Who we are#
Rozi (askrozi.com) is a personal and small-business finance app operated by Human Direct, based in Șimleu Silvaniei, Stadion Street No. 8, postal code 457300, Romania, Trade Registry no. J31/403/2012, Unique Registration Code RO29300200. Human Direct is the controller of the personal data described here. Contact for anything about your data: privacy@askrozi.com.
Rozi is invitation-based for now: it is used by a family, its company and the people they invite, and others can join a waiting list. We do not sell data, show ads or use your data to train AI models.
What we process#
- Account: your name, email address, password hash, two-factor and passkey settings, and the Books (household or company ledgers) you are a member of.
- Financial data you bring in: bank accounts, transactions, categories, budgets, goals, invoices, documents and period closes of your Books, from statement files you upload, from bank feeds you connect, from invoicing systems you connect, and from mailboxes you connect.
- Waiting list: if you join it, your email address and, optionally, what you would use Rozi for (household, PFA, SRL). It is used only to tell you when Rozi opens, never for marketing.
- Technical data: server logs (IP address, browser, time of request) kept for security and troubleshooting, and the cookies listed below.
Gmail and Google user data#
When you connect a Google account to Rozi, you grant read-only access (gmail.readonly). Rozi uses it for one feature: finding supplier invoices and receipts in your mailbox and adding them to the Book you chose.
- Rozi searches your mailbox for mails with invoice-like attachments (PDF, XML, images) from a start date you pick (3 months by default, 12 at most), then follows new mail.
- Rozi stores only the attachments it recognises as invoices or receipts, plus a reference to each mail it read: the mailbox, the sender's address, the receive time and a one-way hash of the mail's Message-ID, so the same mail is never read twice. Rozi does not store the subject, the body or the sender's name of any mail. Bodies are read in memory only, to notice a download link to an invoice.
- Mails you sent, drafts, spam and trash are skipped.
- Rozi never sends, deletes, labels or changes mail.
- You can disconnect a Google account at any time in Rozi, or revoke access at myaccount.google.com/permissions. Documents already added to a Book stay there until you delete them.
Rozi's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. In particular, Google user data is used only to provide the invoice-collection feature you see in Rozi; it is not used for advertising, not sold, not used to train AI models, and not read by people unless you ask us to (for example in a support request), it is needed for security, or the law requires it.
AI processing#
Rozi uses AI models to read invoices (amounts, dates, supplier details), to suggest categories for transactions and to answer questions in the in-app assistant. Only what a task needs is sent: the document or the transaction description, never your password or credentials. Card numbers and account numbers are masked before transaction descriptions are sent. Extracted data is never applied automatically: a person confirms it.
Our AI provider is OpenAI (under its API terms, API data is not used to train its models). We use Langfuse to monitor AI quality and cost. If you connect Rozi to your own AI assistant (for example Claude through MCP), the data that assistant reads from Rozi is processed under your agreement with that provider.
Why and on what legal basis#
- To provide Rozi to you (contract, GDPR Art. 6(1)(b)).
- To keep Rozi secure, prevent abuse and fix problems (legitimate interest, Art. 6(1)(f)).
- To meet legal obligations, for example accounting records of company Books (Art. 6(1)(c)).
- Optional connections (Google, bank feeds, invoicing systems) only with your consent, which you can withdraw by disconnecting (Art. 6(1)(a)).
Who processes data for us#
- DigitalOcean (servers) and Amazon Web Services (encrypted file storage and backups)
- Cloudflare (network protection, DNS, bot check on some forms)
- Brevo (transactional email: invitations, sign-in codes, notifications)
- OpenAI and Langfuse (AI processing and its monitoring, see above)
- Google (Gmail API, when you connect a mailbox)
- Salt Edge (bank feeds, when you connect a bank)
- SmartBill (invoicing data of company Books, when connected)
Each acts on our instructions under a data processing agreement. Some of them are outside the European Economic Area; transfers rely on the European Commission's standard contractual clauses or an adequacy decision.
How long we keep data#
- Book data stays while the Book exists; company Books keep accounting records as long as Romanian law requires.
- Assistant conversations are deleted after 180 days without activity, or when you leave the Book.
- Database backups are kept for 7 days; deleted files remain in versioned storage for at most 30 days.
- Waiting-list entries are kept until you are invited or ask us to remove them.
- Server logs are kept for a limited time for security only.
Cookies#
Rozi uses only cookies it needs to work: the session cookie, security tokens for forms, and, if you choose "trust this device", a cookie that skips the second sign-in step on that device for 30 days. Your light or dark theme is remembered in your browser. There are no advertising or analytics cookies. Cloudflare's bot check may set its own technical cookies on forms that use it.
Your rights#
Under the GDPR you may ask for access to your data, correction, deletion, restriction, portability (every Book can be exported) and object to processing, and you may withdraw consent at any time. Write to privacy@askrozi.com; we answer within 30 days. You can also complain to the Romanian supervisory authority, ANSPDCP (dataprotection.ro).
Security#
Passwords are hashed, two-factor authentication is required for company Books, connection secrets are encrypted, files are stored privately and served only to members of the Book, and every Book's data is kept apart from every other Book's. No system is perfectly secure; we will inform you and the authority of a breach as the law requires.
Changes#
We will update this page when Rozi's data handling changes and show the date above. Material changes are announced in the app or by email.