App-owned legal content

Privacy Policy

Last updated: August 26, 2026

This page is maintained by the Rosalina team to answer common privacy and data-handling questions about the Rosalina service. It is not an independent certification or legal advice; it describes the current practices and controls enabled for your account.

What Rosalina Office does

Rosalina is an AI office manager for service businesses. It helps owners and their teams with client communication, follow-ups, marketing drafts, email replies, review responses, social-media post drafts, appointment and customer notes, and a daily summary of tasks and opportunities. Rosalina acts as a behind-the-scenes assistant: it drafts and recommends actions, and the owner approves anything that goes out to customers or the public.

Rosalina does not replace your existing booking, payment, or point-of-sale systems. When a customer asks to book, Rosalina shares your business booking link and helps them find the right service and price from your service list.

What information we collect

We collect the information you choose to provide, plus limited technical data needed to run the service:

  • Account information: owner name, business name, email address, industry, services, business hours, location, brand voice, goals, and any logo or files you upload.
  • Customer information: names, contact details, appointment history, communication history, notes, reviews, and follow-up tasks you add to a customer timeline.
  • Connected inbox data: when you connect a business Gmail or Microsoft 365 account, Rosalina reads the subject, sender, body, and thread metadata of incoming mail so it can triage, draft replies, and log activity in the customer timeline. We do not sell or use this data for advertising.
  • Social account data: when you connect an Instagram Business account, we store your Instagram Business account handle, Facebook Page name, and an encrypted access token so Rosalina can publish approved posts on your behalf.
  • Usage and billing data: subscription status, plan details, payment processor tokens, and feature usage logs for support and troubleshooting.
  • Technical data: IP address, browser type, session cookies, and error logs to keep the service secure and reliable.

How account data is used

We use your account data only to operate Rosalina for your business:

  • To personalize drafts, replies, and recommendations so they match your services, prices, and brand voice.
  • To log customer interactions in the timeline, suggest follow-ups, and surface daily opportunities.
  • To send transactional emails such as login links, billing receipts, founder-setup reminders, and account notifications.
  • To provide support, fix bugs, and improve product quality.
  • To enforce account security and prevent abuse.

We do not train general AI models on your private customer data. Any AI processing is scoped to generating drafts and recommendations for your workspace.

Instagram and Facebook (Meta) integration data usage

Rosalina integrates with the Meta Instagram Graph API so you can draft and publish posts to your own Instagram Business account. When you connect the integration, you authenticate directly with Meta and grant Rosalina limited access.

We use the integration only to:

  • Read the Instagram Business account linked to your connected Facebook Page.
  • Create media containers and publish single-image feed posts you have explicitly approved inside Rosalina.
  • Store a long-lived access token so you do not have to re-authenticate every day.

We do not read your Instagram direct messages, stories, reels, or follower lists beyond what is needed to identify the connected account and publish your approved posts. Published posts are sent from your own Instagram Business account, not from Rosalina's account.

Permissions requested through Meta APIs

When you connect Instagram, Meta asks you to approve the following permissions:

  • instagram_basic — identify your Instagram Business account and linked Facebook Page.
  • instagram_content_publish — create and publish approved single-image posts to your feed.
  • pages_show_list — list Facebook Pages you manage so you can choose the one linked to Instagram.
  • pages_read_engagement — verify Page ownership and access needed for Instagram publishing.
  • business_management — manage the business connection between your Facebook Page and Instagram account.

You can revoke these permissions at any time from your Facebook Business Integrations settings, or by disconnecting Instagram inside Rosalina Settings.

Data storage and security

  • Hosting: Rosalina is hosted on the Lovable platform, which uses Supabase for authentication, database, and storage. Data is encrypted in transit using TLS and at rest by the cloud provider.
  • Access tokens: social and email connection tokens are encrypted with AES-256-GCM before they are stored in the database. The encryption keys are never exposed to the client.
  • Access controls: database access is protected by Row Level Security (RLS) and each workspace can only read its own data. Server-only functions perform privileged operations such as decrypting tokens or publishing posts.
  • Retention: we keep your data as long as your account is active, or longer if required by law. Backups are retained for a limited period for disaster recovery.

Security is a shared responsibility: we protect the platform, encryption, and access controls, while you are responsible for keeping your login credentials safe, choosing strong passwords, and only connecting accounts and granting permissions you intend Rosalina to use.

How to delete your data

You have control over your data:

  • Disconnect integrations: in Rosalina Settings you can disconnect Gmail, Instagram, and other connected services at any time. This removes stored tokens and stops future syncing.
  • Delete individual records: you can delete customers, notes, communications, posts, files, and follow-ups from inside the Rosalina app.
  • Close your account: to request a full account deletion and removal of all workspace data, email us at support@rosalina.app from your registered email address. We will confirm the request and delete personal data within 30 days unless legal obligations require us to retain it.

Contact information

If you have questions about this Privacy Policy, your data, or your rights, contact us:

Privacy & data questions
support@rosalina.app

Changes to this policy

We may update this Privacy Policy as the service evolves. When we make material changes, we will update the "Last updated" date at the top of this page and notify active account owners by email. Continued use of Rosalina after changes means you accept the revised policy.