Privacy Policy — Rosvon

Last Updated: September 3, 2026

Effective Date: September 3, 2026

"We are all alone in this dark universe. We need to help each other, get stronger, and achieve technological breakthroughs so we can leave our cradle and become a starfaring civilisation—because we cannot stay on Earth forever. To grow together, we must build on transparent privacy practices and trust."

🛡️ Our Commitment to You

📱
Core personal records are local by default.

Tasks, habits, journals, projects, and raw Protocol usage records are stored in Rosvon's app-private storage. Optional account, community, AI, backup, purchase, advertising, analytics, and diagnostics features use network services as described below.

☁️
Google Drive backup is opt-in; sign-in sync is separate.

Drive backup starts only after you set it up. Signing in also creates Firebase account, entitlement, game-state, and community records. The current version creates a public community profile by default; review Section 8.2 before signing in.

🚫
The App does not contain a personal-data sale mechanism.

Rosvon does not transmit your private tasks, journals, habits, or raw screen-time records for sale. Google and other service providers may process limited data to provide the services described in this Policy.

🤖
AI is cloud-processed and configurable.

Aria sends your message, recent chat, and enabled context to Google's Firebase AI Logic / Agent Platform Gemini service. AI context controls are enabled by default in the current version and can be changed from Aria → three-dot menu → Privacy.

🗑️
Account deletion is available, with disclosed limits.

The in-app flow attempts to remove local, Drive, Firebase/Auth, community, Storage, and purchase-token data. Network or provider failure may require a retry. The current backend does not automatically delete two transaction/audit collections identified in Section 9. Email requests cannot remove local-device or Drive data.

This Privacy Policy describes how Roshan Sharma ("Developer", "we", "us", or "our") handles information when you use the Rosvon Android application ("App" or "Service"). It distinguishes local storage, Google Drive backup, Firebase/Google Cloud processing, community visibility, AI processing, diagnostics, advertising, and billing.

1. Information We Collect

1.1 Information You Provide Directly

1.2 Information Collected Automatically

1.3 Information Accessed On-Device Only (Never Collected)

The following raw Protocol data is processed locally and is not serialized to Rosvon's cloud services by the audited code:

2. What We Do NOT Collect

No: We do not collect your location data.

No: We do not access your contacts, call logs, or SMS.

No: We do not read your emails or messages.

No: Rosvon does not implement its own cross-app or website tracking profile. Embedded Google Analytics and Mobile Ads SDKs may process device or advertising identifiers under Google's policies.

No: Rosvon does not build its own advertising profile from your tasks, habits, journals, or raw Protocol records. Google Mobile Ads processing is described in Section 7.

No: The audited App contains no mechanism that sells your private app records. This does not mean that no data is processed by service providers; those disclosures appear in Section 8.

No: We do not upload your screen time or app usage data to any server.

No: We do not use Accessibility Service to read screen content, messages, passwords, form fields, notifications, or web content.

No: We do not use Accessibility Service to click buttons, perform gestures, change settings, or control other apps.

3. How We Use Your Information

We use the information we collect for the following purposes:

Purpose Legal Basis (GDPR)
Provide, operate, and maintain the App Contract performance
Provide signed-in account, community, entitlement, and game-state services Provide the requested account/service; consent where required
Deliver an AI response and, when enabled, personalize it with app context Provide the requested AI interaction; consent where required
Load Google test penalty/rewarded advertising and prevent ad fraud Consent where required; the current App does not yet implement UMP consent collection
Send service-related notifications (not marketing) Legitimate interest
Diagnose crashes and improve performance Legitimate interest
Improve the App based on aggregated analytics Legitimate interest
Comply with legal obligations Legal obligation

4. Permissions and Their Purpose

Runtime and special-access permissions are optional for the core task, habit, journal, and project features. Denying Usage Access or Accessibility disables or weakens Protocol monitoring and enforcement; denying notifications or exact-alarm access can reduce reminder or timer reliability. Some library-declared permissions do not produce a user prompt.

Permission Purpose Data Leaves Device?
Internet Firebase account/community/storage/functions, Drive backup, AI, model/image downloads, ads, analytics, diagnostics, and Google Play services Yes (only when features active)
Usage Access (PACKAGE_USAGE_STATS) Read on-device app usage totals and app package names to display your screen-time metrics, app-limit history, top apps, and Protocol calendar insights. No - never leaves device
Accessibility Service (BIND_ACCESSIBILITY_SERVICE) Detect when an app window opens by package name so Rosvon can show the breathing intervention screen for user-defined app limits, daily limits, and focus-session whitelist rules. Rosvon does not read screen content, messages, passwords, form fields, notifications, or web content, and does not perform gestures or clicks. No - never leaves device
Notifications (POST_NOTIFICATIONS) Deliver task reminders, focus session alerts, and service notifications No
Exact Alarms (SCHEDULE_EXACT_ALARM) Schedule exact focus-session completion timers when Android allows this special access No
Boot Completed (RECEIVE_BOOT_COMPLETED) Restore active focus timers and scheduled habit notifications after device restart No
In-App Billing (BILLING) Process optional in-app purchases and subscriptions via Google Play Store Yes (processed by Google Play)
Advertising identifiers / AdServices (SDK-declared) Google Mobile Ads measurement, delivery, security, and fraud prevention. The current build uses Google test identifiers. Yes (processed by Google)
Biometric / fingerprint (dependency-declared) The merged release manifest contains these permissions through dependencies, but the audited App has no active biometric authentication feature and makes no biometric API call. No active App use found

5. AI Features and Data Processing

Rosvon includes an AI assistant called "Aria". AI requests are cloud requests. In the current version, the master AI-content switch and individual context categories are enabled by default; change them before sending a message if you do not want a category attached.

5.1 Firebase AI Logic / Agent Platform Gemini Processing

Aria sends requests through Firebase AI Logic to Google's Agent Platform Gemini service (formerly described as Vertex AI). A request can contain your message, recent chat, locally learned memories, enabled tasks/habits/projects/resources/focus summaries, and profile or runtime context such as name, age, personality/coaching fields, current screen, time, battery/offline state, streak, discipline, burnout, and mood. Google processes requests under the applicable Firebase, Google Cloud, and Gemini terms, project configuration, and retention practices. The App cannot verify or guarantee zero provider retention or model-training use.

5.2 AI Privacy Controls

You can disable app-data categories via Aria → three-dot menu → Privacy. Notes are separately controlled from Journal and Reflection entries, and project resource links follow Tasks & Projects. Turning off the master content control blocks new live app content and runtime context; it does not erase recent chat or learned memories, and your typed message is still sent when you request a response. Rosvon may make a second AI request using the raw user message and up to 500 characters of the response to decide whether to save a local memory. Aria does not receive raw Usage Access events, screen-time totals, individual package names, app limits, or blocked-app lists. If Focus Context is enabled, selected recent or active focus-session summaries may be attached.

6. Data Storage and Security

6.1 Local Storage

Local data uses Room (SQLite), DataStore, SharedPreferences, and app-private files/cache. Android's app sandbox limits ordinary access by other apps. Rosvon does not add SQLCipher or another app-layer encryption scheme to its Room database, preferences, or local media.

6.2 Cloud Storage (Opt-In)

Signing in activates Firebase account/community/game services. Google Drive backup is a separate optional feature:

6.3 Security Measures

7. Advertising

Rosvon includes Google Mobile Ads for penalty-display and user-initiated rewarded-ad flows. The current App uses Google's sample/test application and ad-unit identifiers and therefore does not currently serve production monetized inventory. If an ad request is made, Google's SDK may process:

Rosvon does not attach journal text, tasks, habits, projects, raw screen-time records, app-limit lists, or focus history to an ad request. The current App makes ordinary Google ad requests and does not implement Google UMP consent collection, a privacy-options entry point, or an application-level guarantee that requests are non-personalized. Production ads must not be enabled in regions requiring consent until those controls are implemented.

Google's processing and device-level ad controls are described in Google's Privacy Policy. Device settings do not replace any consent flow the App is legally required to provide.

8. Data Sharing and Disclosure

The audited App contains no mechanism that sells private user records. It does transmit or expose data in the following provider, community, legal, and safety circumstances:

8.1 Service Providers

We use the following third-party services that may process data on our behalf:

Service Provider Purpose
Firebase Authentication Google LLC User account management and secure sign-in
Cloud Firestore Google LLC Signed-in account, game-state, community, entitlement, purchase/credit/redemption, and operational records
Firebase Storage Google LLC Signed-in user's selected profile-photo upload and community display
Firebase Analytics Google LLC Automatic app/session/device analytics and pseudonymous installation data
Google AdMob Google LLC In-app advertising
Google Play Billing Google LLC In-app purchases and subscription processing
Google Drive API Google LLC App data backup and restore (opt-in)
Firebase App Check Google LLC Abuse protection via Play Integrity
Firebase AI Logic / Agent Platform Gemini API Google LLC Aria responses and AI memory-classification requests
Firebase Cloud Functions Google LLC Community projection, account deletion, purchase verification, entitlement, AI-credit, and redemption operations
Firebase Crashlytics Google LLC Crash reports, stack traces, app/device diagnostics, and pseudonymous installation data
Firebase Performance Monitoring and Sessions Google LLC App/session performance and AI request timing/length/status metadata
Firebase Remote Config component Google LLC Present transitively in the release Firebase component graph; no direct App fetch call was found in the audited source
Google Credential Manager / Google Sign-In Google LLC Google account selection and Firebase sign-in
Hugging Face model hosting Hugging Face, Inc. Download the optional on-device embedding model files over HTTPS; the host may receive ordinary network request metadata such as IP address and user agent
YouTube and external browser links Google LLC and linked-site operators Open educational videos or web pages outside Rosvon; the destination handles data under its own policy
Remote article/image hosts The host configured by the content URL Load remote learning images/content through HTTPS clients; the destination can receive ordinary network metadata

8.2 Community Features

Signing in currently creates a community profile with its privacy flag set to public by default. The active community client can make the following fields visible to signed-in Rosvon users:

The active public payload does not include Health/HP, Gold, active challenges, personal tasks, habits, projects, journal text, raw screen-time records, or email address. Current privacy mode hides statistics but may continue to expose username, display name, bio, and profile photo to signed-in users.

8.3 Legal Requirements

We may disclose your information if required to do so by law, regulation, court order, or governmental authority, or if we believe in good faith that such disclosure is necessary to protect the rights, property, or safety of our users or the public.

9. Data Retention and Account Deletion

10. Your Rights

Depending on your jurisdiction, you may have the following rights regarding your personal data:

For All Users

For EU/EEA Users (GDPR)

Under the General Data Protection Regulation, you additionally have the right to:

For California Users (CCPA/CPRA)

Under the California Consumer Privacy Act and California Privacy Rights Act, you have the right to:

For Users in Other Jurisdictions

If you are located in any other jurisdiction with applicable data protection laws (e.g., LGPD in Brazil, POPIA in South Africa, PDPA in Singapore/Thailand, or India's DPDP Act), we will honor your rights as required by applicable law. Contact us using the details in Section 15 to exercise your rights.

To exercise a legally available right, contact us using Section 15. We will respond within the period required by applicable law after any necessary identity verification. The App itself does not guarantee a fixed response time.

11. International Data Transfers

Rosvon uses cloud services provided by Google LLC (United States). If you are located outside the United States, your data may be transferred to and processed in the United States or other countries where our service providers maintain facilities.

The transfer location and safeguard depend on the selected provider, service configuration, and current provider contract. Where required, we will rely only on a transfer mechanism that actually applies to the relevant service and jurisdiction.

12. Children's Privacy

Rosvon is intended only for people aged 18 or older and is not offered through parental consent. The current App does not technically verify date of birth or age, so a user must not use it if under 18.

If you believe an under-18 person has created an account, contact us using Section 15. We will handle the report and any required restriction or deletion under applicable law. The current general deletion limitations in Section 9 also apply until the implementation is corrected.

13. Data Security Incident Response

If a security incident affects personal information, response timing and notice will follow applicable law and the facts of the incident. Intended response steps include:

14. Changes to This Privacy Policy

We may update this Privacy Policy to reflect changes in the App, providers, or law. The current App has no remote policy-version notification or versioned-consent ledger.

Continued use alone does not replace consent where applicable law requires affirmative consent.

15. Contact Us

If you have any questions, concerns, requests, or complaints regarding this Privacy Policy or our data practices, please contact us at:

Developer: Roshan Sharma

Email: rosvon.support@gmail.com

App: Rosvon

Platform: Google Play Store (Android)

We aim to handle requests promptly and will meet any response period required by applicable law. The App does not provide a guaranteed 48-hour acknowledgement.

16. Google Play Data Safety Disclosure Summary

In accordance with Google Play Store requirements, the following is a summary of our data handling practices:

Data Type Collected? Shared? Purpose
Account identifiers, name, and email Yes, when signed in Processed by Google/Firebase as service provider Authentication, account state, entitlement, and support
Community username, name, bio, photo, XP, level, rank, and achievements Yes, when signed in Visible to signed-in community users; processed by Firebase Public-by-default community profile and leaderboard
Core user content: tasks, habits, journals, notes, and projects Local by default; selected records go to Drive backup or AI when those features are used Processed by Google Drive or Google AI for the requested purpose App functionality, backup/restore, and AI personalization
Raw screen time, Usage Access events, package names, app limits, and blocked-app lists On-device only in the audited code No off-device path found Protocol metrics, limits, calendar insights, and interventions
Focus-session summaries Local; also sent when AI Focus Context is enabled Processed by Google AI when enabled and an AI request is made Focus features and AI personalization
AI messages, recent chat, memories, profile/coaching fields, and enabled app/runtime context Yes, when AI is used Processed by Firebase AI Logic / Google Agent Platform Gemini Generate responses and classify local AI memories
Crash logs, diagnostics, performance, session, and automatic analytics data Yes, through Firebase SDKs Processed by Google/Firebase Stability, performance, security, and product analytics
Device or advertising identifiers and ad interactions May be processed when Google test ads initialize/load Processed by Google Mobile Ads Test ad delivery, measurement, security, and fraud prevention
Purchase history, tokens/hashes, products, entitlements, AI-credit use, and redemptions Yes, when purchase/credit/redemption features are used Processed by Google Play and Firebase Payment verification, entitlement, fraud prevention, reconciliation, credits, and rewards
User-selected profile photo Local; uploaded to Firebase Storage when selected while signed in; optionally backed up to Drive Visible to signed-in users and processed by Firebase/Drive Profile display and backup

Data security: Audited network integrations use HTTPS/TLS. Local Room/preferences and Drive backup content do not have additional Rosvon app-layer encryption. Google-hosted services apply their own platform protections.

Data deletion: The App and email request paths are available, but the limitations and current backend exceptions in Section 9 apply. Do not interpret this summary as a guarantee that every provider or transaction record is deleted immediately.