← Back to Roost

Roost Privacy Policy

Effective date: August 12, 2026 · Last updated: August 12, 2026 · Previous version: June 11, 2026

What changed in this version: we added Section 5 covering the morning quest photo feature (how photos are stored, who can see them, how long we keep them, the AI caption and safety screen, and how reporting works), and we added Google and Resend to the sub-processor list.

This Privacy Policy explains how TC Fusion LLC ("TC Fusion," "we," "us," or "our") collects, uses, shares, and protects personal data when you use the Roost mobile application and related services (together, the "Service"). It also describes your rights under the EU and UK General Data Protection Regulation ("GDPR") and other applicable laws.

The short version

Contents
  1. Who we are
  2. Scope
  3. Data we collect
  4. Your sleep & health data
  5. Morning quest photos
  6. How & why we use data
  7. Legal bases (GDPR)
  8. Sharing & sub-processors
  9. What others can see
  10. International transfers
  11. Data retention
  12. Your rights
  13. Children
  14. Security
  15. Automated decisions
  16. Changes
  17. Contact & complaints

1. Who we are (data controller)

TC Fusion LLC is the controller responsible for your personal data under the GDPR.

EU / UK representative. Where required under Article 27 of the EU GDPR and UK GDPR, we will appoint a representative in the EU and the UK and list their contact details here. Until then, EU and UK users may contact us at the email above for any matter relating to their personal data.

2. Scope of this policy

This policy applies to the Roost mobile app and the services it connects to. It does not cover third-party services that have their own privacy policies (such as Apple, Google, or your device's operating system), or the TC Fusion company website, which is covered by a separate website privacy policy.

3. The data we collect

We collect the following categories of personal data, mostly directly from you or generated as you use the Service:

Account & identity

Profile & social

Sleep & progress data

Morning quest photos & reactions

Device & technical

Subscription & billing

Consent records

Analytics, diagnostics & support

4. Your sleep & health data — how it works

Sleep and health information is "special category" data under Article 9 of the GDPR and deserves the strongest protection. Roost is built around a two-layer model:

Layer 1 — Stays on your phone, always

The detailed, sample-level recordings Roost reads from Apple Health (HealthKit) or Android Health Connect — minute-by-minute sleep stages, heart-rate series, and similar raw streams — are read on your device, used for on-device calculations, and never transmitted to our servers. We also never place this data in iCloud. To grant Roost read access to this data, you approve it through your operating system's own health-permission screen, which you can revoke at any time in your device settings.

Layer 2 — Your progress syncs (encrypted, EU servers)

From the raw data, your device computes gameplay results — quality bands, Sleep Points, ranks, streaks, and your hidden baseline. The results (not the underlying samples) are stored on our servers so your progress survives a lost or replaced phone and powers your roost. Because a long-running record of sleep quality can itself reveal information about your health, we treat this entire server-side sleep layer as Article 9 health data and protect it accordingly.

Layer 2 (optional) — Nightly summary backup

Separately and optionally, you can opt in to summary sync. When enabled, about a dozen numeric figures per night (bedtime, wake time, duration, latency, efficiency, time awake, REM/deep percentages, heart-rate dip) are backed up to our servers so your detailed history can be restored on a new device. This is:

Our lawful basis for all health data is your explicit consent (GDPR Article 9(2)(a)). Consent is requested separately, in plain language, and is always withdrawable. Declining or withdrawing summary sync simply keeps your detailed history on your device only — the rest of the app continues to work.

5. Morning quest photos

Roost's morning quest asks you to take one photo when you wake up: your made bed, the view out the window, the glass of water you drank, whatever the quest is. These photos are user content rather than health data, but they are pictures taken inside people's homes moments after waking, so we treat them as sensitive and have built the feature to be private first.

Camera only

A morning photo can only be taken with the live camera inside the app. There is no option to pick one from your photo library, and Roost does not read your photo library for this feature. (Your photo library is used only if you choose to set a profile picture.) Roost asks for camera permission through your operating system, and you can revoke it at any time in your device settings. Declining simply means you skip the morning photo. The rest of the app works normally, and the quest is always skippable in one tap.

Private by default

Every photo starts out visible to you alone. Sharing is a separate, deliberate choice you make on the screen after you take the photo, and you pick which of your roosts it goes to. There is no public feed, no discovery, no profiles strangers can browse, and no direct messages. The only people who can ever see a morning photo are members of a roost you chose to share it with, which is at most a handful of people you invited.

How photos are stored

Owly's comment and the safety screen (processing by Google)

Right after you take a morning photo, the image and the name of the quest are sent to Google's Gemini API so that Owly can write its one-sentence comment and so the photo can be automatically screened for objectionable content. This happens for every morning photo, including ones you keep entirely private, because the safety screen runs at capture.

Owly's comment is flavour, not judgement. It never blocks your progress, and the automated safety result is separate from whether your quest counts.

Who can see a shared photo, and for how long

A photo you share is visible to the members of the roost(s) you selected for 7 days, after which it leaves the feed. Your own photos stay in your private gallery: the last 7 days on the free plan, and all of them with Roost Pro. You can delete any photo yourself at any time, which removes it from our storage and from any roost feed it appeared in.

How long we keep photos

Reporting, moderation, and blocking

Even though photos only travel between people who invited each other, we moderate the feature:

Legal bases for photos. We process morning photos to provide a feature you chose to use (contract, GDPR Art. 6(1)(b)), including sending them to our AI provider for the caption and safety screen. We process reports, blocks, and moderation records in our legitimate interests (Art. 6(1)(f)) in keeping Roost safe for its users and meeting the app stores' content requirements. Morning photos are not part of the sleep summary-sync consent described in Section 4, and we do not treat them as health data.

6. How and why we use your data

PurposeData used
Create and secure your account; sign you inAccount identifier, email, account ID
Provide core features — compute ranks, Sleep Points, streaks, quests; sync your progress across devicesDerived metrics, profile, sleep summaries (if opted in)
Power social features — your roost, leaderboards, kudosDisplay name, avatar, rank/SP, roost membership
Run the morning quest — store your photo, generate Owly's comment, screen it for objectionable content, and share it to the roosts you chooseMorning photo, quest name, your sharing choices, reactions
Keep Roost safe — review reported content, remove it, and act on repeat offendersReport records, photo snapshot, reporter and reported account IDs, blocks
Send reminders and roost notifications (never during your sleep window)Push token, time zone
Process subscriptions and manage Premium accessSubscription status from our payments processor
Keep the Service secure and prevent cheating in the ranking systemDerived gameplay metrics, technical identifiers
Understand and improve the productBehavioral analytics events (no sleep values)
Diagnose crashes and errors to keep the app stableCrash/error reports (no sleep data, no personal identifiers)
Respond to your support requestsYour message and contact details
Comply with legal obligations and keep consent recordsConsent log, billing records

8. Sharing & sub-processors

We do not sell your personal data, and we do not use it for third-party advertising. We share data only with service providers ("sub-processors") who process it on our behalf under contract, and only as needed to run the Service:

ProviderPurposeDataLocation
SupabaseBackend database, authentication, file storage, notifications backendAccount, profile, progress, sleep summaries (if opted in), push tokens, avatars, morning photos, consent logEU (Frankfurt, Germany)
AppleSign in with Apple; App Store billingAccount identifier, email, subscriptionUnited States / global
GoogleGoogle sign-in; Google Play billingAccount identifier, email, subscriptionUnited States / global
Google (Gemini API)Generating Owly's comment on a morning photo and automatically screening it for objectionable contentThe morning photo and the quest name only. No account identifiers, no sleep data. Not used to train Google's models.United States / global
ResendDelivering moderation emails when content is reportedReport details and a link to the reported photo that expires after 72 hoursUnited States
ExpoDelivery of push notificationsPush token, platformUnited States
RevenueCatSubscription managementYour account ID, subscription eventsUnited States
PostHogPrivacy-protective product analyticsAccount ID + behavioral events only (never sleep values)EU
SentryCrash & error diagnosticsError/crash reports — no sleep data, no personal identifiersUnited States

We may also disclose data if required by law, to enforce our terms, or to protect the rights, safety, and security of our users or the public. If TC Fusion is involved in a merger, acquisition, or asset sale, personal data may be transferred, and we will notify you and honor the commitments in this policy.

9. What other people can see

Roost is social by design, but tightly scoped. Other members of your roost can see your display name, profile photo, current rank and Sleep Points, and time-related context needed for the weekly race. They cannot see your email, your raw or numeric sleep data, your baseline, or your individual night details. Profile photos are stored so they can be displayed in the app; treat your display name and photo as information visible to people you share a roost with.

They can also see any morning quest photo you chose to share with that roost, together with Owly's comment on it, for 7 days. They can react to it (cheer, heart, laugh) and they can report it. A photo you did not share is visible to nobody but you. Once shared, a photo can be viewed by people who may keep their own copy by taking a screenshot, so share what you would be comfortable with those people keeping.

10. International data transfers

Your core account and sleep data is stored in the European Union. Some sub-processors listed above are based in the United States. Where personal data of EU/UK users is transferred outside the EEA or UK, we rely on appropriate safeguards under the GDPR — such as the European Commission's Standard Contractual Clauses (and the UK Addendum), or an adequacy decision where one applies. You can request a copy of the relevant safeguards by contacting us.

11. How long we keep your data

12. Your privacy rights

Subject to applicable law, you have the right to:

Delete your account yourself, any time. In the app, go to Profile → Delete account. This permanently erases your account and the data tied to it — your profile, sleep summaries, ranks, Sleep Points, streaks, quests, morning photos, push tokens, consent records, your roost memberships, kudos, and reactions — and wipes your sleep history from the device. If you created a roost, ownership is handed to another member, or the roost is removed if you were the only one in it.

One thing we can't cancel for you: an active Apple App Store or Google Play subscription. Deleting your Roost account does not stop store billing — you must cancel the subscription in your App Store or Google Play account settings.

To exercise any right, email privacy@tcfusion.dev. We respond within the timeframes required by law (generally within one month under the GDPR). We will not charge a fee or discriminate against you for exercising your rights. We may need to verify your identity before acting on a request.

13. Children

Roost is intended for users aged 16 and older. It is not directed to children under 16, and we do not knowingly collect personal data from them. If you believe a child under 16 has provided us personal data, contact us and we will delete it.

14. How we protect your data

We use industry-standard measures to protect your data, including encryption in transit and at rest, strict database access controls that limit your data to you (and, for the narrow social fields above, your roost), private photo storage reachable only through short-lived signed links, an architecture that keeps raw health data off our servers entirely, and analytics and crash-reporting pipelines designed so sleep values are never sent to third parties. No method of transmission or storage is completely secure, however, and we cannot guarantee absolute security.

15. Automated decision-making

Roost computes ranks, Sleep Points, and quest progress automatically. These power the game and do not produce legal or similarly significant effects about you, and we do not use your data for automated decisions of that kind, nor for profiling for advertising.

Morning photos are screened automatically for objectionable content (Section 5). A flagged photo cannot be shared with a roost, but it still counts for your quest and your points, and it stays in your own gallery. If you think a photo was flagged in error, email us and a person will look at it.

16. Changes to this policy

We may update this policy as the Service evolves. When we make material changes, we will update the "Last updated" date and, where appropriate, notify you in the app. Continued use of the Service after an update means you accept the revised policy.

17. Contact & complaints

Questions, requests, or concerns? Email privacy@tcfusion.dev or write to TC Fusion LLC, 5678 Davis Ford Rd, Manassas, VA 20112, USA.

If you are in the EU or UK and believe we have not handled your data lawfully, you have the right to lodge a complaint with your local data protection authority. In the EU, you can find yours via the European Data Protection Board; in the UK, the Information Commissioner's Office (ICO). We would, however, appreciate the chance to address your concern first.

Roost is a consumer wellness app, not a medical device, and does not provide medical advice, diagnosis, or treatment. See the Terms of Service for details.