Skip to main content

Privacy Policy

← Back to Home

Last Updated: August 11, 2026

ROID INC, a California corporation ("ROID," "Company," "we," "us," or "our"), operates the ROID iOS application, the roid.app website (including ROID AI on the web), and related services (collectively, the "Platform" or "Service"). This Privacy Policy describes how we collect, use, disclose, and protect your personal information when you use the Platform. By using the Platform, you agree to the practices described in this Privacy Policy. If you do not agree, please do not use the Platform.

1. Information We Collect

Information you provide:

  • Account details: name, username, email address, and password (managed by Firebase Authentication), or your Apple, Google, or Facebook account identifiers if you sign in with those providers
  • Profile information: profile photo, bio, date of birth, sex/gender, height, weight, and fitness goals
  • Phone number, if you enable two-factor authentication or where it is used to verify referral eligibility
  • Daily check-ins and self-reported wellness responses
  • Nutrition information: meals you log, meal photos you submit for AI analysis, and nutrition goals
  • Messages you send to our AI coach and to other users
  • Information you submit through forms on roid.app (for example, contact, application, or creator forms)
  • Payment-related information for creator programs and web subscriptions (processed by Stripe; see Section 6)

Health and fitness data (with your permission, via Apple HealthKit):

  • Steps, walking/running distance, flights climbed, and active energy burned
  • Heart rate, resting heart rate, and heart rate variability (HRV)
  • Blood oxygen saturation and VO₂ Max
  • Sleep analysis and mindfulness sessions
  • Time in daylight and environmental audio exposure
  • Body weight, body fat percentage, and dietary water intake
  • Workout data, and — if you choose — workouts we save back to your Health app

Content and social data:

  • Posts, reels, photos, videos, and captions you create
  • Comments, likes, shares, saves, and follow relationships
  • Direct messages with other users
  • Training programs and journeys you create, purchase, or follow
  • AI conversations, AI-generated plans, and AI answers you choose to share publicly
  • Derived fitness metrics we compute, such as your Health Score, Vitality Age, and streaks

Optional contact discovery:

  • If you grant Contacts access, contact names and raw phone numbers are processed on your device and are not sent to or stored on our servers
  • The app derives one-way phone-number identifiers on your device and sends them to our authenticated matching service solely to find existing ROID accounts
  • Match-request identifiers are not logged or retained after the real-time request
  • The matching index is created only from phone numbers that ROID members supplied and verified for their own accounts
  • Members must opt in to "Find Me by Phone Number" before their verified number is added to the matching index, and can turn it off at any time in Privacy Settings
  • Contact invitations are prepared one person at a time and are sent only after you choose to send them through the iOS Messages interface

Information collected automatically:

  • Device information (model, OS version, app version, language, time zone)
  • Usage data: screens viewed, features used, session and interaction events
  • Approximate location derived from your IP address, and precise location only if you grant the location permission
  • Performance data and crash/diagnostic logs
  • Push notification tokens and notification interaction data
  • On roid.app: cookies and similar technologies (see Section 8)
  • Referral data: invite codes, invite link clicks, and referral outcomes

2. Device Permissions

The ROID app requests the following iOS permissions. Each is optional, requested in context, and can be revoked at any time in iOS Settings:

  • Health (HealthKit): read the health metrics listed above and, if you choose, save workouts and health data back to the Health app
  • Camera and Microphone: capture photos, videos, and audio for posts, reels, and profile pictures
  • Photo Library: select media for your content and save videos you create
  • Location: suggest nearby gyms and let you tag where you train
  • Contacts: optionally find and invite friends using on-device processing and transient one-way identifiers, as described in Section 1
  • Calendar: add your training program workouts to your calendar so you get reminders
  • Apple Music / Media Library: add music from your library to content you create
  • Notifications: deliver the notification types described in Section 9

3. How We Use Your Information

  • Provide, maintain, and improve the Platform and its features
  • Calculate personalized metrics such as your Health Score, Vitality Age, streaks, and trends
  • Power AI coaching, AI training program generation, AI meal planning, and meal photo analysis (see Section 4)
  • Enable social features: feeds, posts, reels, comments, likes, messaging, and search
  • Match contacts you choose with existing ROID members without retaining your address book
  • Process purchases, subscriptions, AI credits, referrals, and creator earnings
  • Send notifications you have enabled (activity, messages, AI replies, reminders, milestones)
  • Understand product usage and improve performance, stability, and design (analytics)
  • Attribute and measure our own marketing on roid.app (see Section 8)
  • Keep the Platform safe: verify referrals, prevent fraud and abuse, moderate content, and enforce our Terms of Service and Community Guidelines
  • Comply with legal obligations and respond to lawful requests

4. AI Features and Your Data

ROID's AI features (the AI coach, AI program builder, AI meal planning, meal photo analysis, and ROID AI on the web) are powered by third-party large language models, currently provided by OpenAI. When you use these features:

  • Your messages, relevant profile details (such as age, sex, height, weight, and goals), recent health and nutrition metrics, and conversation history are sent to our AI provider to generate a response. Meal photos you submit for analysis are also processed by the AI provider.
  • AI requests are routed through our own servers; our AI provider processes this data to provide the service under contractual restrictions. Per our provider's API terms, data submitted through the API is not used to train their models.
  • We store your AI conversations and AI-generated plans in your account so they sync across sessions, and we record AI usage events (for credit accounting and abuse prevention).
  • We may use web search services (such as Google Programmable Search) to retrieve research sources for AI answers; your search topic — not your identity — is sent to those services.
  • You can delete individual AI chats or clear your AI history in the app, and AI conversations are removed when you delete your account.
  • If you explicitly share an AI answer, it may be published at a public roid.app link (see Section 7). AI answers are never public unless you share them.

AI output is informational only and is not medical advice. See our Terms of Service for health disclaimers.

5. Health Data and Apple HealthKit

  • HealthKit access requires your explicit permission for each data type, and you can revoke it at any time in iOS Settings → Privacy & Security → Health
  • We use HealthKit data solely to provide fitness features: your Health Score, activity tracking, trends, and personalized AI coaching
  • We never use HealthKit data for advertising or marketing, and we never sell it
  • Health context is shared with our AI provider only to generate your coaching responses when you use AI features, as described in Section 4, and is never disclosed to advertisers or data brokers
  • ROID is not a healthcare provider and is not a "covered entity" under HIPAA; instead, your health data is protected as described in this Privacy Policy and applicable consumer privacy laws

Note: disabling health permissions limits features that depend on them, including the Health Score and personalized coaching.

6. How We Share Information

We do not sell your personal information. We share it only as described below:

Service providers (processors):

  • Google Firebase / Google Cloud — authentication, database, file storage, cloud functions, push notifications, analytics, and performance monitoring (servers located in the United States)
  • OpenAI — AI response generation, as described in Section 4
  • Apple — App Store billing for in-app subscriptions, Sign in with Apple, HealthKit, and push notification delivery
  • Stripe — payment processing for web subscriptions and creator program purchases, and payouts to creators (Stripe receives your payment details directly; we never store full card numbers)
  • PostHog — product analytics that help us understand how features are used
  • Meta (Facebook) — only if you use Facebook Login or share content to Meta platforms, and via the Meta Pixel on roid.app (see Section 8)
  • Email delivery services — to send and receive messages from website contact and application forms

Other users and the public:

Content you post and profile information are visible to other users according to your settings, and may be publicly visible on the web as described in Section 7.

Legal and safety:

  • To comply with law, legal process, or enforceable government requests
  • To enforce our Terms, investigate fraud or abuse, or protect the rights, property, and safety of ROID, our users, or the public

Business transfers:

In connection with a merger, acquisition, financing, or sale of assets, your information may be transferred as part of that transaction, subject to this Privacy Policy.

7. Public Content and Sharing

  • Posts, reels, training programs, profiles, and AI answers you choose to share can be viewed on public roid.app pages (for example, roid.app/post/…, roid.app/reel/…, roid.app/program/…, roid.app/profile/…, roid.app/a/…) and may be indexed by search engines
  • When you share content outside ROID, we may generate a watermarked video rendition of it for the share
  • Invite links you share include your referral code
  • You can control visibility through your privacy settings and by deleting content you no longer want shared

8. Analytics, Cookies, and Advertising

In the ROID app:

  • We use Google Analytics for Firebase, PostHog, and Firebase Performance Monitoring to measure feature usage, stability, and performance
  • The app contains no third-party advertising SDKs, does not use the IDFA, and does not track you across other companies' apps or websites — which is why it does not show an App Tracking Transparency prompt

On roid.app (the website):

  • We use Google Analytics 4, Google Tag Manager, and PostHog to understand site usage
  • We use advertising and conversion tools — Google Ads conversion tracking and the Meta Pixel — to measure the performance of our own ad campaigns; these providers may set cookies or receive event data and process it per their own privacy policies
  • You can limit these technologies via your browser's cookie controls, the Google Analytics opt-out, and Meta ad preferences

Where the use of advertising cookies on our website constitutes "sharing" for cross-context behavioral advertising under California law, you may opt out by emailing privacy@roid.app and adjusting your browser settings. We do not use your in-app health, nutrition, or AI conversation data for advertising.

9. Notifications and Communications

  • Push notifications may include: social activity (likes, comments, follows), direct messages, AI coach replies, workout and streak reminders, milestone celebrations, and important account or purchase updates
  • You can turn each category on or off in the app's notification preferences, or disable push entirely in iOS Settings
  • We send service emails (such as password resets and account verifications); we do not currently send marketing email newsletters

10. Data Security

  • Data is encrypted in transit (TLS) and encrypted at rest on Google Cloud infrastructure
  • Access to production data is restricted and authenticated
  • Purchases and subscription entitlements are validated server-side; credit balances are maintained in server-authoritative ledgers
  • Optional two-factor authentication is available for your account

No method of transmission or storage is 100% secure; while we work to protect your information, we cannot guarantee absolute security.

11. Data Retention

  • Account, profile, content, health, nutrition, and AI data: kept until you delete it or delete your account
  • After account deletion, residual copies are purged from active systems within 30 days, except where longer retention is required
  • Purchase, credit-ledger, and payout records: retained up to 7 years for tax, accounting, and fraud-prevention obligations
  • Analytics data is retained per our analytics providers' configured retention periods and is aggregated or de-identified over time
  • Contact-discovery request identifiers are discarded immediately after the real-time matching request
  • Contact invite status is stored only on your device as a one-way identifier

12. Your Rights and Choices

  • Access / portability: request a copy of your personal data by emailing privacy@roid.app
  • Correction: update your profile and settings in the app, or ask us to correct inaccurate data
  • Deletion: delete individual content and AI chats in the app, or delete your entire account (see Section 13)
  • Permissions: revoke Health, camera, photos, location, contacts, calendar, or music access at any time in iOS Settings
  • Notifications: manage categories in-app or disable push in iOS Settings
  • Analytics/advertising: use the opt-outs described in Section 8

We respond to verified privacy requests within 30 days (or sooner where required by law).

13. Deleting Your Account

You can permanently delete your ROID account in the app (Profile → Settings → Account Security → Delete Account) — step-by-step instructions are on our Delete Account page. Deletion removes your profile, content (posts, reels, comments), health and fitness data, nutrition data, AI conversations, messages, and social connections, subject to the limited retention described in Section 11. If you cannot use the in-app flow, email privacy@roid.app and we will process the deletion after verifying your identity.

14. Children's Privacy

The Platform is not directed to children under 13, and we do not knowingly collect personal information from children under 13. If you believe a child under 13 has created an account, contact us at privacy@roid.app and we will delete it. Users under 18 must have permission from a parent or guardian to use the Platform.

15. California Privacy Rights (CCPA/CPRA)

California residents have the right to know, access, correct, and delete their personal information; the right to opt out of "sale" or "sharing" of personal information; and the right not to be discriminated against for exercising these rights.

  • We collect the categories of information described in Section 1 for the purposes in Section 3
  • We do not sell personal information
  • Except for website advertising cookies described in Section 8, we do not "share" personal information for cross-context behavioral advertising — and you can opt out of that sharing as described there
  • Health, nutrition, and AI conversation data are never sold or shared for advertising

To exercise these rights, email privacy@roid.app.

16. Privacy Rights in the EEA, UK, and Other Regions (GDPR)

Where GDPR or similar laws apply, we process personal data on these legal bases:

  • Contract: providing the Platform you signed up for
  • Consent: health data, contacts, location, and other permission-based features (you may withdraw consent at any time)
  • Legitimate interests: analytics, security, fraud prevention, and service improvement
  • Legal obligation: tax, accounting, and lawful requests

You additionally have the rights of access, rectification, erasure, restriction, portability, and objection, and the right to lodge a complaint with your supervisory authority. Our services are hosted in the United States; where we transfer data from the EEA/UK, we rely on appropriate safeguards such as Standard Contractual Clauses.

17. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. We will post the updated policy on this page with a new "Last Updated" date, and for material changes we will provide additional notice in the app or by email. Continued use of the Platform after the effective date constitutes acceptance of the updated policy.

18. Contact Us

BY USING OUR PLATFORM, YOU ACKNOWLEDGE THAT YOU HAVE READ, UNDERSTOOD, AND AGREE TO BE BOUND BY THIS PRIVACY POLICY.