Last updated: 15.08.2026
Your photos never leave your phone unless you send them somewhere yourself.
Rollo has no accounts, no sign-in, and no way to identify you. The only information that leaves your device is anonymous usage counts, crash reports, and performance measurements — described in detail below, and two of the three can be switched off in Settings.
Pyae Thu Aung is the data controller for Rollo.
Contact: rolloapp.pyaethuaung@gmail.com
Rollo never uploads your photos. There is no server, no cloud, no backup, and no account holding them.
Photos you take are saved inside Rollo's own storage on your device. They are included in your device's normal iCloud or computer backup, the same as any other app's files — but Rollo itself never transmits them anywhere.
A photo leaves Rollo only when you personally choose to send it somewhere: saving it to your Camera Roll, sharing it through the iOS share sheet, or using the "Save to Camera Roll" setting if you switch that on. In each case the photo goes where you sent it, not to us.
Rollo cannot read your photo library. The app asks iOS only for permission to add photos, never to browse them. That is why Rollo's gallery shows only photos taken with Rollo, and can never show anything else on your device.
Rollo uses your camera to take photos. Camera frames are processed entirely on your device to produce the live preview and apply the film look. They are never recorded, never stored beyond the photo you deliberately capture, and never transmitted.
Location tagging is switched off unless you turn it on in Settings and grant iOS permission.
When it is on, your coordinates are embedded into the photo file itself as standard photo metadata, exactly as your phone's built-in camera does. That metadata stays inside the photo, on your device. Rollo never transmits your location anywhere.
If you later share or export that photo, the location travels inside the file — so if you would rather it did not, turn the setting off before taking photos you plan to share.
Three services receive information from Rollo. None of them receives your photos, and none of them can identify you personally.
Service: TelemetryDeck (Germany, servers in the EU)
To understand which film looks people actually use and how much the app is used, Rollo records four kinds of event:
| Event | What it records |
|---|---|
| A photo was taken | which look, its intensity setting, the aspect ratio, whether the self-timer was used |
| Photos were deleted | how many |
| The whole roll was cleared | how many photos |
| Photos were exported | how many, and from which screen |
That is the complete list. No photo content, no filenames, no location, no identifiers you could be traced by.
TelemetryDeck identifies devices using a value that is hashed twice — once by Rollo, once by TelemetryDeck — with a salt that changes daily, so the same device cannot be recognised across days, by us or by them.
To switch it off: Settings → turn off the usage-data option. Data stops immediately.
Service: Firebase Crashlytics, operated by Google (processed in the United States)
When Rollo crashes, a report is sent so the bug can be found and fixed. It contains the technical state of the app at the moment it failed: the code location, your device model, iOS version, and a short trail of recent app activity such as "a photo failed to save."
It does not contain your photos, your location, or anything you typed.
To switch it off: Settings → turn off the crash-reporting option. Collection stops immediately.
Service: Firebase Remote Config, operated by Google (processed in the United States)
Rollo checks whether your installed version is too old to keep working safely — for example, if a serious bug needs everyone moved to a newer version. This check sends only a request for the current minimum supported version.
This one cannot be switched off. It is part of how the app keeps working correctly, and it runs even if you have turned crash reporting off. It means Google's servers are contacted by Rollo regardless of your other choices, so we state that plainly rather than implying the crash-reporting switch prevents it.
Service: Apple MetricKit, forwarded to Firebase Crashlytics
iOS itself measures how well apps perform and delivers a daily summary to the app: how long Rollo took to launch, whether it froze, how much battery and disk it used. Apple collects this on your device; Rollo receives the summary.
Rollo forwards these measurements alongside its crash reports so that freezes and slow launches can be diagnosed the same way crashes are. They contain no personal information and no photo content.
To switch it off: the same Settings switch as crash reports. When crash reporting is off, nothing is forwarded.
| What | Why | Legal basis |
|---|---|---|
| Photos, camera, location | To provide the app's core function | Processed only on your device — not shared with us at all |
| Anonymous usage statistics | To understand which features are worth keeping and improving | Anonymised, so outside the scope of data-protection law; a switch is offered regardless |
| Crash reports and performance data | To find and fix defects and keep the app stable | Legitimate interest in a working, reliable app — with an opt-out |
| Version checks | To ensure you are not running a version with a known serious problem | Legitimate interest in app safety and correct functioning |
TelemetryDeck processes data within the European Union.
Firebase Crashlytics and Firebase Remote Config are operated by Google and process data in the United States. Google participates in the EU–US Data Privacy Framework and offers standard contractual clauses covering these transfers.
If you are in the EU, UK, or another region with similar law, you have the right to access, correct, delete, restrict, or object to the processing of your personal data, and to receive it in a portable form.
In practice, most of these rights have nothing to act on: Rollo holds no account and no personal profile, your photos are on your own device and outside our reach, and the usage statistics are anonymised so they cannot be traced back to you or retrieved individually.
For crash reports, you can stop future collection at any time using the Settings switch. To request deletion of past reports, contact us at the address above and we will pass the request to Google.
You also have the right to lodge a complaint with your local data protection authority.
Rollo is not directed at children under 13 and does not knowingly collect information from them.
If this policy changes, the updated version will be published at this address with a new "last updated" date. Significant changes to what Rollo collects will be described in the app's release notes.
Pyae Thu Aung
rolloapp.pyaethuaung@gmail.com