The basics
Roona (“we”, “us”) is a skincare-journal app for iOS and Android, plus the website at roona.app. It's made and run by one independent developer—not a company—and we're the ones responsible for your data. Questions any time: support@roona.app.
Local first
Your routines, check-ins, photos, and products live on your device as the working copy of your journal, and it works without a connection.
Signing in backs up your structured journal—routines, check-ins, products, notes, and profile—to Roona's cloud on every account, so it can be restored across devices. Progress and scan photos are backed up only with Roona Plus.
Your profile picture is the one image that syncs on every account, free or Plus. It's kept in your own private folder in our cloud storage so your profile still looks like you on a new device.
Routine reminders are scheduled by the app on your device. Roona has no push server: we never send you a notification from our servers, and we don't collect a push token.
If Plus ends, your journal and its cloud sync keep working; photo backup pauses, and existing photo backups are retained until you delete them or your account.
What we collect
- Account — your email and name (or what Google/Apple share when you sign in), plus optional profile details like age or sex if you choose to add them. Passwords are handled by our sign-in provider (Supabase); we never see them in plain text.
- Your journal — routines, products, check-offs, check-ins, notes, streaks, and your profile. This lives on your device and is backed up to our cloud when you're signed in, on every account.
- Photos — progress photos and scan photos. They live on your device; they're backed up to our cloud only while Roona Plus is active. Your profile picture is the exception: it's stored in your private cloud folder on every account. Photos you take for the shelf scanner or the ingredient label reader are sent for recognition and never stored on our servers—see Other AI features.
- AI readings and ingredient explanations — the text of a reading or an ingredient breakdown you ask for is kept with your account so you can look at it again later, along with a small job record (time and status). Not the analysis copy of the photo—see below.
- Subscriptions — if you get Roona Plus, we see your subscription status, never your card number (the app store handles payment).
- Usage — we use PostHog to see how the app is used: screens you open, taps, app version and device type, and automatic crash and error reports. While you're signed in, these events are linked to your account and email, so this isn't anonymous. We use it to fix bugs and decide what to build—never to sell you anything or build an advertising profile. Email support@roona.app if you'd rather be left out and we'll delete your analytics profile.
- Early-access email — if you ask to be notified at launch, we store that email address, plus the IP address and browser string of the request to keep out spam sign-ups, so we can send you one message when Roona is out. We don't add you to a newsletter and we don't share it; email support@roona.app any time to be removed.
- Web deletion requests — if you use the account deletion page, we store the email address you enter, the reason if you give one, and the IP address and browser string of the request, so we can verify it's really you and stop abuse.
- Website visits — we count page views on roona.app ourselves, without cookies and without tracking you across sites. We don't store your IP address or browser string: they're combined with a secret that changes every day and turned into a short code that only tells us "same visitor, same day", and that code is deleted after 120 days. We do keep a count per country — your IP address is matched against a list of address ranges on our own server, so it's never sent anywhere, and only the country is kept. Nothing here is sent to an advertising network.
AI readings
AI features are opt-in per request. Before a scan you choose exactly which context (check-ins, routines, shelf, earlier readings) is included, with nothing preselected against you.
Roona's analysis service receives the scan photo and the consented context in request memory and does not write that analysis copy to Roona's database or object storage. The service forwards them to OpenAI to produce the reading. OpenAI does not use API data to train its models by default, but may retain API inputs and outputs for abuse monitoring for up to 30 days, unless shorter or zero-retention controls apply, and may retain them longer when legally required.
Roona never uses scan photos for advertising or marketing. Scan photos you keep in your journal are backed up to the cloud only with Roona Plus and stay in that photo backup until you delete them or your account.
AI readings are informational and cosmetic only—not medical advice or a diagnosis.
Other AI features
Roona Plus also includes the AI routine builder, routine improvements, the shelf advisor, the shelf scanner, the ingredient label reader, and weekly and monthly reports. Each one sends only the journal context that feature needs—your routines, check-ins, shelf, products, and earlier readings—to OpenAI to produce the result, on the same terms described above. None of them send your progress or scan photos.
The shelf scanner and the ingredient label reader send the photos you take of your products or their labels. Those images are held in our service's memory only for as long as recognition takes: they are never written to our database or storage, never added to your journal, and never used for advertising or marketing. At OpenAI they follow the same handling as a scan photo, including the abuse-monitoring retention described above.
Scanning a product barcode looks it up in Open Beauty Facts, a public product database. The lookup is made by our server, so Open Beauty Facts receives the barcode and nothing else—not your IP address, your account, or anything from your journal.
Face data
The camera preview is processed on your device with Google ML Kit to check the number of faces, face position, distance, and head angle; Roona also samples frame brightness for capture guidance. These temporary measurements are not saved or sent off the device, and Roona does not create a face template, faceprint, embedding, identity match, or biometric identifier.
When you confirm a capture, Roona stores the resulting JPEG scan photo in the app's private storage on your device until you delete the photo, delete your account, or remove the app. The photo is used only to produce your requested skin reading, show your private journal and comparisons, and, if Roona Plus photo backup is active, restore your photos across your devices. The separate copy sent for AI analysis follows the retention described in AI readings above.
Face-data processors and sharing
Roona does not sell face data, share it with data brokers, or share it for advertising.
- Google ML Kit — processes camera frames entirely on your device; Google does not receive the frames or the face-detection output.
- Supabase — hosts Roona's analysis service, and stores photo backups uploaded while Roona Plus is active in the private
journalstorage bucket under that user's account; after Plus ends, existing backups remain until you delete the photo or your account. - OpenAI — processes the scan photo and consented context to generate the requested skin reading, and may retain API inputs and outputs for up to 30 days for abuse monitoring as described above.
- PostHog, RevenueCat, Apple, and Google Play — do not receive scan photos or on-device face-detection measurements from Roona.
How we keep it, and keep it safe
We keep your data while your account is active. It's protected with encryption in transit, per-account access rules so no one else can read your journal, hashed passwords, and secure on-device storage for your login. Website visitor codes are deleted after 120 days. No system is ever 100% secure, but we take it seriously.
Deleting your data
Delete any scan, photo, or product from the app at any time; the deletion also syncs to your cloud journal, on every account.
Deleting a photo removes its on-device files and queues removal of any Roona Plus cloud-backup copy. Removing your profile picture clears the synced copy too. Deleting the app removes the on-device copy; your cloud journal backup, and with Plus any backed-up photos, may still exist until you remove the items in the app or delete your account.
Deleting your account
You can delete your account at any time from Profile → Settings → Delete account in the app, via our account deletion page (no login needed), or by emailing support@roona.app.
When you request deletion, your account is deactivated immediately and permanently deleted after 30 days. Signing in again within those 30 days lets you cancel the deletion and restore your account.
Deletion removes your sign-in identity, your reading and ingredient-analysis records, and your cloud journal backup (including your profile picture and any backed-up photos) from our servers, and clears your on-device journal—routines, check-ins, and photos—from this device once deletion is final. You may also choose to erase photos from your device immediately when you request deletion.
We keep an anonymized record of the reason for deletion, no longer linked to you, to understand why people leave. Deleting your account does not cancel any App Store or Google Play subscription; manage that in your store account.
Subscriptions
Purchases are processed by Apple or Google and by RevenueCat, which receives an anonymous identifier and purchase receipts, never your journal or photos through that path.
Your rights
You can view and edit most of your data right in the app, and request a copy by emailing support@roona.app. If you're in the EU/UK or California, you have some extra rights—like access, deletion, objecting to certain processing, and no “sale” of your data (which we don't do anyway). Just email us and we'll help.
Kids
Roona isn't for children. You need to be at least 13 (or older where your country requires). We don't knowingly collect data from anyone under that age—if you think we have, email support@roona.app and we'll delete it.
Changes & contact
If we make meaningful changes, we'll update the date at the top and, where it matters, let you know in the app. Questions or requests are always welcome at support@roona.app.