Privacy Policy

Last updated: 11 September 2026

Roveri is a riding journal. It is built so that your rides stay yours — on your device and in your own private iCloud. Roveri has no accounts and no advertising, and your ride data never leaves your device except as described below, or when you share a ride yourself. The only data Roveri collects about app usage is anonymous — never tied to who you are, and never used for tracking. The developer never sees the rides you have not shared.

The short version. Everything Roveri records lives on your iPhone and syncs only through your personal iCloud account. App data leaves your device in just two cases: to fetch weather for a ride, and to send anonymous usage statistics that help improve the app (see “Weather” and “Analytics” below). Your rides are never sent to the developer unless you share one yourself (see “Shared rides” below), and nothing is ever sold or passed on. This website measures its own traffic separately and anonymously — see “Website” below.

What Roveri stores

When you record a ride, Roveri saves: the route (GPS coordinates), distance, speed, elevation, duration and timestamps, the weather you rode through, any notes you write, and a basic vehicle profile. This information is stored locally on your device.

Where your data lives

Your rides are kept on your device and synced through Apple’s iCloud, in your account’s private database — so your history survives an app reinstall and syncs across your own devices signed in to the same Apple ID. This is Apple’s iCloud; it is governed by Apple’s Privacy Policy. The developer of Roveri cannot access your iCloud data.

Location

Roveri uses location while you ride to record your route. Location data is processed on your device and is not transmitted anywhere, except as described under “Weather”.

Weather

To show the conditions you rode through, Roveri sends the coordinates and time of a ride to Open-Meteo, a third-party weather service, and receives historical weather in return. Open-Meteo does not require an account and states that it does not track users; see the Open-Meteo terms and privacy. No other ride information is sent.

Analytics

To understand how Roveri is used and where to improve it, the app uses TelemetryDeck, a privacy-focused analytics service. It records anonymous events — such as completing onboarding or starting and finishing a ride — together with a hashed device identifier used only to estimate how many people use the app. This data is not linked to your identity, is never used for advertising or cross-app tracking, and is never sold or shared. No routes, locations, ride contents, or personal information are sent to the analytics service — only the fact that an action happened.

Website

This section covers the roveri.app website only — not the app. To measure how many people visit these pages, the site uses Cloudflare Web Analytics. It is cookieless: it sets nothing on your device, collects no personal information, builds no profile of you, and does not track you across other sites. What it records is the page you viewed and coarse technical context such as country, browser and referring site. Nothing it collects is linked to your app data or to any Roveri account — there are no Roveri accounts. Visiting this website sends nothing about your rides. Ride pages you open under roveri.app/r/… show only what their sharer chose to publish.

Shared rides

When you tap Share → Link on a ride, Roveri uploads that ride to our server and publishes it at roveri.app/r/…, where anyone with the link can view it. What is uploaded: the route after your privacy settings (start and finish trimmed if you chose so, top speed removed if you chose so), the ride’s statistics, its weather, the place names, and a preview image. Your note is never uploaded. No account or name is attached.

Shared pages are public: anyone with the link can open them, and search engines may index them. The link cannot be guessed. The data is stored on Cloudflare (R2 and KV) until you remove it.

Opening a shared page draws the map in your browser: the map software is loaded from Cloudflare’s CDN and the map tiles come from OpenFreeMap, so that provider sees your IP address and the part of the map you are looking at — nothing about who you are, and nothing else from Roveri. On the upload side, the server counts uploads per IP address for one hour, so the endpoint cannot be abused, and then forgets them; that counter is the only thing it records about the device that shares a ride.

You can remove a shared ride at any time from the ride’s Share menu or from History → Shared; the page then answers “no longer shared”. If you no longer have the device, email us the link and we remove it.

The app can also open GPX files and shared links from other riders. Those rides are stored only on your device, separately from your journal, and are not synced to iCloud.

Subscriptions

Roveri Pro is an optional subscription sold through Apple’s App Store. Apple processes all payments — the developer never receives your payment details. Roveri learns only whether your subscription is active, through Apple’s StoreKit.

Reporting a problem

If you use “Report a problem”, Roveri opens your email app with a pre-filled message that includes basic diagnostic information (device model, OS and app version) and an export of the ride you chose. Nothing is sent until you send that email yourself.

What Roveri does not do

Children

Roveri is a general-audience app. It is not directed at children and does not knowingly collect personal information from them.

Your choices

You are in control of your data: delete any ride inside the app to remove it; remove a shared ride from the ride’s Share menu or from History → Shared; delete the app to remove its data from your device; and manage or delete Roveri’s iCloud data from iOS Settings under your Apple ID.

Changes to this policy

If this policy changes, the updated version will be posted here with a new date above.

Contact

Questions about privacy? Email support@roveri.app.