Privacy Policy
Effective date: 24 July 2026 · Last updated: 1 August 2026 · Version 1.1 (DPDP Rules 2025 alignment)
This Privacy Policy explains how Rosnil Technology Private Limited ("Rosnil", "we", "us", "our") handles information in connection with every mobile application, website, and service we operate (each, a "Service", and together, the "Services"). It is a single, universal policy that applies across our entire app portfolio.
Contents
- Who we are & how to contact us
- Scope of this policy
- Information we process
- On-device processing
- How we obtain information
- Purposes & legal bases
- Device permissions
- Sharing & disclosure
- Service providers & sub-processors
- App stores & platforms
- Artificial intelligence features
- International data transfers
- Data retention
- Security
- Your rights
- EEA/UK (GDPR) disclosures
- California (CCPA/CPRA) disclosures
- India (DPDP Act) disclosures
- Children's privacy
- Cookies & the website
- Changes to this policy
- Grievance & contact
1. Who we are & how to contact us
Rosnil Technology Private Limited is a company incorporated in India and is the data controller (and, under India's DPDP Act, the Data Fiduciary) for the Services, except where we act as a processor on another party's behalf.
- Developer name on the App Store & Google Play
- ApeLabs is the developer/brand name under which our apps are published on the stores. The company that operates the apps and is the controller / Data Fiduciary is Rosnil Technology Private Limited, whose details are below.
- Email (all privacy matters)
- rosnil@apeitnow.com
- Registered office
- Rosnil Technology Private Limited, 1st Floor, Shop No. 14, Palm Beach Residency, Akhandanand Saraswati Marg, Nerul West, Navi Mumbai, Thane, Maharashtra 400706, India.
- Grievance Officer (India)
- Mr. Nilesh Jagtap, reachable at nilesh.jagtap@apeitnow.com.
2. Scope of this policy
This policy covers our mobile apps distributed through the Apple App Store and Google Play, and the website at appstore.rosniltech.com and related Rosnil web properties. It does not cover third-party products, websites, or services that we do not operate, even where our Services link to or interoperate with them.
3. Information we process
The categories below describe what our Services can involve. For most of our apps, the great majority of this stays on your device and is never received by us.
- Content you create or import
- Photos, camera captures, scanned pages, documents, files, and any text recognised from them. For our on-device apps, this content is processed and stored locally on your device and is not transmitted to us.
- App preferences & settings
- Choices such as output format, quality, or theme, stored on your device.
- Technical & diagnostic data
- Where applicable: app version, device model, operating-system version, language, and — during update checks or any network request — your IP address (which is inherent to internet communication). We do not use this to build a profile of you.
- Support communications
- If you email us, we receive your email address and the contents of your message so we can respond.
- Website data
- Standard server/CDN logs and any strictly-necessary cookies, as described in the Cookies section.
We do not sell personal data. We request sensitive permissions or data — such as precise location, contacts, the microphone, or the camera — only where a specific app's feature genuinely needs them, and that app explains why before asking. We do not intentionally collect special-category / sensitive data except where a clearly-disclosed app feature requires it.
4. On-device processing (where it applies)
Many of our apps are designed so that document and media processing happens on your device. For those apps and features, operations such as image-to-PDF conversion, cropping, compression, enhancement, and on-device text recognition (OCR) run locally; the underlying bytes are not uploaded to Rosnil or to any third party, and files you save remain in the app's private storage on your device until you delete them or uninstall the app. Some apps or features instead run in the cloud (for example, format conversion, sync, backup, or cloud AI) — where that is the case, the app discloses it, and Sections 8–9 explain how such data is handled.
5. How we obtain information
- Directly from you — content you add, settings you choose, and messages you send us.
- Automatically — limited technical data generated when the app runs or checks for updates, and standard website logs.
- From platforms — aggregate, non-identifying statistics that Apple or Google may provide to developers (e.g. download counts, crash aggregates). We do not receive your identity through these.
6. Purposes & legal bases
We process information only for the purposes below. Where the GDPR or similar laws apply, the relevant legal basis is shown.
- To provide the Services
- Run the features you use. Basis: performance of our terms with you (contract); legitimate interests.
- To maintain, secure, and improve the Services
- Deliver updates, fix bugs, and keep the Services safe. Basis: legitimate interests.
- To provide support
- Respond to your requests. Basis: legitimate interests; contract.
- To comply with law
- Meet legal, tax, and regulatory obligations, and respond to lawful requests. Basis: legal obligation.
7. Device permissions
Our apps request only the permissions a feature needs, and only when you use it — for example, Camera to capture a page, or Photo Library to import images. The data enabled by a permission stays on your device unless you explicitly share it. You can grant or revoke any permission at any time in your device settings; the related feature will simply be unavailable if revoked.
8. Sharing & disclosure
We do not sell or rent personal data. We disclose information only:
- At your direction — when you use a share/export feature, your device's system share sheet hands the file to the app or service you choose (e.g. WhatsApp, Mail, Files, iCloud, Google Drive). That destination's own policy then governs the file. We neither control nor receive anything through this step.
- To advertising partners (ad-supported apps only) — where an app shows ads, limited data such as an advertising identifier, IP address, and device/usage signals may be shared with our ad providers (for example, Google AdMob, and any mediation networks) to show and measure ads. This applies only to apps whose listing states they contain ads; apps without ads do not share your data for advertising, and where consent is required we ask for it.
- To AI or cloud providers (features that use them) — where an app offers a cloud or AI feature, the data needed for that feature may be processed by the provider that powers it, as described in the app's disclosures and our AI Policy.
- To service providers — the limited processors listed below, under contract, to operate the Services.
- For legal reasons — to comply with law, enforce our terms, or protect the rights, safety, and property of Rosnil, our users, or the public.
- In a corporate transaction — in connection with a merger, acquisition, or asset sale, subject to this policy.
9. Service providers & sub-processors
We keep our vendor footprint deliberately small. Current providers include:
- Apple Inc. & Google LLC
- App distribution, delivery, and crash/aggregate statistics for apps on their stores.
- Expo (650 Industries, Inc.)
- Over-the-air update delivery (EAS Update). When an app checks for updates, Expo's servers receive technical request data such as IP address, platform, and app/runtime version, used only to serve the correct update. See expo.dev/privacy.
- GitHub, Inc.
- Hosting for our website and policy pages (GitHub Pages).
We will update this list as our infrastructure changes.
10. App stores & platforms
When you download or purchase an app, Apple or Google processes your account, payment, and download under their privacy policies, not ours. We receive only aggregate, non-identifying information from them.
11. Artificial intelligence features
Some apps include AI or machine-learning features. These may run in two ways, and each app tells you which it uses:
- On-device AI (for example, text recognition or document enhancement) — your content is processed locally and is not sent to us or to a third party for that feature.
- Cloud or generative AI — some features send the specific input you provide (such as a prompt, image, or document) to an AI provider that returns a result. Where an app does this, it discloses it in-app, and our AI Policy explains what is sent, which provider is used, and how outputs and inputs are handled.
We do not use your content to train general-purpose / foundation models, and we do not permit our AI providers to train their general models on your content, unless an app explicitly says so and you opt in. AI outputs can be imperfect — check anything important before you rely on it.
12. International data transfers
Rosnil is based in India, and our providers may process limited technical data in other countries, including the United States. Where personal data of EEA/UK individuals is transferred, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses. Because our apps are on-device by design, the volume of any such transfer is minimal (e.g. an IP address during an update check).
13. Data retention
Content created in our apps is retained on your device until you delete it or uninstall the app — we hold no server copy to retain. Support emails are kept only as long as needed to handle your request and meet legal obligations. Website logs are kept for a short period for security and diagnostics.
14. Security
We design for data minimisation — the strongest protection is that your content never leaves your device. For data in transit (such as update checks) we use encryption (HTTPS/TLS). No method of storage or transmission is 100% secure; you are responsible for securing your device and keeping your own backups of important files.
15. Your rights
Subject to your local law, you may have rights to access, correct, delete, port, or restrict the processing of your personal data, and to object to processing or withdraw consent. Because our apps store your content on your device and we hold no personal profile of you, you can exercise most of these rights directly — by managing or deleting your content in the app, or uninstalling it. For anything you cannot do yourself, contact rosnil@apeitnow.com and we will respond within the timeframe your law requires. You will not be discriminated against for exercising your rights.
16. EEA/UK (GDPR) disclosures
If you are in the European Economic Area or the United Kingdom: the controller is Rosnil Technology Private Limited; the legal bases are described in Section 6; and you have the rights in Section 15, including the right to lodge a complaint with your local supervisory authority. Where we rely on legitimate interests, you may object at any time.
17. California (CCPA/CPRA) disclosures
If you are a California resident: we do not sell personal information for money. Some of our apps are ad-supported, and delivering ads can involve "sharing" an advertising identifier for cross-context behavioural advertising as the CPRA defines it. This applies only to apps whose listing states they contain ads; for those, you can opt out via your device's ad settings (and, where required, the consent prompt we show). Apps without ads do not sell or share your personal information. You always have the rights to know, delete, correct, and opt out, and we do not knowingly sell or share the personal information of consumers under 16.
18. India — Digital Personal Data Protection Act 2023 & DPDP Rules 2025
Where we process the digital personal data of Data Principals in India, Rosnil Technology Private Limited is the Data Fiduciary, and the following applies. Many of our apps process no personal data at all; this section governs the apps and features that do.
- Notice & consent
- Where we rely on your consent, we obtain it through a clear affirmative action and give you an itemised notice — available in English or, on request, any language listed in the Eighth Schedule to the Constitution of India — that describes the personal data we seek, the purpose, and how to withdraw consent, exercise your rights, and complain to the Data Protection Board. We may also process personal data for the legitimate uses permitted by the Act.
- Withdraw consent
- You may withdraw consent at any time and as easily as you gave it, through the relevant app setting or by emailing us. Withdrawal is not retroactive, and the related feature may stop working. Where available, you may also act through a Board-registered Consent Manager.
- Your rights as a Data Principal
- You have the right to (a) access a summary of your personal data and how we process it; (b) correction, completion, updating and erasure; (c) grievance redressal; and (d) nominate another individual to exercise your rights if you die or are incapacitated. To exercise any of these, email rosnil@apeitnow.com or contact our Grievance Officer (Section 22).
- Grievance redressal
- Our Grievance Officer is your first point of contact and will respond within the period the DPDP Rules require (currently within 90 days). If you remain unsatisfied, you may complain to the Data Protection Board of India.
- Children & persons with disabilities
- See Section 19. We do not process a child's personal data without verifiable parental/guardian consent, and we do not carry out tracking, behavioural monitoring, or targeted advertising directed at children.
- Personal-data breach
- If a breach affects your personal data, we will notify you and the Data Protection Board of India in the manner and within the timelines the DPDP Rules require.
- Retention & erasure
- We keep personal data only as long as needed for the stated purpose or as the law requires, and then erase it (Section 13).
19. Children & persons with disabilities
Under India's DPDP Act, a "child" is anyone under 18. Where an app would process a child's personal data, we will first obtain verifiable consent from a parent or lawful guardian, and we will not undertake tracking, behavioural monitoring, or targeted advertising that is directed at children — as the Act requires. The same guardian-consent protection applies to a person with a disability who has a lawful guardian. In other regions, we follow the local minimum age of digital consent (for example, 13 in the United States). Our current apps are general-purpose and, where they collect no personal data, this does not arise. If you believe a child's data has been processed without the required consent, contact us and we will address it promptly.
20. Cookies & the website
Our website uses only strictly-necessary cookies and standard server/CDN logs to serve pages securely; it does not run advertising or cross-site tracking cookies. See our Cookie Policy for details.
21. Changes to this policy
We may update this policy to reflect changes in our Services or the law. We will revise the "Last updated" date and, for material changes, provide a more prominent notice. Continued use of the Services after an update takes effect means you accept the revised policy.
22. Grievance & contact
For any question, request, or complaint about privacy, contact:
Rosnil Technology Private Limited
Grievance Officer: Mr. Nilesh Jagtap —
nilesh.jagtap@apeitnow.com
1st Floor, Shop No. 14, Palm Beach Residency, Akhandanand Saraswati Marg,
Nerul West, Navi Mumbai, Thane, Maharashtra 400706, India
General enquiries: rosnil@apeitnow.com
We aim to acknowledge grievances within 72 hours and to resolve them within the period required by applicable law — for India, within 90 days as required by the DPDP Rules 2025. If you are in India and remain unsatisfied, you may escalate to the Data Protection Board of India.