Privacy policy

The short version. Rovyn stores the playlists your assistant sends you, how far you got through them, the episodes you saved and the shows you follow, and the feedback you chose to give. Your assistant gets summarized listening receipts and your feedback in your own words, sent along as it works rather than only when it asks — not your raw playback history, and not what you granted your other connections. There is no ad network and there are no third-party trackers, and we do not sell your data. Our own measurement is thin and worth naming: a few first-time stamps on your account, identity-free counts on the sign-in screen, and ordinary web-server logs. Deleting your account deletes your data — in one transaction, not a hidden flag on a row you can no longer see.

What Rovyn stores

What Rovyn sends your assistant

Each assistant you connect (Claude, ChatGPT, and so on) is a separate connection with its own permissions, and each one can be disconnected on its own. Disconnecting ends that connection's access — its credentials stop working on their next use — and leaves your other connections running. It erases nothing: the editions, receipts, and notes that connection produced stay on your account until you remove them, or the account.

How signing in works, and what it discloses

Every sign-in method contacts Google's Firebase servers. If you sign in with Apple or Google, that provider additionally learns that your identity signed in to Rovyn. Firebase holds your account record and refreshes your session over time, so Google also sees when your app or browser is active — address, device, timing, the ordinary shape of any web sign-in. What it does not get from us is anything about your listening: Rovyn sends the identity providers no goals, no briefs, no playback, no feedback, no library contents. Firebase Analytics is deliberately not integrated. Firebase itself holds your account record (identifier, sign-in method, email) because it must, to authenticate you.

If you use the email-and-password option on the page that appears when you connect an assistant, your password goes from your browser straight to Firebase. The Rovyn server never receives it, never stores it, and cannot read it; what reaches Rovyn is the same verified token the other two methods produce. That sign-in page loads Google's sign-in code and keeps your session in your browser; this website itself sets no cookies and loads no third-party scripts.

What podcast publishers see

Rovyn plays audio from publishers' servers directly, like any podcast app — the same fetch whether you are streaming or downloading an episode for offline listening. Downloaded files stay on your device; we keep no copy. Publishers see ordinary CDN logs — IP address, user agent, byte ranges — and our servers also fetch the RSS feed itself, identified as Rovyn. Rovyn attaches nothing else to those requests: no goals, no briefs, no feedback, no account identity.

What Rovyn doesn't do

Deletion deletes

Deleting your account removes your rows in one transaction — editions, briefs, playback events, progress, receipts, saved episodes, feedback, follows, connections, device records, and the identity record with its email. Every assistant token dies with it. There is no soft-delete and no tombstone.

What survives is shared rather than personal: the public podcast catalog, the registry of assistant clients allowed to connect, and a daily tally of sign-in screen outcomes — a date, an event, a number, with no account or address attached. Database backups and ordinary server logs age out on their own schedules. The app then asks Firebase to delete the sign-in record on Google's side; that step runs on your phone after your Rovyn data is already gone and can fail on a bad connection, so if you signed in only through a browser, or you want it confirmed, write to support and we will finish it.

The protocol is specified apart from this service

Rovyn implements Cueback, a protocol specified apart from this service. The boundaries above — what crosses to an assistant and what does not — are properties of that design rather than private promises. The specification is published, Apache-2.0, at github.com/tinkon/cueback — so you can check this page against it yourself.

Changes and contact

If this policy changes, the date at the top changes, and material changes will be called out plainly on this page. Questions: support@polimati.com.