This policy describes how Rovelix handles information when you use our app website service at rovelix.app or visit a website hosted through Rovelix.
Information you provide
We store account details such as your name and email address, a password hash (for password sign-in), Google account identifiers when you connect Google, workspace membership, and the content and settings you add to app websites. We also store support messages you submit and billing references needed to manage subscriptions. Payment details are collected by our payment processor; Rovelix does not store complete card numbers.
App information from Google Play
When you import an app, we retrieve its public store information through GPAPI. This can include descriptions, screenshots, ratings, release information, and developer contact details. You control whether an imported website is published and can edit or remove content through the portal.
How we use information
We use information to authenticate accounts, publish and synchronize websites, process subscriptions, provide support, maintain the service, and prevent abuse. We use service providers for hosting, app-listing data, and payments. When enabled, Brevo delivers verification and account recovery emails, and Google verifies Google sign-ins. Public app images may be copied to Cloudflare R2 and delivered through our CDN. We store expiring verification challenges and encrypted pending email jobs to provide these features securely.
Sessions, analytics, and logs
The portal uses a session cookie to keep you signed in. API credentials are stored as hashes. Hosted websites can record aggregate page visits and Google Play button clicks for the website owner's analytics. Operational logs may contain request details needed for troubleshooting and security. We do not use these features to serve advertising.
Published content and support messages
Content on a published app website is publicly accessible. Messages sent through an app website's support form are available to its authorized workspace members. The app developer is responsible for the privacy practices of their Android app; consult the developer's own policy for information about the app itself.
Retention and your choices
We retain information needed to provide the service, resolve disputes, meet applicable recordkeeping obligations, and protect the service. Deleted information may remain in backups until those backups expire. You can edit app content and revoke API keys in the portal. Contact us to request access, correction, export, or deletion of account information, or to exercise rights available under the law that applies to you.
Security and transfers
We use access controls, encrypted web connections, hashed credentials, and database backups to protect the service. No system can guarantee absolute security. Providers and infrastructure may process information in countries different from your own.
Contact and changes
For privacy questions or requests, email support@rovelix.app. We may update this policy as the service changes and will update the date on this page.
