Privacy Policy for Roosta
Roosta is built so that there is very little to write a privacy policy about. Everything You create in it — Your alarms, Your wake-up history, Your settings — is written to the Application's own storage on Your device, and by default it stays there and nowhere else. There is no advertising, no tracking, and no profile of You anywhere. The one thing that does leave is a short, fixed list of anonymous usage statistics about where in the initial setup people get stuck, described in Section 2.
That includes the parts that sound as though they could not possibly be local. Roosta asks You to photograph things, counts Your push-ups through the camera, and listens to You read a passage out loud. None of that leaves Your phone: no photograph is saved, no video is recorded, no audio is transmitted, and the transcript of what You read is discarded with the screen. Section 3 sets out exactly how each of those works, because they are the parts most worth being specific about. That commitment is absolute and is not affected by anything else in this Policy.
There is one deliberate exception to "stays on Your device", and it is Yours to switch on. If You create an Account — optional on both platforms, and never required to use the Application — Your alarms, Your wake-up records, Your settings and the names of any songs You have chosen as alarm sounds are backed up to Our database in the European Union so that a new phone can get them back. Section 4 describes exactly what is copied, who processes it, and how to delete all of it. Without an Account, none of that happens.
This Privacy Policy explains the whole arrangement, names every company that handles anything on Our behalf (Section 10), and sets out what rights You have under the General Data Protection Regulation (GDPR) and its UK and Swiss equivalents, the California Consumer Privacy Act (CCPA/CPRA) and other U.S. state privacy laws.
By using the Application, You agree to the terms of this Privacy Policy.
Interpretation and Definitions
For the purposes of this Privacy Policy, capitalized terms have the meanings defined below, whether they appear in singular or plural form.
- Account means the optional Roosta account described in Section 4. On an Apple device it is created with Sign in with Apple or Sign in with Google; on an Android device, with Sign in with Google or a sign-in code sent to Your email address.
- Account Data means the copy of Your alarms, wake-up records, settings and custom sound names held against Your Account, together with the identifiers listed in Section 4.
- Application refers specifically to Roosta, the mobile software application provided by the Company — the Apple version for iPhone, together with its NightMonitor extension, or the Android version. Where a passage below is true of only one of them, it says which.
- Company ("We", "Us", "Our", or NovApps ApS) refers to NovApps ApS, the developer of the Application.
- Device means the iPhone or Android phone on which You have installed the Application.
- Local Data means the information the Application stores on Your Device, as described in Section 1.
- Mission means the task the Application requires You to complete in order to stop a ringing alarm.
- Personal Data means any information relating to an identified or identifiable individual.
- Processor means a company that handles Personal Data on Our instructions and on Our behalf, under a contract that forbids it from using that data for its own purposes. Every one is named in Section 10.
- Screen Time means Apple's Family Controls, Device Activity and Managed Settings frameworks, which the Apple version uses for the two optional features described in Section 6. Android has no equivalent framework. The Android version offers app blocking, built a different way and with different privacy consequences, and has no deletion guard at all — both are described in Section 6.
- Subscription means the auto-renewing subscription that gives access to the Application, described in Our Subscription Terms.
- You means the individual using the Application.
1. What the Application Stores, and Where
The Application stores the following on Your Device. Without an Account it is held there and nowhere else; with one, the items marked below are also copied to the backup described in Section 4.
- Alarms (backed up) — the time, optional label, days of the week, chosen Mission and how much of it (repetitions, shakes, questions, words, or a difficulty level), sound choice, whether a check-in follows and how long afterwards, whether the alarm is enabled, and when the alarm was created.
- Wake-up records (backed up) — one record per scheduled morning: the date, the target time and deadline, whether and when the alarm rang, when the Mission was started and completed, the resulting outcome (success, failure, or still pending). Your Streak, and the two protected mornings a week that can absorb a missed one, are calculated from these records each time they are displayed; neither is stored as a figure of its own. Records written before August 2026 may still carry a rest-day flag, left by a feature that has since been removed; nothing sets it now.
- Alarm and Mission preferences (backed up) — Your defaults for new alarms (Mission, difficulty, sound), whether a Mission deadline applies and how long it is, whether the alarm falls silent while a Mission is on screen, whether the Device vibrates while one is, how loud the Device is turned up to for one, and whether alarms lock before they ring and for how long.
- Sleep and bedtime preferences (backed up) — how long a night You are aiming for, whether reminders are allowed at all, whether the bedtime reminder is on and how many there are and how far apart, whether the reminder about not having set an alarm is on and at what time of day it should arrive, and whether You may claim a morning without running a Mission and from how long before the alarm.
- Custom alarm sounds (their names are backed up; the audio never is) — if You choose a song to wake up to, the Application keeps the thirty-second preview it downloaded from Apple's catalogue as an audio file in its own storage, together with the track's title, artist, the address of its artwork, the address the preview came from, and when You added it. If instead You import an audio file of Your own, the file is copied into the same storage and carries only the name it arrived with. The audio itself, imported or downloaded, stays on the Device: it is never uploaded, to Us or to anybody. See Section 4 for what an Account does with the names, and Section 10 for what a search asks Apple.
- Mission setup (backed up) — the list of household items You have told Item Search You own, the item it used most recently, which reading passage You have chosen, and the text of a passage of Your own if You have written one.
- App blocking — whether the feature is on, and which apps You chose to shield. What that second part actually is differs by platform, and the difference matters. On the Apple version it is an opaque Screen Time reference that the Application cannot read, and neither can We. On the Android version it is a plain list of the package names You picked — readable text such as
com.example.socialapp— because Android's picker hands over names rather than tokens. That list is written to the Application's own private storage on Your Device, it is deliberately excluded from Your Account backup, and it is never sent to Us. See Section 6. - Interface preferences (backed up) — Your light/dark preference, whether You read the clock as 12- or 24-hour, and which setup steps the checklist has seen done.
- First-run state — whether You have finished onboarding, and Your answers so far if You left it partway through. Deliberately not backed up, even with an Account: this is a fact about this installation rather than about You, and restoring it onto a new phone would drop You straight into an app with no alarm in it.
- Subscription status — a locally cached record of whether Your Subscription is currently active, derived from the App Store on an Apple device and from Google Play on an Android one.
- Legal acceptance — which version of these documents this Device last agreed to, and nothing else about it. See Section 17.
- Your Account session, if You have created one — the sign-in tokens issued by Our authentication provider, erased when You sign out. On an Apple device these are held in the iOS Keychain rather than in ordinary storage. On an Android device they are held in a private preferences file inside the Application's own sandbox, excluded from device backup and from device-to-device transfer so that a copy of Your phone does not carry a live session with it.
On the Apple version this information is written to the Application's private container using Apple's standard on-device storage (SwiftData and user defaults). The app-blocking settings additionally live in a shared App Group container (group.com.novapps.roosta) so that the Application's own NightMonitor extension can read them while the Application is not running; that container is part of the same sandbox and is reachable only by the Application and its extension. All of it is protected by iOS's app sandbox and file protection.
On the Android version it is written to the Application's own private data directory — a local database for the alarms and wake-up records, and private preference files for the settings — protected by Android's app sandbox. There is no shared container, because there is no extension to share with. On both platforms, the sandbox is what keeps this inaccessible to other applications on the Device.
Purpose: to ring Your alarms at the times You set, to require and score Your Missions, to shield the apps You asked to be shielded during the night, and to show You an honest record of the mornings You got up on.
We do not collect Your phone number, contacts, location, photographs, health or fitness data, advertising identifier, or any device identifier. There is one identifier of Our own, and it is the same on both versions: a random value that Your copy of the Application generates for itself on first launch and stores with its other preferences, used only for the anonymous usage statistics described in Section 2. It is not derived from Your Device, is not Your Account identifier, is never sent to any other Processor, and is destroyed when You delete the Application. Beyond that one value We assign You nothing unless You create an Account, in which case the identifiers are those listed in Section 4 and no others.
2. What the Application Does Not Do
These are commitments about how the Application is built, not merely statements of current practice. They are a reason the Application exists in the form it does.
- Nothing from a camera or a microphone is ever transmitted. No photograph, no video frame, no audio, no transcript — not to Us, not to a Processor, not to Apple or Google. This holds whether or not You have an Account, and it is the one commitment here with no exception at all. See Section 3.
- No crash-reporting, and no analytics software. The Application contains no crash reporter on either platform, and no analytics library from anybody: the usage statistics above are sent by a few hundred lines of Our own code, posting the fixed list of events in this Section and nothing else. There is no analytics SDK to autocapture screens, read device identifiers, record sessions or grow what is collected in an update. The third-party code in the Application is RevenueCat's subscription library (Section 7); on the Android version it sits alongside Google's own on-device libraries — ML Kit for the Mission checks, Credential Manager for Sign in with Google, and the Play Billing library — none of which is analytics, and all of which are described where they are used.
- Anonymous usage statistics. So that We can find the points where setting the Application up is confusing or fails, the Application records a short, fixed list of things You did, against the random identifier described in Section 1 rather than against You. It records which screens of the initial setup You reached, by screen name only, and for each one how many whole seconds it was in front of You and whether You went on or stopped there; whether You reached the end of setup at all; whether the subscription screen was opened, and if it was closed without subscribing, which of its pages was showing at the time; which plan was tapped, and whether a purchase was started, completed, cancelled or failed; whether You have completed a first morning; and the version of the Application and of the operating system it is running on. It records none of Your answers to the setup questions — that You reached the screen asking a question, never what You replied — and no alarm times, wake-up times, target times, Mission text, history, name or email address. Your IP address is not recorded and no location is derived from one: IP collection is switched off at the point the data is sent, so no address is stored and no country, region or city is inferred. Nothing from a camera or a microphone is involved, which remains absolute under Section 3. The list above is the whole of it, fixed in the Application's source code so that it cannot grow without this Policy changing with it. The data is held by PostHog in the European Union (Section 10). It is never used for advertising, never sold, and never combined with data from any other application or website.
- No advertising, tracking, or profiling. The Application does not display advertisements, does not participate in any advertising network, and does not track You across applications or websites. It has never requested App Tracking Transparency permission and has no reason to.
- No photo library, and no camera roll of its own. The Application cannot open Your photographs and does not save the ones it takes. See Section 3.
- No sale or sharing of Personal Data. We do not sell Your Personal Data, do not share it for cross-context behavioural advertising, and do not disclose it to anyone except the Processors named in Section 10, each of which acts on Our instructions and may not use it for its own purposes.
- No marketing. Creating an Account does not put You on a mailing list. We do not send marketing email and have no mechanism to.
- An Account is optional, and the Application is whole without one. Nothing is withheld, degraded, or nagged at if You never make one. Every feature works signed out, permanently.
What does involve a network, stated plainly.
- Your Subscription is bought through the App Store or Google Play, whichever You installed from, and checked through RevenueCat (Section 7). This happens whether or not You have an Account, because access to the Application depends on it.
- Your Account, if You create one — signing in, and the backup of Your alarms, records and settings (Section 4).
- The two legal documents: the Application checks their current version at launch so it can tell You when they have changed (Section 17). That request identifies nobody and is made whether or not You are signed in.
- The speech recogniser used by the Reading Mission is an operating-system asset rather than part of the Application. On an Apple device it is a model iOS downloads from Apple, if You ask for it in Settings (Section 3). On an Android device it is the on-device recogniser the phone already ships with; the Application downloads nothing.
- Searching for a song, if You go looking for one in the sound picker. What You type is sent to Apple's public iTunes Search endpoint, along with Your store region, and comes back as a list of tracks; choosing one downloads its thirty-second preview from Apple's content network to Your Device. No key, no account and no Apple ID are involved, and the request carries nothing about You beyond the words You typed and the region — not Your Account, not Your alarms, not any identifier of Ours. It happens only while You are actually searching, never while an alarm rings, and never at all if You do not use the feature. See Section 10.
- The anonymous usage statistics described above, sent in small batches while You are using the Application and again when it goes into the background. Nothing in the Application waits on them: a batch that cannot be sent is abandoned rather than queued or retried, and everything behaves identically whether they arrive or not.
- Links You tap — this page, the Store's refund page, the Store's review page, or the support email — hand off to Your browser, Your store app or Your mail app, and are then that app's business rather than Roosta's.
An alarm never waits on any of it. The Application will ring, run a Mission and record a morning with the Device in aeroplane mode indefinitely: a song already chosen is a file on the Device by then and rings from there, and the usage statistics are abandoned rather than queued. A network is needed to buy the Subscription, to sign in, and to search the catalogue — never to wake You up.
3. The Camera, the Microphone, and Your Voice
Most of Roosta's Missions ask for a camera or a microphone, which in almost any other application would be the paragraph where a privacy policy becomes vague. Here is the specific version.
Missions that end in a photograph
Item Search, Picture of Sky, Touch Grass and Make Your Bed open the rear camera and ask You to photograph something. When You press the shutter, the photograph is held in memory, examined on the Device to check that the requested subject is in shot — by Apple's Vision framework on the Apple version, and by Google's ML Kit image labelling on the Android version, both of which run entirely on the phone, and shown back to You. It is never written to disk, never added to Your photo library, and never transmitted. It ceases to exist when the Mission screen closes. The Application keeps no photograph of any kind, and the classification model runs entirely on the Device — the picture of Your bedroom does not go anywhere, because there is nowhere for it to go.
The Application has no access to Your existing photographs. There is no picker and no library permission, deliberately: the whole content of these Missions is that You got up and pointed a phone at something.
Missions that count repetitions
Push Ups, Sit Ups and Squats use the rear camera to watch You and count. Although it looks like a recording, nothing is recorded: individual video frames pass from the sensor to on-device body-pose analysis — Apple's Vision on the Apple version, Google's ML Kit pose detection on the Android version — and are discarded immediately. There is no file, no buffer retained, and nothing to delete afterwards. What survives the frame is a number — how many repetitions You have done, and whether a body is currently in view — and that number is not stored once the Mission ends.
The Reading Mission and Your voice
The Reading Mission asks You to read a passage aloud and uses the microphone to check that You did. Both versions transcribe on the Device by construction, and both pick the API that cannot do otherwise: the Apple version uses Apple's on-device SpeechAnalyzer rather than the older speech API, which can send audio to Apple's servers; the Android version uses createOnDeviceSpeechRecognizer rather than the ordinary recogniser, which can send audio to Google. Where a phone has no on-device recogniser at all, the Android version says so and substitutes the arithmetic Mission rather than falling back to one that would transmit. Your voice is not recorded to a file, is not transmitted to Us, and is not transmitted to Apple or Google. The transcript exists in memory for the duration of the Mission, is compared against the passage, and is discarded when the Mission ends.
On the Apple version, on-device transcription requires a speech model for Your language, which is an operating-system asset rather than part of the Application. If it is not already installed, the Application will tell You so and offer to fetch it from Settings, while You are awake; iOS then downloads it from Apple. That download is a transaction between Your Device and Apple, governed by Apple's Privacy Policy, and it carries nothing about You from Us. Roosta will never start that download during a ringing alarm. On the Android version there is nothing to download: the Application uses whatever on-device recogniser the phone has, and where there is none it substitutes the arithmetic Mission.
The passage itself is either one of the texts bundled with the Application or one You have written, which is stored locally with Your other preferences (Section 1).
When a Mission cannot run
If a permission has been refused, hardware is unavailable, the room is too dark, or the speech model is missing, the Application does not leave You trapped behind a Mission that cannot be completed: it offers the arithmetic Mission instead. Refusing the camera or the microphone therefore costs You those Missions, not the alarm.
4. Your Account and the Backup
An Account is optional. It exists for one reason: without it, a lost, reset or replaced phone takes Your alarms and Your entire wake-up history with it, permanently. Everything in the Application works signed out, indefinitely, with nothing withheld — an Account buys a backup and nothing else.
How You create one
Which routes are offered depends on Your platform. There is never a password to choose and never a password to reset, because there is no password anywhere in this.
- Sign in with Apple (Apple version) returns a stable identifier for You and — the first time, and only if You allow it — Your name and an email address. Apple's Hide My Email gives Us a private relay address instead of Your real one, and that is fine here: We send no marketing email of any kind, so a relay address costs Us nothing and is the better choice for You.
- Sign in with Google (both versions) returns Your Google account identifier, the email address on that account, and Your name and profile picture. The Application requests no other scope — no access to Gmail, Drive, Contacts, or anything else in Your Google account.
- A sign-in code by email (Android version) is the alternative where You would rather not involve Google. You type an email address, We send a six-digit code to it, and typing the code back proves the address is Yours. This is the one route where You hand Us an email address directly, and it means two things worth stating plainly: the address is stored against Your Account, and it is passed to the mail Processor named in Section 10 for the sole purpose of delivering that code. It is never used for marketing, and there is nothing to unsubscribe from.
In each case the provider or the code confirms who You are, and the Application passes the resulting signed token to Our authentication Processor.
Your relationship with Apple and with Google is theirs to govern, under Apple's Privacy Policy and Google's Privacy Policy. Signing in tells that provider that You use Roosta.
What is held against Your Account
- An account record — an identifier We generate for You, the email address Your provider returned (or its relay), which provider it was, the name it supplied if any, and the dates the Account was created and last used.
- Your alarms — the same fields listed in Section 1.
- Your wake-up records — one row per scheduled morning, as in Section 1. Your Streak is not stored anywhere; it is recalculated on the Device.
- Your settings — the preferences listed in Section 1, as a single document. This includes the text of a reading passage You wrote Yourself, if You wrote one.
- The names of Your custom alarm sounds — for each one, the title, the artist, the address of its artwork, the address its preview came from, and when You added it. Never the audio. That is the whole of the point: a song is a name and an address, so a new phone can fetch the same thirty seconds back from Apple by itself, and an imported file is a name alone, so a restored phone can tell You which sound is missing instead of silently ringing a rooster in its place.
- Your legal acceptance — which version of these documents You accepted, and when (Section 17).
- A token from Apple, and only if You signed in with Apple on an Apple device — a credential Apple issues Us at sign-in, held so that deleting Your Account can also tell Apple to revoke Roosta's access to Your Apple Account. It is not readable as information about You: it says nothing about who You are, and it exists for exactly one purpose, described below. Signing in with Google produces no equivalent, because Google needs none.
What is never uploaded, Account or no Account: nothing from a camera or a microphone — no photograph, no video frame, no audio, no transcript, none of it, because none of it is kept in the first place (Section 3). Nor any alarm audio: neither the previews downloaded from Apple's catalogue nor the files You imported Yourself ever leave the Device, only their names (Section 1). Nor the apps You chose to shield, on either version, though for different reasons: on the Apple version Screen Time hands the Application opaque tokens it cannot itself read, so there is nothing there to send, and on the Android version the list of package names is readable but is deliberately excluded from the Account backup and is never uploaded (Section 6). Nor Your Subscription, which belongs to the Store account that bought it — Your Apple Account or Your Google Account — rather than to Your Roosta Account.
The Application backs up when it goes into the background and when a morning is decided. It is a backup rather than a live sync: it adds what a Device is missing and overwrites nothing, so signing in on a phone You have been using cannot replace a morning You actually lived through with an older copy.
Coming back down works on the same rule. Your alarms, Your records and Your sound names are added to whatever the Device already holds. Your settings are the one thing that could overwrite rather than add, so they are applied only to a Device with no alarms on it — a new or reset phone, which is the situation a restore exists for. Sign in on a phone You have been using and it keeps the preferences You have been living with.
Where it is, and who can reach it
Account Data is held in a Postgres database and an authentication service operated for Us by Supabase as Our Processor, hosted in the European Union (Paris, on Amazon Web Services). It travels there over TLS. Every table enforces row-level security keyed to Your own identifier, so one Account cannot read another's rows even in principle, and the key that ships inside the Application is a publishable one that grants no access on its own.
We can reach Account Data through Our provider's administrative console. We look at it only where necessary to operate or repair the service, or to answer a request You have made — never for marketing, and never to build any profile of You.
Signing out, and deleting Your Account
Sign out ends the session and clears the tokens from the Device. Nothing on the Device is removed and the backup simply stops.
Delete account, in the Application's own settings, erases the Account and everything held against it — the account record, the alarms, the wake-up records, the settings, the email address if You signed in with a code, the Apple token if there is one — in a single operation, with no copy retained and nothing recoverable afterwards. It leaves the Device untouched, and it does not cancel Your Subscription (Section 14). You do not need to email Us, and We do not ask why.
Where You signed in with Apple, deletion does one further thing (this applies to the Apple version only): Our server tells Apple to revoke the access You granted, so that Roosta stops appearing under Sign in with Apple in Your Apple Account settings. Without that step the rows would be gone while Apple went on listing Roosta as an app You had signed in to — deleted in fact, but not in the one place You would think to look. It is the only moment We contact Apple about You, and it happens because You asked for the Account to be destroyed.
Legal basis: performance of Our agreement with You (Article 6(1)(b)) — You asked for a backup, and this is the backup — and, for the sign-in itself, Your consent (Article 6(1)(a)), which You withdraw by deleting the Account.
5. Device Permissions
Every permission below is requested by the operating system, granted by You, and revocable by You at any time in Your phone's own settings. Granting one gives Us no information about You.
- Alarms (required). The Apple version schedules alarms through Apple's AlarmKit framework. The Android version uses Android's exact-alarm scheduling together with a foreground service and a full-screen intent, which is the equivalent arrangement and is what Android requires of anything that must sound and take over the screen at a set time. Either way it is what allows an alarm to ring when the Device is locked or the Application is not running, and without it the Application cannot function.
- Notifications (optional). Used for three things, and nothing else: the bedtime reminders, if You switch them on; a reminder on an evening when no alarm is set for the following morning, if You switch that on; and a single reminder two days before a free trial converts into a paid Subscription, if You took a trial and allowed notifications. All three are ordinary local notifications, composed and scheduled on the Device and delivered by the operating system on the Device. Which evenings the second one is scheduled for is worked out on the Device from Your own alarms, in advance; nothing about Your alarms is sent anywhere in order to decide it. No push service is involved, We send nothing to Your phone, and no push token exists to identify it. On Android, notification permission is additionally what lets the alarm show its own alert, so refusing it there does affect the alarm and the Application says so; on Apple it does not.
- Live Activities (optional, Apple version only). If You switch on the check-in that follows a Mission, the Application asks iOS to show a banner on Your lock screen and in the Dynamic Island counting down to it. It carries two dates and nothing else — when the wait began and when the check-in is due — and the countdown You see is drawn by iOS from those two dates. It is not a push notification: there is no push token, nothing is sent to Your phone, and the Application does not update the banner while it is showing. Live Activities can be switched off for Roosta in Your phone's own settings; the check-in still rings if You do, because it is a real alarm rather than a banner.
- Camera (optional). Requested only by the Missions in Section 3, and only when one of them runs or is being set up.
- Microphone and speech recognition (optional). Requested only by the Reading Mission.
- Screen Time (optional, Apple version only). Requested only if You reach for app blocking or the app-deletion guard. See Section 6.
- Usage access (optional, Android version only). Requested only if You switch on app blocking, and never otherwise. It is Android's only route to knowing which application is currently in front, which is the one thing the block has to know. While the block is running the Application reads the package name of the app on screen, compares it with the list You chose, and discards it. No history of what You use is kept, logged, or sent anywhere. It is granted on a screen in Android's own settings and can be withdrawn there at any time, which switches the feature off.
- Display over other apps (optional, Android version only). Requested for the same feature, and not, despite its name, in order to draw over anything: Android does not normally let an application in the background open a screen at all, and holding this permission is one of the few exemptions. It is what allows the block to appear. Also withdrawable at any time.
- Accessibility services and device-administrator rights. Neither version requests either, on any platform, for any feature.
- Exemption from battery optimisation (optional, Android version only). Android may defer or drop work on a phone that has been idle, which for an alarm clock means an alarm that arrives late or not at all, so the Application offers to be excluded from it. It is a switch on a system screen, it tells Us nothing whatever, and refusing it costs reliability rather than any feature.
- Nothing at all. Shake, Memory, Typing and Math ask for no permission. Shake counts the operating system's own shake events, which are handed to any application without one — it reads no sensor directly and keeps no reading. The other three are a screen and Your fingers.
Neither version requests, or can access, Your location, contacts, calendar, photo library, health data, motion and fitness data, Bluetooth, local network, or tracking permission. The Android version does not request QUERY_ALL_PACKAGES, the broad permission that would let it see everything installed on Your phone. It does declare the narrow package-visibility entries Android requires in order to list applications that have an icon in Your launcher, which is how the app-blocking picker draws its list for You to choose from, and to find Your speech recogniser and Your dialler. That list is assembled on the Device, only when You open the picker, and is never sent to Us. Importing an audio file needs no storage permission either: the Application opens the operating system's own file picker and receives only the single file You choose, and it cannot see the rest of Your storage before, during, or afterwards.
6. App Blocking, and the Deletion Guard
Both versions offer app blocking, and they are not the same feature underneath. Apple's is built on Screen Time and cannot tell what You blocked. Android has no such framework, so the Android version is built on usage access and can read the names of the apps You chose. The deletion guard exists on Apple devices only. Everything here is off until You switch it on, and an installation that never touches these features never meets any of it.
On Apple devices, two optional features use Apple's Screen Time frameworks. Both are off until You switch them on, and an installation that never touches them never meets the framework at all.
App blocking at night — Apple devices
If You turn this on, You choose apps, categories and web domains to be shielded from Your bedtime until You are up. Apple's picker hands the Application an opaque token for each choice — not a name, not a bundle identifier, not anything that can be read back. The Application therefore shields apps it cannot name, list, or identify, and neither can We. The only fact it can derive is how many things You picked. That is the framework's design, and it happens to be the strongest possible form of "all data local": not merely unsent, but unreadable.
So that the shield goes up at bedtime even when the phone is in a pocket, the Application registers the night's start and end times with iOS, which wakes its NightMonitor extension at both ends. The times come from Your own alarm and sleep settings and stay on the Device.
The app-deletion guard — Apple devices only
If You turn this on, the Application asks iOS to restrict app deletion so that You cannot escape a locked alarm by deleting Roosta. iOS offers no way to protect a single app, so while it is on, no app on the Device can be deleted — this is stated on the screen where You turn it on, and again in Our Terms of Service. It is a setting applied on Your Device and reports nothing to Us.
What Screen Time authorization means — Apple devices
Both features require Screen Time authorization, which the Application requests for Your own device ("individual" authorization) rather than through a family organizer. You can withdraw it at any time in the Settings application, and both features stop with it. We receive nothing when You grant it, nothing while it is in force, and nothing when You withdraw it.
App blocking at night — Android devices
Android has no Screen Time. The Android version therefore builds the same idea out of two ordinary Android permissions, and the result is less private than the Apple one in a way We would rather state than let You discover.
If You turn this on, You pick apps from a list the Application draws for You, and it stores the package names You picked — readable text, not opaque tokens. That list is written to the Application's own private storage on Your Device. It is deliberately kept out of Your Account backup: it is the one setting that does not travel to another phone when You sign in, precisely because a list of the apps a person is trying to stay away from is nobody else's business, Ours included. It is never transmitted to Us.
While the block is running — that is, between Your bedtime and the morning You claim, and at no other time — the Application asks Android which application is in front, compares the answer with Your list, and throws the answer away. It does this by polling, because Android provides no way to be told. No record of what You use, when, or for how long is kept, written down, or sent anywhere, and the Application does not read usage history even though the permission would allow it. Android requires a visible, persistent notification for the whole time the watch is running, and there is one.
Two permissions make this possible, both granted by You on Android's own settings screens and both withdrawable there at any moment: usage access, which is the only way to learn what is in front, and display over other apps, which is what permits a background service to put a screen up at all. Withdrawing either stops the feature. Nothing about granting, holding or withdrawing them reaches Us.
There is no deletion guard on Android
Nothing on Android lets an application prevent its own removal, and the Android version does not try. It requests no device-administrator role and no accessibility service. You can uninstall it at any time, from anywhere, and it cannot object.
7. Your Subscription
Access to the Application requires an auto-renewing Subscription, billed weekly or yearly. There is no free tier. Our Subscription Terms describe it in full.
The Subscription is sold and billed by the Store You installed from, using that Store's own in-app purchase system: Apple through the App Store on an Apple device, Google through Google Play on an Android one. That Store is the merchant of record and handles the payment, the renewals and Your billing relationship. We never see or store Your payment card details, billing address, Apple Account or Google Account credentials, or the identifier the Store uses to track Your Subscription. Within the Application, Your entitlement is verified on the Device against the Store's own signed record of what You bought.
Apple and Google each provide Us with sales, subscription and payment reports for Our accounting and tax obligations, and each makes aggregated store analytics available to Us — for example, how many subscriptions are active, how many were cancelled, and in which countries. Those reports are aggregated or otherwise do not identify individual customers, and We do not attempt to connect them to any individual. Apple's and Google's own handling of Your information is governed by Apple's Privacy Policy and Google's Privacy Policy, neither of which We control.
8. Device Backups
If You have iCloud Backup or encrypted local backups enabled on an Apple device, iOS may include the Application's Local Data in those backups, in the same way it does for other applications. The equivalent is true on Android: if You have Google's backup or device-transfer features enabled, Android may include the Application's Local Data in them. One thing is deliberately excluded on both — Your Account sign-in tokens, which are kept out of backup and out of device transfer so that a copy of Your phone does not carry a live session with it (Section 2).
Either way this is a function of Your Device and Your Apple or Google account rather than of the Application: We have no access to Your backups and cannot read, restore, or delete them. Backup behaviour is governed by Apple's Privacy Policy or Google's Privacy Policy, and can be changed in Your phone's own settings.
9. If You Contact Us
Support is the one place where information genuinely reaches Us. If You email Us — for instance to report a bug or ask a question — We receive Your email address, whatever You choose to put in Your message, and anything You attach, such as a screenshot.
The Application's "Report a bug" and "Contact" rows open a draft in Your own mail app. Nothing is sent until You send it, and You can read and edit every line first. For convenience the draft is prefilled with three technical details — the Roosta version and build, Your operating-system version, and Your device model identifier (for example "iPhone17,1" on an Apple device, or the manufacturer and model on an Android one). Nothing else is attached: no identifier, no alarms, no history, no logs. Delete the line if You would rather not send it.
Purpose and legal basis: to answer You and to fix what You have reported. We rely on Our legitimate interest in providing support for Our products, and on the performance of Our agreement with You where the request concerns Your Subscription.
Retention: We keep support correspondence for as long as needed to resolve the matter and to handle any follow-up, and delete it no later than two years after the exchange ends, unless We are required to keep it longer (for example, records relating to a purchase, which bookkeeping law requires Us to retain for five years).
Our email is delivered by Our business email provider acting as a processor on Our behalf. We do not use anything You send Us for marketing, and We do not add You to any mailing list.
10. Who Processes What, and Where
This is the complete list of companies involved in the Application working at all, or that handle anything from it on Our behalf. There are no others, and there is no advertising, attribution, or data-broker relationship of any kind. The single analytics relationship is with PostHog, on both versions, and is described below and in Section 2. Support correspondence, which reaches Us only if You choose to write to Us, is dealt with separately in Section 9.
- Apple Inc. and Apple Distribution International Ltd (Ireland). Relevant to the Apple version, and to the Android version not at all. Apple distributes the Application, is the merchant of record for Your Subscription, provides the operating-system frameworks the Application is built on (alarms, Screen Time, on-device speech and vision), and — if You have it enabled — makes Your Device backups. Apple also runs the public catalogue the sound picker searches: on either version, a search sends the words You typed and Your store region to Apple's iTunes Search endpoint, and choosing a track downloads its thirty-second preview from Apple's content network. That request goes from Your Device to Apple with no key and no account attached and carries nothing of Ours; what Apple records of it is Apple's to describe, under the Privacy Policy linked below. Apple acts as an independent controller for Your purchase and Your Apple Account, under Apple's Privacy Policy, and is not Our Processor. If You use Sign in with Apple, Apple also authenticates You (Section 4).
- Supabase, Inc. (United States; hosting in the EU). Our Processor for the optional Account: authentication and the Postgres database holding Account Data. The instance serving Roosta runs in the European Union — Paris, on Amazon Web Services, so Account Data is stored in the EU. Supabase and its own infrastructure sub-processors act under a data processing agreement, with the European Commission's Standard Contractual Clauses covering any support access from outside the EEA. Engaged only if You create an Account.
- RevenueCat, Inc. (United States). Our Processor for knowing whether a Subscription is active. It receives an application user identifier — a random one generated on the Device, or Your Roosta Account identifier once You have signed in — together with the App Store's own record of Your purchases, Your country, and basic device and operating-system details. It never receives Your alarms, Your wake-up records, Your settings, or anything from a camera or microphone. Transfers to the United States are covered by the Standard Contractual Clauses. Engaged for everybody, because access to the Application depends on the answer.
- PostHog, Inc. (United States; hosting in the EU). Our Processor for the anonymous usage statistics described in Section 2, on both the Apple and the Android version. Neither contains PostHog's own code: both send the fixed list of events in Section 2 over plain HTTPS from a few hundred lines of Ours. The data is held on PostHog Cloud EU, hosted in the European Union — Frankfurt, on Amazon Web Services, so it is stored in the EU and is not transferred out of it. It receives the fixed list of events in Section 2 against a random per-installation identifier, and nothing else: no name, no email address, no Account identifier, no alarms, no wake-up records, no settings, no IP address, no location, and nothing from a camera or microphone. PostHog acts under a data processing agreement, with the European Commission's Standard Contractual Clauses covering any support access from outside the EEA. We do not use its session-recording, feature-flag or survey products, and the Application contains no code capable of them.
- Google LLC and Google Ireland Ltd. On the Apple version, involved only if You choose Sign in with Google, and only at the moment You do. On the Android version, Google additionally distributes the Application, is the merchant of record for Your Subscription, and provides the operating-system and on-device libraries the Application is built on (alarm scheduling, ML Kit for the Mission checks, the on-device speech recogniser, Credential Manager) — and makes Your Device backups if You have them enabled. The ML Kit and speech components run on Your phone and send Us nothing; they are not a channel to Google for anything a Mission sees or hears (Section 3). Google acts as an independent controller for Your Google account and Your purchase, under Google's Privacy Policy, and is not Our Processor.
- Brevo (Sendinblue SA, France). Our Processor for one message and one message only: the six-digit sign-in code sent to Your email address, if You use that route to create an Account on the Android version (Section 4). It receives the address and the code so that it can deliver the mail, acts under a data processing agreement, and is established in the European Union. It is engaged nowhere else in the Application, sends You nothing else, and is never involved if You sign in with Apple or Google.
We do not use any advertising network, attribution service, crash reporter, customer-messaging tool, or push-notification service, and We use no analytics platform other than PostHog as described above. Every reminder the Application sends is composed and delivered entirely on Your Device, so no third party is involved in any of them and no push token exists.
11. Legal Basis and Our Role Under GDPR
Local Data on Your Device is not something We hold: You hold it, on equipment You control, and the Application reads and writes it solely to deliver the functionality You asked for. Where You have created an Account, the copy held against that Account is Personal Data that We control, and everything below applies to it.
Where We do process Personal Data — support correspondence (Section 9), Account Data (Section 4), and Our subscription and accounting records (Section 7) — We act as controller, and We rely on the following legal bases:
- Performance of a contract (Article 6(1)(b)): to supply the Subscription You bought and to deal with questions about it.
- Legitimate interests (Article 6(1)(f)): to provide support, diagnose faults, and improve the Application — including the anonymous usage statistics described in Section 2, which carry no identifier of Yours, no IP address and no location, and are used only to find where the Application is confusing or fails.
- Legal obligation (Article 6(1)(c)): to keep accounting and tax records as required by Danish law.
- Consent (Article 6(1)(a)): for any Device permission You grant, which You may withdraw at any time in the Settings application.
The Application performs no automated decision-making producing legal or similarly significant effects, within the meaning of Article 22. It uses two on-device machine-learning models — image classification, to judge whether a photograph shows what was asked for, and body-pose analysis, to count repetitions — together with on-device speech transcription: Apple's Vision and Speech frameworks on the Apple version, Google's ML Kit and the phone's own on-device recogniser on the Android version. All three run locally, decide nothing about You beyond whether a Mission was completed, and are backed by the fallback in Section 3 so that a wrong answer can never leave an alarm ringing indefinitely. Nothing in the Application generates content: Mission tasks, such as arithmetic problems, are produced by ordinary arithmetic on the Device.
International transfers. Local Data is not transferred anywhere. Account Data is stored in the European Union (Section 4), and the usage statistics described in Section 2 are stored in the European Union likewise (Section 10). Where a Processor is established outside the EEA — RevenueCat in the United States, and Supabase for any support access from outside the EEA — the transfer is covered by the European Commission's Standard Contractual Clauses. Brevo, which delivers the sign-in code, is established in the European Union, so no transfer arises there. Section 10 names every one of them.
12. Your Rights Under GDPR (EU/EEA, UK and Switzerland)
If You are in the European Union or European Economic Area, You have the rights of access (Article 15), rectification (Article 16), erasure (Article 17), restriction (Article 18), data portability (Article 20), objection (Article 21), and withdrawal of consent (Article 7(3)), together with the right to lodge a complaint with a supervisory authority (Article 77).
In practice these rights apply differently to the two categories of information:
- Local Data: You already have complete and direct control. You can view and change every alarm and every setting inside the Application, delete alarms individually, and remove all of it at once by deleting the Application from Your Device. We cannot access, produce, correct, or delete this data on Your behalf, because We do not hold it; where You have an Account, the copy We do hold is covered by the next bullet.
- Account Data: You exercise access, rectification and erasure directly in the Application — the Account screen shows what We hold about You, every alarm and setting in it is editable, and Delete account erases all of it at once, immediately and without asking Us (Section 4). For a portable copy, or for anything the Application cannot do for You, email Us.
- Support correspondence and subscription records: email Us and We will action Your request.
Our lead supervisory authority is the Danish Data Protection Agency (Datatilsynet), as NovApps ApS is established in Denmark; You may contact it at datatilsynet.dk. You also have the right to complain to the supervisory authority in Your own country of residence.
If You are in the United Kingdom, the same rights apply to You under the UK GDPR and the Data Protection Act 2018, and We handle Your requests in exactly the same way. Your regulator is the Information Commissioner's Office rather than Datatilsynet, and You may complain to it at ico.org.uk. Account Data is stored in the European Union, which the UK recognises as adequate for this purpose.
If You are in Switzerland, the revised Federal Act on Data Protection gives You equivalent rights of access, correction and deletion, exercised the same way. Your regulator is the Federal Data Protection and Information Commissioner, at edoeb.admin.ch. Switzerland likewise recognises the European Union as providing adequate protection.
We respond to requests within 30 days. If a request is unusually complex, We will tell You and may extend that period by up to 60 further days.
13. Your Rights Under U.S. State Privacy Laws
Several U.S. states have comprehensive consumer privacy laws, including California (CCPA/CPRA), Virginia, Colorado, Connecticut, Utah, Texas, Oregon, and Montana, among others. As a small business established in the European Union We are generally below their applicability thresholds; We nonetheless extend the following to residents of those states as a matter of good practice.
For the twelve months preceding the effective date of this Policy, and on an ongoing basis:
- Without an Account, the only thing the Application itself sends Us is the anonymous usage statistics described in Section 2, recorded against a random per-installation identifier, with no IP address and no location. So far as that random value counts as an identifier under these laws, it is the single category collected — and it corresponds to no name, no address, no device and no person We could find.
- With an Account, We collect identifiers (an identifier We generate, and the email address and name Your sign-in provider returns) and customer records (Your alarms, wake-up records and settings). We collect the same categories, plus message content, if You choose to write to Us.
- We have not sold personal information, have not shared it for cross-context behavioural advertising, and do not use it for targeted advertising or for profiling that produces legal or similarly significant effects. We do not knowingly sell or share the personal information of consumers under 16.
- We collect no sensitive personal information. In particular, the photographs, video frames and audio described in Section 3 are processed transiently on Your Device, are never transmitted to Us, and are never retained — so there is nothing for a right to limit its use to apply to.
You may exercise the rights to know, delete, correct, and port the information described above, and You will not be discriminated against for doing so. Where state law provides for it, You may appeal a decision on Your request by replying to Us. You may use an authorised agent, in which case We may need to verify both the agent's authority and Your identity. For California residents: We will acknowledge a request within 10 business days and respond substantively within 45 calendar days, extendable once by a further 45 days where reasonably necessary.
14. Data Retention and Deletion
- Photographs, video frames, and audio: not retained at all. They exist for as long as the Mission is on screen and are gone with it (Section 3).
- Local Data: retained on Your Device until You delete it or delete the Application. Deleting the Application removes Your alarms, Your wake-up history, Your settings, and every alarm sound You downloaded or imported, permanently. Unless You have an Account, there is no copy anywhere for Us to restore from — please see Our Terms of Service.
- Account Data: kept for as long as the Account exists. Deleting the Account erases it immediately and completely; We keep no archived copy and no soft-deleted row, and there is nothing We can restore You from afterwards (Section 4). If You simply stop using the Application without deleting the Account, the data stays until You come back or delete it.
- Support correspondence: up to two years after the exchange ends (Section 9).
- Subscription and accounting records: five years from the end of the financial year, as required by Danish bookkeeping law.
Deleting the Application does not cancel Your Subscription. A Subscription is cancelled through the Store that sold it — Your Apple Account settings on an Apple device, or Payments and subscriptions in the Google Play app on an Android one — and nowhere else; see Section 5 of Our Subscription Terms. If You turned on the app-deletion guard, You will need to switch it off inside the Application, or withdraw Screen Time authorization in the Settings application, before iOS will let You delete anything.
15. Security
The strongest protection here is still architectural: photographs, video frames and audio are never transmitted and never written, so there is nothing there to intercept or to steal, and no breach of Ours can expose them. On the Device, the Application relies on the platform's own app sandbox — iOS's, together with its file-level encryption, or Android's. Your Account session tokens are kept in the iOS Keychain rather than in ordinary storage on an Apple device, and on an Android one in a private preferences file excluded from device backup and from device-to-device transfer.
For Account Data: it travels over TLS, it is stored in the EU, every table enforces row-level security keyed to Your own identifier so one Account cannot read another's rows, and the key that ships inside the Application is publishable and grants no access by itself. There is no password to be stolen, because there is no password anywhere in this — authentication is Apple's, or Google's, or a single-use code sent to an address You can already read.
The security of Your Device passcode, of Your Apple Account, and of Your backups is Yours to maintain. Should a breach nevertheless occur in the limited information We do hold, We will notify affected individuals and the competent supervisory authority within 72 hours, as GDPR requires.
16. Children's Privacy
You must be at least 13 years old to use the Application, as set out in Our Terms of Service. The age at which a person can consent to the processing of their Personal Data without parental authorisation varies: under Article 8 of the GDPR it is 16 by default, though member states may lower it to 13 (it is 13 in Denmark, 15 in France, and 16 in Germany and the Netherlands). If You are under the applicable age in Your country, You may use the Application only with the consent of a parent or legal guardian.
Apart from the anonymous usage statistics in Section 2, the Application collects nothing from anyone, children included, unless an Account is created. Those statistics contain nothing about who is holding the phone — no identifier of a person, no IP address, no location — so they cannot distinguish a child from an adult and are not capable of being about a child in the first place. An Account requires an Apple or Google account of Your own, which those providers already gate by age, or an email address You can receive a code at. Two points are worth making to parents specifically. First, the Application uses Apple's Screen Time frameworks (Section 6) for self-restriction on the Device it is installed on; it does not manage, monitor or report on anybody else's device, and it is not a parental-control product. Second, the Missions use the camera and microphone as described in Section 3 — transiently, locally, and with nothing kept.
If You are a parent or guardian and believe Your child has sent Us Personal Data by email without Your consent, contact Us and We will delete it.
17. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. Where a change is material — in particular, any change to the commitments in Sections 2 and 3 — the Application will tell You so the next time You open it, summarise what changed, link to this page, and ask You to accept the new version before You carry on. We will revise the effective date above at the same time.
To do that, the Application asks Our server which version of this document is current. That request carries no identifier and is made whether or not You have an Account. What is recorded when You accept is the version number and the date: on Your Device always, and against Your Account as well if You have one, so that the record of what You agreed to survives a new phone. Continued use of the Application after a change takes effect constitutes acceptance of the updated Policy.
18. Contact Us
Questions, concerns, or requests about this Privacy Policy or Your Personal Data: roosta@novapps.dev.