Privacy Policy
Rove
This Privacy Policy explains what information Rove (operated by Erebos Lab) collects, how it is used, who it is shared with, and the choices you have. By using Rove you agree to the practices described here.
Data-safety summary
At a glance, here is the data the app collects, whether it is linked to your identity, and whether it is used to track you across other companies’ apps and websites.
| Data category | Linked to you | Used for tracking | Purpose |
|---|---|---|---|
| Location (Precise, incl. background) | Yes | No | Record, measure, draw, and save running routes. With permission, location continues in the background while a run is active. For signed-in users, completed route points and metrics commit to the private Neon-backed account; the device retains active-workout continuity and Neon-confirmed read mirrors. |
| Contact Info | Yes | No | Authenticate your Rove account with Sign in with Apple or Google through Supabase Auth and associate it with account data stored in Neon. |
| User Content and Fitness | Yes | No | Provide account synchronization, training features, community interactions, and competition progress through Neon. |
| Usage Data (optional) | Yes | No | Improve reliability and understand feature use. Telemetry excludes route points and precise location and can be disabled in Rove settings. |
| Purchases | Yes | No | Manage the optional Pro subscription (removes ads) through Apple/Google via RevenueCat. We never store card numbers. |
| Advertising Identifiers | No | Yes | Display and measure free-tier ads via Google AdMob. Used only after you grant the iOS App Tracking Transparency prompt and resolve the UMP consent flow; Pro removes ads. The app declares tracking (NSPrivacyTracking is true). |
| App Preferences (on-device only) | No | No | Remember your preferences. Stored on your device only. |
What we collect
Location (Precise, incl. background)
- GPS coordinates and timestamps recorded while you track a route
- Saved routes: distance, duration, pace, elevation, bounding box, and route points
Record, measure, draw, and save running routes. With permission, location continues in the background while a run is active. For signed-in users, completed route points and metrics commit to the private Neon-backed account; the device retains active-workout continuity and Neon-confirmed read mirrors.
Contact Info
- Email address
- Account user identifier
Authenticate your Rove account with Sign in with Apple or Google through Supabase Auth and associate it with account data stored in Neon.
User Content and Fitness
- Profile and activity details
- Training plans, goals, clubs, challenges, kudos, and comments
Provide account synchronization, training features, community interactions, and competition progress through Neon.
Usage Data (optional)
- Feature-use and reliability events after explicit opt-in
Improve reliability and understand feature use. Telemetry excludes route points and precise location and can be disabled in Rove settings.
Purchases
- Subscription state and purchase history for the optional Pro upgrade
Manage the optional Pro subscription (removes ads) through Apple/Google via RevenueCat. We never store card numbers.
Advertising Identifiers
- Advertising identifier (IDFA / Android Advertising ID)
- Advertising interaction data
Display and measure free-tier ads via Google AdMob. Used only after you grant the iOS App Tracking Transparency prompt and resolve the UMP consent flow; Pro removes ads. The app declares tracking (NSPrivacyTracking is true).
App Preferences (on-device only)
- App settings and preferences
Remember your preferences. Stored on your device only.
What we do NOT do
- Background location is used only to keep an in-progress run recording; you grant it explicitly and can revoke it in Settings, and it stops when you finish the run.
- Advertising identifiers are used only after you grant App Tracking Transparency; Pro removes ads.
- You can export or delete account data in Rove; uninstalling removes active-workout continuity data and confirmed read mirrors from that device.
- We do not sell your personal information.
Third parties who process your data
We share data only with the processors below, each bound to use it only to provide their service to us. Items marked "unverified" are placeholders we must confirm and name before this policy is treated as final.
- Neon — Primary PostgreSQL database and authenticated Data API for route, training, and community account data
- Supabase — Identity provider for account authentication (Apple/Google sign-in); not the Rove application database
- Apple — Optional “Sign in with Apple”
- Google — Optional “Sign in with Google”
- RevenueCat — Optional Pro subscription and entitlement state
- Apple App Store — Subscription billing and receipts
- Google Play — Subscription billing and receipts
- Google AdMob — Advertising, only when you consent to tracking (ATT) and resolve UMP consent; removed by Pro
- Apple Maps / Google Maps — Map tiles only — react-native-maps uses Apple Maps on iOS and Google Maps on Android. The map provider receives your map viewport (approximate location) to render tiles, per its own privacy policy.
How we use your information
- Operate and personalize the app and its core features.
- Maintain your account, authenticate sessions, and provide support.
- Process payments and manage subscriptions/entitlements.
- Keep the service secure and prevent fraud and abuse.
- Comply with legal obligations and enforce our Terms of Service.
- Improve the product through aggregated, de-identified analytics.
Data retention
We keep personal information only as long as needed to provide the service. Account data is retained while your account is active and for a short recovery window after deletion, then deleted or anonymized. Billing records are retained as required by tax and accounting law. Backups are purged on a rolling basis.
Your rights and choices
Depending on your jurisdiction you may access, correct, export, or delete your personal data, object to or restrict certain processing, and withdraw consent. You can delete your account and its server-side data from within the app, or by emailing us. We respond within 30 days.
Children’s privacy
The app is not directed to children under 13 (under 16 in the EEA/UK) and we do not knowingly collect their data. If you believe a child has provided us data, contact us and we will delete it.
Security
We use industry-standard safeguards including TLS in transit, encryption at rest for sensitive fields, hashed passwords, least-privilege access, and audit logging. No system is 100% secure; please use a strong, unique password.
Changes to this policy
We may update this policy. Material changes will be reflected by a new "Last updated" date and, where required, announced in the app.
Contact
Privacy questions? Email caelum0x42@gmail.com.