RosterOSfor personal trainersDownload

Privacy

RosterOS
Privacy Policy

Effective September 13, 2026. This page describes what RosterOS collects, how it's used, and your choices. It is a plain-language starter policy; the canonical version inside the iOS app links to the same content.

Overview

RosterOS ("RosterOS", "we", "our") is a personal-training business app made for individual trainers and small studios. We collect only what's needed to run the app and your account, and we don't sell, rent, or share your personal data with third parties for advertising.

Information we collect

Information you provide

  • Account details: your name, email address, and password (or an Apple-provided identifier if you sign in with Apple).
  • Business data: the client records, sessions, payments, notes, measurements, progress photos, intake answers, and workout templates you create in RosterOS.

Information collected automatically

  • Product interaction analytics: controlled event names, timestamps, counts, durations, app and operating-system versions, device class, locale, plan, and product identifiers. RosterOS creates random installation and session identifiers for delivery and can associate signed-in events with your account on the server. These events never include contact details, client records, notes, pasted content, measurements, media, payment descriptions, raw payloads, or raw error messages. We do not use IDFA, IDFV, hardware fingerprints, or cross-app tracking.
  • Diagnostic data: privacy-filtered crash reports and performance metrics collected via Sentry so we can fix bugs. Reports may include exception messages, internal account, tenant, or record UUIDs, operational status, and bounded financial diagnostic values such as a payment total or appointment price. Structured diagnostic context is filtered for names, contact details, notes, health and measurement fields, and raw payload fields before it is sent.
  • Subscription data: receipts and entitlement state provided by the Apple App Store and RevenueCat so we can grant or revoke RosterOS Pro access.

Information collected only with your permission

  • iPhone Contacts: read only when you tap Import from Contacts, used to create client records you select.
  • Calendar: written to when Calendar Sync is enabled, so sessions you create in RosterOS mirror to your phone's calendar.
  • Camera and Photo Library: used when you capture or save a progress photo.

How we use information

  • To provide the app, sync your data across devices, and recover it on a new device.
  • To process subscriptions through the Apple App Store.
  • To measure onboarding, feature use, conversion, and reliability so we can improve RosterOS.
  • To diagnose crashes and improve reliability.
  • To respond to support requests you send us.
  • To enforce our Terms of Use and prevent abuse.

We do not use your business data, client records, or session notes to train machine learning models, sell to advertisers, or target ads.

Third-party processors

RosterOS uses a small set of third parties to deliver the service. Each has its own privacy policy:

  • Supabase: authentication and cloud database. Privacy policy.
  • RevenueCat: subscription receipts and entitlement management. Privacy policy.
  • Sentry: privacy-filtered crash and performance reporting that may remain linked to internal account, tenant, or record identifiers. Privacy policy.
  • Apple: Sign in with Apple, App Store distribution, and in-app purchases. Privacy policy.

Retention & deletion

Your data persists while your account is active. From Settings → Account → Delete account you can request permanent deletion. Deletion is scheduled with a 24-hour grace period. During that period, you can cancel the request from Settings while authenticated. Once the grace period ends, sole-owned tenant data, linked product events, installation links, growth touchpoints, and non-required subscription analytics are removed from our servers. In a shared tenant, your membership and user-linked data are removed while records belonging to the remaining members are preserved. An owner must transfer ownership of a shared tenant before deleting the account.

Raw product events linked to an account are retained for up to 180 days. Product event rows with no authenticated user are retained for up to 30 days, and aggregate ingestion-rejection facts are retained for up to 30 days. Normalized subscription lifecycle facts are retained for up to 24 months for webhook idempotency and audit; account and tenant identifiers that are not required are removed during account deletion. Reporting views do not store separate copies of raw product events. Non-identifying acquisition and cohort results may remain after account deletion because they cannot be linked back to a person; stored daily acquisition aggregates are retained for up to 24 months. Privacy-filtered crash and diagnostic records may be retained by Sentry for debugging and reliability analysis and may include exception messages, internal identifiers, operational status, and bounded financial diagnostic values.

Children

RosterOS is intended for use by adult personal trainers running their business. The service is not directed to children under 13 and we do not knowingly collect personal information from them. If you believe a child has provided personal information to RosterOS, email support@rosteros.app and we'll delete it.

International users

RosterOS production data is hosted in the United States. If you use the app from outside the United States, your information is transferred to and processed in the U.S., where data-protection laws may differ from those in your country. By using RosterOS you consent to this transfer.

Security

We use HTTPS/TLS for all network traffic between the app and our backend. The local SQLite cache on your device is stored in the app's sandbox; sensitive credentials are kept in the iOS Keychain. No security practice is perfect; you can reduce risk by using a strong, unique password (or Sign in with Apple) and keeping iOS up to date.

Your rights

  • Access: export your data via Settings → Data, or by emailing support.
  • Correction: edit any record from inside the app.
  • Deletion: delete a single record from its detail screen, or your entire account from Settings → Account → Delete account.
  • Object / restrict: write to support@rosteros.app with the request and we'll respond.

Changes to this policy

Material changes will be announced in the app and dated here. The effective date at the top of this page reflects the most recent revision.

Contact

Questions about this policy or your data? Email support@rosteros.app.