Rollit app icon
Rollit Privacy Policy

Your media stays yours.

Keep every transfer direct, local, and under your control. Rollit never uploads your photos or videos to the internet or sends them through our servers.

Direct local transfers

Your media moves device to device without passing through the internet or a remote server.

Temporary connection details

Rollit briefly stores a six-digit verification code, local connection addresses, and random session details to connect your browser. Active connection details expire automatically shortly after use.

No accounts or ad tracking

Rollit does not require an account and does not use advertising trackers or behavioral analytics.

Private computer backups

Rollit Backup writes media to your chosen computer folder without uploading it to Bytely or another cloud service.

1. Scope

This Privacy Policy applies to the Rollit app, the Rollit Web Page at rollit.bytely.app, the Rollit Backup browser extension, and related local transfer services operated by Bytely. It explains how information is handled when you add media to Photos, back up media to your computer, or use optional browser pairing.

2. Information on your iPhone or iPad

  • Photos and videos: Media added from your computer stays in the Rollit folder on your iPhone or iPad until you move it to Photos or delete it. When you start a backup, the items you choose are read from Photos and streamed directly to your computer.
  • Photos permission: Rollit requests access only when needed to save media into Photos or let you browse and back up items you select.
  • Camera permission: The camera is used only when you choose to scan a QR code to pair a browser.
  • Local network permission: This is used to run the local transfer server and connect your computer directly to your iPhone or iPad.

3. Optional browser pairing

When you choose Rollit Web Page, Rollit temporarily sends connection details to Bytely's pairing service so your browser can find your iPhone or iPad. These details include:

  • A six-digit verification code.
  • Random session identifiers and temporary access tokens.
  • Your local network address, hostname, and port.
  • The app name, connection status, and expiration time.

Rollit does not send a separate device display name. However, a local network hostname may include a name assigned to your iPhone or iPad.

Your media is never sent to the pairing service. Photos, videos, filenames, and file contents transfer directly between your browser and your iPhone or iPad over your local network.

Bytely processes these connection details only to provide browser pairing and keep it secure. Active details are deleted when pairing closes or expire automatically within approximately five to ten minutes. Cloudflare recovery systems may keep deleted records technically recoverable for up to 30 days.

4. Rollit Backup browser extension

Rollit Backup saves the photos and videos you select to a folder on your computer when you start a local backup in a supported Chromium browser using Device Name or Numeric IP Address.

Information handled during a backup

  • The local Rollit connection address and temporary session identifiers and access tokens.
  • The destination folder permission you select.
  • Photo and video metadata needed to name, transfer, and verify files.
  • The photo and video file bytes being saved.
  • Local progress, errors, and completed-file checkpoints used to continue or resume a backup.

Local storage and transfer

Temporary pairing and backup-job details are stored locally by Chrome. Pairing details expire after 30 minutes of inactivity. Job details may remain for up to seven days within the same browser session so an interrupted backup can report its status.

Your selected folder permission and completed-file checkpoints remain in local extension storage until you clear the extension's data or remove the extension. Rollit uses them to confirm the destination and skip files already completed when you resume. Choosing another folder replaces the saved folder permission but does not remove older checkpoints.

Rollit also creates a small hidden .rollit-backup-state folder inside the generated Rollit Backup folder. Its state file contains version information and a random destination identifier used only to keep resume checkpoints tied to the correct folder.

Your backup does not pass through Bytely. Media moves directly from your paired iPhone or iPad to the folder you choose over your local network.

Extension permissions

  • Offscreen: keeps a backup you started running after the destination confirmation window closes.
  • Storage: keeps local folder, progress, and resume information.
  • Access to local HTTP pages: supports Rollit's Device Name and Numeric IP Address connections. Local addresses vary, so the extension declares access to HTTP pages. It activates only on supported private or local hosts and verified Rollit backup pages, relays only explicit backup messages, and does not collect unrelated page content or browsing history.

Rollit Backup does not sell or transfer user data, use it for advertising or profiling, or use it for any purpose unrelated to its local backup function. Its use of information complies with the Chrome Web Store User Data Policy, including the Limited Use requirements.

5. Service providers and disclosures

Cloudflare hosts and protects the online pairing service and may process standard request data, including IP address and browser information. Apple provides the App Store, Photos, and optional iCloud services. Our email provider processes support messages, which are kept only as needed to respond.

We do not sell personal information, share it with data brokers, or use it for targeted advertising. Information may be disclosed when legally required or necessary to protect users and the service.

Cloudflare operates globally, so technical information may be processed outside your country under applicable safeguards.

6. Your choices and rights

You can avoid online pairing by choosing Device Name or Numeric IP Address. You can manage Rollit permissions in Settings, close an active transfer session, and delete files stored in Rollit.

You choose the computer folder used by Rollit Backup and can change it from the extension. Removing the extension clears its extension-owned local storage. Files already written to your chosen folder, including the small backup-state folder, remain under your control and can be deleted with your computer's normal file tools.

Where privacy law applies, you may contact us to exercise your rights over the limited connection or support information handled by Bytely. You may also complain to your local data protection authority.

Because Rollit has no accounts and pairing details expire quickly, we may be unable to identify an expired session.

7. Security

Hosted pairing uses HTTPS, short-lived access tokens, verification codes, rate limits, and automatic expiration.

Browser media transfers over your local network currently use local HTTP with a random session token and are not protected by local TLS. Use Rollit on a trusted network and close the transfer screen when finished.

8. Children's privacy

Rollit is not directed to children under 13 or the minimum age required in their country. Contact us if you believe a child has provided personal information.

9. Changes to this policy

We may update this policy when Rollit, its providers, or legal requirements change.

10. Contact

For privacy questions or requests concerning Rollit, contact Bytely at [email protected].

Contact Support