Legal

Privacy notice

Last updated: 13 September 2026

This website

This website sets no cookies, runs no analytics, and loads no third-party trackers. Fonts and all assets are served from this domain. If you use the contact form, it opens your own email client; nothing you type is stored by this site.

The Rosa service

The Rosa service (the Customer Portal and API) is a separate system with its own operational safeguards: processing in the UK (AWS eu-west-2, London, under the EU-UK adequacy decision), encrypted storage, API keys stored only as hashes, no personal data written to logs, and tiered retention for job artifacts: your debiased datasets and reports expire after days, not years, and trained model files are kept for up to a year so you can run inference against an earlier job.

The Run Manifest is the one job record we keep permanently. Rosa retains an immutable Run Manifest for every job indefinitely as its audit record - the data lives for days, the evidence lives for good. The manifest holds:

  • Per-column statistics - for categorical columns the distinct values and their counts, and each column's number of categories; for numeric columns the minimum, maximum, and standard deviation.
  • Bias-detection results - the discriminator's accuracy at recovering the protected attribute and the resulting bias score, plus the post-debiasing residual on training jobs; the significance of each (the p-value, the shuffled-label chance level, the permutation count and resolution, and the detection thresholds); and the measurement regime that records how the score was measured.
  • Per-group figures - for each value of the protected attribute, its rows in the training sample and how well the detector picked it out, marked exploratory. If a group was too small for the detection test to run, the manifest names that group and its row count.
  • The per-feature debiasing adjustment (diagnose jobs) - indicative of how much each column will be adjusted to remove the protected signal.
  • Each feature's association with the protected attribute - its measured univariate association, and on training jobs that association recomputed on the debiased output.
  • Advisory warnings (inference jobs) - for example a training category absent from the inference file, or a numeric column outside its training range, with the values or range concerned.
  • Job metadata and content hashes - identifiers, status and any structured failure reason, timestamps, the Rosa version and container digest, the training job an inference model came from, the declared columns, the dataset's size before and after encoding, and SHA-256 hashes of the input (so anyone holding the original file can verify exactly what was processed), the schema, the configuration and every output.
  • Operational metrics about the run, not your data - stage timings, peak memory, the number of engine attempts and the hardware it ran on.

It never holds the row-level data you submitted, the debiased output, or the trained model. Because the per-column statistics, the per-group figures and the inference warnings can include category labels drawn from your data, keep direct identifiers (names, emails, customer IDs) out of the analysis as ignored columns so they are never recorded.

You are responsible for ensuring you have a lawful basis for any personal data contained in datasets you submit to the service. Datasets are processed to deliver the service and are not used for any other purpose.

Contact and rights

Rosa is operated by Jason Lee in the United Kingdom. For any privacy question, or to exercise your rights under UK GDPR (access, rectification, erasure, restriction, objection), email jason@rosadebias.com. You also have the right to complain to the Information Commissioner's Office (ICO).