LOCAL-FIRST BY DESIGN

Privacy Policy

Your schedule belongs on your device. This policy explains both that boundary and the limited technical processing needed to operate RosterSnap.

Last updated:

Privacy policy in English

1. Introduction

This policy applies to the RosterSnap mobile app and describes the supporting technical services and this public website. RosterSnap turns work schedules into shifts, optional calendar events and reminders, paid-hour totals, and estimated earnings. It is designed around on-device processing, without a RosterSnap user-account system.

Local-first does not mean that every feature is network-free. Store purchases, trial verification, remote configuration, and access to this website can involve limited technical information, as described below.

2. Schedule data and on-device processing

RosterSnap processes selected or captured schedule images, OCR text and observations, names and aliases, job details, shifts, hourly rates and wages, workplaces, paid hours, and estimated earnings on your device. OCR and schedule parsing do not upload these images or business data to RosterSnap servers. They are not used by RosterSnap for cloud OCR, cloud AI, advertising, or model training.

Confirmed business records are kept in local app storage. Original scan images and OCR working data are temporary by default; confirming a schedule does not create a permanent server copy. A photo already in your photo library remains subject to your own library settings.

If you enable an operating-system backup or an account-backed calendar, selected local business data or calendar events may be backed up or synchronized by Apple, Google, or your chosen calendar provider. This is not RosterSnap cloud synchronization and is controlled by your device/account settings.

3. Information that may be processed

Trial and device verification. Where the service is configured, the app sends its platform, a random installation identifier, a request or scan-transaction identifier, and a device-verification token to RosterSnap over the configured secure connection. These support eligibility checks, the three-successful-scan trial, security checks, and prevention of duplicate deductions.

The current backend derives an installation digest using a server-held HMAC key and stores limited trial state, transaction identifiers, and timestamps. Raw installation identifiers and verification tokens are processed for the request, rather than stored in the trial tables or application request logs. DeviceCheck tokens may be forwarded to Apple; Play Integrity tokens may be forwarded to Google. Device Recall is used only when enabled and available.

Remote configuration and operational logs. The app may retrieve public configuration, such as trial limits, parser thresholds, minimum versions, and feature availability. Backend application request logs are restricted to a server-generated request identifier, matched route, response status, error category, and latency. They must not include schedule images, OCR, names, wages, workplaces, calendar content, purchase payloads, tokens, or installation digests.

Platform SDK diagnostics. Android uses Google's bundled ML Kit for on-device text recognition. Google's SDK documentation describes limited device/app information, installation-scoped identifiers, performance/error metrics, and API/input-output size information for diagnostics and usage analytics. This is distinct from uploading schedule images or recognized text for processing. Store and integrity services also handle technical information under their own policies.

Website and support. Visiting a website necessarily exposes network/request information to its hosting and security infrastructure. This website currently has a Cloudflare proxy layer; that provider may process IP addresses, request time, browser/protocol information, and security or connection diagnostics. The operator must confirm the active hosting/logging configuration and retention. These pages include no advertising or third-party analytics scripts. Hosting security features can have their own technical behavior; we do not claim that all infrastructure processing is absent.

If you voluntarily contact support, the contact service receives the email address and message information you choose to send. Please do not include real schedules, wages, identity documents, banking information, or other sensitive business content.

Website language preference. If you choose a language, this website stores only that functional preference in your browser's localStorage under rostersnap.web.language, shared by Privacy and Support. It is not sent to the RosterSnap backend or used for advertising/tracking. You can switch language or clear this site's browser storage; if storage is unavailable, your choice may apply only to the current page.

4. Purchases

RosterSnap Pro Lifetime is a one-time, non-consumable purchase processed by the Apple App Store or Google Play. RosterSnap does not directly receive or store your full payment-card or bank details.

The app processes store product identifiers, prices, purchase/transaction status, and verified entitlement information to purchase, restore, and manage Pro. Android also processes signed purchase data and a purchase token, including a local verified cache, and acknowledges valid completed purchases without consuming the lifetime product.

The current RosterSnap backend does not receive purchase tokens, purchase signatures, order identifiers, receipts, or transaction payloads for purchase verification. Payment and store-account processing is performed by the corresponding store. Any future server-side purchase verification would require a policy update before it is introduced.

5. Notifications

Shift-start and previous-evening reminders are scheduled as local device notifications when you enable the feature and grant the relevant permission. RosterSnap servers do not read your shift details to send these reminders. Notification text may be visible on your lock screen or connected devices according to your operating-system preferences.

You can adjust reminders in the app and change or revoke notification permission in system settings. Delivery can also depend on device power restrictions, Android alarm permissions, and platform scheduling limits.

6. Calendar access

If you grant calendar access and enable synchronization, RosterSnap creates, updates, or removes the calendar events it manages in the calendar you select. Calendar selection, event identifiers, and event content are handled on the device; calendar content is not sent to the RosterSnap backend.

Your selected calendar may synchronize through its own Apple, Google, employer, or other account. That provider's synchronization, access, backup, and deletion rules apply to those copies. You can disable synchronization or revoke calendar permission. Turning off synchronization or uninstalling the app does not guarantee removal of previously created calendar events.

7. Data sharing and service providers

RosterSnap does not sell personal data. The app does not include an account-registration service, advertising SDK, or a RosterSnap behavioral-tracking service. Necessary processing can involve Apple StoreKit/App Store, Google Play Billing, Apple DeviceCheck, Google Play Integrity/Device Recall when enabled, Google ML Kit diagnostics, operating-system calendar/backup services you choose, and website hosting/security services.

The data involved depends on the specific service and is limited to its described purpose. A local OCR SDK is not a cloud OCR service. Adding a new SDK, processing purpose, or server data flow requires review and an updated policy; this policy does not authorize future analytics, ads, or business-data uploads.

Provider information: Apple Privacy Policy, Google Privacy Policy, ML Kit data disclosure, and Cloudflare Privacy Policy.

8. Data retention

You control how long confirmed business records remain in the app through the available edit/delete actions and device storage controls. Temporary scan data is kept only for the scan workflow. Copies in system backups, your photo library, or selected calendars follow the settings and policies of those services.

Limited backend trial and device-verification records support eligibility, anti-abuse, and idempotent processing. Raw verification tokens are not persisted by the current backend. The current trial schema does not implement an automatic expiry/deletion job, and no fixed production retention period has been confirmed. We therefore do not promise a specific number of days or automatic erasure.

The operator's retention policy must keep technical data only as long as reasonably necessary for the stated purpose and applicable obligations. Production database, backup, reverse-proxy, and logging lifecycles must be confirmed and implemented by the operator; contact support with questions. This wording is not a claim that an unimplemented deletion schedule already exists.

9. Data deletion and your choices

You can edit or delete shifts and supported local information in the app, remove saved recognition preferences using the app's controls, or use your platform's app-data deletion/uninstall controls. On iOS, offloading an app is not the same as deleting its data. System backups, photos, and synchronized calendar copies may remain separately and must be managed in their own services.

There is no RosterSnap account to delete. Uninstalling the app does not necessarily erase store purchase history or anti-abuse/device-recall state held by platform services. Reinstallation is not a guaranteed way to reset the free trial.

For limited server-side technical information, contact the privacy address below. There is currently no public self-service backend deletion endpoint. Identification, what can be located, lawful retention needs, and provider-held information must be assessed before a request can be fulfilled; we do not guarantee that all provider records can be erased by RosterSnap.

10. Children

RosterSnap is a work-schedule utility and is not specifically designed for children. No numerical age restriction is stated here because the operator's final store age settings and applicable requirements still need confirmation. If you believe a child has submitted sensitive information to support, contact the privacy address without sending additional sensitive documents.

11. Security

This website uses HTTPS. RosterSnap's production technical services are intended to use secure connections, narrow request schemas, limited data storage, signature/device verification, and reasonable technical and organizational safeguards. Operational access, logging, backups, and retention require configuration by the responsible operator.

No system or transmission is absolutely secure. We do not promise 100% security, zero risk, or that local storage removes all operating-system or physical-device risks.

12. International processing

Necessary technical services, store platforms, and hosting/security providers may process information outside your country or region. No specific RosterSnap server location or legal transfer mechanism is asserted here because the operator has not confirmed the deployment/data-processing region. The website's network edge location does not establish the origin server's location.

13. Changes to this policy

We may update this policy when features, providers, data flows, or legal requirements change. The updated text and last-updated date will appear on this page. Changes requiring additional notice or permission must be handled as applicable; a policy update does not itself grant permission to upload your schedule data.

The last-updated date above identifies the latest revision of this policy.

14. Contact

Privacy and support contact: echo.akihi@gmail.com.

Developer and operator: akihi (individual). Copyright holder: akihi.

See RosterSnap Support for troubleshooting and safe information to include when reporting an issue.

Back to top