Privacy Policy for RODY AI

Last Updated: 23 October 2025 At AI-R Metaverse Limited ("we," "us," or "our"), a company incorporated and registered in Hong Kong, we prioritise your privacy. We are dedicated to ensuring that your personal data is collected, used, stored, and shared responsibly. This Privacy Policy provides a comprehensive overview of our practices related to RODY AI (the "App"), an AI-enhanced educational mobile application designed for children aged 4-17 ("Child Users"), supervised by Adult Users aged 18 or older ("Adult Users"). By downloading, installing, accessing, or using the App, you acknowledge and agree to the terms outlined in this policy and our Terms of Use. We comply with Hong Kong’s Personal Data (Privacy) Ordinance (PDPO) where applicable. This policy applies to all users globally and reflects our commitment to safeguarding data in an AI-driven educational context. For users outside Hong Kong, local laws may supplement this Policy, but PDPO governs to the extent permitted.

1. Introduction and Scope

RODY AI leverages artificial intelligence to deliver animated stories and interactive 3D AI character chats, augmented reality (AR) experiences, and subscription-based premium features, fostering an engaging learning environment for children. As a Hong Kong-based entity, we operate under strict privacy standards to protect both Adult Users and Child Users. This Privacy Policy details:

  • The types of data we collect and how we obtain it.
  • The purposes for which we use your data.
  • How we share, store, and secure it.
  • Your rights and options regarding your data.

If you disagree with this policy, please do not use the App. For Adult Users acting on behalf of Child Users, your consent extends to the use of their data as described herein.

2. Data We Collect

We collect data to provide, personalise, and improve the App’s educational services, categorised as follows:

2.1 Adult User Data

When you create an account or interact with the App, we may collect:

  • Account Information: Full name, email address, and account credentials (e.g., username, password) to authenticate and manage your account.
  • Payment Information: Billing details processed securely by third-party providers (e.g., Apple App Store, Google Play Store) for subscriptions; we do not retain this data ourselves.
  • Technical and Usage Data: Device information (e.g., device model, operating system version, unique device identifiers), IP address, and usage analytics (e.g., session duration, unique features accessed) to optimise performance and troubleshoot issues.

2.2 Child User Data

For Child Users linked to an Adult User’s account, we collect:

  • Usage Data: Information from interactions with AI features, such as chat logs with 3D characters, story preferences, educational progress (e.g., completed lessons or activities), AR-captured environmental images processed for real-time interactions, and usage of premium features like quotas for high-quality voices or AI-generated content, used to tailor content.
  • No Direct Identifiers: We do not collect personal data (e.g., name, email, or birth date) directly from Child Users unless an Adult User provides it with the Child User's consent.

2.3 Automatically Collected Data

We use cookies, web beacons, and similar technologies to gather:

  • Device and Network Data: Browser type, internet service provider, and connection details.
  • Behavioural Data: Pages visited, time spent on features, and interaction patterns, anonymised where possible for analytics.

2.4 Data from Third Parties

If you link your account to third-party services (e.g., app stores), we may receive limited data (e.g., purchase confirmations) under their privacy terms.

3. Parental Consent and Supervision

3.1 Age and Consent Requirements

RODY AI is designed for children aged 4-17. We require Adult Users to:

  • Supervise Child Users’ activities within the App.
  • Provide explicit consent for the collection and use of Child User data, granted by registering and linking Child Users to your account.
  • Optionally consent to receiving product updates or promotional emails from AI-R Metaverse Limited about RODY AI, which you can manage via account settings.

3.2 Verifiable Consent Process

  • Consent for Child User data is obtained via in-app prompts or email verification sent to the Adult User’s registered address, ensuring compliance with PDPO.
  • Consent for Adult User marketing emails is obtained during account setup or during settings updates, using an opt-in checkbox or a similar mechanism. You may withdraw this consent at any time (see Section 7).
  • If we detect that a Child User has accessed the App without consent (e.g., bypassing account creation), we will suspend access and delete any collected data.

3.3 Parental Management

  • Adult Users can access, review, or delete Child User data through account settings at any time.
  • Contact support@rodyssey.ai if you suspect unauthorised use by a child, and we’ll take swift action to address it.

4. How We Use Your Data

We process data for specific, legitimate purposes to deliver and enhance RODY AI’s educational offerings:

4.1 Providing Educational Services

  • Deliver personalised AI-driven stories, interactive chats, AR experiences, and premium features based on Child User preferences and progress.
  • Enable Adult Users to manage subscriptions, monitor quotas, and oversee Child User activities.

4.2 Operational Purposes

  • Process subscription payments securely via third-party providers.
  • Maintain account functionality and user support (e.g., responding to inquiries).

4.3 Improving the App

  • Analyse usage trends (e.g., popular stories, AR interactions) and technical performance to refine features and AI algorithms.
  • Use anonymised feedback to enhance educational content and user experience.

4.4 Legal and Safety Compliance

  • Fulfil legal obligations (e.g., responding to PDPO requests).
  • Detect and prevent fraud, abuse, or security threats (e.g., unauthorised account access).

4.5 Limited Marketing Use

  • With your explicit consent, we may use Adult User email addresses to send you product updates, promotional offers, or news related to RODY AI and other AI-R Metaverse Limited services. You can opt out at any time via account settings or unsubscribe links in emails.
  • Child User data is never used for marketing, advertising, or profiling purposes, ensuring their privacy remains protected.
  • We do not sell, rent, or share any user data with third parties for marketing or advertising purposes.

5. Data Sharing

We limit data sharing to essential operations and legal compliance:

5.1 Third-Party Service Providers

We partner with trusted providers, including:

  • Payment Processors: E.g., Apple App Store, Google Play Store, to handle billing securely (Apple Privacy Policy, Google Privacy Policy).
  • Analytics Providers: E.g., Google Analytics, to track usage trends and improve the App.
  • Cloud Storage: Secure servers to store encrypted data.

These providers are contractually bound to process data only on our behalf, in accordance with strict confidentiality requirements and applicable laws. We audit providers annually and ensure they comply with PDPO-equivalent standards.

5.2 Legal Disclosures

  • We may share data with law enforcement or regulators if required by law (e.g., court orders under PDPO), ensuring minimal disclosure.

5.3 Business Transitions

  • In the event of a merger, acquisition, or sale, data may be transferred to a successor entity, with notice provided to Adult Users and safeguards maintained.

5.4 No Third-Party Marketing Sharing

  • Neither Adult User nor Child User data is shared with third parties for advertising or marketing purposes.

6. Data Security

We employ robust measures to protect your data:

6.1 Security Practices

  • Encryption: AES-256 for data at rest, TLS for data in transit.
  • Server Security: Hosted on secure, audited servers with regular updates.
  • Access Controls: Limited to authorised personnel via multi-factor authentication.

6.2 Security Limitations

  • Despite our efforts, no system is immune to all threats (e.g., advanced cyberattacks). We mitigate risks through continuous monitoring and updates.

6.3 Breach Notification

  • If a breach occurs, we will:
  • Notify affected Adult Users via email or in-app message promptly (within 72 hours if the breach is serious, in accordance with applicable laws). A "serious" breach involves sensitive data or a high risk of harm.
  • Investigate and mitigate the breach, reporting to authorities if mandated.

7. Your Rights and Choices

We provide comprehensive rights under applicable laws:

7.1 Rights Available

  • Access: Obtain a copy of your or your Child User’s data.
  • Correction: Update inaccurate or incomplete data.
  • Deletion: Remove your data, subject to legal retention needs (e.g., billing records).
  • Restriction: Limit processing in some instances (e.g., during disputes).
  • Withdrawal of Consent: Stop data processing, including marketing emails, potentially limiting App use.

7.2 Exercising Your Rights

  • How to Request: Submit written requests to our Data Protection Officer at dpo@rodyssey.ai, specifying your request (e.g., “stop marketing emails”).
  • Verification: We may verify your identity (e.g., via email confirmation) to prevent unauthorised access.
  • Fees: A reasonable fee may apply for data access requests under PDPO, covering administrative costs, notified upfront and not exceeding HKD 100.
  • Response: We’ll respond within 30 days, with extensions for complex cases (e.g., due to volume or complexity).

7.3 Managing Data Collection and Marketing Preferences

  • Disable cookies via device settings, though this may affect functionality.
  • Uninstall the App to stop all data collection (standard device uninstall processes apply).
  • Opt out of marketing emails via account settings or unsubscribe links in each email, effective immediately upon request.

7.4 Complaints

  • Contact us for resolution or escalate to a supervisory authority (e.g., Hong Kong’s PCPD: www.pcpd.org.hk).

8. International Data Transfers

8.1 Processing Location

  • Data is processed in Hong Kong in accordance with local laws, including the PDPO.

8.2 Cross-Border Transfers

  • Transfers outside Hong Kong are conducted with appropriate safeguards, such as binding corporate rules or standard clauses approved by PCPD, in line with PDPO requirements.

9. Data Retention

  • Retention Period: We keep data only as long as necessary for App operation, legal compliance (e.g., 12 months post-account closure for billing), or analytics (anonymised).
  • Deletion: Upon request or account termination, we delete data within 30 days, except where legally required to retain it. We review retention annually and delete data securely by overwriting or anonymising it.

10. Policy Updates

  • Changes: We may update this policy to reflect legal, operational, or feature changes.
  • Notification: Material updates will be posted in the App, emailed to Adult Users, or announced via in-app messages. Continued use post-update signifies acceptance. Review periodically on our website. "Material" updates are those affecting data uses or rights.

11. Contact Us

For inquiries, requests, or concerns about this Privacy Policy or your data, contact: Data Protection Officer AI-R Metaverse Limited Email: dpo@rodyssey.ai The Data Protection Officer oversees all privacy matters, including requests and complaints. For urgent issues (e.g., data breaches), include "Urgent Privacy Concern" in your email subject for expedited handling.

12. Additional Protections

12.1 Liability Limitations

To the extent permitted by law, we disclaim liability for data losses caused by user error or force majeure events (e.g., cyberattacks beyond our control).

12.2 Indemnity Clause

You agree to indemnify us for claims arising from your breach of this Policy or misuse of the App, including unauthorised data sharing.

12.3 AI-Specific Disclaimers

AI outputs may contain errors or biases; we are not liable for reliance on them. Data used for AI training is anonymised.

12.4 Force Majeure

We are not liable for data processing delays caused by events beyond our control (e.g., natural disasters or regulatory changes).

12.5 No-Sale Confirmation

We do not sell personal data to third parties.

12.6 Overseas Disclaimer

Users outside Hong Kong acknowledge local laws may apply supplementarily, but this Policy prevails under PDPO.

12.7 Arbitration for Disputes

Privacy disputes shall be resolved by arbitration under the HKIAC Rules, as per our Terms of Use.

12.8 Tax/Compliance

You are responsible for taxes on services; we may share data for AML compliance.