Privacy policy
Effective August 21, 2026 · Applies to the Rovyn app and the hosted Rovyn service (rovyn.app)
The short version. Rovyn stores the playlists your assistant sends you, how far you got through them, the episodes you saved and the shows you follow, and the feedback you chose to give. Your assistant gets summarized listening receipts and your feedback in your own words, sent along as it works rather than only when it asks — not your raw playback history, and not what you granted your other connections. There is no ad network and there are no third-party trackers, and we do not sell your data. Our own measurement is thin and worth naming: a few first-time stamps on your account, identity-free counts on the sign-in screen, and ordinary web-server logs. Deleting your account deletes your data — in one transaction, not a hidden flag on a row you can no longer see.
What Rovyn stores
- Your editions (playlists). The recommendations your assistant created, each episode's one-line rationale, and the goal ("brief") the assistant stated when it made the playlist. A brief marked as a temporary interest is cleared once its playlist is finished or you archive it — a sweep runs hourly. Two things worth stating plainly: a playlist you never finish keeps its brief, and the goal is copied onto the receipts that playlist produced, so clearing the brief afterwards does not rewrite them. Deleting the edition removes both.
- Playback events and progress. The app records playback events (started, paused, completed, skipped) and your resume position. These raw events are server-internal: no MCP tool and no API route returns them, and the only code that reads them is the receipt builder that produces the summaries below. We do not currently expire them, so they are kept until you delete your account, and they go with it.
- Listening receipts. A per-episode summary: outcome, rough progress, time spent, whether you saved the episode, and any feedback you gave. A receipt names the episode, never the phone: there is no device identifier in one. It does carry times — when the summary was taken, when you wrote each note, when you saved it.
- Your feedback, verbatim. Notes you write are stored exactly as typed. Rovyn never summarizes, classifies, sentiment-scores, or auto-tags them. What you can read back in the app is what Rovyn hands an assistant you authorized, in your words; a very long note can arrive as a marked excerpt, with the full text a request away.
- Your feeds. RSS feeds you added and podcast catalog metadata (shows and episodes — this is public data, not yours).
- One email address. Rovyn is signed in by design — you use it with your Apple or Google account, or, when you connect an assistant from a browser, with an email address and a password (all three via Firebase Auth). Rovyn stores an opaque account identifier, which method you used, and the email address. The email is there for one job: finding your account when you write to support. It does not appear in the app, we send no mail to it, we do not pass it to anyone, and it is deleted with your account. Firebase holds the same address, because that is where you sign in, and the browser sign-in page shows it back to you once you have. The account record has no column for your name or your photo, even though sign-in providers offer both.
- Saved episodes. Episodes you bookmark in the player, kept on your account. A save is not private to the app: it rides out in the receipt for that episode, so an assistant you granted receipts access can see that you saved it, and when.
- What you type into show search. Directory searches are answered by Podcast Index, so the words you type reach them. Searching your own library does not leave our service.
- Your devices. One row per sign-in — the platform, a hashed session token, when it was created and when it was last seen. Your playback position is kept per device, which is why the row exists.
- A few first-time stamps. When your account first paired a device, first granted a connection and to which assistant, first got an edition, first opened a player link, first produced a receipt. A player link carries two of its own: when its page was first served, and the first time a claim on it was refused. These are our product measurement, they are per account, and they die with the account.
What Rovyn sends your assistant
Each assistant you connect (Claude, ChatGPT, and so on) is a separate connection with its own permissions, and each one can be disconnected on its own. Disconnecting ends that connection's access — its credentials stop working on their next use — and leaves your other connections running. It erases nothing: the editions, receipts, and notes that connection produced stay on your account until you remove them, or the account.
- Assistants receive summarized receipts, never raw playback history. There is no interface through which an assistant can read raw events — the limitation is structural, not a setting.
- Your written feedback goes, word for word, to assistants you granted permission to read receipts. That is the only place the product sends it: no other connection, and no third party we hand it to. It is stored on our servers and with our database provider, like everything else here.
- Under that same permission, your notes are also sent with the tools your assistant already calls, rather than only when it asks for receipts: on every playlist it builds, and at most once every twenty minutes on the tools it uses to look things up — searching episodes, listing shows, and checking whether something it found is playable. What goes is bounded — at most forty notes, each with its episode, its show, when you wrote it, what you did with it, and the goal it was heard under when there's one to attach — and long notes arrive cut at 500 characters and marked as cut. Rovyn doesn't decide which note is relevant to what's being built; that reading is the assistant's, not the server's.
- No tool tells one connection what your other connections are or what you granted them. It can see which assistant built a given edition, because every edition is credited to its author — that credit is the point.
- Rovyn does not ask for your assistant's memory or your conversation history, and the brief has no field that would hold either. What crosses the boundary inbound is the brief the assistant states when it builds a playlist — a goal, the time you have, a level, preferences, and how long we may keep it — plus the one-line rationale it writes for each pick, and, if you granted it, feedback filed in your words. Fields the schema does not define are dropped when the brief arrives rather than stored. The free-text fields it does have are roomy, so what your assistant writes into them is its own doing; the brief is shown to you on the playlist it produced.
How signing in works, and what it discloses
Every sign-in method contacts Google's Firebase servers. If you sign in with Apple or Google, that provider additionally learns that your identity signed in to Rovyn. Firebase holds your account record and refreshes your session over time, so Google also sees when your app or browser is active — address, device, timing, the ordinary shape of any web sign-in. What it does not get from us is anything about your listening: Rovyn sends the identity providers no goals, no briefs, no playback, no feedback, no library contents. Firebase Analytics is deliberately not integrated. Firebase itself holds your account record (identifier, sign-in method, email) because it must, to authenticate you.
If you use the email-and-password option on the page that appears when you connect an assistant, your password goes from your browser straight to Firebase. The Rovyn server never receives it, never stores it, and cannot read it; what reaches Rovyn is the same verified token the other two methods produce. That sign-in page loads Google's sign-in code and keeps your session in your browser; this website itself sets no cookies and loads no third-party scripts.
What podcast publishers see
Rovyn plays audio from publishers' servers directly, like any podcast app — the same fetch whether you are streaming or downloading an episode for offline listening. Downloaded files stay on your device; we keep no copy. Publishers see ordinary CDN logs — IP address, user agent, byte ranges — and our servers also fetch the RSS feed itself, identified as Rovyn. Rovyn attaches nothing else to those requests: no goals, no briefs, no feedback, no account identity.
What Rovyn doesn't do
- We don't sell your data.
- We don't use your listening to train models. If that ever changes, it will be opt-in, and this page will say so first.
- There is no recommendation engine or taste profile in Rovyn today: curation happens in your assistant, and the only preferences in the system are ones you or your assistant stated in words — all of them rows you can read. If we ever add inference of our own, the ability to inspect and delete it ships with it.
Deletion deletes
Deleting your account removes your rows in one transaction — editions, briefs, playback events, progress, receipts, saved episodes, feedback, follows, connections, device records, and the identity record with its email. Every assistant token dies with it. There is no soft-delete and no tombstone.
What survives is shared rather than personal: the public podcast catalog, the registry of assistant clients allowed to connect, and a daily tally of sign-in screen outcomes — a date, an event, a number, with no account or address attached. Database backups and ordinary server logs age out on their own schedules. The app then asks Firebase to delete the sign-in record on Google's side; that step runs on your phone after your Rovyn data is already gone and can fail on a bad connection, so if you signed in only through a browser, or you want it confirmed, write to support and we will finish it.
The protocol is specified apart from this service
Rovyn implements Cueback, a protocol specified apart from this service. The boundaries above — what crosses to an assistant and what does not — are properties of that design rather than private promises. The specification is published, Apache-2.0, at github.com/tinkon/cueback — so you can check this page against it yourself.
Changes and contact
If this policy changes, the date at the top changes, and material changes will be called out plainly on this page. Questions: support@polimati.com.