Effective date: 2026-06-16 Last updated: 2026-07-23
App: Rooky · Bundle ID: com.zezosmac.SPYBotV2App · Category: Finance
Rooky ("Rooky", "we", "us", "the app") is an iOS companion app published by RookyTech Inc. ("the Developer"), a company incorporated in Alberta, Canada. You can contact us at support@rookytech.com.
Rooky is a read-only monitoring app. It lets you watch the activity and performance of an automated, paper-trading (no real money) options bot that the Developer runs on the Developer's own private server. The app does not connect to your brokerage, does not handle real money, and cannot place trades. It is informational and monitoring only — see our Terms of Service and the in-app About screen for the full disclaimer.
We collect only the categories described below. We do not collect your location, contacts, photos, health data, browsing history, advertising identifier, or financial-account information.
Sign-in is handled by Google Firebase Authentication. Depending on the method you choose (Sign in with Apple, Sign in with Google, or email and password), we receive and retain:
We use these records to create and secure your account, identify you across sessions, keep your data isolated from other users, process approval, and let you recover access.
When you use Chat or its feedback controls, our backend may retain:
This is Other User Content under Apple's App Privacy categories. It is linked to your account, used only for App Functionality, and not used to track you across apps or websites.
To generate a Chat answer, Rooky sends the question, recent conversation context, and the grounded bot context needed to answer to OpenRouter and the routed model provider (currently OpenAI models). If the backend's optional model-observability service is configured, Langfuse Cloud may also process the question, returned answer or refusal, and model, token, cost, intent, and citation metadata. These processors are used to operate and troubleshoot Chat, not for Rooky's advertising or cross-app tracking.
To provide Chat reliably and enforce per-account service limits, our backend retains limited operational records such as daily Chat counts, model cost attributed to the account, account limits, interaction timestamps, access lifecycle events, and registration/update timestamps for devices and Live Activities.
This is Product Interaction under Apple's App Privacy categories. These records support feature operation, abuse prevention, quota enforcement, data export, and account deletion. They are not third-party analytics and are not used for advertising, profiling, or cross-app tracking.
When an eligible account registers for notifications or a Live Activity, the backend may retain an APNs device token or ActivityKit push token, a device/activity identifier, device name, platform, app version/build, notification preference, Live Activity type/metadata, and associated registration/update timestamps. The tokens are used only to route the requested Apple push delivery. Exported files redact push tokens.
Rooky keeps interface preferences, read/dismissed markers, appearance choices, refresh choices, the Face ID lock preference, and caches of public bot data on the device. Saving one of these settings locally does not by itself transmit it to our backend. The owner's separate control bearer, when present, is stored in the iOS Keychain and is not provided to ordinary viewer accounts.
Device-local interface preferences and cached public bot data are not server account records and are not included in the account-data export. General local preferences may remain on that installation after account deletion; removing the app removes its ordinary app-container data. Account deletion clears the authenticated account/session and clears the owner's control bearer from Rooky's Keychain.
We use the information above only to:
We do not use your information for advertising, cross-app tracking, data-broker sharing, or automated decision-making that produces legal effects.
Legal bases (where GDPR/UK GDPR applies): performance of a contract (providing the app you requested), our legitimate interests (securing and maintaining the service), your consent (push notifications), and compliance with legal obligations.
We do not sell personal data. We use the following providers only as needed to operate Rooky:
| Provider | What it handles |
|---|---|
| Google Firebase (Authentication) | Sign-in, account identity, authentication tokens, and email-password reset |
| Google Sign-In | Optional Sign in with Google flow |
| Apple | Sign in with Apple, Apple Push Notification service, and ActivityKit push delivery |
| Hostinger | Hosts the Developer's backend and its user-scoped records |
| Cloudflare | Routes encrypted traffic to the backend and may process connection metadata needed for delivery and security |
| OpenRouter and routed model providers (currently OpenAI models) | Process Chat prompts, recent conversation and grounded bot context, model responses, and token/cost metadata needed to answer Chat questions |
| Langfuse Cloud (when configured) | Processes limited backend model-operation traces, which may include the Chat question, answer or refusal, model/token/cost metadata, routed intent, and citation identifiers |
These providers process data under their own terms and security controls. We may also disclose information if required by law, to enforce our Terms, or to protect users or the service. We do not share data with advertisers, data brokers, or services that use it for their own advertising or cross-app tracking.
Account-linked backend records are retained while your account exists. When you confirm in-app account deletion, Rooky first requests deletion of the authenticated user's backend records and then deletes the Firebase Authentication account. Sign in with Apple users complete a fresh Apple reauthorization so Rooky can revoke the associated Apple authorization as part of deletion.
The backend deletion removes the user's Chat turns, interaction and feedback logs, usage/quota and profile rows, access-request records, device and Live Activity registrations, and other user-scoped records. A consumed access-code audit row may remain with a random, non-reversible tombstone so the credential cannot be reused; the user's ID and operator note are removed from that row. Public bot statistics are not personal to the user and are not removed.
If a provider or network step fails, the app reports that deletion did not fully complete and the user can retry. We may retain limited records only where required by law or necessary to resolve a dispute, and only for the required period.
We use encrypted transport (HTTPS/TLS), verified authentication, and user-scoped storage so an account cannot request another user's retained records. Export responses are scoped to the authenticated user and redact push tokens and approval credentials. No system is completely secure, but we limit what we collect and protect access to it.
Regardless of where you live, Rooky provides these controls:
Depending on your location, you may also have rights of access, correction, deletion, restriction, portability, objection, or withdrawal of consent. To exercise a right not available in-app, contact support@rookytech.com. We do not discriminate against users for exercising these rights.
Rooky is not directed to children and is intended for users 17 years of age or older. We do not knowingly collect personal data from children under 13 (or the applicable minimum age in their jurisdiction). Contact us if you believe a child supplied personal data.
We are based in Canada. Our providers may process and store data in other countries, including the United States. Where required, those transfers are protected by applicable safeguards.
We may update this policy as the app changes. We will revise the "Last updated" date and provide a more prominent notice for material changes where appropriate. If a future release collects a new category of data, we will update this policy and the App Store privacy disclosures before that practice is introduced.
Questions or requests about this policy or your data:
RookyTech Inc. Email: support@rookytech.com Alberta, Canada