Privacy Policy for RODY AI

Last Updated: 2 May 2026

At AI-R Metaverse Limited ("we," "us," or "our"), a company incorporated and registered in Hong Kong, we prioritise your privacy. We are dedicated to ensuring that your personal data is collected, used, stored, and shared responsibly. This Privacy Policy provides a comprehensive overview of our practices related to RODY AI (the "App"), an AI-enhanced educational mobile application designed for children aged 4-17 ("Child Users"), supervised by Adult Users aged 18 or older ("Adult Users"). By downloading, installing, accessing, or using the App, you acknowledge and agree to the terms outlined in this policy and our Terms of Use. We comply with Hong Kong's Personal Data (Privacy) Ordinance (PDPO) where applicable. This policy applies to all users globally and reflects our commitment to safeguarding data in an AI-driven educational context.

1. Introduction and Scope

RODY AI leverages artificial intelligence to deliver animated stories and interactive 3D AI character chats, augmented reality (AR) experiences, and subscription-based premium features, fostering an engaging learning environment for children. As a Hong Kong-based entity, we operate under strict privacy standards to protect both Adult Users and Child Users. This Privacy Policy details:

  • The types of data we collect and how we obtain it.
  • The purposes for which we use your data.
  • How we share, store, and secure it.
  • Your rights and options regarding your data.

If you disagree with this policy, please do not use the App. For Adult Users acting on behalf of Child Users, your consent extends to the use of their data as described herein.

2. Geographic Scope and Local Laws

AI-R Metaverse Limited is incorporated in Hong Kong and operates the App from Hong Kong. We do not actively market, solicit, or offer the App for sale to users outside Hong Kong. The App is made available globally on Apple App Store and Google Play as a convenience; if you choose to download or use the App from another country, you do so on your own initiative.

This Privacy Policy is governed by the laws of Hong Kong and is designed around the protections of the Personal Data (Privacy) Ordinance (PDPO). Where mandatory data-protection or consumer-protection laws of your country of residence grant you rights stronger than those set out in this Policy, those local rights apply to the extent of any conflict.

3. Data We Collect

We collect data to provide, personalise, and improve the App's educational services, categorised as follows:

3.1 Adult User Data

When you create an account or interact with the App, we may collect:

  • Account Information: Full name, email address, and account credentials (e.g., username, password) to authenticate and manage your account.
  • Payment Information: Billing details processed securely by third-party providers (e.g., Apple App Store, Google Play Store) for subscriptions; we do not retain this data ourselves.
  • Technical and Usage Data: Device information (e.g., device model, operating system version, unique device identifiers), IP address, and usage analytics (e.g., session duration, unique features accessed) to optimise performance and troubleshoot issues.

3.2 Child User Data

For Child Users linked to an Adult User's account, we collect:

  • Interaction Content (collected under Adult User consent): Chat messages with 3D AI characters, voice inputs, AR-captured environmental images processed for real-time interactions, story preferences, and educational progress (e.g., completed lessons or activities), used to tailor content. This content is collected and processed under the explicit consent of the supervising Adult User.
  • Usage Data: Usage of premium features such as quotas for high-quality voices or AI-generated content.
  • Direct Identifiers Not Requested: We do not request a Child User's name, email, or date of birth directly from the Child User. Such identifying information is collected only if an Adult User chooses to provide it on the Child User's behalf.

3.3 Automatically Collected Data

We use a combination of technologies depending on whether you are using our mobile App or our website:

  • On the mobile App: mobile SDKs, device identifiers (such as IDFA on iOS or Android Advertising ID), and local storage.
  • On our websites (rodyssey.ai and askrody.ai): cookies, web beacons, and similar browser-based technologies.

These technologies are used to gather:

  • Device and Network Data: Device model, operating system, browser type (website only), mobile network or Wi-Fi connection details.
  • Behavioural Data: Pages or features accessed, time spent, and interaction patterns, anonymised where possible for analytics.

You can manage cookies on the website through your browser settings, and manage app-level identifiers through your device's privacy settings (iOS: Settings > Privacy & Security > Tracking; Android: Settings > Privacy > Ads).

3.4 Data from Third Parties

If you link your account to third-party services (e.g., app stores), we may receive limited data (e.g., purchase confirmations) under their privacy terms.

4. Parental Consent and Supervision

4.1 Adult-Only Download and Account Creation

Only an Adult User may download, install, and create an account for the App. Child Users may not download, install, or register on their own. By creating an account, the Adult User represents and warrants that they (a) have reached the age of majority in their country of residence, (b) are downloading and using the App on their own initiative, and (c) authorise the use of any Child User profile linked to their account.

RODY AI is designed for children aged 4-17. We require Adult Users to:

  • Supervise Child Users' activities within the App.
  • Provide explicit consent for the collection and use of Child User data, granted by registering and linking Child Users to your account.
  • Optionally consent to receiving product updates or promotional emails from AI-R Metaverse Limited about RODY AI, which you can manage via account settings.

4.2 Verifiable Consent Process

- Consent for Child User data is obtained via in-app prompts or email verification sent to the Adult User's registered address.

  • Consent for Adult User marketing emails is obtained during account setup or during settings updates, using an opt-in checkbox or a similar mechanism. You may withdraw this consent at any time (see Section 10).
  • If we detect that a Child User has accessed the App without consent (e.g., bypassing account creation), we will suspend access and delete any collected data.

4.3 Parental Management

- Adult Users can access, review, or delete Child User data through account settings at any time.

  • Contact support@rodyssey.ai if you suspect unauthorised use by a child, and we'll take swift action to address it.

5. Children's Privacy

We take children's privacy seriously and apply heightened protections for any data relating to Child Users.

5.1 Default Privacy Protections

Before verifiable parental consent is obtained:

  • The App does not collect personal information from Child Users without parental consent.
  • Voice inputs are processed in real time for generating AI responses. Audio is not retained after processing unless parental consent has been given.
  • Children cannot create accounts; only Adult Users may register and link Child Users.
  • No marketing communications or push notifications are sent to Child Users.

5.2 Verifiable Parental Consent Mechanism

We use a two-step verification process:

  • A direct notice screen is displayed to the Adult User before linking a Child User, explaining our data collection practices and parental rights.
  • Payment confirmation or email verification is used to verify adult status and complete the consent process.

5.3 Parental Rights

Parents and legal guardians may at any time:

  • Review the personal information collected from their child.
  • Request deletion of their child's personal information.
  • Refuse further collection or use of their child's information.
  • Withdraw consent previously given.
  • Contact us at dpo@rodyssey.ai to exercise any of these rights.

5.4 Information We Collect from Children

With verifiable parental consent, we may collect:

  • First name (optional, provided by the parent on behalf of the child).
  • Chat messages with AI characters.
  • Voice inputs (processed in real time; audio is not permanently stored).
  • Educational progress and usage data.

We do NOT collect from Child Users: email addresses, phone numbers, physical addresses, photos of the child, or precise geolocation.

5.5 How We Use Children's Information

- Solely to provide the educational service, personalise learning content, and monitor safety.

  • We do NOT use children's data for advertising, profiling, or marketing purposes.
  • We do NOT sell, rent, or share children's personal information with third parties for any commercial purpose.

6. How We Use Your Data

We process data for specific, legitimate purposes to deliver and enhance RODY AI's educational offerings:

6.1 Providing Educational Services

- Deliver personalised AI-driven stories, interactive chats, AR experiences, and premium features based on Child User preferences and progress.

  • Enable Adult Users to manage subscriptions, monitor quotas, and oversee Child User activities.

6.2 Operational Purposes

- Process subscription payments securely via third-party providers.

  • Maintain account functionality and user support (e.g., responding to inquiries).

6.3 Improving the App

- Analyse usage trends (e.g., popular stories, AR interactions) and technical performance to refine features and AI algorithms.

  • Use anonymised feedback to enhance educational content and user experience.

6.4 Legal and Safety Compliance

- Fulfil legal obligations (e.g., responding to lawful regulatory or law-enforcement requests).

  • Detect and prevent fraud, abuse, or security threats (e.g., unauthorised account access).

6.5 Limited Marketing Use

- With your explicit consent, we may use Adult User email addresses to send you product updates, promotional offers, or news related to RODY AI and other AI-R Metaverse Limited services. You can opt out at any time via account settings or unsubscribe links in emails.

  • Child User data is never used for marketing, advertising, or profiling purposes, ensuring their privacy remains protected.
  • We do not sell, rent, or share any user data with third parties for marketing or advertising purposes.

7. Data Sharing

We limit data sharing to essential operations and legal compliance:

7.1 Third-Party Service Providers

We partner with trusted providers, including:

  • Payment Processors: Apple App Store and Google Play Store, to handle billing securely.
  • Analytics Providers: Google Analytics, to track website usage trends and improve the App.
  • AI Providers: OpenRouter (routing) and Google Gemini (model), to provide AI-powered chat features under Zero Data Retention (see Section 12).
  • Cloud Infrastructure: Cloudflare, for hosting, CDN, and security.

These providers are contractually bound to process data only on our behalf, in accordance with strict confidentiality requirements, applicable laws, and written data-processing agreements. We audit providers regularly and ensure they meet PDPO-equivalent standards.

7.2 Legal Disclosures

- We may share data with law enforcement or regulators if required by law (e.g., a valid court order or lawful request from a competent authority), ensuring minimal disclosure.

7.3 Business Transitions

- In the event of a merger, acquisition, or sale, data may be transferred to a successor entity, with notice provided to Adult Users and safeguards maintained. Children's personal information receives heightened protection during any business transfer.

7.4 No Third-Party Marketing Sharing

- Neither Adult User nor Child User data is shared with third parties for advertising or marketing purposes.

8. Data Security

We employ robust measures to protect your data:

8.1 Security Practices

- Encryption: AES-256 for data at rest, TLS for data in transit.

  • Server Security: Hosted on secure, audited servers with regular updates.
  • Access Controls: Limited to authorised personnel via multi-factor authentication.

8.2 Security Limitations

- Despite our efforts, no system is immune to all threats (e.g., advanced cyberattacks). We mitigate risks through continuous monitoring and updates.

8.3 Breach Notification

If a data breach occurs, we will:

  • Notify affected Adult Users via email or in-app message promptly (within 72 hours if the breach is serious, in accordance with applicable laws). A "serious" breach involves sensitive data or a high risk of harm.
  • Notify the relevant supervisory authority where required by applicable law.
  • Investigate and mitigate the breach, reporting to authorities if mandated.

8.4 Data Retention

We retain your personal data only for as long as necessary to fulfil the purposes for which it was collected, in accordance with Data Protection Principle 2 of the PDPO:

  • Account and profile data (Adult and Child User): Retained until you request account deletion; erased from active systems within 30 days.
  • AI conversation content (chat messages, voice recordings, AR-captured images): Stored on our servers until you delete your account, to allow parents to review their child's interactions, improve the App, and monitor safety.
  • Voice recordings sent for AI processing: Processed in real time and not permanently stored by AI providers (see Section 12).
  • Payment records: Retained for 7 years as required by Hong Kong tax and anti-money-laundering laws.
  • Technical and usage data (anonymised): Retained for up to 24 months for analytics purposes.
  • Data transmitted to AI providers (OpenRouter, Google Gemini): Not retained by these providers under our Zero Data Retention configuration (see Section 12).
  • Marketing consent records: Retained until consent is withdrawn.

Upon account deletion, we will erase your personal data from our active systems within 30 days, except where retention is required by law (e.g., tax records). De-identified, aggregated data may be retained in anonymised form for service improvement.

9. Your Rights and Choices

We provide the following rights to all users:

9.1 Rights Available

- Access: Obtain a copy of your or your Child User's data.

  • Correction: Update inaccurate or incomplete data.
  • Deletion: Remove your data, subject to legal retention needs (e.g., billing records).
  • Restriction: Limit processing in some instances (e.g., during disputes).
  • Withdrawal of Consent: Stop data processing, including marketing emails, potentially limiting App use.

Where mandatory laws of your country grant you additional rights (such as data portability or the right to object to processing), we will honour those rights to the extent required.

9.2 Exercising Your Rights

- How to Request: Submit written requests to our Data Protection Officer at dpo@rodyssey.ai, specifying your request (e.g., "stop marketing emails" or "export my data").

  • Verification: We may verify your identity (e.g., via email confirmation) to prevent unauthorised access.
  • Fees: A reasonable fee may apply for data access requests under PDPO, covering administrative costs, notified upfront and not exceeding HKD 100. Where mandatory law of your country requires us to provide access free of charge, we will do so.
  • Response: We will respond within 30 days, with reasonable extensions for complex cases.

9.3 Managing Data Collection and Marketing Preferences

- Disable cookies via your browser settings on the website, though this may affect functionality.

  • Uninstall the App to stop all data collection (standard device uninstall processes apply).
  • Opt out of marketing emails via account settings or unsubscribe links in each email, effective immediately upon request.

9.4 Complaints

- Contact us first at dpo@rodyssey.ai so we can attempt to resolve your concern. You may also escalate to Hong Kong's Office of the Privacy Commissioner for Personal Data (PCPD) at www.pcpd.org.hk, or — where applicable — to the supervisory authority of your country of residence.

10. International Data Transfers

10.1 Processing Location

- Data is processed in Hong Kong and, where necessary, via cloud infrastructure in other jurisdictions.

10.2 Cross-Border Transfers

Transfers outside Hong Kong are conducted with appropriate safeguards, including:

  • Contractual safeguards requiring recipients to maintain protection standards substantially similar to PDPO.
  • Technical safeguards including encryption in transit and at rest.
  • De-identification of data where feasible before cross-border transmission.

11. AI Services and Third-Party Data Sharing

- To provide AI-powered conversational features, we transmit user inputs — including text questions, voice recordings, and photos — to Google's Gemini AI service via OpenRouter. We have configured our OpenRouter account with the following privacy protections:

  • Zero Data Retention (ZDR) enforced — requests are routed only to provider endpoints that do not retain prompts or completions after processing
  • Training opted out — neither paid nor free endpoints may use your data to train AI models
  • Public dataset publication disabled — data will not be published to any public dataset
  • OpenRouter product-improvement use disabled — OpenRouter itself will not use your inputs or outputs to improve its product
  • As a result, your child's questions, voice recordings, and photos are not retained by OpenRouter or Google after the immediate processing of each request, and are not used to train any AI model.
  • We do, however, store the conversation content (text, voice recordings, and photos) on our own servers for the following purposes:
  • To allow parents to review their child's interactions with the app
  • To improve our app experience and educational content
  • To monitor safety and filter inappropriate content
  • We do not sell or share user data with any third parties for advertising or marketing purposes. Users may request deletion of their conversation history by deleting their account through the App's settings, or by contacting our customer support team at info@rodyssey.ai.
  • Users must provide explicit consent before any AI-powered features are activated.

12. Cookies and Tracking Technologies

12.1 Website (askrody.ai / rodyssey.ai)

We use Google Analytics (gtag.js) on our websites to understand traffic and improve the user experience. For users in the EEA/UK, we will obtain consent before setting non-essential cookies, in compliance with GDPR and the ePrivacy Directive. You may manage your cookie preferences through your browser settings or our cookie consent mechanism.

12.2 Mobile App

The App uses mobile SDKs, device identifiers (such as IDFA on iOS or Android Advertising ID), and local storage for analytics and crash-reporting purposes. No browser cookies are used within the App. Where required by mandatory local laws — for example, the ePrivacy Directive in the EEA or the Privacy and Electronic Communications Regulations (PECR) in the UK — we will obtain your consent before activating non-essential SDKs or accessing non-essential identifiers. You can manage app-level tracking via your device's privacy settings (iOS: Settings > Privacy & Security > Tracking; Android: Settings > Privacy > Ads), and via any in-app consent controls we provide.

12.3 No Advertising or Profiling

We do not use cookies, SDKs, identifiers, or tracking technologies for advertising, behavioural profiling, or retargeting purposes — on the website or within the App.

13. Policy Updates

- Changes: We may update this policy to reflect legal, operational, or feature changes.

  • Notification: Material updates will be posted in the App, emailed to Adult Users, or announced via in-app messages. Continued use post-update signifies acceptance. Review periodically on our website. "Material" updates are those affecting data uses or rights. Where required by applicable law, we will obtain your express consent for material changes.

14. Contact Us

For inquiries, requests, or concerns about this Privacy Policy or your data, contact: Data Protection Officer AI-R Metaverse Limited Email: dpo@rodyssey.ai The Data Protection Officer oversees all privacy matters, including requests and complaints. For urgent issues (e.g., data breaches), include "Urgent Privacy Concern" in your email subject for expedited handling.

15. Additional Protections

15.1 Liability Limitations

To the extent permitted by law, we disclaim liability for data losses caused by user error or force majeure events (e.g., cyberattacks beyond our control).

15.2 Indemnity Clause

You agree to indemnify us for claims arising from your breach of this Policy or misuse of the App, including unauthorised data sharing.

15.3 AI-Specific Disclaimers

AI outputs may contain errors or biases; we are not liable for reliance on them. Data used for service improvement is de-identified or anonymised.

15.4 Force Majeure

We are not liable for data processing delays caused by events beyond our control (e.g., natural disasters or regulatory changes).

15.5 Do Not Sell or Share My Personal Information

We do not sell, rent, or share personal information — of either Adult Users or Child Users — to third parties for cross-context behavioural advertising or any other purpose.

15.6 Overseas Disclaimer

Users outside Hong Kong acknowledge that the laws of their country may apply to their use of the App. Where there is a conflict between this Policy and a mandatory law of the user's country of residence, that mandatory law prevails to the extent of the conflict.

15.7 Arbitration for Disputes

Privacy disputes shall be resolved by arbitration under the HKIAC Rules, as per our Terms of Use. This does not affect any non-waivable right you may have to lodge a complaint with a supervisory authority (such as Hong Kong's PCPD).

15.8 Tax/Compliance

You are responsible for taxes on services; we may share data for anti-money-laundering compliance where required by law.