Privacy Policy

This policy explains how Rolino handles information when you join the waitlist, use the hosted service, or connect an account, including Google Search Console.

Effective August 10, 2026

Who this policy covers

This policy applies to the official Rolino website and managed service at getrolino.com, including its waitlist, web application, API, CLI authorization, and connected social publishing features. Rolino is currently operated by Vlad Palacio in Ontario, Canada.

A self-hosted Rolino deployment is controlled by its operator, not by the official hosted service. That operator is responsible for its own privacy notices, data practices, and legal obligations.

Information we collect

Depending on how you use Rolino, we may process:

  • Waitlist and contact information, such as your email address and messages you send us.
  • Account information, including your name, email address, authentication records, organization membership, and account settings.
  • Workspace content, including brand details, captions, drafts, schedules, uploaded media, publishing settings, and team invitations.
  • Connected-account information, including Instagram, TikTok, YouTube, Bluesky, Google Search Console, or Google Analytics identifiers, display names, profile images, granted permissions, encrypted access credentials, connection health, and publishing or synchronization results.
  • Search performance information, when you connect Google Search Console, including the properties you select and bounded query/page aggregates such as clicks, impressions, click-through rate, average position, comparison period, and derived opportunity evidence. Rolino does not store raw Search Console API responses or user-level visitor data.
  • External search estimates, when you enable SEO Intelligence, including the brand and competitor domains, selected market and language, and bounded keyword, rank, demand, and competition estimates used to explain content opportunities. Rolino stores normalized results, not raw provider responses.
  • Aggregate analytics information, when you connect Google Analytics, including selected GA4 properties and bounded landing-page aggregates such as sessions, active users, page views, engagement, average session duration, key events, comparison period, and derived opportunity evidence. Rolino does not import event-level or user-level Analytics data.
  • Hosted billing information, including the workspace plan, Stripe customer and subscription identifiers, billing interval, invoice and payment status, and refund or dispute state. Stripe processes payment details; Rolino does not store your full card number.
  • Technical and security information, including session identifiers, IP address, browser or device information, timestamps, application logs, API activity, and agent authorization or audit records.

We receive some of this information directly from you and some from services you choose to connect, including Meta, TikTok, Google/YouTube, and Bluesky.

How we use information

  • Provide authentication, workspaces, media storage, scheduling, and publishing.
  • Connect to social accounts and carry out actions you expressly request.
  • Use read-only data from Search Console properties you select to identify and explain content opportunities.
  • Use bounded aggregate reports from GA4 properties you select to identify and explain content opportunities.
  • Use bounded external search estimates to compare an owned brand with the competitor domains that you select.
  • Let agents that you expressly authorize read bounded SEO opportunities, evidence, complete tasks, and weekly reports.
  • Operate hosted trials and subscriptions, enforce workspace plan limits, and provide billing support.
  • Deliver transactional emails and important publishing or security notices.
  • Protect accounts, prevent abuse, troubleshoot failures, and maintain audit records.
  • Operate the waitlist, respond to support requests, and improve Rolino.
  • Comply with applicable law and enforce our terms.

Google API data and AI-assisted features

Rolino requests only the dedicated read-only permission for the Google source you connect: Search Console read-only or Analytics read-only. It uses that permission to list the properties available to the connected Google account and to read bounded aggregates for the properties you intentionally select. Rolino uses this information only to provide user-facing Rolino features, including identifying search trends, content gaps, and content-performance patterns, explaining recommendation evidence, and generating editable content ideas you request.

When you request an AI-assisted idea, Rolino may send a bounded opportunity summary, including relevant query or page evidence and aggregate metrics, to its configured AI generation provider solely to return that feature to you. Rolino configures its current AI gateway, OpenRouter, to deny provider data collection for these requests. Rolino does not use, sell, or transfer raw or derived Google API data for advertising, credit or lending decisions, data brokerage, or training or improving generalized AI or machine learning models.

SEO topic grouping is deterministic by default. If optional model-assisted clustering is enabled for your deployment, Rolino may send only bounded search text and opaque item identifiers to the configured model provider. It does not send search metrics, connected-account credentials, provider responses, or source instructions for this clustering step. The resulting group assignments are validated and bounded before use.

Rolino's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.

Service providers and sharing

We share information only as needed to operate Rolino, follow your instructions, protect the service, or comply with law. Current categories of recipients include:

  • hosting and application delivery providers, including Vercel;
  • database and infrastructure providers, including Supabase;
  • object storage and delivery providers, including Cloudflare;
  • transactional email providers, including Zoho ZeptoMail;
  • payment and subscription providers, including Stripe for the official hosted service;
  • waitlist providers, including FeedbackBasket when waitlist mode is enabled;
  • AI routing and generation providers, currently OpenRouter, only when you request an AI-assisted feature;
  • external search-data providers, only when SEO Intelligence is enabled for your workspace; and
  • platforms you connect, currently Meta/Instagram, TikTok, YouTube, Bluesky, Google Search Console, and Google Analytics.

These services process information under their own terms and privacy policies. We do not sell personal information and do not use it for third-party targeted advertising.

An agent credential can read SEO opportunities, evidence, complete tasks, and weekly reports only after a user explicitly grants the separate Read SEO Intelligencepermission. Existing credentials do not receive this access automatically. You can revoke the credential at any time. Rolino does not give an authorized agent direct or unrestricted access to an external search-data provider.

Retention and deletion

We generally keep account and workspace information while your hosted account is active. Publishing history, billing and transaction records, security records, and limited logs may be retained as reasonably necessary for reliability, fraud prevention, accounting, dispute resolution, or legal compliance.

Disconnecting a social account removes its active credentials from Rolino but does not delete posts already published to that platform. To request deletion of hosted Rolino data, follow our data-deletion instructions. Residual copies may remain temporarily in backups or where retention is legally required.

Disconnecting Search Console stops future synchronization and keeps existing evidence snapshots attached to saved ideas. Its normalized search signals expire after 180 days. The separate Delete imported data action removes the connection, selected properties, sync history, signals, opportunities, generation records, and Search Console evidence snapshots while retaining saved idea text and drafts.

Disconnecting Google Analytics likewise stops future synchronization while keeping saved evidence snapshots. Normalized aggregate analytics signals expire after 180 days. Its separate Delete imported data action removes the connection, selected GA4 properties, sync history, aggregate signals, opportunities, generation records, and Analytics evidence snapshots while retaining saved idea text and drafts.

Normalized external search estimates and topic signals expire after 180 days. Weekly report snapshots remain unchanged and are kept as report history until the related imported SEO data or the workspace is deleted. The confirmed Delete imported data action removes the managed external-search connection, competitor resources, sync history, normalized signals, derived opportunities, related generation records, affected weekly reports, SEO settings, competitor choices, and report subscriptions. It keeps user-created draft text and the separate Search Console connection. Rolino keeps a private monthly aggregate spend record for the active cost-control period so deletion cannot reset a project budget. This record contains no customer query, competitor domain, provider response, or credential. Turning off SEO Intelligence or weekly reports does not delete saved history. Confirmed imported-data deletion removes older project spend rows and keeps only the active monthly control record.

Security

Rolino uses safeguards intended to protect information, including encrypted connected-account credentials, access controls, scoped API credentials, confirmation for consequential agent actions, and secret-safe logging practices. No online service can guarantee absolute security, so please use a strong account and protect any credentials issued to you.

Your choices and rights

Depending on where you live, you may have rights to access, correct, export, delete, or restrict processing of personal information, or to withdraw consent and complain to a privacy regulator. We may need to verify your identity before completing a request.

You can disconnect connected platforms or delete imported Search Console and SEO Intelligence data from Integrations, revoke CLI and MCP access from Agent access, and delete individual brands from Brand settings. For an account-level request, email privacy@getrolino.com.

International processing

Rolino and its service providers may process information in Canada, the United States, and other countries. Those countries may have different privacy laws from your home country. Where required, we use appropriate contractual or other safeguards for these transfers.

Children

The hosted service is intended for adults and is not directed to children under 13. We do not knowingly collect personal information from children under 13. If you believe a child has provided information to Rolino, contact us so we can investigate and remove it.

Changes and contact

We may update this policy as Rolino evolves. Material changes will be identified by a new effective date and, when appropriate, an additional notice.

Questions or privacy requests can be sent to privacy@getrolino.com. Please do not send passwords, access tokens, or other secrets by email.