Skip to content

Privacy Policy

Roost is a product of Ponuz, LLC.

Last updated August 1, 2026 · effective August 1, 2026

Data Controller: Ponuz, LLC, a United States company, is the data controller for personal information processed through the Services. You can reach our privacy team at contact@roostalarm.app. EEA and UK users who would like to contact a local representative under Article 27 of the GDPR / UK GDPR may also write to contact@roostalarm.app and we will route the request appropriately.

This Privacy Policy ("Policy") applies to the Roost mobile application, the roostalarm.app website, and any related services (collectively, the "Services") provided by Ponuz, LLC ("we," "us," "our," or "Ponuz"). Roost is an alarm application that requires users to complete a challenge — such as a physical-movement challenge, a photo challenge, or a drawing challenge — to dismiss the alarm. This Policy explains what information we collect from users of our Services ("user," "you," or "your"), including information that may be used to personally identify you ("Personal Information"), how we use it, and your rights regarding that information.

By using our Services, you agree to the collection and use of information in accordance with this Policy. If you do not agree with this Policy, please do not use our Services.

Changes to This Policy

We reserve the right to modify this Policy at any time. We will notify you of material changes by: (a) posting the updated Policy with a new "Last Updated" date, (b) sending notice to the primary email address associated with your account, or (c) providing in-app notification. Your continued use of our Services after such notification constitutes acceptance of the updated Policy. We encourage you to review this Policy periodically.

1. Information We Collect

a. Information you provide directly

  • Account information: when you create an account, we collect your email address, which we use for passwordless sign-in (a one-time code sent to your inbox). We do not use or store a password. You may also provide a display name, username, and a profile photo.
  • Alarm and challenge data: information about the alarms you configure, the challenges you select, your challenge-completion status, streak data, and achievement progress. This data is essential to provide our core service functionality.
  • Communications: when you contact us for support at contact@roostalarm.app, provide feedback, or otherwise communicate with us, we collect the information you provide.
  • Waitlist sign-ups on the Site: if you join the waitlist before Roost is publicly available, we collect the email address you enter and the language of the page you signed up from.
  • Payment information: we do not directly collect or store your full payment card information. In-app purchases are processed through Apple's App Store or Google Play, and are subject to their respective privacy policies. Superwall, our subscription management provider, receives purchase and subscription-status events from the store on our behalf but does not itself process payments — see Section 4.

b. Challenge verification data (camera)

  • Photo and drawing challenges: some alarms are configured to require a photo (for example, of your kitchen, bathroom, or made bed) or a drawing to be dismissed. When you complete one of these challenges, the image is transmitted to our backend and, from there, to our third-party AI verification provider to confirm it matches what was asked for. On-device processing is not used for this check — the image itself is what's sent. We do not store the photo or drawing on our servers; it is used only to produce a completion result and is then discarded on our end. See Section 4 (Third-Party AI Processing) and "Sensitive Personal Information" below for what our provider may do with it on their end.
  • Exercise challenges (push-ups, squats): these use your device camera together with on-device pose detection (Google ML Kit, running locally on your phone) to count repetitions. Real-time guidance such as rep-counting happens entirely on your device. Roost does not create, transmit, or store biometric identifiers, images, or video from this feature — the camera feed is analyzed locally to count movement and is never uploaded to us or to any third party.

c. Other device permissions

With your explicit permission, the App may also access your photo library, solely so you can pick an existing photo as your profile picture — we do not scan or upload your full library, and this permission is separate from the camera access used for challenges. You can grant or revoke this permission at any time in your device settings.

d. Information collected automatically

  • Device information: your device's time zone, operating system, app version, and the status of permissions the App has requested (such as notifications, exact alarms, or camera access) — collected to keep alarms reliable, not to build an advertising profile.
  • Subscription status: whether you have an active Premium subscription, the subscription provider, and store-issued identifiers needed to keep your entitlement in sync (see Section 4).
  • Referral activity: your referral code, any code you redeem, and credits earned, tracked in our systems as an internal ledger denominated in U.S. dollars, even though rewards are issued as free subscription time, not cash.

e. Advertising identifiers and attribution — none collected

Roost does not request or use advertising identifiers (such as Apple's IDFA or the Android advertising ID), does not show an App Tracking Transparency prompt, does not use a mobile attribution or marketing-measurement provider, and does not use the App or Site for advertising tracking of any kind.

f. Location — not collected

We do not collect precise or approximate location data (including GPS or IP-derived location) from the App or the Site.

g. Cookies on the Site

The Site sets a single, strictly functional cookie (NEXT_LOCALE) to remember which language you last viewed the Site in. We do not use analytics, advertising, or tracking cookies or pixels on the Site, and we do not use browser local storage to track you. Server logs may briefly record your IP address to rate-limit the waitlist form and prevent abuse; that IP address is not stored in our database or linked to your waitlist entry.

h. Analytics and crash reporting — not currently in use

As of the effective date of this Policy, the App does not use any third-party analytics or crash-reporting service, and does not use a third-party push-notification service — alarms and wake-check reminders are scheduled locally on your device using each platform's native alarm and notification APIs, not delivered by a push service. If we begin using such services in the future, we will update this Policy and, where required by applicable law, request your consent.

i. Information from third parties

We do not currently obtain information about you from social identity providers, advertising networks, or data brokers.

2. Sensitive Personal Information

Some features may involve information that is treated as sensitive under applicable law, specifically:

  • Camera captures made for the photo and drawing challenges, which may depict your home, your body, or your surroundings.

We process this information only for the specific feature you have enabled — verifying that a challenge was completed — only for as long as needed to deliver that feature plus any short operational retention by our processor described in Section 4, and we do not use it for advertising, profiling, or sale. We use these captures solely to verify that the requested challenge was performed; we do not generate, store, or compare unique biometric templates from this content, and the exercise challenge's pose-detection processing never leaves your device (see Section 1(b)). You can disable camera-based challenges at any time by choosing a different challenge type for your alarms, and you can request deletion of associated data by contacting us at contact@roostalarm.app. Where applicable law treats this content as biometric or other special-category data, we rely on your explicit, in-app action of choosing and completing a camera-based challenge as your consent (see "Legal Bases for Processing" below), which you may withdraw at any time by not selecting that challenge type again.

3. How We Use Your Information

We use the information we collect for the following purposes:

  • Service delivery: to provide, operate, and maintain our alarm and challenge-verification features.
  • Account management: to create and manage your account and authenticate you when you sign in.
  • Subscription management: to process and manage your Premium subscription and referral rewards.
  • Personalization: to customize your experience, including streaks, achievements, and insights based on your activity.
  • Communication: to send service-related messages, respond to support requests, and, if you have joined the waitlist, send you a launch notification email (you can unsubscribe at any time).
  • Security: to detect, prevent, and address fraud, abuse, security risks, and technical issues.
  • Legal compliance: to comply with applicable laws, regulations, legal processes, and governmental requests.

We do not use the content of your challenge-verification captures, or any sensitive Personal Information described in Section 2, to train our own machine-learning models or to build advertising profiles.

4. Third-Party AI Processing

We use OpenAI, a third-party AI provider, to analyze photo- and drawing-challenge submissions and return a completion result. When a challenge requires this analysis, the relevant image is transmitted securely from our backend to OpenAI. Under OpenAI's API data usage policies: (a) inputs and outputs are processed solely to perform the verification we request, (b) they are not used to train OpenAI's models, and (c) they are not retained as persistent application data, with only short-term retention in abuse-monitoring logs (up to 30 days) before deletion, except where longer retention is legally required or necessary to detect abuse. International transfers to this provider are made under the European Commission's Standard Contractual Clauses (SCCs) and the equivalent UK addendum where applicable. OpenAI is identified, along with our other principal processors, in the "Sub-Processors" section below.

5. Information Sharing and Disclosure

We do not sell, rent, or trade your Personal Information to third parties for their own marketing purposes.

We share information with the following categories of recipients, and only as needed to provide the Services:

  • Cloud hosting and backend infrastructure providers (to store and serve data).
  • Authentication and database providers (to manage your account and sign-in).
  • Our third-party AI verification provider (to analyze challenge submissions and return a result, as described in Section 4).
  • Our subscription-management provider (to relay purchase and subscription-status events from the app stores).
  • Apple Inc. and Google LLC (to distribute the App and bill subscriptions through the App Store and Google Play; their handling of your payment information is governed by their own privacy policies, not this one).
  • Professional advisors, such as auditors and lawyers, where necessary.

We may also disclose information: to comply with a legal obligation, subpoena, or governmental request; to protect the rights, property, or safety of Ponuz, our users, or the public; to detect, prevent, or address fraud, security, or technical issues; in connection with a merger, acquisition, bankruptcy, or sale of assets (in which case we will notify you by email and/or a prominent in-app notice, and will require the successor to honor the commitments in this Policy); with your consent; or as aggregated or de-identified data that cannot reasonably be used to identify you.

6. Sub-Processors

The following are the principal sub-processors that handle personal data on our behalf. We may add or replace sub-processors from time to time, and we will update this Policy when we do.

  • Supabase, Inc. — hosts our database, authentication, file storage (for profile pictures), and server-side functions. Most App data is stored locally on your device first and syncs to Supabase only when you are signed in.
  • Superwall, Inc. — manages our subscription paywall and relays purchase and subscription-status events from the app stores. Superwall does not itself process payments; purchases are transacted through Apple's App Store or Google Play.
  • OpenAI — AI analysis of photo- and drawing-challenge submissions, as described in Section 4.
  • Apple Inc. and Google LLC — operate the App Store and Google Play, through which the App is distributed and subscriptions are billed.
  • Google LLC (ML Kit) — provides the on-device pose-detection library used for exercise challenges. Included here for transparency only: as described in Section 1(b), this processing happens locally on your device, and Google does not receive any data through this feature.

7. Legal Bases for Processing (EEA, UK, and Switzerland)

If you are located in the European Economic Area, the United Kingdom, or Switzerland, we process your personal data on the following legal bases under the General Data Protection Regulation (GDPR) and equivalent UK/Swiss law:

  • Contract performance — to create your account, deliver core App functionality, and process your subscription.
  • Legitimate interests — to secure the Service, prevent abuse, and understand and improve how Roost is used, balanced against your rights and interests.
  • Consent — where we ask for it specifically, such as your in-app choice to use a camera-based challenge involving sensitive data (Section 2), or the waitlist launch email; you may withdraw consent at any time.
  • Legal obligation — where we must process data to comply with applicable law.

8. Data Security

We implement appropriate technical and organizational security measures designed to protect your Personal Information against unauthorized access, alteration, disclosure, or destruction, including: encryption of data in transit (TLS/SSL); row-level database access controls that restrict your data to your own account; secure authentication mechanisms; and restricted, need-to-know access to production systems. No method of transmission over the Internet or electronic storage is 100% secure, and we cannot guarantee absolute security. You are responsible for maintaining the confidentiality of the email account used to sign in to Roost.

9. Data Retention and Deletion

We retain your Personal Information for as long as your account is active or as needed to provide you with the Services:

  • Account data: retained while your account is active. Upon a verified deletion request, we delete it from our active systems, with any residual copies purged from encrypted backups within 30 days as part of our standard backup rotation.
  • Alarm and challenge data: retained while your account is active; deleted upon account deletion, subject to the same backup-rotation window above.
  • Challenge verification captures (photos, drawings): we do not retain these on our servers as part of your profile — see Section 1(b). Our AI provider processes them under terms that prevent retention as persistent application data and prohibit their use to train the provider's models; they are retained only transiently in the provider's abuse-monitoring logs for up to 30 days and then deleted, except where longer retention is legally required or necessary to detect abuse.
  • Subscription and entitlement records: retained as required by applicable tax and accounting law, typically up to 7 years.
  • Referral and credit-ledger records: retained while your account is active; deleted upon account deletion, subject to legal retention exceptions.
  • Waitlist email addresses: retained until the App launches and the associated communications are sent, or until you ask us to remove your entry, whichever comes first.

10. Account Deletion

You may request deletion of your account and associated Personal Information at any time by:

  • Using the "Delete Account" option in the App's Settings.
  • Emailing us at contact@roostalarm.app with the subject line "Account Deletion Request."

Upon receiving a valid deletion request, we permanently delete your profile, synced alarms and alarm history, achievements, avatar, and subscription-entitlement records from our active systems, with any residual copies purged from encrypted backups within 30 days. We retain only data required by law or for legitimate business purposes (for example, fraud prevention or tax records). Data stored only on your device is removed when you delete the App or clear its data. Aggregated or de-identified data that cannot reasonably be used to identify you may be retained indefinitely for analytical and service-improvement purposes.

11. Your Rights and Choices

Depending on where you live, you may have rights over your personal information, which can include the right to:

  • Access: request a copy of the Personal Information we hold about you.
  • Correction: request correction of inaccurate or incomplete information.
  • Deletion: request deletion of your Personal Information, subject to the legal retention exceptions above (you can also do this directly from the App under Settings → Delete Account).
  • Portability: request a copy of your data in a structured, machine-readable format.
  • Restriction: request that we restrict certain processing.
  • Objection: object to processing based on legitimate interests.
  • Withdraw consent: withdraw consent for processing based on consent at any time, including for the camera-based challenges described in Section 2, without affecting the lawfulness of processing before withdrawal.

To exercise these rights, email us at contact@roostalarm.app. We will respond to your request within 30 days, or as required by applicable law, and may need to verify your identity before fulfilling certain requests.

Marketing communications: you can opt out of promotional emails, including the waitlist launch email, by clicking the "unsubscribe" link in any marketing email or by emailing us. Push notifications: you can disable push notifications for the App through your device settings at any time — note that this affects reminders, not the local alarms themselves.

12. California Privacy Rights (CCPA/CPRA)

If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA):

  • Right to know: you may request disclosure of the categories and specific pieces of Personal Information we have collected, the sources, purposes, and categories of third parties with whom we share it.
  • Right to delete: you may request deletion of your Personal Information, subject to the exceptions described in Section 9.
  • Right to correct: you may request correction of inaccurate Personal Information.
  • Right to opt out of sale/sharing: we do not sell your Personal Information for money, and we do not use advertising or attribution tools that would constitute "sharing" under the CCPA — see Section 1(e). There is accordingly nothing to opt out of, but you may still contact us with any question.
  • Right to limit use of sensitive Personal Information: the sensitive Personal Information we process (camera captures used for challenge verification, described in Section 2) is used solely to deliver the specific feature you enabled, is not used to infer characteristics about you for advertising, and is not sold or shared.
  • Right to non-discrimination: we will not discriminate against you for exercising your privacy rights.

To submit any of the requests above, contact us at contact@roostalarm.app. We may require verification of your identity before processing your request.

California "Shine the Light"

California Civil Code §1798.83 permits California residents to request information about disclosures of Personal Information to third parties for those third parties' direct marketing purposes. We do not disclose Personal Information to third parties for their own direct marketing purposes.

California Minors

California Business & Professions Code §22581 permits California residents under age 18 who are registered users to request removal of content they have publicly posted on the Services. Roost does not currently include a feature for publicly posting content, so this right is not presently applicable to normal use of the Services; if that changes, we will update this Policy. To submit a removal request in the meantime, email contact@roostalarm.app with the subject line "California Minor Removal Request."

13. European Privacy Rights (GDPR)

If you are in the European Economic Area (EEA), United Kingdom, or Switzerland, you have rights under the General Data Protection Regulation (GDPR) and applicable local laws:

  • All rights listed in Section 11 (Your Rights and Choices) above.
  • Right to lodge a complaint: you have the right to lodge a complaint with your local data protection supervisory authority.
  • International transfers: when we transfer your data outside the EEA or UK — for example, to our AI verification provider and our U.S.-based hosting and operational providers — we rely on the European Commission's Standard Contractual Clauses (and the UK addendum where applicable) as the transfer mechanism, together with any supplementary measures set out in our processors' data processing agreements.
  • Special category data: where we process data that may reveal information about your home or body in connection with the optional camera-based challenges described in Section 2, we rely on your explicit consent, which you may withdraw at any time.

For GDPR-related inquiries, contact us at contact@roostalarm.app.

Nevada Privacy Rights

Nevada residents have the right to opt out of the "sale" of their Personal Information. We do not sell Personal Information as defined under Nevada law. To submit an opt-out request in any case, contact us at contact@roostalarm.app.

14. International Data Transfers

Ponuz, LLC is based in the United States. If you access our Services from outside the United States, your information will be transferred to, stored, and processed in the United States and potentially other countries where our sub-processors operate. For transfers of personal data out of the EEA, UK, or Switzerland, we rely on the European Commission's Standard Contractual Clauses (and the UK addendum where applicable) as our transfer mechanism, as described in Sections 4 and 13. A copy of the relevant safeguards can be requested at contact@roostalarm.app.

15. Children's Privacy

Roost is not directed to, and is not intended for use by, individuals under 16 years of age, and our eligibility requirements in the Terms of Use reflect this. We do not knowingly collect Personal Information from anyone under 16 without verifiable parental consent where required. If we learn that we have collected Personal Information from a child under 16, we will take steps to delete it promptly. If you are a parent or guardian and believe your child has provided us with Personal Information, please contact us at contact@roostalarm.app.

16. Third-Party Links

The Services may contain links to third-party websites or services, including our social media profiles and the App Store / Google Play listings. We are not responsible for the privacy practices of those third parties, and we encourage you to review their privacy policies.

Do Not Track Signals

Some browsers have a "Do Not Track" feature that signals to websites that you do not want your online activity tracked. Our Services do not currently respond to Do Not Track signals — largely because, as described in Section 1(g), the Site does not use tracking technologies for a DNT signal to act on. You can still manage cookies through your browser settings.

17. Contact Us

If you have questions about this Privacy Policy or how we handle your information, contact us at:

Ponuz, LLC

301 Blanco Road, San Antonio, TX 78212, United States

Email: contact@roostalarm.app

Website: roostalarm.app

This Privacy Policy was last updated and became effective on August 1, 2026.

Back to home