๐ Privacy Policy
Last updated: January 27, 2025 | Version 1.0
โ YOUR CONTROL OVER DATA
RoastCam respects your privacy.
- โ We DON'T store your photos
- โ We DON'T store generated roasts
- โ We DON'T sell your data
- โ All processing is temporary
1. Introduction
This Privacy Policy describes how RoastCam ("the App", "we", "our") collects, uses, and protects users' personal data ("you", "your", "user").
Data Controller:
Simone Olianti (CyberCrow)
Email: simone.olianti@gmail.com
This Privacy Policy applies to the use of the RoastCam mobile application, available on Google Play Store.
2. Legal Basis for Processing (GDPR)
The processing of your personal data is based on:
- Explicit consent (Art. 6(1)(a) GDPR) - for photo processing
- Contract performance (Art. 6(1)(b) GDPR) - to provide the service
- Legitimate interest (Art. 6(1)(f) GDPR) - to improve the service
- Legal obligation (Art. 6(1)(c) GDPR) - for tax and legal compliance
3. Data Collected
3.1 Data We Collect
| Data Type | Details | Retention |
|---|---|---|
| ๐ธ Photos | Images uploaded by user | TEMPORARY |
| ๐ญ Generated roasts | Satirical texts produced by AI | TEMPORARY |
| ๐ค Firebase UID | Anonymous user identifier | PERMANENT |
| ๐ Usage data | Anonymous statistics (Firebase Analytics) | AGGREGATED |
| ๐ณ Payment data | Managed by Google Play Billing | NOT ACCESSIBLE |
| ๐ฑ Device info | Model, OS, app version | ANONYMOUS |
3.2 Photos and Visual Content
๐จ IMPORTANT: Your Photos Are Safe
- โ Photos are uploaded ONLY temporarily for processing
- โ Deleted IMMEDIATELY after roast generation
- โ NOT saved on our servers
- โ NOT used to train AI models
- โ NOT shared with third parties (except AI provider for processing)
3.3 Data NOT Collected
RoastCam does NOT collect:
- โ Name, surname, address
- โ Phone number
- โ Email (except if provided for support)
- โ Precise GPS location
- โ Device contacts
- โ SMS or calls
- โ Biometric data
4. How We Use Your Data
4.1 Processing Purposes
- Provide the Service
- Process photos to generate roasts
- Manage daily limits and subscriptions
- Save preferences (language, roast intensity)
- Improve the App
- Analyze app usage (Firebase Analytics)
- Identify bugs and crashes (Firebase Crashlytics)
- Test new features (A/B testing)
- Communications
- Push notifications (optional, require consent)
- Customer support
- Important updates
- Security and Abuse Prevention
- Prevent fraudulent use
- Monitor usage limits
- Protect infrastructure
5. Data Sharing with Third Parties
5.1 Service Providers
We share data with the following service providers:
| Service | Purpose | Data Shared |
|---|---|---|
| Firebase (Google) | Backend, analytics, authentication | UID, usage data, crash reports |
| OpenAI / Anthropic | AI roast generation | Photos (temporary), prompts |
| Google Play Billing | Payment management | Purchase ID, purchase token |
| Google Cloud | Hosting and temporary storage | Photos (during processing) |
๐ Security Measures
All providers are GDPR compliant and use:
- Encryption in transit (HTTPS/TLS)
- Encryption at rest
- Secure authentication
- Regular security audits
5.2 When We DON'T Share Data
RoastCam does NOT:
- โ Sell your data to third parties
- โ Share data with advertisers
- โ Use data for targeted advertising
- โ Share photos with social media (only you can do that)
6. Data Retention
6.1 Retention Periods
| Data Type | Retention | Reason |
|---|---|---|
| Uploaded photos | < 1 minute | Only during processing |
| Generated roasts | < 1 minute | Only during display |
| User preferences | Until account deletion | App functionality |
| Subscription data | Until deletion + 10 years | Tax obligations |
| Anonymous analytics | 14 months | Firebase policy |
| Crash reports | 90 days | Debugging and improvements |
6.2 Automatic Deletion
The following data is automatically deleted:
- ๐๏ธ Photos: < 60 seconds after upload
- ๐๏ธ Temporary cache: cleared daily
- ๐๏ธ Processing logs: 7 days
7. Your Rights (GDPR)
7.1 Guaranteed Rights
In accordance with GDPR, you have the following rights:
- Right of Access (Art. 15)
You can request a copy of your personal data.
- Right to Rectification (Art. 16)
You can correct inaccurate or incomplete data.
- Right to Erasure (Art. 17) - "Right to be Forgotten"
You can request complete deletion of your account and data.
- Right to Restriction (Art. 18)
You can request restriction of processing.
- Right to Data Portability (Art. 20)
You can receive your data in structured format.
- Right to Object (Art. 21)
You can object to processing based on legitimate interest.
- Right to Withdraw Consent (Art. 7)
You can withdraw consent at any time.
7.2 How to Exercise Your Rights
๐ง Email: simone.olianti@gmail.com
๐ฑ From the app: Settings โ Info โ Contact developer
โฑ๏ธ Response time: Within 30 days of request
To delete your account:
- Send an email to simone.olianti@gmail.com with subject "RoastCam Account Deletion"
- Include your User ID (available in App โ Info)
- You'll receive confirmation within 7 business days
- All data will be deleted within 30 days
8. Data Security
8.1 Technical Measures
- ๐ End-to-End Encryption: All data in transit encrypted with TLS 1.3
- ๐ Encryption at Rest: Database and storage protected with AES-256
- ๐ Secure Authentication: Firebase Authentication with JWT tokens
- ๐ Firewall and DDoS Protection: Google Cloud protection
- ๐ 24/7 Monitoring: Anomaly and intrusion detection
8.2 Organizational Measures
- โ Data access limited to developer only
- โ Daily encrypted backups
- โ Regular security audits
- โ Data retention policies
8.3 Data Breach Notification
In case of data breach:
- ๐ข Notification to authorities within 72 hours
- ๐ข Notification to affected users via email/push
- ๐ข Notice publication in the app
9. International Data Transfers
Your data may be transferred and processed in countries outside the European Union, particularly:
- ๐ United States (Firebase, Google Cloud, OpenAI)
- ๐ United Kingdom (Anthropic)
Protection guarantees:
- โ EU standard contractual clauses
- โ Privacy Shield equivalents
- โ EU Commission adequacy decisions
10. Minors
RoastCam is intended for users aged 13 or older.
๐ Parent Alert
- If you are under 18, you must have parental/guardian consent
- We do NOT knowingly collect data from children under 13
- If we learn of data collected from children under 13, we delete it immediately
11. Cookies and Similar Technologies
11.1 Cookies Used
The app uses cookie-like technologies for:
- ๐ช Local SharedPreferences: Save user preferences (language, theme)
- ๐ช Firebase Analytics: Track app usage (anonymous)
- ๐ช Crash Reporting: Identify and fix issues
11.2 Consent Management
You can control tracking in Settings โ Privacy:
- โ Disable Firebase Analytics
- โ Disable Crash Reporting
- โ Disable Push Notifications
12. Changes to Privacy Policy
We reserve the right to update this Privacy Policy. In case of substantial changes:
- ๐ง We'll notify you via push notification or email
- ๐ฑ We'll show a notice in the app
- ๐ The new policy will take effect 30 days after notification
Previous versions: Archived and available upon request
13. Supervisory Authority
You have the right to file a complaint with the data protection supervisory authority:
๐ฎ๐น Italy:
Garante per la Protezione dei Dati Personali
Website: www.garanteprivacy.it
Email: garante@gpdp.it
๐ช๐บ Other EU jurisdictions:
European Data Protection Board - Member Authorities
14. Contact
Data Controller:
Simone Olianti (CyberCrow)
Email: simone.olianti@gmail.com
Privacy Support:
For privacy-related requests, write in subject: "PRIVACY - RoastCam"
Response time: Within 30 days of request (GDPR Art. 12)
15. Consent
By using RoastCam, you accept this Privacy Policy.
If you do not accept, do not use the app and request deletion of your account.