Trust & Transparency

Privacy Policy

Effective date: 20 June 2026 · App: Rosio (iOS and Android)

Rosio is a shared workspace for couples. Your messages, photos, financial logs, and memories belong to the two of you — never to advertisers, data brokers, or third parties.

1. Who we are

Rosio is a shared workspace for couples, published by MHZDev Ltd ("MHZDev", "we", "us", "our"). Rosio is a single account shared by two partners. This policy explains what personal data we collect when you use the Rosio mobile app, why we collect it, who processes it on our behalf, and the rights you have over it.

Rosio is intended for adults (18+) and is not directed at children.

If you have any questions about this policy or your data, email us at mhzdev.contact@gmail.com.

2. What data we collect

Because Rosio is a shared couple's account, most of the data below belongs to and is visible to both partners on the account.

  • Account information — the email address used to sign in to your shared account.
  • Partner display names — the two names ("partner 1" and "partner 2") you choose during onboarding.
  • Shared content you create — everything you put into Rosio, including: photos uploaded to Daily Snap, Chapters and Memory Box; chat messages and shared notes; todos, shopping list and wishlist items; bucket list items; cookbook recipes; finance figures (bills, expenses, debts, savings); mood check-ins; quiz answers; calendar events; and minigame sessions.
  • Push notification token — a device token used to deliver notifications to you.
  • Device timezone — your device's IANA timezone string (e.g. Europe/London), used to send time-appropriate notifications.
  • Purchase status — your Rosio Plus subscription / entitlement status.
  • Product analytics — anonymous usage events (event names, plus count/category properties), associated with your user id and partner display names. We do not put your content or other personal information into analytics event properties.
  • Diagnostics — crash and error reports (stack traces, basic device information), which may include a screenshot captured at the moment of a crash.

We do not collect your precise location, contacts, or advertising identifiers.

3. How we use your data

  • Provide the app — store and sync your shared content between both partners' devices, keep you signed in, and operate every Rosio feature.
  • Send notifications — deliver push notifications (e.g. reminders and partner activity) at times appropriate to your timezone, where you have enabled them.
  • Manage subscriptions — determine whether your shared account has Rosio Plus and unlock Plus features for both partners.
  • Improve the app — understand which features are used (in aggregate, anonymously) so we can make Rosio better. You can opt out of analytics at any time in Settings.
  • Keep the app reliable — diagnose crashes and fix bugs.

4. Processors and sub-processors

We use a small number of trusted service providers ("processors") to run Rosio. They process data only on our instructions and only for the purposes below.

Processor Purpose Processing region
Supabase Core backend: database, authentication, file storage, and edge functions. Stores your account email, partner display names, all shared content (including photos in storage buckets), push tokens, and device timezone. EU (eu-west-1)
RevenueCat Subscription and purchase management. Receives the shared account user id to track your Rosio Plus entitlement. United States
PostHog Anonymous product analytics: event names and count/enum properties, plus user id and partner display names via identify. No content or other PII is sent in event properties. EU Cloud (eu.i.posthog.com)
Sentry Crash and error diagnostics (stack traces, device info, and a possible crash screenshot). United States
Expo push (Apple APNs / Google FCM) Delivers push notifications to your device using the push token. United States

5. Legal bases

Where data protection law (including the UK GDPR / EU GDPR) applies, we rely on the following legal bases:

  • Performance of a contract — to provide the Rosio app and the features you ask for, including syncing content, sending the notifications you enable, and managing your subscription.
  • Consent — for product analytics. You can withdraw consent at any time by opting out of analytics in Settings.

6. Data sharing

  • We do not sell your personal data.
  • We do not use your data for cross-app advertising or third-party ad tracking.
  • Our analytics are first-party product analytics used only to improve Rosio. They are not cross-app tracking and are not shared with advertisers.
  • We share data only with the processors listed in Section 4, who act on our behalf, and where we are legally required to do so.

7. Data retention

We keep your data for as long as your shared account is active. When you delete your account (see Section 8), all of your rows in our database and all of your files in storage are removed. Anonymous analytics and diagnostic records may be retained for a limited period by our analytics and diagnostics processors in line with their standard retention windows, and are not linked to deleted content.

8. Your rights

You have the right to access, export, correct, and delete your personal data.

  • Deletion (in-app) — You can delete your account and all associated data directly in the app: Settings → Delete Account. This permanently removes every database row and all stored files for your account. Because Rosio is a shared account, this affects both partners.
  • Access and export (in-app) — You can download a copy of everything Rosio holds for your account at any time: Settings → Export My Data. This produces a JSON file containing all of your database rows plus time-limited download links for every photo. It is available to every account, free and Plus alike.
  • Access and export (by email) — If you cannot use the in-app export for any reason, email mhzdev.contact@gmail.com and we will send you a copy of your data.
  • Correction — Most of your data can be edited directly in the app. For anything you cannot change yourself, contact us.
  • Analytics opt-out — You can turn off product analytics at any time in Settings.

Depending on where you live, you may also have the right to lodge a complaint with your local data protection authority.

9. Security

  • All data is encrypted in transit (HTTPS / TLS) between your device and our processors.
  • Access to your shared content in our database is protected by Supabase Row Level Security (RLS), so each account can only reach its own data.
  • We restrict access to production systems to what is necessary to operate the service.

No method of transmission or storage is perfectly secure, but we take reasonable steps to protect your information.

10. International transfers

Our primary database and storage (Supabase) are hosted in the EU (eu-west-1). Some of our processors — PostHog (EU Cloud), Sentry, and Expo push (Apple APNs / Google FCM) — may process data outside the EU, including in the United States. Where data is transferred outside the EU/UK, we rely on appropriate safeguards (such as standard contractual clauses provided by those processors) to protect it.

11. Children

Rosio is intended for adults aged 18 and over. It is not directed at children, and we do not knowingly collect personal data from anyone under 18. If you believe a minor has provided us with personal data, contact us and we will delete it.

12. Changes to this policy

We may update this policy from time to time. If we make a material change, we will update the effective date above and, where appropriate, notify you in the app. Continued use of Rosio after an update means you accept the revised policy.

13. Contact

Publisher: MHZDev Ltd
Email: mhzdev.contact@gmail.com
Web: https://rosio.app