ROSEFORGE

Privacy policy

Last updated: 30 July 2026

ROSEFORGE processes manuscripts — your intellectual property. This policy states in plain words what happens to your data: nothing is sold, nothing is published, nothing is used to train third-party models.

1. Controller

THE RED ROSE MEDIA LLC, 1621 Central Ave, Cheyenne, WY 82001, USA · hello@therose.media.

2. Data we process

Order data: work title, author name, language, word count, chosen package, order status.

Work data: the uploaded manuscript (DOCX), optionally the cover (JPEG), and the inspection and final editions derived from them.

Payment data is processed exclusively by Stripe as Merchant of Record — card details never reach our systems.

Technically necessary data: server logs (IP address, time, page requested) for operational security.

3. Manuscripts: encryption and deletion

Manuscript and cover are encrypted with AES-256 on receipt and are stored exclusively in encrypted form. Unencrypted working copies exist only transiently for the duration of an inspection or production run and are deleted immediately afterwards.

During upload, files are received via a secured object store (Cloudflare R2): access requires a short-lived signed address or a server-side secret; immediately after being taken over into our system the file is deleted there (automatically after 24 hours at the latest). Permanent storage happens exclusively AES-256-encrypted on our server.

Your works are never publicly accessible; retrieval requires your order ID, and final files become available only after delivery.

After delivery, all work files are automatically and completely deleted after 30 days (unless expressly agreed otherwise); the deletion is logged in the order history.

Your works are not used to train AI models — neither by us nor by our processors.

4. AI inspection (category B)

For AI-assisted checks, manuscript excerpts are transmitted to the Anthropic API (Anthropic PBC, USA). Anthropic states that API data is not used for model training. Transmission is encrypted and serves solely to perform the commissioned inspection.

5. Recipients

Stripe (payment processing, Merchant of Record) · Anthropic (AI checks) · hosting/infrastructure providers for the website and encrypted file storage. Contracts with all providers restrict processing to the performance of the order.

6. Cookies and local storage

This website uses no tracking cookies and no analytics services. Your browser’s local storage holds functional settings only (chosen colour scheme, language; cached exchange rates). No consent banner is therefore legally required. On your first visit we nonetheless show a brief, purely informational notice about this necessary storage, which you confirm with a click; your confirmation is stored locally in your browser so the notice does not reappear.

7. Your rights

You have the right to access, rectification, erasure, restriction of processing, data portability and objection. Contact hello@therose.media. You also have the right to lodge a complaint with a data protection supervisory authority.

8. Retention

Order and invoice data is kept for as long as statutory retention duties require. Work data is deleted per section 3. Certificate data (ID, file hashes, issue date) remains permanently in the register — it contains no work content.