Privacy Policy
Version 3.1 · Effective August 25, 2026 · Last updated August 25, 2026
1. Who we are, and how to reach us
Rova (“Rova,” “we,” “us,” “our”) is operated by KOSHERHQ LLC, a limited liability company organised under the laws of the State of New York, United States. KOSHERHQ LLC is the controller of the personal information described in this Policy — meaning we decide why and how it is processed.
Everything reaches us at support@rova-app.com. To make sure your message is handled properly, please use the subject line that matches it:
- “Privacy Request” — access, correction, deletion, portability, objection, or an appeal.
- “Under-13 Account” — a parent or guardian reporting a child’s account (§15).
- “Safety Concern” — content or behaviour that needs a person to look now.
- “Security” — a vulnerability you have found in Rova (§10).
We answer privacy requests within 30 days, and tell you before that deadline if we need longer and why. A real person reads every one of these.
2. What this Policy covers
This Policy covers the Rova application at rova-app.com, any Rova mobile application, and every feature inside them (together, the “Service”). It does not cover a third party’s own handling of your information — for example, what Google or Apple do with your account when you choose to sign in through them, which is governed by their privacy policies, not this one.
This Policy is part of, and incorporated into, the Rova Terms of Service. Where this Policy and the Terms describe the same thing differently, this Policy governs on questions of personal information.
3. A note on how Rova is built
Three design decisions shape everything below, and you should know them up front, because they explain why this Policy is shorter than the ones you are used to:
- There is no advertising business here. Rova has no advertisers, no ad network, no ad identifier, no data broker, and no “partners” who receive your information for their own purposes. We therefore have no reason to build a profile of you, and we have not built one.
- Measurement is first-party and minimal. Rova runs no Google Analytics, no Meta pixel, no Segment, no Mixpanel, no Amplitude, and no advertising or analytics SDK of any kind, and loads no script from anyone else’s server. There is exactly one piece of third-party code in the app — Sentry, which reports crashes so we can find and fix them. It is served from our own servers rather than Sentry’s, it stays silent unless something actually breaks, and it is never told who you are; precisely what it receives is listed in §6(b). The handful of counts we keep sit in our own database, described exhaustively in §4(e).
- Your content is not training data. We do not use your posts, photos, video, captions, comments, or messages to train artificial-intelligence or machine-learning models, and we do not give them to anyone else to train theirs. §14 says what would have to happen before that could ever change.
4. Information we collect
(a) Information you give us when you create an account. Your email address; a password, if you sign up with one; your display name; your username (handle); and your date of birth. Passwords are hashed by our authentication provider and are never visible to us in readable form.
Why we ask for your date of birth. Rova is for people aged 13 and over, and we ask for a date rather than a tick-box so that the answer is a real one we can act on. We use it only to apply that age limit and to meet our obligations to younger users — it is not shown on your profile, not visible to other people, and not used for advertising, recommendations, birthday prompts, or anything else. If you sign in with Google or Apple, neither provider sends us a date of birth and we do not currently ask for one afterwards, so those accounts have none on record.
Your account also carries an account type. Today every account is the same ordinary type and there is nothing to choose — the creator and business types exist in our database but are not offered in the app. If we ever open them up, we will say so here first.
(b) Information you choose to add to your profile. Your profile photo, bio, and neighborhood. All of these are optional, all of them are visible to other people, and all of them can be changed or emptied at any time in Settings → Edit profile. “Neighborhood” is a free-text label you type — Rova never asks your device for your location, and we say more about that in §4(g).
(c) Information from Google or Apple, if you sign in that way. If you choose Sign in with Google or Sign in with Apple instead of a password, the provider tells us a limited set of fields so we can create your account:
- Google — your email address, whether that address is verified, your name, and your profile picture URL. Nothing else. Rova requests only the basic
emailandprofilescopes; it does not request, receive, or have any access to your Gmail, Drive, Contacts, Calendar, Photos, or any other Google service. - Apple — your email address, and your name only on the very first sign-in. If you use Apple’s Hide My Email, what we receive is a private relay address, not your real one; Rova works normally with a relay address, and we never attempt to unmask it.
We use these fields to create and populate your Rova profile and to sign you in. We do not import your contacts, we do not post anywhere on your behalf, and we hold no ongoing access to your Google or Apple account beyond the sign-in itself. See §7 for the specific commitments we make to Google about this data.
(d) The things you create on Rova. Posts and their captions; photos; reels and other video; stories; comments; likes and saves; who you follow and who follows you; direct messages; feature suggestions you submit to the Ideas board and your votes on them; and reports you file about content or people. We also store the choices you make about your own privacy: whether your account is private, who you have blocked, your Hidden words list, who may comment on your posts, who may message you, and any pending follow requests. Those are kept on our servers and enforced there, rather than only in your copy of the app — a privacy setting that only the app respects is not really a privacy setting. Your notification preferences are a display choice and stay on your device.
Who viewed your story. When you open someone’s story, Rova records that you saw it, so the author can see a “seen by” list. That list is visible to the story’s author only. A story expires 24 hours after it is posted, and is then deleted — the story, its image, and its “seen by” list are removed automatically. A scheduled job does this every hour, so removal happens shortly after the 24 hours are up rather than at the exact minute. You can delete a story yourself at any time before that. See §9.
(e) Measurement. To know whether anyone is actually using Rova, we write a small event to our own database at thirteen moments: the app was opened; a screen was viewed; someone tapped through to sign up; an account was created; someone signed in; a post was made; something was shared; a visitor with no account was shown the invitation to join; and, if they accepted it, whether they went on to sign up or to sign in. Three more were added in September 2026, to tell us where the app is losing people: how many seconds Rova was actually on your screen during a visit; how many posts went past before you stopped scrolling; and which of the four boxes on the sign-up form you reached. Each row holds exactly this and nothing more:
- a random visitor identifier that Rova generated and stored in your browser — it is not derived from your device, contains nothing about you, and means nothing outside this one table;
- a random session identifier for that one opening of the app;
- the screen that was viewed;
- the source the visit came from — a tagged share link, or the website that referred you;
- whether the app was installed to a home screen;
- your user ID, but only while you are signed in;
- a single whole number, on the three events that need one — a count of seconds, or a count of posts. It is never anything but a number;
- the time.
That list is exhaustive. This table holds no IP address, no user-agent string, no location, no device fingerprint, and nothing you do outside Rova, and none of it leaves our database for any analytics or advertising company. If your browser sends a Do Not Track or Global Privacy Control signal, Rova records no measurement events at all — we treat both as a binding instruction rather than a suggestion. Rows are deleted automatically 180 days after they are written, and if you delete your account before then, your user ID is stripped from them immediately and what remains is an anonymous count.
Stopping someone from faking those counts. Because the measurement events above can be written by any visitor — they have to be, since we count people before they have an account — somebody could otherwise sit and invent thousands of them and make our own numbers lie to us. To prevent that we keep a small counter, separate from the table above, that limits how many events can be written from one internet connection in one hour. That counter does not store your IP address. What it stores is a one-way scrambled value made from your IP address, a secret key of ours, and the current hour — a value that cannot be turned back into an address, that is different every hour so it cannot be used to follow anyone over time, and that is deleted after three hours. Each row is that value and a number. It is not linked to your visitor identifier, to your account, or to anything you did, and it is never used for any purpose other than refusing an excessive number of writes. We also keep a daily tally of how many writes were refused and why, which is a count and nothing else.
How many people saw a post. So that a business or creator can see how their own posts are doing, Rova keeps a running count against each post: how many times it was shown on a screen, how many times it was opened, and how many times a link on it was tapped. A post is counted as shown only when at least half of it was on screen for a full second, so scrolling quickly past something does not count as seeing it.
These counts are attached to the post, not to you. Each row is a post, a date, and three numbers. There is no visitor identifier, no session identifier and no user ID anywhere in it, so there is no record — here or anywhere else in Rova — of which posts any particular person looked at. The work of not counting the same post twice in one visit is done inside your own browser, using a list that never leaves your device and is erased when you close the tab. Only the author of a post, and Rova's own administrators, can see these counts; other members cannot. They are deleted after 400 days. If your browser sends a Do Not Track or Global Privacy Control signal, nothing here is recorded either.
(f) Technical records created by the infrastructure that carries your traffic. This one deserves more care than most policies give it, because “we don’t log IP addresses” is a claim that is easy to make loosely and we would rather be exact.
Getting a request from your device to our servers and back necessarily involves your IP address, and the companies that carry that traffic on our behalf keep operational logs of it. Concretely: our hosting and content-delivery providers process your IP address to route your request, deliver your photos and video, and absorb attacks; and our database and authentication provider keeps request logs that record your IP address, the country it resolves to, and your browser’s user-agent string, and records the IP address and user-agent of the session created when you sign in.
So, precisely: Rova’s own application database contains no IP address, no user-agent string, and no location — §4(e) is the only place we write anything about a visit, and it holds none of those fields. The single qualification is the anti-abuse counter described at the end of §4(e), which holds a one-way scrambled value derived from an IP address, rotated hourly and deleted after three hours; it is not an IP address, it cannot be turned back into one, and it is attached to nothing else. What exists are the operational logs our providers keep in order to run and defend the Service. They age out on a short cycle set by those providers — days, not months. We do not use them to build a profile of you, to target anything at you, or to work out where you live; we do not export them; we do not join them to your account activity; and we look at them only when we are diagnosing a fault or investigating abuse or an attack.
(g) Information we deliberately do not collect. We think the absences matter as much as the list, so we state them plainly. Rova does not collect or ask for: your precise or approximate geolocation (location access is switched off at the server level by our permissions policy, so the app cannot request it even by mistake); your contacts or address book; advertising identifiers; biometric identifiers of any kind, including face templates and voiceprints; consumer health data, including anything about fitness, reproductive health, or a diagnosis — we have no field for it and we infer none from what you post, so there is nothing for a separate consumer-health-data policy to cover; financial or payment information, because Rova is free and takes no payments; your browsing activity on other sites or apps; or any special-category data under the GDPR — including religious belief. Rova is made for the Jewish community, but we do not ask you to state a religion, we have no field for one, and using Rova is not a declaration of anything.
Rova asks for your camera and microphone only at the moment you choose to record or attach media, through your device’s own permission prompt, and only to capture the thing you are posting. You can refuse, and everything else in the app keeps working.
(h) Information stored on your device. Rova keeps data in your browser’s local storage and, for video you are preparing to post, in its local database. This includes your sign-in session, your profile and preferences, drafts and cached content so the app opens instantly and works offline, and the random measurement identifier from §4(e). None of this is a third-party cookie, and no advertising or analytics service can read it. Clearing your browser’s data for Rova, or deleting your account, removes it — see §12.
5. Why we use your information, and our legal basis for doing so
We use personal information only for the purposes below. For people in the European Economic Area, the United Kingdom, and Switzerland, the “legal basis” note is our basis under Article 6 of the GDPR.
- To operate the Service — create your account, show your profile, build your feed, deliver your messages, keep you signed in. Legal basis: performance of our contract with you.
- To keep Rova safe — act on reports, enforce our Terms and Community Guidelines, detect and stop abuse, spam, impersonation, and attacks on the Service. Legal basis: our legitimate interest in a safe platform, and compliance with legal obligations.
- To keep the Service standing up — route traffic, deliver media, diagnose faults, and absorb attacks, using the technical records in §4(f). Legal basis: legitimate interest in the security and availability of our own service.
- To rank what you see — order your feed and suggestions using signals such as who you follow, recency, and how many people engaged with a post. Legal basis: legitimate interest. This is described further in §14.
- To communicate with you — service messages about your account, security notices, email confirming your address or resetting your password, and in-app notifications about activity you asked to hear about. Legal basis: contract, and legitimate interest.
- To understand whether Rova works — the counts in §4(e). Legal basis: legitimate interest in measuring and improving our own product, honoured against your right to object through DNT/GPC.
- To meet our legal obligations — respond to lawful requests, handle copyright notices, keep records we are required to keep. Legal basis: legal obligation.
We have carried out the balancing exercise the GDPR expects wherever we rely on legitimate interests, and you can object to any of it under §13(d). If we ever want to use your information for a materially different purpose, we will update this Policy and, where the law requires it, ask your consent first.
6. How your information is shared
We do not sell your personal information, and we never have. We do not “share” it for cross-context behavioural advertising as California defines that term. We do not disclose it to data brokers. There is no advertising business attached to Rova. Information leaves Rova in only the five ways below.
(a) With other people on Rova. Your username, display name, profile photo, bio, neighborhood, and anything you post publicly are visible to other users, and — if your account is public — to anyone on the internet who visits your profile. Each public post also has a web address of its own, and those addresses can be found and listed by search engines such as Google, so a public post may appear in search results outside Rova. Making your account private limits your posts to approved followers, and removes them from those public addresses and from search engines. Direct messages are visible to you and the person you sent them to. We do not read your messages in the ordinary course of running Rova, and the database itself enforces that: the rule that only the two people in a conversation can read it is a database rule, not application code that could have a bug. We may access a specific message if we are legally compelled to, or if it is reported to us and we need it to investigate a serious safety issue.
(b) With the companies that run Rova’s infrastructure. These are our processors. They handle data only on our written instructions, only to provide their service to us, and never for their own purposes. This is the complete list:
- Supabase — accounts, authentication, and the database that holds everything in §4(a)–(e), plus the request logs in §4(f). United States.
- Bunny.net — storage and delivery of photos and video. Serves your media from edge locations worldwide.
- Cloudflare — hosting and delivery of the application itself, protection against attacks, and the email routing that forwards messages sent to our support address.
- Resend — delivery of the account email we send you: confirming your address, resetting your password, and security notices. It handles your email address and the contents of those messages, and nothing else. United States.
- Sentry (Functional Software, Inc.) — crash reporting, so we find out when Rova breaks on someone’s device instead of never hearing about it. When something goes wrong it receives the error, the place in our code it happened, your browser and operating system version, the address of the page you were on with everything after the “?” removed, a short trail of the last few actions the app took with those addresses trimmed the same way, and the city your internet connection appears to be in. It is not given your name, username, email address, account identifier, or the contents of anything you wrote, and it is not given your IP address to keep. It sends nothing at all while the app is working normally. United States.
- Google LLC and Apple Inc. — identity providers, but only for people who choose to sign in through them, and only as described in §4(c).
We keep this list current, and we treat it as a commitment rather than an illustration: if we add a processor that handles personal information, it is named here before it goes live.
(c) When the law requires it. We may disclose information if we are legally required to — a subpoena, court order, or other valid legal process — or where we have a good-faith belief that disclosure is necessary to prevent imminent physical harm, to investigate a violation of our Terms, or to protect the rights, safety, and property of Rova, our users, or the public. We review every request for validity and scope, we push back on requests that are overbroad, we disclose only what the request actually reaches, and we will notify you of a legal demand for your information unless we are prohibited from doing so or believe notice would create a risk of harm.
(d) With your direction. When you use a share button, you are asking us to hand that content to whatever app you picked.
(e) In a business transfer. If Rova is involved in a merger, acquisition, financing, or sale of assets, information may transfer as part of that transaction. We will give you notice through the Service before your information becomes subject to a materially different privacy policy, and any acquirer remains bound by this Policy for information collected under it until you are given that notice and a chance to delete your account.
7. Google API Services — Limited Use
Rova’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.
Concretely, this means that the Google account data described in §4(c) — your email address, email-verified status, name, and profile picture — is used only to create your Rova account, populate your Rova profile, and sign you in. We do not transfer it to others except as necessary to provide the Service, to comply with applicable law, or as part of a merger or acquisition; we do not use it for advertising, ad personalisation, or any advertising purpose; we do not use it to develop, improve, or train generalised artificial-intelligence or machine-learning models; we do not sell it; and we do not allow humans to read it, except with your explicit consent for a support issue you have raised, where it is necessary for security purposes or to comply with applicable law, or where the data has been aggregated and de-identified.
You can withdraw Rova’s access at any time from your Google Account permissions page. Doing so stops future Google sign-ins; it does not by itself delete your Rova account, which you can delete in Settings as described in §12.
8. Where Rova is offered, where your information is stored, and international transfers
Rova is operated from, and directed to, the United States. We do not target the European Economic Area or the United Kingdom, we do not offer the Service in any language other than English, and we take no payment in any currency. We have therefore not appointed a representative under Article 27 of the GDPR. We would rather tell you plainly where we stand than imply an establishment we do not have — and if you use Rova from Europe anyway, we still honour every right in §13(d) and hold ourselves to this Policy.
Your information is stored and processed on servers in the United States. Photos and video are additionally cached on content-delivery servers around the world so they load quickly wherever you are.
If you use Rova from the European Economic Area, the United Kingdom, or Switzerland, your information will be transferred to the United States, which those jurisdictions do not treat as offering equivalent protection by default. Where we make such a transfer, we rely on the European Commission’s Standard Contractual Clauses (and the UK International Data Transfer Addendum, where applicable) as incorporated into our agreements with our processors. You may request a copy of the relevant safeguards by writing to support@rova-app.com.
9. How long we keep it
We keep personal information only for as long as we need it, and we work to specific periods rather than an open-ended promise:
- Your account and profile — for as long as your account is open. Deleted with the account.
- Your date of birth — kept for as long as your account is open, and deleted with it (see the 30 days in §12). We keep the date rather than only the age it implies, because a stored age silently becomes wrong a year later and could not be checked against anything.
- Posts, reels, comments, likes, saves, follows, and notifications — until you delete them, or until you delete your account. Deleting your account hides them from everyone immediately and deletes them for good 30 days later, so that the deletion can be undone in the meantime. See §12.
- Direct messages — until you delete your account, plus the 30 days described in §12. Because a conversation is a single record shared by two people, deleting your account removes the whole conversation, including the messages the other person sent you and the ones you sent them. It disappears from their inbox as well as yours straight away, and is deleted for good when the 30 days are up.
- Stories and their view lists — deleted automatically once the story expires 24 hours after posting, together with the image itself. The deletion job runs hourly, so a story is gone within about an hour of expiring. Deleted sooner if you delete the story.
- Measurement events — 180 days, then deleted automatically by a scheduled job. Your user ID is stripped from them when your account is deleted for good at the end of the 30 days in §12, and what is left cannot be traced back to you.
- Technical records held by our infrastructure providers (§4(f)) — a short window set by each provider, measured in days rather than months, after which they age out automatically. We keep no copy of our own.
- Reports and moderation records — kept for up to 24 months after the matter is closed, so that repeat behaviour can be recognised and enforcement decisions can be reviewed. Retained in a form that identifies the account reported; the reporter’s identity is never shown to the person reported.
- Copyright notices and counter-notices — kept for 3 years, which is what the repeat-infringer obligations in the Terms require.
- Backups and copies. Where a backup or replica of our database exists, deleted data can survive in it briefly before ageing out. Any such copy is encrypted, is never used to serve the app, and is re-deleted if it is ever restored. The window is short — days rather than months — and we keep no archival copy of deleted content.
- Records we are legally required to keep — for the period the law requires, and no longer.
10. How we protect your information
Security is enforced structurally, not by policy alone:
- Row-level security is switched on for every table in our database, so the rules about who can read what are enforced by the database itself rather than by application code that might have a bug. Your direct messages are readable only by the two accounts in the conversation, and your Hidden words list only by you — as a database rule.
- Encryption in transit for every connection (HTTPS/TLS), with HSTS preloaded so a browser will not even attempt an insecure connection, and encryption at rest for data held by our providers.
- A strict content security policy, which blocks the injection attacks that are the usual route to stealing a session, permits no third-party script to run at all, and denies any other site the ability to embed Rova.
- Location access disabled at the server level by our permissions policy, so the app cannot ask your device for your position even by mistake.
- Privileged operations run server-side, behind functions that verify who is calling before they act. Administrative access is limited to people who need it.
- Passwords are hashed by our authentication provider and are never stored or visible in readable form.
If you find a vulnerability, please tell us. Write to support@rova-app.com with the subject “Security”. We will acknowledge you, we will keep you posted, and we will not pursue or support legal action against anyone who reports a flaw in good faith, gives us a reasonable chance to fix it, and does not access, alter, or destroy anyone else’s data in the process.
No system is perfectly secure, and we will not pretend otherwise. If we discover a breach affecting your personal information, we will notify you and the relevant regulators without undue delay and within the deadlines the applicable law sets — for the GDPR, within 72 hours of becoming aware of it — and we will tell you what happened, what was affected, and what we are doing about it, rather than the minimum a lawyer could get away with.
11. Your controls inside Rova
Most privacy decisions should not require writing to anyone, so they are in the app. These are the ones that exist today, described as they actually behave:
- Private account — the switch under “Who can see your content” in Settings. Only approved followers see your posts, and it is enforced by our database, not just by the app.
- Follow requests — approve or decline each one, in Settings → Follow requests.
- Block — from the ••• menu on someone’s profile, or on any of their posts. It is a real wall, enforced by our servers rather than hidden in your copy of the app: the database drops the follow in both directions, and a blocked account cannot see your posts, follow you, or message you. Settings → Blocked accounts lists everyone you have blocked and lets you undo it.
- Hidden words — Settings → Hidden words. Give us a list of words or phrases and comments containing them are hidden from you. Your list is stored against your account and is readable only by you.
- Comments — Settings → Comments controls who may comment on your posts, and an individual post can be set more restrictively than your account default.
- Messages — Settings → Messages controls who may start a conversation with you.
- Notifications — control what you are told about, or pause them entirely. This is a display preference and is kept on your device.
- Edit or empty your profile — Settings → Edit profile, at any time.
- Report a post or an account — the ••• menu, then “Report”, then a reason. To report a comment, a story, or a message, write to support@rova-app.com with the subject “Safety Concern”; it reaches the same people and is acted on the same way.
- Delete your account — Settings → Delete account. See §12.
- Do Not Track / Global Privacy Control — switch either on in your browser and Rova stops recording measurement events entirely. No setting inside Rova is needed, and we do not ask you to prove anything.
12. Deleting your account
You can delete your account yourself, at any time, in Settings → Delete account. No email to us, no retention offer, no dark pattern between you and the button.
Deletion happens in two steps, and we would rather be plain about it than sound tidier than we are.
Straight away. The moment you delete your account it disappears from Rova. Your profile, posts, reels, stories, comments and direct messages stop being visible to everyone — other members, signed-out visitors, search, shared links. Everything Rova holds on your device is erased at that moment too, and you are signed out. As far as anybody using Rova is concerned, you are gone.
Thirty days later. Your data is not actually erased on day one. It is kept, hidden, for 30 days, so that you can change your mind — a mis-tap, a moment of anger, or somebody else getting into your account should not cost you everything you have made. Sign back in within those 30 days and press Restore my account, and it all comes back exactly as it was. We tell you the exact date when you delete, and it does not move.
When those 30 days are up, an automatic job deletes it for real: your profile, posts, photos, reels, stories, comments, likes, saves, follows, direct messages, settings and blocks are removed from our live systems, your identifier is stripped from our measurement records, and your photos and video are deleted from the media servers themselves, not only the rows that pointed at them — an account deletion that leaves your pictures reachable at a public address is not a deletion. After that we cannot bring any of it back, and neither can you.
If we close an account for breaking the rules, the same 30 days apply before it is erased, but the person cannot restore it themselves — they can write to us at support@rova-app.com within that window.
Two honest caveats. First, deleted data can survive briefly in an encrypted backup or replica before it ages out, as described in §9. Second, if someone else screenshotted or re-shared something you posted, that copy is theirs and outside our reach — as it would be on any platform.
13. Your rights
(a) Everyone. Wherever you live, you may ask us to give you a copy of the information we hold about you, correct it, delete it, or send it to you in a portable form, and you may object to how we are using it. Write to support@rova-app.com with the subject “Privacy Request”. We will verify that the request really comes from you — usually by asking you to write from the email address on the account — and we will not charge you, slow you down, or treat you worse for asking. We respond within 30 days.
(b) California. Under the California Consumer Privacy Act as amended by the CPRA, California residents have the right to know what personal information we have collected, the sources, the purposes, and the categories of recipients; to access a portable copy; to correct inaccuracies; to delete; to opt out of sale or sharing; to limit the use of sensitive personal information; and not to be discriminated against for exercising any of them.
Applied to Rova: the categories we collect are identifiers (name, username, email address, date of birth, account identifier, and the random measurement identifier), internet or other electronic network activity information (the counts in §4(e) and the technical records in §4(f), which include an IP address held by our providers), audio, electronic, visual, or similar information (the photos and video you post), geolocation data only to the extent an IP address in a provider’s log is treated as such — we collect no device location — and other information you volunteer (bio, neighborhood, and the content you create). We collect them from you, from your device, and from Google or Apple if you choose to sign in that way. We collect them for the purposes in §5, we retain them for the periods in §9, and we disclose them for a business purpose only to the processors named in §6(b). We do not sell personal information and we do not share it for cross-context behavioural advertising — including the personal information of anyone we know to be under 16 — so there is no opt-out to offer. We do not collect sensitive personal information as the CCPA defines it, so there is nothing for a right-to-limit request to reach. You may use an authorised agent, with written permission we can verify.
(c) Other US states. If you live in Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, Delaware, Iowa, Nebraska, New Hampshire, New Jersey, Tennessee, Minnesota, Maryland, or another state with a comprehensive privacy law, you have substantially the same rights — access, correction, deletion, portability, and opting out of targeted advertising, sale, and profiling that produces legal or similarly significant effects. Rova does none of those last three. Where your state provides an appeal from our decision on a request, you may appeal simply by replying to our response; we will answer the appeal within 45 days, in writing, with our reasons, and tell you how to contact your Attorney General if you remain dissatisfied.
(d) European Economic Area, United Kingdom, and Switzerland. You have the rights of access, rectification, erasure, restriction of processing, portability, and objection — including an absolute right to object to direct marketing, which we do not do. Where we rely on legitimate interests, you may object and we will stop unless we can show compelling grounds that override your rights. Where we rely on consent, you may withdraw it at any time without affecting what happened before. You also have the right to lodge a complaint with your national supervisory authority; we would rather you came to us first, but that right does not depend on it. Please also read §8 on where Rova is offered.
(e) Nevada. Nevada residents may direct a business not to sell certain covered information. Rova does not sell information to anyone, so there is nothing to opt out of — but if you would like that confirmed in writing, send a verified request to support@rova-app.com with the subject “Nevada Opt-Out” and we will confirm it.
14. Ranking, artificial intelligence, and the absence of automated decisions about you
Your feed is ordered by an algorithm. It uses who you follow, how recent a post is, and how many people liked or commented on it. That is the whole of it: there is no behavioural profile of you, no inferred interests, no model of your personality, and nothing bought from a third party feeding into it.
We do not train artificial-intelligence or machine-learning models on your content. Your posts, photos, video, captions, comments, and messages are not training data — not for us, and not for anyone we hand them to, because we do not hand them to anyone for that purpose. If that were ever to change it would be a material change under §17: we would tell you in advance, and for anything you had already posted it would be opt-in, not opt-out.
Rova does not make automated decisions producing legal or similarly significant effects about you within the meaning of Article 22 of the GDPR. Decisions to remove content or suspend an account are made by a person reviewing the matter.
15. Children and teens
Rova is not directed to children under 13, and you must be at least 13 to have an account. We ask for your date of birth when you create one, and an account cannot be created with a date that puts you under 13. That is a check, not a verification — we have no way to confirm that what someone types is true, and we do not claim to. We do not knowingly collect personal information from anyone under 13, and if we learn that we have, we delete the account and its information promptly.
If you are a parent or guardian and believe your child under 13 has created an account, write to support@rova-app.com with the subject “Under-13 Account” and we will act on it, without requiring you to prove more than that you are the parent. If you are between 13 and 18, please read this Policy together with a parent or guardian, and remember that a public account is public. We show no advertising to anyone, so none of the practices that make advertising to teenagers a problem exist here.
16. Cookies and similar technologies
Rova sets no advertising cookies and permits no third-party tracker to run — our content security policy blocks any script served from another company’s servers outright, so this is enforced rather than promised. The single third-party component in the app — the crash reporter named in §6(b) — runs from our own servers, is not a tracker, and sets no cookie of any kind. What Rova stores on your device is listed in §4(h): your sign-in session, your preferences and cached content, and the random measurement identifier. All of it is strictly necessary to run the app or, in the case of the measurement identifier, is disabled outright when your browser sends a DNT or GPC signal. Because we run no third-party trackers, Rova does not show you a cookie-consent banner — there is nothing to consent to.
17. Changes to this Policy
We may update this Policy. When we do, we will change the “Last updated” date above and post the new version here and in the app. If a change is material — for example, a new category of information, a new purpose, a new recipient, or any use of your content as training data — we will give you reasonable advance notice inside the Service before it takes effect, and where the law requires consent we will ask for it rather than assume it. Prior versions are available on request.
18. How to contact us
Questions, requests, complaints, or a correction to something we have written here: support@rova-app.com. A real person reads it. If any part of this Policy is inaccessible to you in this format, tell us and we will provide it in another.
KOSHERHQ LLC · New York, United States · operator of Rova