Skip to content
Roosta

Legal

Privacy Policy

Short version: Roosta has no accounts and no servers of its own. Your alarms, settings and streak are stored on your device. Camera frames and audio used by wake-up missions are processed on the device and are never saved or sent to us.
Effective:
July 25, 2026
Last updated:
July 29, 2026

1. Who we are

This Privacy Policy explains how Roosta (“Roosta”, “we”, “us”) handles information in connection with the Roosta mobile application (the “App”) and the website at roosta.app (the “Site”).

For any privacy question, contact hello@roosta.app.

2. Information we do not collect

Roosta does not require an account. We do not ask for your name, email address, phone number, or date of birth, and we do not have a login. We do not sell personal information, and we do not share it with advertisers or data brokers.

3. Information stored on your device

The App stores the following locally on your device so it can work. This information is not transmitted to us:

  • Alarms and schedules: times, repeat days, labels, sound and volume settings, and the wake-up mission you chose for each alarm.
  • Mission settings: difficulty, target counts, and any text you enter yourself (for example, a custom phrase for a speaking mission).
  • Wake history and progress, whether an alarm was completed, snoozed or missed, and the timestamps used to calculate your streak, statistics and achievements.
  • App preferences: such as theme, sound and notification choices.

You can erase all of it at any time by clearing the App’s storage in your device settings, or by uninstalling the App.

4. Device permissions and how each is used

The App requests permissions only for features you use. Denying a permission disables the related mission, not the alarm itself.

Alarms, notifications and full-screen display

Used to schedule alarms with the operating system, to show the ringing screen over the lock screen, and to keep alarms working after a restart. On Android this may include the exact-alarm, full-screen notification, and battery-optimisation exemptions, without which an alarm cannot be relied upon to fire on time.

Camera

Used only by scan missions (for example, finding an object or photographing the sky). Camera frames are analysed on your device, in real time, to decide whether the mission is complete. Frames are never written to storage, never added to your photo library, and never transmitted off the device. We never see them.

Microphone and speech recognition

Used only by speaking missions, and only while such a mission is running. Audio is used to check whether you said the required phrase and is not recorded or stored by the App. Speech recognition is performed by your device’s built-in speech service; where your device supports on-device recognition, the App requests it. If your device falls back to its own network-based recognition service, that processing is governed by your device manufacturer’s or operating system provider’s privacy policy.

Physical activity and motion sensors

Used by movement missions (shaking, walking, squats, push-ups) to count motion while the mission runs. Sensor readings are processed on the device, used to score the mission, and then discarded. Only the outcome, completed or not, is kept.

5. Analytics and advertising

The App contains no advertising SDKs on any plan. It does not build an advertising profile, does not use your data for targeted advertising, and does not sell or share personal information with data brokers.

It does use product analytics, so we can tell which features are used and which missions actually work. This is provided by PostHog and processed on servers in the European Union.

What is sent to PostHog:

  • Product events, for example that an alarm was created, which mission type was chosen, whether a mission was completed, snoozed or escaped, and which screens were opened.
  • Technical context: app version, operating system and version, device model, language and country, and a randomly generated installation identifier.

What is never sent to PostHog:

  • Camera frames, photographs or any image data.
  • Audio recordings or speech from voice missions.
  • Precise location.
  • Your name, email address or any other direct identifier. We do not hold these, because the App has no accounts.
  • The content of anything you type, such as a custom mission phrase.

The installation identifier is random and is not linked to your identity. It exists so two events from the same device can be recognised as related, and it is reset if you reinstall the App or clear its data.

You can turn analytics off in the App’s Settings. Nothing about how the alarm or any mission works depends on it: no part of the wake-up path uses the network at all.

5a. Subscriptions and RevenueCat

Roosta purchases and subscriptions are managed with RevenueCat, which acts as our subscription infrastructure provider. It checks with the App Store or Google Play whether your subscription is active, so the App knows which features to unlock.

What RevenueCat receives:

  • The anonymous app-user identifier described above, plus the purchase receipt or token issued by the App Store or Google Play.
  • Subscription status and history, whether a trial is active, when a period renews or expires, and which product was purchased.
  • Basic technical context such as platform, country and app version.

RevenueCat does not receive your payment card details. Those are handled entirely by Apple or Google and are never visible to us or to RevenueCat.

Both providers act as processors on our behalf, under contracts restricting them to processing data only for these purposes. Where data is transferred outside the European Economic Area, that transfer is covered by appropriate safeguards such as Standard Contractual Clauses.

Our legal basis for analytics is our legitimate interest in understanding how the App is used and improving it, which you may object to at any time by turning analytics off. Our legal basis for subscription processing is performance of our contract with you.

6. The website

The Site is a marketing site. It has no accounts and no sign-up form, it does not set advertising cookies, and it runs no third-party tracking scripts. Our hosting provider may keep short-lived server logs (such as IP address and user-agent) for security and reliability, as is standard for any web host.

The Site does measure two things, using PostHog — the same provider, and the same European Union servers, as the App: which page was viewed, and whether an App Store or Google Play button was clicked. It also records your answer to the cookie banner. That is the complete list, and the Cookie Policy sets it out in full.

Until you answer the banner, and if you decline it, no cookie is set. The visit is counted against a random id that your browser throws away when you close the tab, so it cannot connect one visit to the next. If you accept, that id moves into a first-party cookie so a returning visitor can be told from a new one. Either way it stays anonymous: the Site has no accounts, so no profile is created and nothing is linked to a name or an email address, because we do not have one. You can change your answer at any time on the Cookie Policy page, and a Global Privacy Control or Do Not Track signal from your browser is treated as a decline.

7. Purchases

Payments are processed by the App Store or Google Play. We never receive or store your payment card details. Your purchase is governed by the store’s own terms and privacy policy, and your entitlement is verified through RevenueCat as described in section 5a.

8. Children

Roosta is not directed at children under 13 (or the minimum age of digital consent in your country, where that is higher). We do not knowingly collect personal information from children. Because the App has no accounts and holds no direct identifiers, the only data associated with you is the anonymous installation identifier described in section 5, and reinstalling or clearing the App’s storage resets it.

9. Your rights

Depending on where you live, you may have rights to access, correct, delete, or port your personal data, and to object to its processing (for example under the GDPR or the CCPA). Because Roosta keeps your data on your own device and holds no copy, you exercise those rights directly: view your data in the App, and delete it by clearing the App’s storage or uninstalling. If you believe we hold information about you, contact hello@roosta.app and we will respond within the time the law allows.

10. Data retention and security

Data lives on your device for as long as the App is installed and is protected by your device’s own security (screen lock, disk encryption, and app sandboxing). Because we do not operate a backend for the App, there is no server-side copy to be breached. Keeping your device updated and locked is the most effective protection.

11. Changes to this policy

If this policy changes materially, we will update the date at the top of this page and, where appropriate, notify you in the App. Continuing to use Roosta after an update means you accept the revised policy.

12. Contact

Questions, requests or complaints: hello@roosta.app.