Privacy policy

The short version. Rovyn stores the playlists your assistant sends you, how far you got through them, and the feedback you chose to give. Your assistant gets summarized listening receipts and your feedback in your own words — never your raw playback history, and never the other assistants you've connected or what you granted them. There are no analytics, no trackers, no ads, and no data sales. Deleting your account deletes your data — actually deletes it.

What Rovyn stores

What Rovyn sends your assistant

Each assistant you connect (Claude, ChatGPT, and so on) is a separate connection with its own permissions, which you can revoke independently at any time.

How signing in works, and what it discloses

Every sign-in method contacts Google's Firebase servers. If you sign in with Apple or Google, that provider additionally learns that your identity signed in to Rovyn — that is the whole disclosure. Rovyn sends the identity providers nothing else: no goals, no briefs, no listening behavior, no feedback, no library contents. Firebase Analytics is deliberately not integrated. Firebase itself holds your account record (identifier, sign-in method, email) because it must, to authenticate you.

If you use the email-and-password option on the page that appears when you connect an assistant, your password goes from your browser straight to Firebase. The Rovyn server never receives it, never stores it, and cannot read it; what reaches Rovyn is the same verified token the other two methods produce.

What podcast publishers see

Rovyn streams audio directly from publishers' servers, like any podcast app. Publishers see ordinary CDN logs — IP address, user agent, byte ranges. Rovyn sends them nothing else: no goals, no briefs, no feedback, no identity.

What Rovyn will not do

Deletion deletes

Deleting your account removes every row of your data — editions, briefs, playback events, progress, receipts, feedback, connections, and the identity record with its email — in one transaction. Every assistant token dies with it. There is no soft-delete, no tombstone, and no "anonymized" aggregate kept behind. Only shared public catalog data (shows and episodes) survives, because it was never yours. The app then deletes the Firebase user, which removes the account on Google's side.

Self-hosting

Rovyn implements Cueback, an open protocol, and the backend is a single service designed to be run by anyone. A self-hosted Rovyn has the identical privacy properties by construction — nothing above depends on us behaving well.

Changes and contact

If this policy changes, the date at the top changes, and material changes will be called out plainly on this page. Questions: support@polimati.com.