Skip to content
Roster Roster
Features Support Privacy Terms
Back to home

Privacy Policy

Last updated: 2026-07-09

This Policy provides notice about our data practices. Where consent is legally required or a feature is optional, we ask separately in the App. Safety moderation of content submitted to community and communication features is a required part of providing those features and cannot be disabled while using them.

This Privacy Policy explains how Silvauren Software LLC, a Wyoming limited liability company ("Company", "we", "our", "us"), collects, uses, and shares information when you use the Roster mobile application and related websites (collectively, "Roster" or "the App"). Roster is offered for adults in the United States.


1. INFORMATION WE COLLECT

1.1 Information You Provide Voluntarily

  • Account Information: Name, email address, phone number, date of birth
  • Profile Data: Photos, ratings, reviews, notes, and other content you upload
  • Partner Information: Data about individuals you add to your roster, including names, phone numbers, email addresses, and social media handles. This information is submitted by you and processed as user-generated content for relationship safety purposes. We process this data under legitimate interest. Partner information is used solely for overlap detection with other users' submissions and is never independently verified or treated as factual by the Company. Non-users whose information may have been submitted may contact help@myrosterapp.com to request review and removal.
  • Communication Data: Messages, friend requests, invitations, and other communications
  • Safety Feature Data: Scheduled-date details, check-in status, trusted-circle selections, safety updates, emergency messages, and optional location data when you choose to use date-safety features
  • Contact Information (optional — "Find Friends"): If you choose to use the Find Friends feature, we access your device's address book with your permission. Phone numbers and email addresses from your contacts are converted into one-way hashes on your device and only those hashes are sent to us, solely to match you with contacts who already use Roster. We do not store your contacts' raw phone numbers or email addresses, and we do not contact, add, or share information about people in your address book. This feature is entirely optional and can be skipped.
  • Payment Information: Transaction records (processed by third-party payment processors)
  • Preferences: Settings, customization choices, and notification preferences

1.2 Information Collected Automatically

  • Device Information: Device type, model, operating system, unique device identifiers
  • Usage Data: Features accessed, time spent, interaction patterns, and app performance
  • Location Data: General location (city/region) based on IP address; precise location only with explicit permission
  • Log Data: IP address, browser type, access times, pages viewed, crash reports
  • Analytics Data: Aggregated usage statistics for service improvement

1.3 Cross-Roster Detection Data

When you use our cross-roster detection feature, we process:

  • Cryptographically blinded values derived from identifiers (phone numbers, emails, social handles, payment handles)
  • Anonymized match results that do not reveal other users' identities

We want to be precise about what this protection does and does not do. The blinding happens on your device, so our servers never receive the raw identifier and cannot read it out of the value we store. Those values are not reversible by working backwards from the stored value alone. They are, however, deterministic within each monthly period and are derived using a secret key that we hold. That means someone with access to that key could test whether an identifier they had already guessed is present — it does not let them recover an identifier they do not already have. We restrict access to that key, rotate the derivation every month, and delete the published values on a rolling basis.

1.4 Safety Moderation and Third-Party AI

When you submit messages, posts, comments, reports, appeals, or images, we may send that content and limited recent context to OpenAI, a third-party artificial-intelligence service provider, to classify potential illegal or harmful content, support appeals, and assist our safety team. Automated results may block content, create a moderation record, apply an account restriction, or route an item for human review. We minimize direct identifiers in these requests where practicable.

Safety moderation is required for community, messaging, reporting, and media-upload features. If you do not want content processed for safety moderation, do not submit content through those features. OpenAI states that API business data is not used to train its models by default; OpenAI may process or retain API data for service operation, security, and abuse monitoring under its then-current business/API terms. See OpenAI's enterprise privacy commitments.

2. HOW WE USE YOUR INFORMATION

We use your information to:

  • Provide and maintain the App
  • Process transactions and send related information
  • Send administrative messages, updates, and security alerts
  • Respond to your comments, questions, and requests
  • Analyze usage patterns to improve the App
  • Detect, prevent, and address fraud and security issues
  • Moderate user content, investigate reports and appeals, enforce our rules, and meet legal reporting obligations
  • Deliver optional date-safety check-ins, trusted-circle updates, location sharing, and emergency messages that you initiate
  • Comply with legal obligations

3. HOW WE SHARE YOUR INFORMATION

We disclose information to service providers only for the purposes described in this Policy, including:

  • Google Firebase and Google Cloud: authentication, databases, storage, hosting, server functions, security, and crash/performance services
  • OpenAI: automated safety moderation, report triage, image analysis, and appeal support as described in Section 1.4
  • Apple, Google Play, and RevenueCat: purchases, subscriptions, receipts, entitlements, fraud prevention, and customer support
  • Expo: push-notification delivery and related mobile infrastructure
  • Google Places: place searches you initiate for date-planning features
  • Legal Requirements: When required by law or to protect our rights
  • Business Transfers: In connection with mergers, acquisitions, or asset sales
  • With Your Consent: When you give us permission

We do not sell personal information. We do not share personal information for cross-context behavioral advertising. Optional analytics, marketing, data-sharing, crash-reporting, contacts, location, camera, and photo access are controlled through App or device settings where applicable.

4. DATA RETENTION

We retain information only as long as reasonably needed to provide the App, protect users, prevent fraud, resolve disputes, enforce agreements, and meet legal obligations. Retention varies by category:

  • Account and feature data is generally retained while your account is active
  • User Content is retained until you or an authorized moderator deletes it, subject to safety and legal holds
  • Moderation, security, audit, transaction, and consent records may be retained longer where reasonably necessary for safety, fraud prevention, dispute resolution, accounting, or law
  • Backups and provider systems may take additional time to cycle after deletion

You can request deletion in the App or through help@myrosterapp.com. We ordinarily complete verified account and non-user removal requests within 30 days, except where law or a documented safety, fraud, dispute, or record-preservation need requires limited retention. Deleting an account does not automatically cancel an Apple or Google store subscription.

5. YOUR RIGHTS

Depending on your location, you may have the right to:

  • Access: Request a copy of your personal data
  • Correction: Update or correct inaccurate information
  • Deletion: Request deletion of your data
  • Portability: Receive your data in a portable format
  • Opt-Out: Opt out of certain data processing activities
  • Withdraw Consent: Revoke consent for data processing

To exercise these rights, contact us at: help@myrosterapp.com

We will not discriminate against you for exercising a privacy right. We may need to verify your identity or authority before completing a request. A non-user may also request review or suppression of identifiers they believe a user submitted.

6. DATA SECURITY

We implement appropriate technical and organizational measures to protect your data, including:

  • Encryption in transit and at rest
  • Access controls and authentication
  • Regular security audits
  • Secure data storage practices
  • Anonymous counts of encryption-key recovery attempts (to detect and prevent data loss before it affects you)

6.1 How Different Data Is Protected

Not all data is protected the same way, and we want to be transparent about the difference:

  • Your roster is stored in two tiers, and we are specific about which is which. Basic display details for each person you add — name, photo, age, gender, job title, relationship type, star sign, and the date you met — are stored in readable form on our servers. That is deliberate: it is what lets shared Tea Rooms, notifications, and safety moderation work, and it is what a friend sees if you choose to share that person with them. Everything else is encrypted on your device with a key that stays on your device — phone numbers, emails, social handles, payment handles, notes, ratings, intimacy and gift logs, expenses, birthdays, locations, and attached images. For that encrypted content we store only unreadable ciphertext and cannot read, decrypt, or recover it, including if you lose the device holding the key. Cross-roster matching is performed on cryptographically blinded values, so our servers never receive the raw identifiers.
  • The one exception is Cloud Recovery, and it is off unless you switch it on. Because device-held keys mean a lost device normally means lost private content, you can opt in to Cloud Recovery. If you do, we store a copy of your vault key that is itself encrypted by a key held inside Google Cloud KMS. While Cloud Recovery is on, we are technically able to unlock your private content — that is what makes recovery possible, and it is why the feature is off by default and asks you to confirm. Restoring never happens instantly: it waits 48 hours and alerts every device signed in to your account, so it cannot be done quietly by someone who has your password. You can switch Cloud Recovery off at any time, which deletes our copy of your key, and we delete it automatically when you delete your account.
  • Messages, feed posts, and comments are encrypted in transit and at rest, but are NOT end-to-end encrypted. This content is accessible to our automated safety and moderation systems and, where necessary, trained reviewers. We do this deliberately so we can detect and act on illegal or harmful content — including child sexual abuse material (CSAM), non-consensual intimate imagery, credible threats, and harassment — and to comply with our legal reporting obligations. Do not treat chat as a private, end-to-end-encrypted channel.

However, no method of transmission over the Internet is 100% secure.

7. CHILDREN'S PRIVACY

The App is not intended for users under 18 years of age. We do not knowingly collect personal information from children under 18.

8. INTERNATIONAL DATA TRANSFERS

The App is operated from the United States, and our service providers may process information in the United States or other locations where they operate. Where applicable law requires a transfer mechanism or additional safeguard, we will use one appropriate to the processing. The App is not currently offered to residents outside the United States.

9. THIRD-PARTY SERVICES

Third-party providers process information under their own terms and privacy notices as well as our contractual instructions where applicable. We select providers for defined operational purposes, but we do not control every aspect of their independent systems. The App may also contain links to third-party sites; review their notices before providing information directly to them.

10. CHANGES TO THIS POLICY

We may update this Privacy Policy from time to time. We will notify you of material changes through the App or by email and, where required, request renewed consent or acceptance. The version shown above identifies the Policy associated with your account acceptance.

11. CONTACT US

Data controller/operator: Silvauren Software LLC

Email: help@myrosterapp.com

App website: https://www.myrosterapp.com

Formal notices may be mailed to:

Silvauren Software LLC

c/o Northwest Registered Agent Service, Inc.

30 N Gould St Ste N

Sheridan, Wyoming 82801

United States

Roster Roster
Home Support Privacy Policy Terms of Service Delete account

© 2026 Silvauren Software LLC