# Faro — Privacy Policy **Effective date:** 08/01/2026 **Last updated:** 08/01/2026 Faro ("the app") is developed and published by Rooftop ("we", "us"). This policy explains what data the app handles, what stays on your device, what leaves it, and the choices you have. ## The short version - **Your habit data never leaves your device.** The habits you create, their names, your check-ins, consumption counts, budgets and progress are stored only on your phone. They are never transmitted to us or to anyone else. - We collect a small amount of **anonymous product telemetry** (with your consent) and **crash reports** so we can fix bugs and improve the app. - **No ads. No data selling. No account required.** ## Data that stays on your device Faro is an offline-first app. Everything you enter into it — habit names and types, daily check-ins, resistance budgets, reduction curves, achievements, island decorations, notification preferences — is stored in a local database on your device only. - We have no server that receives this data, and no way to access it. - Deleting the app deletes this data. - Your device's own backup system (e.g. Android device backup, which you control in your device settings) may include the app's local data in your personal backup. That backup belongs to you and is governed by your device vendor's terms, not by us. Because habits can concern sensitive topics (for example smoking or alcohol), we treat all habit content as sensitive by design: it is excluded from every category of data described in the next section. Analytics events and crash reports are engineered to contain no habit names, quantities or other habit content. ## Data that leaves your device The app uses three service providers. Each receives only the minimum described below, always over encrypted connections (TLS). ### 1. Usage analytics — Google Firebase Analytics (only with your consent) If you consent when asked (and you can decline or change your mind at any time), we collect anonymous usage events such as "a check-in was performed" or "a screen was opened", along with general device information (device model, OS version, app version, coarse region derived from IP) and a random app-instance identifier. - Events never include habit content (no habit names, no counts, no budgets). - Advertising ID collection is disabled; this data is never used for advertising. - Purpose: understanding which features are used and improving the app. - Retention: user-level analytics data is retained for at most [2 / 14 — confirm Firebase retention setting] months. If you decline consent, no analytics events are sent. ### 2. Crash and performance reports — Sentry If the app crashes or misbehaves, a technical report is sent so we can fix the problem. Reports contain the technical state of the app (stack trace, device model, OS version, app version, a random installation identifier) and recent technical breadcrumbs (e.g. which internal screens were opened). - Reports are scrubbed of personal content; they never include habit content. - Purpose: diagnosing and fixing crashes and performance problems. ### 3. Purchases — RevenueCat and Google Play Billing If you buy the optional one-time "Faro+" upgrade, the purchase is processed by Google Play. RevenueCat, our purchase-management provider, receives a random app user identifier and the purchase state (which product was bought and when) so the app can verify and restore your purchase. - We never see your payment details; those stay with Google Play. - Purpose: unlocking what you paid for, on this device and after reinstalls. ## What we don't do - No advertising and no advertising SDKs. - No selling or renting of data. - No profiling for marketing. - No account system: we hold no email address, name or password for you. - No collection of contacts, location, photos, files, microphone or any other device content. ## Your choices and rights - **Consent:** the analytics consent prompt can be answered either way, and the app works identically in both cases. You can change your choice at any time in the app's settings. - **Deletion:** habit data lives only on your device; deleting the app deletes it. To request deletion of analytics or crash data tied to your random identifiers, contact us at the address below. - Depending on where you live, you may have additional statutory rights (e.g. under the EU/UK GDPR or Türkiye's KVKK), including access, rectification, erasure and objection. We honour these for the limited data we hold; contact us to exercise them. ## Data processors and transfers Our providers (Google LLC — Firebase; Functional Software, Inc. — Sentry; RevenueCat, Inc.) act as processors on our behalf and may process data on servers outside your country, including the United States, under standard contractual safeguards offered by each provider. ## Children Faro is intended for adults (18+) and is not directed at children. We do not knowingly collect data from children. If you believe a child has used the app and data has been collected, contact us and we will delete it. ## Changes to this policy If we change what the app collects (for example by adding a new feature), we will update this policy and its "Last updated" date before the change ships. Material changes will be announced in the app's release notes. ## Contact faro@rooftop.company ROOFTOP LLC