ropet Privacy Policy

Published: July 20, 2026

Effective: July 20, 2026

Introduction

ROPET LIMITED (“Company,” “we,” “us,” or “our”) operates the ropet desktop AI companion and related services and is the controller of the core processing activities described in this Privacy Policy. This Policy is prepared with reference to applicable U.S. state privacy and children’s online privacy laws, Canadian federal and provincial privacy laws, and the laws of other regions where the services are available.

This Policy explains how we collect, use, retain, share, transfer, disclose, and protect personal information when you use ropet hardware, companion applications, and cloud services (collectively, the “Services”), and how you may exercise your rights. A third-party service governed by its own separately presented agreement or privacy policy is outside this Policy.

We may issue a feature-specific privacy policy, processing notice, or just-in-time notice. A feature-specific document controls within its stated scope; this Policy governs matters it does not address.

This Policy is a transparency notice, not blanket consent. Confirming it in the App means that it was presented to you. Where processing requires consent, separate or express consent, verifiable parental consent, or a device permission, we will provide a specific notice and obtain the required authorization. Other processing relies, as applicable, on contract necessity, legal obligation, vital interests, or legitimate interests following an appropriate balancing assessment. Refusing an optional permission or withdrawing consent affects only the feature that depends on it.

Special notice: Interpreter Collar AI voice conversations, interactive snapshots, and the resulting Paipai Diary are available worldwide only to actual users aged 16 or older. Stricter local age-verification, parental-consent, and minor-protection rules also apply.

1. Scope and Principles

“You” includes the account holder, purchaser, person who binds or administers the device, and any permitted actual user. If the administrator and actual user differ, the administrator must explain camera and audio functions, local detection, cloud AI processing, retention of generated content, and age restrictions, and must ensure informed use.

We process personal information lawfully, fairly, transparently, and for specified purposes; limit collection and retention to what is necessary; support accuracy, integrity, confidentiality, and accountability; and apply safeguards proportionate to risk. Your confirmation of this Policy does not authorize processing unrelated to the device, feature, permission state, or service you actually use.

2. Personal Information We Collect and Use

We collect only for clear, lawful, and necessary purposes and use safeguards such as encryption, protected storage, and access controls.

2.1 Account, login, and support

We process a mobile number, verification code, account identifier, and any avatar or nickname you choose to provide to create and manage an account, authenticate you, bind a device, synchronize data, and protect account security. For inquiries, complaints, repairs, or after-sales service, we process contact details, communications, order or device information, and materials needed to resolve the matter.

If you use Paipai Diary, we process a birthday that you voluntarily provide to personalize content. If a guardian enables Minor Mode and sets a management password, we record the mode’s status to restrict sensitive features.

2.2 Device connectivity, operation, and security

To bind and connect a device, deliver firmware updates, monitor service status, and maintain security, we automatically process device identifiers such as the serial number, hardware and software versions, IP address, network status, operating logs, and diagnostic data. Before you accept the relevant agreements and finish binding and network configuration, the device will not upload its serial number, IP address, logs, or status to us.

2.3 Device and system permissions

Depending on the feature, the App may request camera, photo-library or storage, local-network, location, and notification permissions to set an avatar, select or save an image, scan a QR code, configure or bind a device, remotely control it, or receive device and service messages. Permissions are requested only when relevant and may be disabled in system settings. A system permission controls access but is not automatically equivalent to consent under privacy law.

2.4 Interaction and environment data

When an authorized feature is active, ropet may process authorized images or visual data, voice commands, touch-sensor interactions, and IMU motion data to understand its surroundings and respond to user-initiated interaction. These functions do not mean that ropet has consciousness, genuine emotions, or subjective intent or that it forms a real human relationship.

2.5 Images, photography, and interactive snapshots

When you take a photo, select an image, or activate an interactive snapshot under the stated feature conditions, we process image content, file type and size, capture or upload time, task status, and necessary context to upload and understand the image, select valid snapshots, and generate AI content. The device provides a perceptible status indication when capturing. New captures stop when the interaction ends, the feature is disabled, authorization is withdrawn, or trigger conditions no longer apply, subject to the feature-specific privacy notice.

Images may include you, household members, visitors, or others. Use these functions only with a lawful basis, required notice, and any consent or authorization required by law. Do not record in a setting where another person reasonably expects privacy or that involves highly private or sensitive matters.

2.6 Voice interaction and AI conversations

When you activate voice interaction or an AI conversation, we may process audio, speech-recognition text, AI replies, conversation time, device status, and context necessary to maintain the conversation, understand requests, generate replies, support content safety, and diagnose faults. Where a feature is expressly described as using local wake-word or valid-interaction detection, ambient audio not identified as a valid interaction is discarded locally and does not enter the relevant cloud workflow.

2.7 AI-generated content

AI features are clearly identified at activation, in feature descriptions, and in applicable terms. We may process authorized input, speech-recognition results, necessary conversation context, snapshots, generation-task data, output, title, generation time, file type, and deletion status to generate, display, retain, download, share, and delete content.

Visual analysis of a person, face, expression, movement, or posture is limited to understanding the scene, selecting usable snapshots, and producing creative content; it is not used to identify a specific person. We do not create or retain a biometric template for unique identification, infer health, mental state, or another sensitive trait, or use the result for advertising profiles, credit or risk scoring, or decisions in employment, education, insurance, health care, law enforcement, or another area with significant effect.

2.8 Content safety

We may automatically screen user input, speech-recognition text, images, and generated output to prevent unlawful, harmful, or abusive activity. Authorized personnel conduct a minimum-necessary manual review only when automation is insufficient, a complaint or appeal must be handled, a security incident or dispute investigated, or law requires it. Reviewers are subject to confidentiality and access controls.

If a user voluntarily expresses extreme distress, major financial loss, self-harm or suicide, or excessive dependence or compulsive use, ropet may display a safety reminder. It is not medical, psychological, or other professional advice.

2.9 Restrictions on our use

Unless we separately provide full notice and obtain any legally required consent, we do not use personal conversations, raw audio, images, snapshots, or generated content for a third party’s general-purpose AI model training, user profiling, advertising, or marketing, and we do not sell personal information.

Account and service delivery generally rely on performance of a contract or steps requested before contracting. Regulatory, tax, consumer-protection, and other mandatory processing relies on legal obligation. Account, device, and service security, fraud prevention, diagnostics, and legal claims may rely on legitimate interests after balancing and safeguards. Protection of life or physical safety may rely on vital interests. Microphone, camera, photo-library, optional personalization, marketing, or model-training uses that require consent will be separately disclosed and consented to. You may refuse or withdraw consent for nonessential processing without losing an independent basic service.

2.11 Information from third parties

Where direct collection is not reasonably practicable and law permits, we may obtain information necessary for product sales, account service, activation, order fulfilment, after-sales support, or a directly related service from a party with a lawful source and appropriate authority. We verify source, authority, purpose, and quality and do not process information of unverified origin or beyond necessity. Where required, we will identify the source, categories, purposes, and rights within a reasonable period.

3. Sharing, Transfers, and Disclosure

We may engage processors to handle information necessary for the Services. They may act only under our instructions and contract, may not use it for their own advertising, marketing, model training, or independent purpose, and are subject to oversight.

If information is provided to an independent controller, we provide any required notice, identify the applicable legal basis, and obtain separate or express consent where required.

We generally do not transfer personal information to another person or organization. If a merger, acquisition, asset transfer, restructuring, or similar transaction requires a transfer, we will, where reasonably practicable, identify the recipient, scope, purpose, and likely impact and require continuing protection under this Policy and applicable law. A recipient that changes purpose or means must provide a new notice and obtain consent where required.

We generally do not publicly disclose personal information. If disclosure is necessary, we will identify the purpose, scope, and categories of recipients and obtain separate or express consent where required, unless law provides otherwise.

Without consent where law permits or requires, we may process or disclose information to comply with law, binding regulatory demands, court orders, or legal process; protect life, physical safety, or other vital interests; establish, exercise, or defend legal claims; investigate or prevent fraud, security incidents, or unlawful activity; process information you made public or that was lawfully obtained from public sources; or address another situation recognized by law. We apply legality, necessity, and proportionality.

4. Storage, Retention, and Security

4.1 Location and international transfers

Account information, device logs, uploaded images, and generated diaries are stored in data centers in the United States. AI model and voice processing is performed through internationally deployed Agora real-time audio services and BytePlus ModelArk. Provider details, locations, and recipient categories appear in Section 8.

For transfers from a user’s location to the United States or another processing location, we apply contractual, organizational, and technical safeguards required by the user’s applicable law; limit processing to a defined, necessary purpose; require appropriate security; restrict unauthorized onward transfer; and require deletion or anonymization when purpose or retention ends. Contact us to request information or, where law provides, copies of applicable safeguards.

4.2 Retention

We retain information only as long as necessary for the stated purpose or required by law. Raw audio is processed temporarily for speech recognition and is not retained after recognition. Conversations and user-saved content remain until the user deletes them or closes the account. Device logs are retained for six months. At expiry, information is deleted or anonymized unless law requires otherwise.

Information required for legal obligations, binding regulatory or judicial demands, dispute handling, security investigations, or legal claims is retained only within the necessary scope and period, segregated or access-restricted, and not used for personalization, advertising, marketing, model training, or unrelated purposes.

4.3 Security and incident response

We use safeguards proportionate to the information, scale, context, and risk, including transmission and storage protection, authentication, access controls, logging and audit, monitoring, vulnerability management, personnel training, and confidentiality controls.

We maintain an incident-response plan. Following an incident, we act to contain risk, investigate cause, and mitigate harm and notify competent regulators as required. If affected-person notice is legally required, we provide it within the applicable period by email, App notice, in-app notice, or another effective method, describing the incident, likely impact, response and mitigation, protective steps, and contact channel. Lawful delay, restriction, or exemption applies where available.

No internet, communications, or storage system is absolutely secure. Protect your account credentials and device, use an appropriately strong password, and do not disclose verification information to unauthorized persons. Contact us promptly about a suspected risk.

5. Your Privacy Rights

Subject to local law, you may ask whether we process information about you; access it; correct or complete it; obtain a copy; receive it in a structured, commonly used, machine-readable format; or transmit it to another provider. The App may also allow you to view, download, or share AI artwork and diaries.

You may request deletion when the purpose has been achieved or is no longer necessary, retention has expired, the Service ends, processing violates law or agreement, consent is withdrawn, or law otherwise provides. You may request restriction, object to processing based on legitimate interests or direct marketing, and complain to a competent authority. Generated content may also be deleted through the product.

You may disable camera, photo-library, location, and notification permissions in system settings; end a conversation; disable interactive snapshots or an AI feature; or withdraw separate consent. Withdrawal does not affect prior lawful processing. Disabling a feature does not automatically delete generated content.

Account closure may be requested in ropet App under Settings – Close Account. After identity verification, we will process it within 30 calendar days. The account cannot thereafter be used or restored; related information is deleted or anonymized unless law requires retention.

We may require a written request or identity verification. We respond within 30 calendar days after receiving the request and completing necessary verification, unless a shorter period applies. Reasonable requests are generally free. If we cannot act lawfully, we explain why and identify available complaint or remedy channels.

6. Minors and Interpreter Collar Age Limits

ropet may appeal to children. We apply the child definition, digital-consent age, age assurance, parental-consent, and protective-default rules of the region where the Service is offered. Where required, we provide appropriate notice and obtain valid or verifiable parental consent before collecting, using, or disclosing a child’s information, except for processing lawfully permitted for age assurance, safety, or another specified purpose. We use data minimization, protective defaults, and security appropriate to the child’s age, feature, risk, and best interests.

If you believe we processed a child’s information without required parental consent, contact us. After verification, we will stop processing and delete or anonymize information that may not lawfully be retained. A guardian may exercise the rights in Section 5.

Interpreter Collar AI voice conversations, interactive snapshots, and resulting Paipai Diary features are available worldwide only to actual users aged 16 or older. If age verification is failed or incomplete or Minor Mode is enabled, we do not process new conversation audio or take new snapshots and close the feature entry points. Account holders and administrators must not verify age or enable the feature for a person under 16. Stricter local rules apply.

7. Updates

We may revise this Policy for changes in operations, features, or law. We notify users through the App, website, or another appropriate method and do not use an amendment to improperly reduce statutory rights. Where changed processing requires consent, we provide a specific notice and obtain consent before it begins.

An update applies from its stated effective date and does not retroactively change the basis or rules governing earlier processing. Continued use is not consent to new or changed processing that legally requires consent. Refusal of optional processing affects only the dependent feature.

A material change includes a significant change to purpose, categories, or use; ownership or organizational structure; principal sharing, transfer, or disclosure recipients; privacy rights or how to exercise them; the responsible team, contacts, or complaint channel; or processing assessed as high risk. We provide direct notice through an App push, pop-up, in-app message, or registered contact method; a website announcement is supplementary.

8. Third-Party SDKs and Technology Providers

We review provider privacy capabilities and contractually require processing only under lawful instructions, appropriate confidentiality and security, no independent advertising, marketing, or unrelated model training, and return or deletion when the service ends unless retention is legally required. A provider that independently determines purpose and means is an independent controller and will be identified where applicable.

8.1 JPush SDK

Provider: the JPush service entity actually contracted for the App. Purpose: device-status notifications, interaction messages, service reminders, and important updates. Data may include device identifiers, device and operating-system information, network information, and push logs, limited to the enabled basic push function. Optional capabilities such as application lists, precise location, or user insights are not enabled without separate notice and required authorization.

Privacy Policy: https://www.jiguang.cn/en/license/privacy

8.2 Alibaba Cloud Object Storage Service (OSS)

Provider: the contracted Alibaba Cloud international service entity. Account and device logs, uploaded images, AI artwork, diaries, interactive snapshots, and necessary file information are stored in U.S. data centers as required by the enabled feature for account and log administration, uploads, cloud storage, content access, and security.

Privacy Policy: https://www.alibabacloud.com/help/en/legal/latest/alibaba-cloud-international-website-privacy-policy-20231207

8.3 BytePlus ModelArk

Provider: BytePlus Pte. Ltd. or the contracted BytePlus affiliate used for the feature. Purpose: semantic understanding and content generation for AI voice conversations, AI diaries, and other AI-generation features.

Data may include audio, speech-recognition text, context necessary for continuity, interaction records, generation instructions and output, and authorized images when image understanding or generation is used. Data is encrypted in transit through backend interfaces and limited to what the feature requires. The provider may not use it for its own advertising, marketing, or unrelated model training. We stop transmitting new audio, images, and related information after the conversation ends or the feature is disabled.

Data Processing Terms: https://docs.byteplus.com/en/docs/ModelArk/BytePlus_ModelArk_Data_Processing

Privacy Policy: https://docs.byteplus.com/en/docs/legal/docs-privacy-policy

8.4 Agora Real-Time Audio SDK

Provider: Agora Lab, Inc. or the contracted Agora affiliate used for the feature. Purpose: real-time audio transmission, voice interaction, and connection maintenance for Interpreter Collar AI conversations.

Data may include audio, operating-system version, device IP address, network-access method and type, and in-channel user ID. The Agora audio SDK runs only on ropet hardware, not in the mobile App. The device uses microphone and network capability and provides relevant camera and IMU parameters to the SDK. Data is collected and encrypted in transit and may be processed only under our instructions as necessary for the technical service. We stop sending new audio and device parameters after the conversation ends or the feature is disabled.

Privacy Policy: https://www.agora.io/en/privacy-policy/

9. Contact Us

Questions, requests, suggestions, or complaints may be directed to:

Identity verification and response periods follow Section 5. If you are dissatisfied with our response or believe processing infringes your rights, you may complain to a competent privacy or data-protection authority or bring a claim in a court of competent jurisdiction.