Legal
Privacy Policy
Roolly — AI short-film studio · Last updated: September 27, 2026
This Privacy Policy explains how Stedmy, LLC ("Roolly", "we", "us") collects, uses and shares information when you use the Roolly mobile application and the website at roolly.app (together, the "Service").
Roolly is an AI short-film studio: you build a cast of characters — from a photo or from a written description — and turn a premise into a short film that is generated for you. Roolly is built so that we know as little about you as possible: there is no sign-up form, we never ask for your name or email address, and a photo you add is used only to make the character and the films you ask for. An app that works with a face has to be strict about where that face goes; this document says exactly where.
1. Your account and identifiers
No registration. Roolly creates an anonymous account for you automatically the first time you open the app. We do not ask for, and do not collect, an email address, phone number, real name or social profile. Your account is identified by a random user ID and a random handle (such as "ro482913"). You may set a display name and a profile photo yourself; both are optional, stored with your account, and used nowhere else — the profile photo is never a reference for any generation tool.
Device identifier. On first launch the app generates a random device identifier and stores it in your device's secure keychain. It is used so that the free starter credits are granted once per device and so that activity recorded before your account existed can be attached to it. It is not an advertising identifier, it is not a hardware serial number, and it is not shared with advertisers. Because the keychain survives an uninstall, reinstalling the app usually brings you back to the same account.
Session storage. Your session is stored in your device's secure keychain so that you stay signed in to the same account between launches.
2. Characters: photos and descriptions
A character is built in one of two ways, and you choose which.
From a description. You give the character a name and a few written lines. That text is sent to our AI providers, which write the character's look and draw a portrait and a character sheet from it. No photo is involved. Descriptions are checked by an automated word screen, on your device and again on our servers; a description of a minor or of explicit content is refused before anything is generated.
From a photo. Before the first photo is uploaded, the app shows a consent screen that names every company the photo goes to and what each one does, and asks for your explicit agreement. Nothing is uploaded until you agree. You then choose a photo from your library or take one in the app; it is re-encoded on your device and sent to our server, which stores it and screens it (Section 4). The photo is used, once, as the visual reference for the character's portrait (an image of the character's face) and for a character sheet (six views of the character — front, sides, back, waist-up and face — drawn as one image). From then on the portrait and the sheet, not the original photo, are the references the film tools use to keep the character's likeness consistent from shot to shot.
Face data. Roolly's tools look at a face only to reproduce a likeness in generated pictures. We do not run facial recognition, we do not extract facial geometry, landmarks, templates or any "faceprint", we do not compare faces across accounts, and we never use a photo to identify a person. A photo of a face is still sensitive information, and we treat it as such: it is uploaded only after your explicit consent, sent only to the providers named on the consent screen and in Section 10, never used to train any model, never sold, never shown to other users, and erasable in one step (Section 9). You can withdraw your consent at any time in Settings → Manage consent; withdrawing it erases every character built from a photo and every film they acted in.
Photos of other people. If a photo you add shows someone other than you, you are the one who decides to process their image: they must be an adult, you must have their informed consent before you add it, and you remain responsible for that use and for the results. We process such a photo only on your instruction and only to make the character and films you ask for. If you cannot show that consent, do not add the photo.
What we never do with a photo. We do not use your photos, portraits or character sheets to train AI models, we do not sell them, we do not use them to advertise to anyone, and we do not show them to other users.
3. Films you make
What you provide. A premise (or your own twist on a template's story), the template you chose, a tone, a length and the characters in the cast. Premises and twists pass the same word screen as descriptions.
What is generated and stored. The script (a title, the scenes and their dialogue), one still picture per scene, one video clip per scene, the finished film and its poster. All of it is stored with your account, under unguessable, account-scoped paths on our storage provider, and shown only to you. When you review the storyboard and edit a scene's text, the edit replaces that scene's text in the stored script.
How a film is made. A language model writes the script from your premise, the template's plan and your characters' names and descriptions. An image model draws each scene's still from the script and the cast's portraits. A video model films each clip from its still and the scene's text, generating the dialogue and the sound inside the clip; the clips are then joined into one film. Every still is screened (Section 4) before it is kept. The providers behind each step are listed in Section 10.
Sharing. The finished film is delivered from our content delivery network. When you use Share, the app hands the film's address to your device's share sheet; anyone you send it to can watch the film from that address until the film is deleted. Saving a film to your photo library keeps a copy on your device that we no longer control.
Nothing is real footage. Every picture and every clip Roolly makes is AI-generated. Films are fiction with your cast in them and must never be presented as an authentic recording of a person or an event.
4. Automated safety screening
Every photo you upload and every still generated for a character or a film is checked by a vision model for two things: whether it appears to show a person under 18, and whether it contains nudity. A photo that appears to show a minor is rejected and nothing is generated. A generated picture that fails is redrawn once with stricter instructions, and the character or film is stopped — with its credits returned — if it fails again. Written premises, twists and descriptions are checked against a list of refused terms.
Each screening verdict is recorded in an abuse-prevention log (the verdict, the model used, its cost and the account it belonged to). This log exists precisely to stop repeat abuse, so it is retained after account deletion; the account it points to no longer exists at that point (Section 9). Repeated attempts to make content from photos of minors may lead to the account being blocked.
5. Credits and purchases
Roolly runs on virtual credits. We store your credit balance and an append-only ledger of every credit movement on your account: the starter grant, holds and spends for characters and films, credits returned when a job fails, and credits from purchases.
Credit packs and the Roolly Plus subscription are sold through the Apple App Store. The purchase is processed by Apple and validated for us by our subscription provider (Adapty). We never receive or store your payment card details. What we receive is the record needed to deliver what you bought and to honour restores: the product, the store's transaction identifier, the purchase and expiry dates, and whether the purchase was made in Apple's sandbox. Your current Plus plan and its expiry date are kept on your account so the app can show them.
6. Product analytics
We record product-analytics events — which screens you open, which tools you start, whether a character or a film succeeded or failed, which purchases were started or completed — tied to your random user ID, so we can find broken flows and improve the app. Each event carries the device identifier, a per-launch session ID, the platform, the app version and build, the operating-system version and your locale. Events never contain your photos, your films or the text of your premises and descriptions.
This runs on our own backend. The app embeds no third-party analytics or advertising SDK, and we do not track you across other companies' apps or websites.
7. Content reports
Every generated result carries a flag you can use to report it to us. A report records the reason you chose, any details you wrote, a snapshot address of what was on screen (the film, a storyboard frame or the portrait) and your user ID. Reports are moderation input for us alone: nothing about them is shown to other users. They are kept as a record of moderation; if you delete your account, the link between a report and your account is removed.
8. The website
The website at roolly.app is a static site. It sets no cookies, runs no analytics and does not profile visitors. As with any website, our hosting provider records basic technical request data (such as IP address and user agent) for delivery and security. The template posters and sample films on the site are loaded from our content delivery network, which records the same technical data.
9. Retention, erasure and account deletion
Erase face data. From Settings — Erase face data, or Manage consent and withdrawing your consent — you can erase everything that came from a photo in one step: any character or film still being made is stopped and its credits returned, every character built from a photo is deleted together with the films they acted in and every file behind them, and your profile photo is removed. Characters written from a description stay.
Delete a character or a film. Deleting either removes its record and its files. Our content delivery network may continue to serve a cached copy of a deleted file at its old address until that cache expires.
Delete your account. Deleting your account removes your account record, your cast, your films, every file you uploaded or generated, and the sign-in identity behind the account. A short record of the deletion is kept as the only trace that the account existed: the user ID, the time, the IP address and app identifier of the request, and the reason you gave if you gave one. The records that must survive for accounting and abuse-prevention purposes stay, but under a random user ID that no longer belongs to any account and cannot be traced back to you or to any new account you create: the credit and purchase ledger, the product-analytics events, the safety-screening log and any content reports (with the link to the reporter removed). The device record that says the starter credits were granted to this device also stays, so that the free credits are not granted again; its link to the account is cleared. Opening the app again after a deletion creates a new anonymous account.
Storage paths. Uploaded and generated files are stored under unguessable, account-scoped paths on our storage provider. Once they are deleted and the records that point to them are gone, they can no longer be reached through the Service.
10. Who we share information with
We work with a small number of providers who process data on our behalf:
- Our infrastructure providers — the database and anonymous sign-in behind your account, the servers that run every tool, the storage and content delivery network that hold and deliver your photos, portraits, character sheets, stills, clips and films and the template catalog, and the hosting of this website.
- xAI — the automated safety screening described in Section 4, which receives every photo you add and every generated still to check for minors and nudity; the language model that writes the script from your premise and your characters' descriptions; and the image model that draws a character's portrait (from your photo or your description) and each scene's still (from the script and the cast's portraits).
- Runware — the character sheet, drawn from your photo or the portrait by an image model from Google that Runware runs.
- fal.ai — each clip, filmed from its still and the scene's text by a video model from MiniMax that fal.ai runs, and the joining of the clips into one film.
- Adapty — validation and management of App Store purchases and subscriptions.
- Apple — payment processing and subscription billing.
The AI providers receive your photos, portraits, descriptions and premises only for the request at hand, to produce that result. These providers are bound by contract to process data only on our instructions. We do not sell personal information and we do not share it for advertising.
11. International transfers
We operate from the United States and our providers may process data in the United States, the European Union and elsewhere. Where a transfer requires it, we rely on appropriate safeguards such as the European Commission's standard contractual clauses.
12. Your rights
Depending on where you live — including under the GDPR, the UK GDPR, Turkish KVKK and US state privacy laws such as the CCPA/CPRA — you may have the right to access, correct, delete or receive a copy of your personal data, to restrict or object to its processing, to withdraw consent, and not to be discriminated against for exercising these rights.
The fastest route for erasure is in the app itself (Settings → Erase face data, or Delete my account). For anything else, write to support@stedmy.com and we will respond within the period the applicable law requires. Because Roolly accounts are anonymous, we may need information from the app (such as the handle shown on your profile) to locate your data. You may also lodge a complaint with your local data-protection authority.
13. Security
All traffic is encrypted in transit. Database access is protected by row-level security so that only your own account can read your rows; credits are managed exclusively server-side; the keys to our AI and storage providers never leave our servers; files are stored under unguessable, account-scoped paths; and internal access follows least privilege. No system is perfectly secure, but we apply industry-standard safeguards throughout.
14. Children
Roolly is not directed at children. You must be at least 18 years old to use the Service, and photos or descriptions of minors may never be used to build a character (Section 4). If you believe a person under 18 has provided us personal data, contact us and we will delete it.
15. Changes to this policy
We may update this Privacy Policy from time to time. Material changes will be announced in the Service. The current version is always available at https://roolly.app/privacy.
16. Contact and data controller
The data controller is:
Stedmy, LLC
Delaware, United States
Email: support@stedmy.com