Privacy Policy for Roam.Do

Last updated: 30 August 2026

Roam.Do is a travel checklist app. Everything you write in it stays on your device. Three supporting services — one for purchases, one for crash reports, and one for basic usage analytics — do connect to the internet, and this policy explains exactly what they send.

Summary

Your lists, items, notes and photos never leave your device. There are no accounts and no advertising. Nothing sent by any of the services below is linked to your name, email, or identity, and none of it can see your list content.

Three things use the network:

What the app stores, and where

Everything you enter stays in private storage on your device:

None of this is uploaded anywhere. Other apps cannot read it.

Services the app connects to

Purchases — RevenueCat. When the app starts, it contacts RevenueCat to check whether you have bought the premium upgrade, and it contacts RevenueCat again when you open the purchase screen or make a purchase. There is no account and no sign-in: RevenueCat assigns a random, anonymous identifier that is not linked to your name, email, or Google account. Reinstalling the app produces a new one. What is exchanged is that identifier, the purchase receipt issued by Google Play, and basic technical details such as your device model, platform version and country. Payment itself is handled entirely by Google Play — neither Roam.Do nor RevenueCat ever sees your card details. See RevenueCat's privacy policy.

Crash reports — Firebase Crashlytics. If the app crashes or hits an internal error, a report is sent to Firebase Crashlytics so the problem can be diagnosed. A report contains the error and the line of code it came from, the app version, your Android version and device model, and the state of the device at that moment — such as free memory and storage, screen orientation, and whether the app was in the foreground. It also contains a random installation identifier generated by Firebase, which is not linked to you and is replaced if you reinstall the app.

Crash reports never contain the contents of your lists, your notes, your photos, or anything else you have typed. Crashlytics collects nothing while the app is running normally — reports are created only when something goes wrong, and are sent the next time you open the app. Google deletes crash reports after 90 days. See Firebase's privacy information.

Usage analytics — Firebase Analytics. The app sends Firebase Analytics a small number of named events as you use it — for example that a list was created, an item was added, a list was completed, or that a paywall screen was shown or closed. It also records which screens you visit as you navigate the app. Alongside these events some plain numbers are sent — how many lists you have, how many items were in a finished list, how long it stayed open. Three properties are also attached to your device's analytics profile: the app's display language, whether you have Premium, and a bucket for how many lists you have. The property is coarser than the events — a bucket such as "1–2" or "4+" rather than an exact figure.

These events and properties describe what happened, never what you wrote: no list titles, item text, notes, links, locations, or photos are ever included. Firebase Analytics identifies your device using Google's standard analytics identifier, not your name, email, or Google account, and analytics collection is switched off entirely in development builds. See Firebase's privacy information for how long Google retains this data and how it is used.

Data you choose to send

Roam.Do can export a list as a .notch file so you can send it to someone else. This only ever happens when you initiate it. You choose the recipient and the app or channel used to send it, through Android's own share sheet. Roam.Do has no server of its own, and your list content is never uploaded to the services described above.

Likewise, opening an item's web link or location hands the address to your browser or maps app. Once you leave Roam.Do, that app's own privacy policy applies.

Permissions

Roam.Do declares internet and network-state permissions, which the purchase, crash-reporting and analytics services above require in order to work. It declares no location and no storage permissions.

The only permission it can ever ask you about is camera access, and only at the moment you choose to photograph an item; you can decline and pick an existing photo instead. Photos you select through the system picker need no permission at all.

Roam.Do does not use the Android advertising ID — the permission that would allow it is explicitly removed from the app, so no advertising profile can be built from any of this.

Children

Roam.Do is not directed to children. It asks for no personal information from anyone, and the technical data described above carries no name, email address or account identifier.

Deleting your data

Delete individual lists, items, or photos inside the app at any time. Uninstalling Roam.Do removes the database, all attached photos, and all preferences from your device permanently.

Crash reports, analytics data and purchase records sit outside the app and work differently. Crash reports are deleted by Google after 90 days and are not tied to any identifier that could be used to find yours. Analytics events and properties are retained by Google under Firebase's data retention settings and are likewise not tied to any identifier that could be traced back to you — uninstalling the app stops new analytics data from being sent, but does not retroactively delete what was already recorded. Purchase records are held by RevenueCat and Google Play for as long as needed to honour the purchase — they are what lets you restore it on a new device. If you want a purchase record removed, write to the address below and say which device and roughly when the purchase was made, and it will be dealt with.

Changes to this policy

If this policy changes, the revised version will be posted at this address with an updated date above.

Contact

Questions about this policy: info.myverst@gmail.com