Privacy Policy

Revision 1.0 (2026-07-25) — the revision number and the date it took effect.

This Policy explains which personal data the All OK app and the romanesco.app service process, why, whom the data is shared with and how long it is kept.

The app exists to let the people you choose know if something has happened to you: you check in from time to time, and if a check-in is missing for longer than the interval you picked, the service emails the people you listed. Everything below is processed for that purpose only.

1. Operator

The personal-data operator is Daniel Golovin.

Contact for privacy questions and for exercising your rights: support@romanesco.app.

2. What data is processed

The lists below are exactly what the service processes — they were checked against the app and server code.

2.1. Account and service data

DataSourcePurpose
Your email address you provide it when you register your account and sign-in with a one-time code
Your name you provide it during onboarding or in your profile; the field is optional the signature in the email to your people. If no name is set, the email to a recipient shows your email address instead
Registration date recorded automatically account bookkeeping
Names and email addresses of your alert recipients and the date they were added you enter them during onboarding or in settings delivering alerts. This is other people’s data — see section 3
Check-in interval and monitoring state (on or off) your settings running the service
Service-side settings: the “share coordinates with recipients” flag and the language of the emails to recipients kept on the service side; the app does not currently change them — the flag defaults to on and the language defaults to English they control whether the map link is included in the email to a recipient and which language that email is written in
Check-ins: the time of each check-in and coordinates (latitude and longitude) where the check-in has them — see the note about coordinates after the tables you check in from the app, the widget or the watch detecting that a check-in is overdue; the map link in the email to a recipient
Internal counters: the number of your check-ins, the time and number of alerts sent, the time of the last warning recorded automatically so the same alert is not sent twice and so monitoring switches itself off after a series of alerts

2.2. Security and abuse-prevention data

DataSourcePurpose
One-time sign-in codes: the code itself, its expiry and the number of entry attempts created when you request a sign-in signing you in and preventing brute-force guessing
Code-sending log: an email address and the time it was sent written on every code request limiting how often codes can be sent. This log survives account deletion — see section 6
Device sessions: device type (phone or watch), the time the session was created, last used and revoked created when you sign in signing in without a password on each device and revoking access when you sign out; you can ask us for the list of your devices
The Apple notification device token, the platform (iPhone or Apple Watch) and the environment sent by the app when it registers the device delivering service notifications — see the note right after the tables

2.3. Technical data

DataSourcePurpose
IP address accompanies every request to the service protection against code guessing and request floods; entries in the server logs
User-Agent string: the app’s name, version and build number, its bundle identifier and the operating-system version accompanies every request to the service diagnosing errors
Server logs written automatically investigating failures and security incidents
Support-request data: app and build version, device model, operating-system version, interface language, your email address and your account identifier the in-app feedback form fills them in automatically and you see them before you send handling your request

A note about coordinates. Location access is granted and revoked in your operating system settings; there is no separate switch inside the app at the moment. What actually happens:

The check-in coordinates the service already holds are deleted together with your account, and earlier on request to support@romanesco.app. We have no access to the coordinates stored on the device itself and cannot delete them on request: deleting your account in the app clears the iPhone’s copy, while the watch keeps its copy until the app is removed from the watch.

A note about the device token. The token is used to deliver notifications through the Apple Push Notification service. In the current version the server sends no such notifications: the warning that your check-in is nearly due is raised by the device itself as a local notification and never goes through our server. The token registration is kept for a future server-side notification feature. You can turn notifications off in your operating system settings.

What we do not do. The app contains no advertising, no profiling, no advertising identifiers and no analytics or tracking software. We do not sell your data and do not share it for advertising purposes. We do not process biometrics, health data or other special categories of personal data. Data is not used for solely automated decision-making with legal effects, with one exception: sending an alert to your recipients when a check-in is overdue — which is the very reason you use the service.

3. Other people’s data: your alert recipients

You enter recipients’ names and email addresses yourself, without those people taking part. Under the Terms of Use you must be entitled to give us their data, and you must tell those people yourself that you have listed them in the service.

We describe the actual state of affairs honestly: the service sends a recipient no notification at the moment you add them. The only email the service ever sends to a recipient is the alert about your missing check-in itself. If that situation never arises, the recipient never learns that they were listed — no email is ever sent. A recipient also has no separate unsubscribe channel yet.

Any recipient can have their data removed by writing to support@romanesco.app; we will remove them from the list. You can delete a recipient in the app’s settings yourself, with one exception: the last remaining recipient cannot be removed while monitoring is on (switch monitoring off first, or add another recipient).

4. What is disclosed to whom in an alert

An alert email to a recipient contains:

Nothing else is disclosed: not your check-in history, not your settings, not the list of your other recipients. Each recipient receives a separate email and cannot see the other recipients’ addresses.

5. Who receives your data

We involve the following parties in processing. We do not share data with them for their own purposes: they process it on our instructions or act as infrastructure and communication providers.

WhoWhat they doWhere
Yandex Cloudhosting the service, the database and the server logsRussia
Yandex Mailsending the service’s emails and hosting the support mailboxRussia
Apple Inc.delivering notifications to your deviceUSA
Google LLCshowing the map behind the link in an alert emailUSA

In normal operation some data leaves our infrastructure — that is how the service works:

If you do not want your coordinates to be able to reach Google, deny the app location access in your operating system settings — but mind the note about coordinates in section 2: a check-in from the widget or the watch can still be sent with the coordinates stored on the device after access is revoked. If you do not want the token transferred to Apple, turn notifications off in the same place. Choosing your recipients and their mail services is always up to you.

Data may also be disclosed to state authorities where the law requires it. If we change a provider, we will update this section and publish a new revision of the Policy.

6. Retention and deletion

WhatHow long it is keptWhat happens when you delete your account
Account, name, settings, recipient list for as long as the account exists deleted
Check-ins: times and coordinates there is no automatic deletion — they are kept for as long as the account exists deleted
One-time sign-in codes 5 minutes, or until first use deleted
Code-sending log: email address and time up to 24 hours. Stale entries are not removed on a schedule but on the next code request made in the service — by anyone, not necessarily by you; an entry can therefore outlive the 24 hours if nobody requests a code not deleted — entries remain until that period expires. This is why saying “nothing at all is left after you delete your account” would be inaccurate
Device sessions until the session expires. Revoking one (signing out) marks it revoked, but the record itself lives out its term and is physically deleted at your next sign-in or session refresh — this is what lets us tell a reused revoked session apart from an ordinary error deleted
Notification device tokens 90 days from the device’s last activity deleted
Server logs: IP address, User-Agent, service records a limited time at our infrastructure provider; we set no period of our own account deletion does not touch them
Support correspondence up to 1 year from the date of the request account deletion does not touch it; write to us if you want it deleted sooner
Database backups a limited time at our infrastructure provider; we set no period of our own data from a deleted account remains in backups already taken for as long as those backups live. Backups are used only to restore the service after a failure; individual records are not restored from them into the live database

You can delete your account yourself in the app: “Profile” → “Delete account”. It is a single action and cannot be undone. It immediately removes from the live database your account, name, settings, recipients, all check-ins with their coordinates, sessions and device tokens. The exceptions are the code-sending log, server logs, support correspondence and backups: they live out the periods in the table above.

7. Your rights

8. Revision and changes

The current revision is 1.0 (2026-07-25): the date in brackets is the date it took effect. The revision number is shown in the footer of every page.

We may change this Policy — for example when we change a provider or add a feature. A new revision is published at https://romanesco.app/en/privacy with a new number and date and takes effect on that date. We keep previous revisions and provide them on request at support@romanesco.app.