Rooky — Privacy Policy

Effective date: 2026-06-16 Last updated: 2026-07-23

App: Rooky · Bundle ID: com.zezosmac.SPYBotV2App · Category: Finance


1. Who we are

Rooky ("Rooky", "we", "us", "the app") is an iOS companion app published by RookyTech Inc. ("the Developer"), a company incorporated in Alberta, Canada. You can contact us at support@rookytech.com.

Rooky is a read-only monitoring app. It lets you watch the activity and performance of an automated, paper-trading (no real money) options bot that the Developer runs on the Developer's own private server. The app does not connect to your brokerage, does not handle real money, and cannot place trades. It is informational and monitoring only — see our Terms of Service and the in-app About screen for the full disclaimer.


2. The short version


3. Information we collect

We collect only the categories described below. We do not collect your location, contacts, photos, health data, browsing history, advertising identifier, or financial-account information.

a. Account, identity, and access records

Sign-in is handled by Google Firebase Authentication. Depending on the method you choose (Sign in with Apple, Sign in with Google, or email and password), we receive and retain:

We use these records to create and secure your account, identify you across sessions, keep your data isolated from other users, process approval, and let you recover access.

b. User content: Chat and feedback

When you use Chat or its feedback controls, our backend may retain:

This is Other User Content under Apple's App Privacy categories. It is linked to your account, used only for App Functionality, and not used to track you across apps or websites.

To generate a Chat answer, Rooky sends the question, recent conversation context, and the grounded bot context needed to answer to OpenRouter and the routed model provider (currently OpenAI models). If the backend's optional model-observability service is configured, Langfuse Cloud may also process the question, returned answer or refusal, and model, token, cost, intent, and citation metadata. These processors are used to operate and troubleshoot Chat, not for Rooky's advertising or cross-app tracking.

c. Product-interaction and service-usage records

To provide Chat reliably and enforce per-account service limits, our backend retains limited operational records such as daily Chat counts, model cost attributed to the account, account limits, interaction timestamps, access lifecycle events, and registration/update timestamps for devices and Live Activities.

This is Product Interaction under Apple's App Privacy categories. These records support feature operation, abuse prevention, quota enforcement, data export, and account deletion. They are not third-party analytics and are not used for advertising, profiling, or cross-app tracking.

d. Notification and Live Activity registrations

When an eligible account registers for notifications or a Live Activity, the backend may retain an APNs device token or ActivityKit push token, a device/activity identifier, device name, platform, app version/build, notification preference, Live Activity type/metadata, and associated registration/update timestamps. The tokens are used only to route the requested Apple push delivery. Exported files redact push tokens.

e. Information stored only on the device

Rooky keeps interface preferences, read/dismissed markers, appearance choices, refresh choices, the Face ID lock preference, and caches of public bot data on the device. Saving one of these settings locally does not by itself transmit it to our backend. The owner's separate control bearer, when present, is stored in the iOS Keychain and is not provided to ordinary viewer accounts.

Device-local interface preferences and cached public bot data are not server account records and are not included in the account-data export. General local preferences may remain on that installation after account deletion; removing the app removes its ordinary app-container data. Account deletion clears the authenticated account/session and clears the owner's control bearer from Rooky's Keychain.


4. How we use your information

We use the information above only to:

We do not use your information for advertising, cross-app tracking, data-broker sharing, or automated decision-making that produces legal effects.

Legal bases (where GDPR/UK GDPR applies): performance of a contract (providing the app you requested), our legitimate interests (securing and maintaining the service), your consent (push notifications), and compliance with legal obligations.


5. How your information is shared

We do not sell personal data. We use the following providers only as needed to operate Rooky:

Provider What it handles
Google Firebase (Authentication) Sign-in, account identity, authentication tokens, and email-password reset
Google Sign-In Optional Sign in with Google flow
Apple Sign in with Apple, Apple Push Notification service, and ActivityKit push delivery
Hostinger Hosts the Developer's backend and its user-scoped records
Cloudflare Routes encrypted traffic to the backend and may process connection metadata needed for delivery and security
OpenRouter and routed model providers (currently OpenAI models) Process Chat prompts, recent conversation and grounded bot context, model responses, and token/cost metadata needed to answer Chat questions
Langfuse Cloud (when configured) Processes limited backend model-operation traces, which may include the Chat question, answer or refusal, model/token/cost metadata, routed intent, and citation identifiers

These providers process data under their own terms and security controls. We may also disclose information if required by law, to enforce our Terms, or to protect users or the service. We do not share data with advertisers, data brokers, or services that use it for their own advertising or cross-app tracking.


6. Retention and deletion

Account-linked backend records are retained while your account exists. When you confirm in-app account deletion, Rooky first requests deletion of the authenticated user's backend records and then deletes the Firebase Authentication account. Sign in with Apple users complete a fresh Apple reauthorization so Rooky can revoke the associated Apple authorization as part of deletion.

The backend deletion removes the user's Chat turns, interaction and feedback logs, usage/quota and profile rows, access-request records, device and Live Activity registrations, and other user-scoped records. A consumed access-code audit row may remain with a random, non-reversible tombstone so the credential cannot be reused; the user's ID and operator note are removed from that row. Public bot statistics are not personal to the user and are not removed.

If a provider or network step fails, the app reports that deletion did not fully complete and the user can retry. We may retain limited records only where required by law or necessary to resolve a dispute, and only for the required period.


7. Data security

We use encrypted transport (HTTPS/TLS), verified authentication, and user-scoped storage so an account cannot request another user's retained records. Export responses are scoped to the authenticated user and redact push tokens and approval credentials. No system is completely secure, but we limit what we collect and protect access to it.


8. Your rights and in-app choices

Regardless of where you live, Rooky provides these controls:

Depending on your location, you may also have rights of access, correction, deletion, restriction, portability, objection, or withdrawal of consent. To exercise a right not available in-app, contact support@rookytech.com. We do not discriminate against users for exercising these rights.


9. What we do not do


10. Children

Rooky is not directed to children and is intended for users 17 years of age or older. We do not knowingly collect personal data from children under 13 (or the applicable minimum age in their jurisdiction). Contact us if you believe a child supplied personal data.


11. International transfers

We are based in Canada. Our providers may process and store data in other countries, including the United States. Where required, those transfers are protected by applicable safeguards.


12. Changes to this policy

We may update this policy as the app changes. We will revise the "Last updated" date and provide a more prominent notice for material changes where appropriate. If a future release collects a new category of data, we will update this policy and the App Store privacy disclosures before that practice is introduced.


13. Contact us

Questions or requests about this policy or your data:

RookyTech Inc. Email: support@rookytech.com Alberta, Canada