Incident response procedures
  • Regular security assessments by third-party auditors

No system is 100% secure. While we implement industry-standard security measures, we cannot guarantee absolute security. You are responsible for maintaining the confidentiality of your password.

5. Swiss Privacy Standards

🇨🇭

Protected by Swiss Law

As a Swiss company headquartered in Zurich, RollApp operates under some of the world's strongest privacy protections. This isn't just a marketing point—it fundamentally shapes how we handle your data.

5.1 Federal Act on Data Protection (FADP)

We comply with Switzerland's Federal Act on Data Protection (FADP), which provides comprehensive data protection rights including:

  • Strong consent requirements for data processing
  • Strict limitations on automated decision-making
  • Enhanced transparency obligations
  • Robust rights for data subjects
  • Severe penalties for non-compliance

5.2 Swiss Data Centers

Your data is stored exclusively in Switzerland:

  • Primary data center: Zurich, Switzerland
  • Backup facility: Geneva, Switzerland
  • All data remains within Swiss borders unless you explicitly authorize otherwise
  • Protected by Swiss banking-level physical security standards
  • Powered by renewable Swiss hydroelectric energy

5.3 Jurisdictional Advantages

Switzerland offers unique privacy protections:

  • Not part of the EU: While we comply with GDPR for EU users, we're not subject to all EU data sharing directives
  • Not in the "14 Eyes" alliance: Switzerland is not part of the mass surveillance intelligence-sharing agreements
  • Strong legal protections: Swiss courts require high standards of proof before compelling data disclosure
  • No mandatory data retention laws: Unlike many countries, Switzerland doesn't require blanket data retention

5.4 Government Requests

Under Swiss law, government requests for user data must meet strict requirements:

  • Must be issued by a Swiss court with proper jurisdiction
  • Must specify exact data required (no fishing expeditions)
  • Must demonstrate probable cause
  • We are legally permitted to notify users unless specifically prohibited by court order

Additionally, due to our zero-knowledge encryption architecture, we cannot provide access to the content of your photos and videos—only encrypted data and account metadata.

5.5 Federal Data Protection and Information Commissioner (FDPIC)

We are subject to oversight by Switzerland's Federal Data Protection and Information Commissioner (FDPIC), an independent authority that:

  • Monitors compliance with Swiss data protection laws
  • Investigates data protection complaints
  • Has the power to impose binding orders
  • Provides guidance on data protection best practices

5.6 Cross-Border Data Transfers

When transferring data outside Switzerland (e.g., to EU users or when connecting to third-party services), we ensure:

  • Data is only transferred to countries with adequate data protection (as recognized by Switzerland)
  • Use of Standard Contractual Clauses (SCCs) where required
  • Additional security measures including encryption
  • Your explicit consent for any data transfers

💡 What This Means For You

In practical terms, Swiss privacy laws mean:

  • Your data is protected by some of the world's strictest privacy laws
  • Government access to your data faces significant legal hurdles
  • Your photos never leave Swiss borders unless necessary for the service
  • You benefit from Switzerland's tradition of neutrality and privacy

6. Data Retention

6.1 Active Accounts

We retain your data for as long as your account is active or as needed to provide services.

6.2 Deleted Data

When you delete photos or videos:

  • They are immediately removed from your account
  • Encrypted files are deleted from our storage within 30 days
  • Backups are purged within 90 days

When you delete your account:

  • All your data is permanently deleted within 90 days
  • Backups are purged within 180 days
  • Some metadata may be retained for legal or operational purposes

6.3 Legal Obligations

We may retain certain data longer if required by law or to resolve disputes.

7. Your Privacy Rights

Depending on your location, you may have the following rights:

7.1 Access and Portability

  • Request a copy of your personal data
  • Download all your photos and videos in original quality
  • Receive your data in a structured, machine-readable format

7.2 Correction and Deletion

  • Update or correct your account information
  • Delete specific photos, videos, or your entire account
  • Request deletion of your personal data (subject to legal requirements)

7.3 Control and Objection

  • Control marketing communications preferences
  • Object to certain data processing activities
  • Withdraw consent where processing is based on consent
  • Opt out of cookies (except essential ones)

7.4 Restrict Processing

  • Request restriction of processing in certain circumstances
  • Opt out of automated decision-making and profiling

7.5 Lodge a Complaint

File a complaint with your local data protection authority if you believe your rights have been violated

To exercise your rights: Contact us at privacy@rollapp.com or use the settings in your account dashboard.

8. International Data Transfers

RollApp operates globally. Your data may be transferred to and stored in countries other than your own, including the United States.

We ensure appropriate safeguards are in place:

  • Standard Contractual Clauses (SCCs) approved by the European Commission
  • Adequacy decisions where applicable
  • Other legally approved transfer mechanisms

Your data receives the same level of protection regardless of where it is processed.

9. Children's Privacy

RollApp is not intended for children under 13 (or 16 in the EU). We do not knowingly collect personal information from children.

If you believe we have collected information from a child, please contact us immediately at privacy@rollapp.com, and we will delete it.

10. Cookies and Tracking Technologies

10.1 Types of Cookies We Use

Essential Cookies

  • Required for the service to function
  • Authentication and security
  • Cannot be disabled

Performance Cookies

  • Help us understand how you use RollApp
  • Analytics and error tracking
  • Improve service performance

Functional Cookies

  • Remember your preferences
  • Enable certain features
  • Enhance user experience

Marketing Cookies (with consent)

  • Track effectiveness of campaigns
  • Personalize content
  • Measure advertising performance

10.2 Managing Cookies

You can control cookies through your browser settings. Note that disabling certain cookies may limit functionality.

Third-Party Cookies

We use analytics services that may set their own cookies. See their privacy policies:

  • Google Analytics
  • Stripe (payment processing)

11. Region-Specific Provisions

11.1 European Economic Area (EEA)

Legal Basis for Processing

  • Performance of contract (to provide our services)
  • Legitimate interests (improve services, prevent fraud)
  • Consent (marketing communications, certain cookies)
  • Legal obligations (compliance with laws)

Data Protection Officer

Email: dpo@rollapp.com

EU Representative

RollApp EU Data Services

Dublin, Ireland

eu-privacy@rollapp.com

11.2 California Residents (CCPA/CPRA)

California residents have additional rights:

  • Know what personal information we collect and how it's used
  • Request deletion of personal information
  • Opt out of sale of personal information (we don't sell your data)
  • Non-discrimination for exercising your rights

California Contact: california-privacy@rollapp.com

11.3 United Kingdom

RollApp complies with UK GDPR. UK-specific inquiries:

Email: uk-privacy@rollapp.com

12. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. Changes will be posted on this page with an updated "Last Updated" date.

Material changes will be notified via:

  • Email to your registered address
  • Prominent notice on the service
  • In-app notification

Your continued use of RollApp after changes take effect constitutes acceptance of the updated policy.

13. Third-Party Services

RollApp integrates with third-party services (Google Photos, iCloud, Dropbox, etc.). When you connect these services:

  • You're also subject to their privacy policies
  • We only access data you explicitly authorize
  • You can revoke access at any time

We are not responsible for the privacy practices of third-party services.

14. Data Processing Agreement

For business or enterprise customers, we offer a Data Processing Agreement (DPA) that includes:

  • Standard Contractual Clauses
  • Additional security commitments
  • Subprocessor information

Contact enterprise@rollapp.com for DPA requests.

15. Contact Us

General Privacy Inquiries

Email: privacy@rollapp.com

Address: RollApp AG, Europaallee 41, 8004 Zürich, Switzerland

Data Protection Officer

Email: dpo@rollapp.com

Region-Specific Contacts

EU: eu-privacy@rollapp.com

UK: uk-privacy@rollapp.com

California: california-privacy@rollapp.com

Response Time

We aim to respond to all privacy requests within 30 days.

16. Transparency Report

We publish an annual transparency report detailing:

  • Government data requests received
  • Our responses to those requests
  • Security incidents (if any)
  • Changes to our practices

View our latest transparency report at: rollapp.com/transparency

17. Your Trust Matters

We built RollApp because we believe your photos and memories deserve better protection than what currently exists. Privacy isn't just a policy for us—it's the foundation of our service.

Our Commitments:

  • We will never sell your data
  • We cannot access your encrypted photos
  • We will be transparent about any breaches
  • We will fight overly broad legal requests
  • We will give you control over your data

Thank you for trusting us with your memories.

Questions?

We're here to help.

Contact Privacy Team

This privacy policy was last updated on November 7, 2025.