← Back to Rovy

Privacy Policy

Last updated: March 17, 2026

Rovy (“we,” “us,” or “our”) operates the Rovy mobile application (the “App”). We are committed to protecting your privacy and ensuring transparency about how your data is handled. This Privacy Policy explains what information we collect, how we use it, how we store and protect it, and what rights you have regarding your data.

By downloading, installing, or using the App, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with any part of this policy, please do not use the App.

1. Information We Collect

1.1 Device Identifier

When you first open the App, we generate a unique, anonymous device identifier. This identifier is used to associate your profile, drive data, and preferences with your device. We do not require you to create an account, provide your name, email address, phone number, or any other form of personal authentication. The device identifier cannot be used to identify you personally.

1.2 Profile Information

You may optionally provide a display name, profile picture, and vehicle details (such as make, model, year, horsepower, and fuel type) within the App. This information is entirely voluntary. If you choose to provide it, it may be visible to other users on the leaderboard, depending on your privacy settings.

1.3 Location Data

With your explicit permission (via the iOS location permission prompt), we collect GPS location data while you are actively recording a drive. This data is used to calculate your speed, distance, route, altitude, and to power features such as the live map, replay mode, heat maps, and tracks. We do not collect location data when the App is not actively recording a drive, unless you have granted background location permission for continuous drive tracking.

1.4 Drive Statistics

During each recorded drive, we collect and calculate the following data points: speed (current, average, and top speed), distance traveled, duration, number of stops, idle time, G-forces (longitudinal and lateral), acceleration and braking events, altitude profile, speed distribution, and route coordinates.

1.5 Heart Rate Data (Apple Watch)

If you connect an Apple Watch and grant permission to access Apple HealthKit, we collect heart rate data during your recorded drives. This data is collected solely for display purposes within the App and to enhance your drive analysis. Heart rate data collected via HealthKit is used exclusively for display within the App. It is never shared with third parties, never used for advertising or marketing purposes, and never sold to any entity. We comply fully with Apple’s HealthKit guidelines regarding the handling of health data.

1.6 Weather Data

We use Apple WeatherKit to retrieve current weather conditions at the time of your drive. This data is associated with your drive record and displayed in the App. Weather data is fetched based on your approximate location during the drive.

1.7 In-App Purchase Data

If you subscribe to Rovy Pro, your subscription is managed through Apple’s App Store and RevenueCat. We do not collect or store any payment information, credit card numbers, or billing details. RevenueCat provides us with anonymized subscription status information to determine whether your account has an active Pro subscription.

2. How We Use Your Information

We use the information we collect for the following purposes:

  • To provide core App functionality, including drive tracking, speed monitoring, route recording, and drive analysis.
  • To display your statistics and rankings on the leaderboard.
  • To store your drive history, tracks, and vehicle information in your personal logbook and garage.
  • To sync your profile and drive data across sessions via our cloud infrastructure.
  • To display weather conditions associated with your drives.
  • To display heart rate data during drive replay and analysis (if Apple Watch is connected).
  • To enable features such as replay mode, heat maps, sprint timing, and track comparisons.
  • To improve the App, fix bugs, and develop new features.

We do not use your data for advertising. We do not sell your data to third parties. We do not build advertising profiles based on your driving behavior.

3. Leaderboard and Social Features

Rovy includes a leaderboard where users can compare their driving statistics with others. The following information may be visible to other users on the leaderboard: your display name, profile picture, vehicle details, top speed, total drives, total distance, and ranking position.

Your raw GPS coordinates, route data, and detailed drive analytics are never shared with other users. Only aggregated statistics derived from your drives are displayed on the leaderboard.

4. Privacy Mode

We respect your right to privacy. Rovy includes a Privacy Mode that you can activate at any time in the App’s settings. When Privacy Mode is enabled:

  • Your profile and statistics are completely hidden from the leaderboard.
  • Other users cannot see any of your drive data, profile information, or vehicle details.
  • Your drives continue to be recorded and stored for your personal use.
  • You can toggle Privacy Mode on or off at any time without losing any data.

5. Data Storage and Security

5.1 Local Storage

Drive sessions, preferences, and cached data are stored locally on your device using iOS local storage mechanisms.

5.2 Cloud Storage

Profile information, drive statistics, vehicle data, and profile pictures are synced to our cloud infrastructure powered by Supabase. Our Supabase instance is hosted on servers located within the European Union (Frankfurt, Germany), ensuring that your data remains within the EU. All data transmitted between your device and our servers is encrypted using TLS/SSL protocols.

5.3 Security Measures

We implement appropriate technical and organizational measures to protect your data against unauthorized access, alteration, disclosure, or destruction. These measures include encrypted data transmission, secure cloud infrastructure with access controls, regular security reviews, and adherence to industry best practices. However, no method of electronic storage or transmission is 100% secure, and we cannot guarantee absolute security.

6. Third-Party Services

We use the following third-party services to operate the App. Each service has its own privacy policy governing how they handle data:

  • Supabase: Cloud database and file storage for profile data, drive statistics, and profile pictures. Hosted in the EU (Frankfurt, Germany).
  • RevenueCat: Subscription and in-app purchase management for Rovy Pro. RevenueCat processes anonymized subscription data.
  • Apple HealthKit: Used to access heart rate data from Apple Watch with your explicit permission. HealthKit data is handled in strict compliance with Apple’s guidelines and is never shared with third parties or used for advertising.
  • Apple WeatherKit: Used to retrieve weather conditions during drives. Weather data requests are based on approximate location coordinates.
  • Apple MapKit: Used to display maps, routes, and location data within the App.
  • Mixpanel: Used for anonymous usage analytics to help us understand how the App is used and to improve features. Mixpanel collects anonymized event data and does not receive personally identifiable information.

7. Legal Basis for Processing (GDPR)

For users in the European Economic Area (EEA), the United Kingdom, and Switzerland, we process your personal data on the following legal bases under the General Data Protection Regulation (GDPR):

  • Consent (Art. 6(1)(a) GDPR): We process your location data and health data (heart rate) based on your explicit consent, which you provide through the iOS permission prompts. You can withdraw your consent at any time by revoking the respective permissions in your device settings.
  • Legitimate Interest (Art. 6(1)(f) GDPR): We process your device identifier, profile information, drive statistics, and usage data based on our legitimate interest in providing and improving the App’s functionality. Our legitimate interest is balanced against your rights and does not override your fundamental privacy rights.
  • Performance of a Contract (Art. 6(1)(b) GDPR): We process data necessary to provide the services you have requested, including cloud synchronization and subscription management.

8. Your Rights

Depending on your location and applicable law, you may have the following rights regarding your personal data:

  • Right of Access: You have the right to request a copy of the personal data we hold about you.
  • Right to Rectification: You have the right to request correction of inaccurate or incomplete data.
  • Right to Erasure: You have the right to request deletion of your personal data. You can contact us for complete data removal.
  • Right to Restriction: You have the right to request that we restrict the processing of your data under certain circumstances.
  • Right to Data Portability: You have the right to receive your personal data in a structured, commonly used, and machine-readable format.
  • Right to Object: You have the right to object to the processing of your data based on legitimate interests.
  • Right to Withdraw Consent: Where processing is based on consent, you can withdraw your consent at any time by revoking permissions in your device settings or contacting us.

To exercise any of these rights, please contact us at the email address provided below. We will respond to your request within 30 days, as required by applicable law. If you are located in the EU, you also have the right to lodge a complaint with your local data protection authority.

9. Children’s Privacy

Rovy is not intended for use by children. We do not knowingly collect personal information from children under the age of 16 in the European Union or under the age of 13 in the United States and other jurisdictions. If you believe that a child has provided us with personal information, please contact us immediately so that we can take appropriate steps to remove such information from our systems.

10. Data Retention

We retain your data for as long as you actively use the App. Your drive data, profile information, and vehicle details are stored until you choose to delete them. You can contact us to request complete data deletion at any time.

If you simply uninstall the App without requesting data deletion, your data will remain on our servers. You can contact us to request complete data deletion at any time.

11. International Data Transfers

Our primary cloud infrastructure is hosted within the European Union (Frankfurt, Germany). If you access the App from outside the EU, your data will be transferred to and processed on servers within the EU. For users in the EEA, UK, and Switzerland, this means your data remains within an adequate jurisdiction under GDPR. For users outside these regions, by using the App you consent to the transfer of your data to the EU.

12. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make significant changes, we will notify you through the App or by updating the “Last Updated” date at the top of this policy. Your continued use of the App after any changes constitutes your acceptance of the updated policy. We encourage you to review this policy periodically.

13. Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or your personal data, please contact us at:

Email: rovyapp@proton.me

We will do our best to respond to your inquiry promptly and within the timeframes required by applicable law.

Privacy Policy Terms & Conditions

© 2026 Rovy. All rights reserved.

Imprint: Hinrich Bomsdorf, Hildeboldstraße 21, 80797 München, Germany
Contact: rovyapp@proton.me