Privacy Policy
This Privacy Policy explains how RoxyKovu LLC collects, uses, shares, and protects your information when you use our website, mobile applications, desktop software, and related services. Effective date: March 8, 2026. Last updated: July 22, 2026.
Privacy by app
This one policy covers every RoxyKovu app. The general rules are in sections 1 through 17. Jump straight to your app for exactly what it stores, what can leave your device, and why.
- Fitness for the Fighting ManOn-device by default. No account, no ads.
- 20 QuestionsOn-device AI. Ad-supported on iPhone and iPad.
- Numera SagaPlays offline. Optional rewarded ads only.
- Terminally OnlineMakes no network requests of its own.
- VitalQuest: AscendIn development. Not yet released.
- TriageYour money data never reaches us.
- ViantaYour home data never leaves the device.
- Naval Letter BuilderDrafts stay on your device. No sync.
- EDENClinical software. Server-backed by design.
- ClaraOn-device plus your own iCloud.
- PatchShepherdScans stay on your Windows PC.
1. Who we are
RoxyKovu LLC ("RoxyKovu," "we," "us," or "our") is the data controller responsible for your personal information.
- Company: RoxyKovu LLC
- Location: Charlotte, North Carolina, USA
- Email: Support@roxykovu.com
- Website: roxykovu.com
This Privacy Policy applies to all RoxyKovu products and services, including our website (roxykovu.com), mobile apps distributed through the Apple App Store and Google Play, and desktop software distributed through the Microsoft Store and the Mac App Store. By using our services, you agree to the practices described in this policy. Please also review our Terms of Service.
2. Our privacy-first approach
- App data stays on your device unless a specific feature explicitly requires otherwise.
- No accounts are required to use our apps unless a specific feature says otherwise.
- We do not sell, rent, or trade your personal information.
- We collect only the minimum data necessary to provide and improve our services.
- We do not use or disclose sensitive personal information for purposes beyond what is necessary to provide our services.
3. Information we collect
We collect different categories of information depending on how you interact with our services.
3.1 Information you provide directly
- Contact form submissions: Name, email address, subject, and message content when you use our contact form or email us.
- Feedback and support requests: Any information you include in communications with us (bug reports, feature requests, support inquiries).
- AI chat assistant messages: When you use the Kovu chat assistant on our website, your messages are sent to our servers for processing. We send your messages (and up to six prior messages from the same session for context) to a third-party AI service (Google Gemini) to generate responses. We do not permanently store your chat messages or conversation history on our servers.
3.2 Information collected automatically (website)
- Server logs: IP address, user agent (browser type and version), referring URL, pages visited, and timestamps. Collected for security, uptime monitoring, and abuse prevention.
- Google Ads conversion tracking (gtag.js): With your consent, Google may collect page-view data, IP address, browser information, and set cookies for ad campaign measurement. See Section 7 (Cookies) for details.
- Cloudflare Turnstile: IP address and browser signals processed by Cloudflare on contact forms for bot protection.
- Font delivery: IP address and user agent sent to third-party CDN providers when loading web fonts.
- AI chat assistant rate limiting: A cryptographic hash (not the actual value) of your IP address is temporarily stored with a daily message count to prevent abuse of the chat assistant. This data is automatically deleted after 48 hours.
3.3 Information collected by our apps
- 20 Questions (iOS, iPadOS, iMessage, Apple TV): Game data, preferences, and scores stored locally on your device. The solo Battle Mosey mode runs Apple's on-device Foundation Models - your category, secret word, and questions are processed only on your device and never transmitted (see Section 14.2). Family and Friends multiplayer, TV Group Play, and the iMessage app use peer-to-peer connections over Wi-Fi and Bluetooth via Apple's MultipeerConnectivity framework - these connections do not route through RoxyKovu servers (see Section 14.4). On the iPhone, iPad, and iMessage variants, Google AdMob may collect device identifiers and ad interaction data when optional rewarded ads are displayed (see Section 6). The Apple TV (tvOS) variant collects no personal data, no identifiers, and serves no ads (see Section 14.6).
- Fitness for the Fighting Man / FFM (iOS and Android): Workout data, training history, and fitness metrics stored locally on your device. With your explicit permission, FFM may access Apple HealthKit (iOS) or Health Connect (Android) data and device sensors for fitness tracking. Location data may be accessed for run distance tracking (see Section 5). On iOS, FFM also offers an optional, encrypted iCloud Backup that stores a copy of your app data in your own iCloud account; it is off by default and described in Section 5.5.
- PatchShepherd (Windows): Software update scanning results, health scores, update history, and preferences stored locally on your device. Health scoring, multi-source scanning, and update history are processed and stored entirely on your device. PatchShepherd Pro is a one-time purchase, and the entitlement is checked through Microsoft Store licensing (see Section 5).
- Triage: All financial data you enter or import is stored only on your device in an encrypted database. Triage has no account and no RoxyKovu server, contains no analytics, advertising, or tracking SDKs, and transmits nothing to RoxyKovu. The website analytics and advertising described in this policy apply to roxykovu.com and our ad campaigns, not to the Triage app. Section 18.6 has the full detail.
- VitalQuest: Ascend: Game progress, character data, and preferences will be stored locally on your device. Additional data practices will be disclosed here before the app is released.
- EDEN (clinical EHR for healthcare practices, iOS and iPadOS): EDEN is a clinical electronic health record and on-device AI assistant for licensed healthcare providers and their staff. It is a business product used inside a healthcare practice, not a consumer app, and it requires sign-in to a practice's EDEN account. For the signed-in clinician's account, EDEN collects account and contact information (name, email address, phone number) and a user identifier used to authenticate the user. In the course of care it handles patient charts, encounters, problems, medications, allergies, vitals, notes, clinical photos and documents, and sensitive demographics that may appear in a chart (such as race or ethnicity, sexual orientation, religion, and disability status). A patient's medical record may also include additional identifiers, for example a partial Social Security number, where the practice records them as part of care; these are part of the practice's record, and the "do not collect" list in Section 3.4 describes RoxyKovu's own collection from consumer users. EDEN syncs the practice's records to that practice's EDEN server over encrypted connections (HTTPS/TLS); it does not use them for advertising, sell or rent them, or share them with data brokers. EDEN's clinical health data and HIPAA roles are described in Section 5.6, and its microphone, voice, and "Hey Eden" assistant features in Section 14.7.
3.4 Information we do NOT collect
- We do not collect Social Security numbers, government IDs, financial account numbers, or biometric identifiers.
- We do not collect precise geolocation for advertising or profiling purposes.
- We do not create advertising profiles based on your activity across our apps.
- We do not process payment information - all purchases are handled by Apple, Google, or Microsoft through their respective stores.
4. How we use your information
We use the information we collect for the following purposes:
- To provide and maintain our services: Delivering app functionality, processing contact form submissions, and responding to support requests.
- To improve our services: Understanding how our website and apps are used so we can fix bugs, improve performance, and develop new features.
- To communicate with you: Responding to your inquiries, sending service-related notices, and providing support.
- To measure advertising performance: With your consent, using Google Ads conversion tracking to understand ad campaign effectiveness.
- To protect our services: Detecting, preventing, and addressing fraud, abuse, security issues, and technical problems.
- To comply with legal obligations: Meeting applicable laws, regulations, legal processes, or enforceable governmental requests.
We do not use your information for automated decision-making or profiling that produces legal or similarly significant effects on you.
5. Health and fitness data
FFM accesses health and fitness data only with your explicit permission, and this data stays on your device, except for the optional, encrypted iCloud Backup described in Section 5.5.
5.1 iOS (Apple HealthKit)
- FFM can read and write workout data and Apple Watch activity through HealthKit only when you grant permission through the iOS Health permissions prompt.
- HealthKit data is processed locally on your device and is never sent to RoxyKovu servers, used for advertising, sold to third parties, or shared with data brokers.
- You can revoke HealthKit access at any time in your device Settings under Health > Data Access.
5.2 Android (Health Connect)
- FFM may access health and fitness data through Health Connect and device sensors (accelerometer, gyroscope) only when you grant explicit permission.
- Health Connect data is processed locally on your device and is never sent to RoxyKovu servers, used for advertising, sold to third parties, or shared with data brokers.
- You can revoke Health Connect permissions at any time in your device Settings.
5.3 Location data
- FFM may access your location to track distance during outdoor runs. Location access is optional and requires your explicit permission.
- Location data is processed locally on your device and is not transmitted to RoxyKovu servers.
- You can disable location access at any time in your device settings.
5.4 PatchShepherd
- PatchShepherd runs local package managers (WinGet, Chocolatey, Scoop); updates are downloaded directly from their official sources.
- PatchShepherd Pro is a one-time purchase; the entitlement is checked through Microsoft Store licensing. RoxyKovu operates no licensing server and receives no personal data from that check.
5.5 iCloud Backup (FFM iOS)
- FFM offers an optional iCloud Backup you can turn on in Settings > Data & Backup. It is off by default.
- When enabled, FFM makes an encrypted copy of your on-device app data (workout history and training logs, nutrition and recovery entries, cycle-tracking entries if you use them, preferences, and any health-derived metrics you have logged) and stores it in your personal Apple iCloud account using the app's private CloudKit database.
- The data is encrypted on your device with AES-256-GCM before it is uploaded, using a key generated on your device and kept only in your iCloud Keychain. The copy stored in iCloud is ciphertext that RoxyKovu cannot access, read, or recover, and the encryption key never leaves your control. We do not receive this data.
- Apple stores the encrypted copy subject to Apple's iCloud terms and privacy policy. Raw Apple Health records are not included in this backup; they remain in Apple Health under Apple's control.
- You can turn iCloud Backup off at any time, and you can remove the iCloud copy by deleting the app's data from your iCloud or signing out of iCloud.
5.6 EDEN clinical health data and HIPAA
- EDEN is a clinical electronic health record for licensed healthcare practices, operated by RoxyKovu LLC and CURA Vento LLC. It handles protected health information (PHI), including patient charts, clinical notes, vitals, medications, allergies, clinical photos, and sensitive demographics.
- When a practice uses EDEN, the practice is the covered entity and the controller of the patient health information in its records. RoxyKovu LLC acts as the practice's Business Associate under a Business Associate Agreement (BAA) and processes PHI only under the practice's instructions and as that agreement permits.
- Patient privacy rights are governed by the practice's Notice of Privacy Practices and applicable health-privacy law, including HIPAA, rather than by the consumer choices described elsewhere in this policy. EDEN does not use PHI for advertising, sell or rent it, or share it with data brokers.
- Clinical data syncs to the practice's EDEN server over encrypted connections (HTTPS/TLS) and is stored and processed for the practice as described in the BAA.
- EDEN accounts are created and managed by the practice. To deactivate an account or to request access, correction, or deletion of records, contact your practice administrator; the practice, as data controller, manages retention and deletion, and RoxyKovu acts on its instructions. For help, contact Support@roxykovu.com.
6. Advertising
Two of our games show ads: 20 Questions and Numera Saga, both powered by Google AdMob. In Numera Saga the only ad is a rewarded tile you choose to tap. No other RoxyKovu app displays advertising of any kind.
- When ads are enabled, Google and its certified ad partners may collect device identifiers (IDFA on iOS, Advertising ID on Android), IP address, and ad interaction data for ad delivery, measurement, frequency capping, and fraud prevention.
- Where required by law, we display consent prompts (GDPR/EEA/UK/Switzerland) or opt-out choices (US state privacy laws) before personalized ads are served.
- You can change your ad consent choices in-app via Privacy Options (where available) or by resetting your device advertising ID in your device settings.
- Google's privacy policy governs ad data processing: policies.google.com/privacy
- These display no advertisements at all: FFM, Terminally Online, Triage, Vianta, Naval Letter Builder, EDEN, Clara, PatchShepherd, VitalQuest: Ascend, and the 20 Questions Apple TV version.
7. Cookies and tracking technologies
Our website uses cookies and similar technologies. You can manage your preferences through our cookie consent banner or the "Cookie Settings" link in the footer.
7.1 Essential (always active)
- Cloudflare Turnstile: Session-based tokens for bot protection on contact forms. No persistent cookies.
- Cookie consent preference (localStorage): Stores your cookie consent choices locally in your browser so we can respect your preferences on return visits.
7.2 Analytics (requires consent)
- Google Analytics (gtag.js): Measures website traffic and usage patterns. May set cookies including
_ga(expires after 2 years) and_ga_*(expires after 2 years). Collects page views, session duration, approximate location (country/city level from IP), and browser/device information.
7.3 Marketing (requires consent)
- Google Ads conversion tracking: Measures ad campaign performance and conversions. May set cookies for ad attribution and retargeting. Collects conversion events, ad click data, and browsing activity for ad measurement.
7.4 Managing cookies
- On your first visit, our cookie consent banner lets you accept all, reject all, or choose specific categories.
- You can change your choices at any time by clicking "Cookie Settings" in the website footer.
- You can also block or delete cookies through your browser settings. Note that blocking essential cookies may affect website functionality.
- All non-essential cookies and tracking are blocked by default until you provide consent.
7.5 Do Not Track and Global Privacy Control
Some browsers send a "Do Not Track" (DNT) signal. There is no uniform industry standard for how websites should respond to DNT signals. Our website respects your cookie consent choices as described above. When you reject analytics and marketing cookies through our consent banner, no tracking occurs regardless of your DNT setting.
We recognize and honor Global Privacy Control (GPC) signals. When we detect a GPC signal from your browser, we treat it as a valid opt-out request for the sale or sharing of personal information and for targeted advertising, as required by the CCPA/CPRA and other applicable state privacy laws. If you have GPC enabled, non-essential cookies and tracking will remain disabled even if you have not interacted with our consent banner.
8. Who we share data with
We do not sell, rent, or trade your personal information. We share data only with the following categories of service providers, and only as necessary to operate our services.
- Google (AdMob, Analytics, Ads): Ad delivery and measurement in 2Q; website analytics and ad conversion tracking on roxykovu.com. Data shared only with your consent for non-essential processing.
- Cloudflare: Bot protection on contact forms (IP address and browser signals).
- Google (Gemini AI): Chat messages submitted through the Kovu chat assistant are sent to Google's Gemini API for AI-generated responses. Google's privacy policy governs their processing of this data: policies.google.com/privacy. Google's Gemini API terms apply: ai.google.dev/gemini-api/terms.
- Amazon Web Services (AWS): Website hosting (S3, CloudFront), contact form processing (Lambda, SES), and AI chat assistant infrastructure (Lambda, DynamoDB). AWS processes data as a sub-processor under our instructions.
- Apple, Google, Microsoft (app stores): Distribution, purchase processing, and subscription management for our apps. Each platform has its own privacy policy governing data they collect during transactions.
- Font CDN providers: IP address and user agent data transmitted to deliver web fonts.
We may also disclose your information if required by law, regulation, legal process, or governmental request, or if we believe disclosure is necessary to protect our rights, safety, or property, or that of our users or the public.
9. Data retention
- Local app data: Stays on your device until you delete it or uninstall the app. We have no access to this data.
- Server logs: IP address, user agent, and timestamps are retained for up to 90 days for security and operational purposes, then automatically deleted.
- Contact form submissions and support emails: Retained for up to 2 years to provide ongoing support and maintain conversation history, then deleted unless a longer retention period is required by law.
- Google Analytics data: Retained according to Google's standard data retention settings (default 14 months).
- Cookie consent preferences: Stored in your browser's localStorage with no expiration; cleared when you clear browser data or update your preferences.
- AI chat assistant data: Chat messages are processed in real time, forwarded to the Gemini API for a response, and discarded immediately after the response is delivered. Messages are not logged or stored on our servers. Rate-limiting records (hashed IP addresses and message counts) are automatically deleted after 48 hours.
- Google Ads cookies: Conversion tracking cookies (_gcl_*) are retained for up to 90 days per Google's standard settings.
- Font CDN data: IP addresses transmitted to font CDN providers during font delivery are subject to those providers' own retention policies and are not stored by RoxyKovu.
When data reaches the end of its retention period, it is securely deleted or anonymized. If deletion is not immediately possible (for example, because data is stored in backup archives), we will securely store and isolate the data until deletion is possible.
10. Data security
- We use reasonable administrative, technical, and physical safeguards to protect information in our possession, including encryption in transit (HTTPS/TLS for all web traffic) and secure infrastructure (AWS with CloudFront CDN).
- Our contact form uses Cloudflare Turnstile and a honeypot field to prevent automated abuse.
- Email addresses on our website are obfuscated to prevent scraping.
- No method of electronic transmission or storage is 100% secure. While we strive to protect your information, we cannot guarantee absolute security.
Data breach notification
In the event of a data breach that is likely to result in a risk to your rights and freedoms, we will notify affected users and relevant supervisory authorities as required by applicable law (including within 72 hours under GDPR where applicable).
11. Your rights and choices
Regardless of where you live, you have the following choices regarding your data.
- Device permissions: You can manage app permissions (location, health data, notifications) in your device settings at any time.
- Cookie preferences: You can change your cookie consent choices by clicking "Cookie Settings" in the website footer.
- Ad preferences: You can change ad personalization choices in-app (where available) or by resetting your device advertising ID.
- Delete app data: You can delete locally stored app data by uninstalling the app or using any in-app reset option if provided.
- Opt out of email communications: You can stop receiving responses from us by not contacting us. We do not send marketing emails or newsletters.
- Request data access, correction, or deletion: Contact us at Support@roxykovu.com. We will verify your identity and respond within the timeframes required by applicable law.
12. International privacy rights
Depending on where you live, you may have additional rights under local data protection laws.
12.1 European Economic Area, United Kingdom, and Switzerland (GDPR / UK GDPR)
- Legal bases for processing: We process personal data based on: (a) your consent (e.g., cookie preferences, ad personalization); (b) contract performance (e.g., responding to your contact form submissions); and (c) legitimate interests (e.g., security monitoring, service improvement), where those interests are not overridden by your rights.
- Your rights: You have the right to access, rectify (correct), erase (delete), restrict processing of, object to processing of, and port your personal data. You may also withdraw consent at any time without affecting the lawfulness of prior processing.
- How to exercise your rights: Contact us at Support@roxykovu.com. We will respond within 30 days.
- Data protection authority: You have the right to lodge a complaint with your local supervisory authority. A list of EU data protection authorities is available at edpb.europa.eu. UK residents may contact the Information Commissioner's Office (ICO) at ico.org.uk.
- International transfers: RoxyKovu LLC is based in the United States. When personal data is transferred outside the EEA/UK, we rely on Standard Contractual Clauses (SCCs) adopted by the European Commission, or other approved transfer mechanisms, to ensure adequate protection.
12.2 California, USA (CCPA / CPRA)
- We do not sell or share personal information as defined under the CCPA/CPRA.
- Categories of personal information collected in the preceding 12 months: Identifiers (name, email address, IP address); internet or electronic network activity (browsing history, interactions with our website, chat assistant messages); and geolocation data (approximate location from IP address). See Section 3 for complete details on each category, its source, and the business purpose for collection.
- Categories of personal information sold or shared: None. We have not sold or shared personal information in the preceding 12 months.
- Your rights: California residents have the right to know what personal information is collected and how it is used, request deletion of personal information, request correction of inaccurate personal information, opt out of the sale or sharing of personal information (we do not sell or share), and limit the use and disclosure of sensitive personal information.
- Sensitive personal information: We do not use or disclose sensitive personal information (including health and fitness data accessed by FFM) for purposes other than those necessary to provide our services as permitted under the CPRA.
- How to exercise your rights: Contact us at Support@roxykovu.com. We will verify your identity and respond within 45 days (extendable by an additional 45 days with notice). You may also designate an authorized agent to make a request on your behalf. Authorized agents must provide written proof of authorization (such as a signed letter or power of attorney) along with verification of their own identity. We may contact you directly to confirm the request.
- Global Privacy Control: We honor GPC signals as a valid opt-out of the sale or sharing of personal information, as required by the CCPA/CPRA.
- Non-discrimination: We will not discriminate against you for exercising your privacy rights (e.g., by charging different prices, providing a different quality of service, or denying you services).
12.3 Other US states
- Residents of states with comprehensive consumer privacy laws, including Virginia (VCDPA), Colorado (CPA), Connecticut (CTDPA), Texas (TDPSA), Utah (UCPA), Oregon (OCPA), Montana (MCDPA), Delaware (DPDPA), Iowa (ICDPA), Tennessee (TIPA), Indiana (INCDPA), Kentucky (KCDPA), Rhode Island, and other states with active or upcoming privacy legislation, may have rights to access, correct, delete, and obtain a copy of their personal data, as well as the right to opt out of targeted advertising, the sale of personal data, and profiling.
- We do not engage in the sale of personal data or targeted advertising based on cross-context behavioral data.
- Authorized agents: You may designate an authorized agent to submit a privacy request on your behalf. Authorized agents must provide written proof of authorization and verify their own identity. We may contact you directly to confirm the request.
- Right to appeal: If we deny your privacy request, you have the right to appeal our decision. To appeal, contact us at Support@roxykovu.com with the subject line "Privacy Appeal." We will respond within the timeframe required by applicable law (typically 45-60 days). If your appeal is denied, you may contact your state's attorney general.
- How to exercise your rights: Contact us at Support@roxykovu.com. We will verify your identity and respond within the timeframe required by your state's law.
12.4 Brazil (LGPD), Canada (PIPEDA), and other jurisdictions
- If you are located in a jurisdiction with data protection laws, you may have similar rights to access, correct, delete, or port your personal data.
- To exercise your rights, contact us at Support@roxykovu.com. We will respond within the timeframes required by applicable law in your jurisdiction.
13. Children's privacy
- Our services are intended for users aged 13 and older. We do not knowingly collect personal information from children under 13. All of our apps require users to be at least 13 years of age.
- FFM is intended for older teens and adults and involves physical fitness activities. It is rated 12+ on the App Store.
- 2Q is a family-friendly game rated 4+ on the App Store. While children under 13 may use the app, we do not knowingly collect, use, or disclose personal information from children under 13 without verifiable parental consent as required by COPPA. These apps do not require account creation or the submission of personal information to play. When ads are present, we configure ad content settings appropriate for all audiences and do not serve personalized ads to users identified as children.
- PatchShepherd is a Windows desktop utility, not a consumer app for children. It stores its scan results on your PC, has no analytics or telemetry, and collects no personal information about you.
- Numera Saga and 20 Questions serve advertising, so they are not Kids Category apps and are not directed to children under 13. Terminally Online is adult-flavored satire; check its App Store age rating before handing it to a child.
- Triage, Vianta, Naval Letter Builder, and EDEN are professional tools for adults. EDEN is licensed to healthcare practices and has no consumer signup at all.
- If we learn that we have collected personal information from a child under 13 without verifiable parental consent, we will take steps to delete that information as promptly as possible.
- Parents or guardians who believe a child under 13 has provided personal information may contact us at Support@roxykovu.com and we will delete the information within 30 days.
14. Automated systems, on-device AI, and peer-to-peer connectivity
14.1 AI chat assistant on the website
- Our website features an AI-powered chat assistant ("Kovu") that uses Google's Gemini API to generate responses. When you submit a message, it is sent to our server and forwarded to Google's Gemini API for processing. The AI generates a response based on your message and a knowledge base about RoxyKovu products. We do not use your chat messages to train AI models. Google's Gemini API terms govern their processing of this data.
- No automated decision-making: We do not use AI, algorithms, or automated processing to make decisions that produce legal or similarly significant effects on you. The chat assistant provides informational responses only and does not make decisions about your access to services, pricing, or eligibility for anything.
14.2 On-device Apple Intelligence (2Q Battle Mosey)
- 2Q's solo Battle Mosey mode uses Apple's Foundation Models framework to run an on-device language model that plays 20 Questions against you. Everything runs entirely on your device.
- The category, secret word, and every question you ask are processed only on your device.
- No prompts, no responses, and no game state are sent to RoxyKovu, Apple, or any third party for the AI to function.
- Apple's on-device model is not trained on your prompts. Apple's Apple Intelligence privacy commitments apply.
- Battle Mosey requires a device that supports Apple Intelligence (iPhone 15 Pro+ and M-series iPads). It is not available on the Apple TV variant of 2Q (see Section 14.6).
14.3 Other on-device app processing
- FFM's FFAI on-device coach uses Apple Intelligence on iPhone 15 Pro+ and M-series iPads, or our locally bundled Ember model on other supported devices, to generate workouts, meal plans, and recovery guidance directly on your device. Optional cloud-tier AI features are clearly opt-in and disclosed in-app.
- PatchShepherd processes scan results, health scores, and update history entirely on your Windows device.
14.4 Peer-to-peer multi-device features (2Q)
- 2Q's Family and Friends multiplayer, TV Group Play, and iMessage app use peer-to-peer connections over Wi-Fi and Bluetooth via Apple's MultipeerConnectivity framework. These connections are direct between your devices and do not route through RoxyKovu servers.
- No game state, scores, or chat from these multi-device sessions is transmitted to RoxyKovu, and we have no visibility into peer-to-peer game traffic.
- The iMessage app variant of 2Q is governed by the same privacy practices as the main iPhone app and shares this Privacy Policy.
14.5 Microphone use in 2Q
- During TV Group Play, the microphone on each player's iPhone or iPad is used solely for live, on-device speech transcription so spoken questions appear on the TV screen. Audio is never recorded, retained, or uploaded.
- You can revoke microphone access at any time in your device Settings under Privacy & Security > Microphone.
14.6 2Q on Apple TV (tvOS)
The Apple TV (tvOS) version of 2Q is a strict subset of the iPhone/iPad experience and collects no personal data, no identifiers, and serves no ads:
- The Google AdMob SDK is not included in the tvOS build, so no advertising ID, IP address, or ad interaction data is processed on Apple TV.
- The Battle Mosey on-device AI mode is not available on Apple TV; the Foundation Models framework is not used.
- Apple TV does not have a built-in microphone, so the tvOS app does not request microphone or speech-recognition permissions. Voice transcription during TV Group Play happens on each player's paired iPhone, not on the Apple TV.
- Multi-device features use Apple's MultipeerConnectivity over peer-to-peer Wi-Fi and Bluetooth. Connections are direct between your devices and never route through RoxyKovu servers.
- In short, the Apple TV app is an offline, ad-free, AI-free, peer-to-peer hub for the iPhone-driven game.
14.7 EDEN microphone, voice, and the "Hey Eden" assistant
- With your permission, EDEN uses the microphone for voice dictation, the ambient clinical scribe, and the optional always-listening "Hey Eden" wake phrase.
- For supported features, wake-word detection, speech recognition, and ambient scribe processing are designed to run on your device. Audio is processed on-device and is not stored permanently; the resulting text, such as a draft note, is saved to the patient's chart on the practice server.
- EDEN is a documentation and workflow tool. It does not provide medical diagnosis or treatment recommendations, and every AI-drafted note is reviewed and signed by the clinician before it becomes part of the record.
- You can revoke microphone and speech-recognition access at any time in your device Settings under Privacy & Security.
15. Age verification and minors
- Our apps are distributed through the Apple App Store and Google Play Store. These platforms may implement age verification, parental consent, and age-rating mechanisms as required by applicable law, including the Texas App Store Accountability Act, Utah App Store Accountability Act, and similar legislation in other states.
- We comply with platform-level age-rating requirements and accurately represent the content and data practices of our apps in App Store and Google Play submissions.
- Any age-related data provided through platform APIs (such as Apple's Declared Age Range API or Google's Play Age Signals API) is used solely for compliance purposes, including determining appropriate content and ad settings. We do not use age data for advertising targeting, user profiling, or any purpose beyond compliance.
- For our practices regarding children under 13, see Section 13 (Children's privacy).
16. Third-party links and services
Our services may contain links to third-party websites, services, or content that are not owned or controlled by RoxyKovu. This includes app store listings, social media pages, and external resources referenced in our apps or website. We are not responsible for the privacy practices or content of these third-party services. We encourage you to read the privacy policy of every website or service you visit. Inclusion of a link does not imply endorsement by RoxyKovu.
17. Changes to this policy
- We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors.
- When we make changes, we will update the "Last updated" date at the top of this page.
- If we make material changes that significantly affect how we handle your personal information, we will make reasonable efforts to notify you (such as via a prominent notice on our website or an in-app notification) before the changes take effect.
- Your continued use of our services after the revised Privacy Policy has been posted constitutes your acceptance of the changes.
- We encourage you to review this Privacy Policy periodically to stay informed about how we protect your data.
18. Privacy details by app
Sections 1 through 17 apply to everything we make. This section says exactly what each individual app does, so you never have to guess which general rule covers your app. Where an app is stricter than the general policy, the app wins.
18.1 Fitness for the Fighting Man (FFM)
FFM keeps your training, nutrition, body, and health data on your device. There is no FFM account and no sign-in. Nothing leaves your device unless you switch on a specific optional feature, and each of those features is off until you turn it on.
- Platforms
- iPhone, iPad, Mac, Apple Watch, Android
- Account
- None. No login, email, or user ID exists.
- Ads
- None.
- AI
- Free coaching runs entirely on your device. Premium cloud AI is off by default.
Stays on your device
- Workout history, programs, custom workouts, and progress.
- Your profile: optional name, birthdate, sex, height, weight, body-fat percentage, and affiliation, branch, or discipline.
- Nutrition logs, meal plans, hydration, and targets.
- Menstrual-cycle tracking, including cycle and period length, period start dates, and flow and ovulation-test results imported from Apple Health.
- Every raw Apple Health (iOS) or Health Connect (Android) record the app reads. Raw health records are never copied off your device.
- Location, which is used only to compute distance during a live run. No route, coordinate, or map trace is ever transmitted.
- Microphone audio and speech. Wake-word detection and dictation run on-device wherever your device and language support it. On devices or languages where Apple does not offer on-device recognition, iOS falls back to Apple's server-side speech service and the audio is handled by Apple under Apple's terms.
- Prompts and responses from the free AI coach. On Apple platforms that is Apple Foundation Models plus a bundled local model; on Android it is Gemini Nano through ML Kit. No network is required.
- Debug and crash logs, kept as a local rolling file.
- Apple Watch data. The Watch app makes no network calls of its own.
What can leave your device
- Premium cloud AI (off by default, requires an active subscription). When you turn it on, requests go to RoxyKovu's own AWS service in the US East region, which calls Amazon Bedrock to generate the response. What is sent: an anonymous per-install device hash (a random value created on first launch, not a device identifier), your workout request details, your AI preferences, a role-scoped profile string that deliberately excludes the name you typed, and your App Store receipt or Google Play purchase token so we can confirm the subscription.
- Health-derived numbers, with Premium cloud AI on. So the coach can reason about recovery, requests include values your device computed: readiness score, sleep hours last night and on average, heart-rate variability, resting heart rate, muscle freshness, one-rep-max figures, and recent session history. These are derived summaries, not raw Apple Health or Health Connect records, but they are still health information and we treat them as sensitive.
- Coach chat, meal planning, and food parsing, with Premium cloud AI on. Chat sends your conversation history, which is everything you have typed to the coach in that conversation. Meal planning sends your calorie and macro targets, goal, day count, and any dietary preferences you typed. Food parsing sends the food description you typed.
- Voice command fallback, with Premium cloud AI on. If on-device planning of a spoken command fails, the transcript of that command is sent to the same service. Only a restricted, non-health tool set is available on that path.
- In-app feedback (off by default). Sends the anonymous device hash, your rating, the category, the message you typed, app version, platform, and device model. Kept for one year. On Android you can additionally tick a box to attach your local debug log. Rating an AI response also sends that exchange, up to 2,000 characters of your message and 2,000 of the reply, which can include whatever you typed to the coach.
- AI quality telemetry (same off-by-default toggle). Sends chat mode, which model answered, response time, whether you acted on the answer, timestamp, app version, platform, and the anonymous device hash. It sends no message content. Kept for 90 days.
- Optional iCloud Backup (off by default). Your data is encrypted on your device with AES-256-GCM and written to your own private iCloud, using a key stored only in your iCloud Keychain. RoxyKovu holds no key and cannot read it. Raw Apple Health records are excluded from the backup.
- Optional settings sync and database mirroring (both off by default). These use your own iCloud, not our servers, and exclude consent, health-permission, and feedback keys.
- Food lookup. The food name you type is sent to the USDA FoodData Central public API to find nutrition data. No device hash or identifier is attached.
- Update check. The app's bundle ID is sent to Apple's public app-lookup endpoint to see whether a newer version exists.
- Spotify (optional). If you connect Spotify for now-playing control, Spotify handles the sign-in. FFM does not store your Spotify credentials.
- Nearby workout sharing (you start it). A custom workout is sent straight to the other device over local peer-to-peer networking. There is no server in the middle.
- Purchases. Apple or Google processes payment. Your receipt or purchase token is checked against Apple's or Google's verification service. We never see your card details. On Android, a Google Play Integrity token is attached to cloud AI requests to prevent abuse.
- Android system backup. Android's own Auto Backup is enabled at its platform default, so Android may copy app data to your Google account independently of FFM. You can turn this off in your Android system settings under Backup.
On Mac, FFM has no Apple Health access at all. Health reading happens only on iPhone, iPad, and Apple Watch.
18.2 20 Questions (2Q)
The game and its AI opponent run on your device, and there is no 20 Questions account. 2Q is ad-supported on iPhone and iPad, so unlike the rest of our apps it does involve advertising and tracking. The Apple TV version shows no ads.
- Platforms
- iPhone, iPad, Apple TV, and an iMessage app
- Account
- None. Optional Game Center sign-in only.
- Ads
- Yes, Google AdMob rewarded ads you choose to watch. None on Apple TV.
- AI
- Runs on your device using Apple Intelligence.
Stays on your device
- Battle Mosey's reasoning. Prompts, your questions, and the model's answers are processed by Apple's on-device Foundation Models. No question you ask is sent to any AI service.
- Game progress, stats, coins, cosmetics, theme, nickname, and settings.
- iMessage secret words, which are encrypted at rest on your device. If encryption is unavailable the app refuses to store the word rather than saving it in the clear.
- The offline reference cache the AI reads from.
- Reminders, which are scheduled locally on your device rather than pushed from a server.
What can leave your device
- Advertising. Google AdMob serves the optional rewarded ads. Google and its certified partners may collect your advertising identifier, IP address, and ad-interaction data. Where the law requires it we show a consent prompt before personalized ads run, and on iPhone and iPad we present Apple's App Tracking Transparency prompt. You can revisit these choices from Legal, then Manage Privacy Options.
- Public reference lookups during Battle Mosey. When the answer is not in the bundled offline cache, the app requests the public Wikipedia and Wikidata pages for the secret item. The item's name goes in that request. The questions you ask never do.
- Feedback you send. Your message (up to 4,000 characters), the category, app version and build, platform, device model, timestamp, and a hashed anonymous install ID used only for rate limiting.
- Mosey accuracy telemetry (opt-in, off by default). If you turn on "Help Improve Mosey" in Settings, the app uploads records of how the AI decided an answer, and those records include the exact question you asked. Kept for 180 days. Leave the toggle off and nothing is uploaded; the same records are still kept locally so the in-app inspector works.
- Multiplayer and Group Play. Game state travels directly between devices over Apple's peer-to-peer networking, encrypted by Apple. There is no RoxyKovu server. The peer name shown to others is your device name or the nickname you set.
- iMessage games. Game state rides inside the iMessage conversation and is protected by iMessage's own encryption.
- Game Center and purchases. Handled by Apple if you use them.
- Voice input. Where on-device recognition is unavailable, Apple's speech service transcribes the audio under Apple's terms.
18.3 Numera Saga
Numera Saga plays entirely on your device and sends nothing to RoxyKovu. There is no account and no RoxyKovu server. Numera Saga succeeds SumSquare, which has been retired.
- Platforms
- iPhone and iPad, plus a home-screen widget
- Account
- None. Optional Game Center sign-in only.
- Ads
- Yes, but only the optional rewarded tile you choose to tap. Never forced, never full-screen.
- AI
- None. Puzzles and story are authored content shipped with the app.
Stays on your device
- Settings: theme, high contrast, symbol overlay, text size, sound and music volume, haptics, and daily reminder.
- Your profile: nickname, avatar, and cosmetic choices.
- Progress and stats: coins, wins, streaks, experience, achievements, story progress, star records, and codex entries.
- Any puzzle you have in progress.
- Widget state and locally scheduled daily reminders.
- A key in the device Keychain used to detect tampering with local saves, plus purchase transaction IDs. Both are marked device-only and excluded from iCloud and device transfer.
What can leave your device
- Rewarded ads. Google AdMob serves the ad when you tap the reward tile. Google and its partners may collect your advertising identifier, IP address, and ad-interaction data. Consent prompts are shown where required, along with Apple's App Tracking Transparency prompt.
- Optional iCloud progress sync (on by default, switchable off in Settings). Game state only: coins, streaks, win counters, achievements, unlock flags, nickname, cosmetics, story progress, experience, and volume. It goes to your own iCloud account, not to us. Turn it off in Settings and every sync path stops.
- Game Center and purchases. Handled by Apple if you use them.
Numera Saga has no analytics, no crash reporter, and no telemetry endpoint. Aside from the ad SDK, the app makes no network requests at all.
18.4 Terminally Online
Terminally Online makes no network requests of its own. Your save is encrypted on your device, and the only things that ever leave are Game Center scores and App Store purchases, both handled by Apple.
- Platforms
- iPhone and iPad
- Account
- None. Optional Game Center sign-in only.
- Ads
- None.
- AI
- None. Enemy behavior is hand-written game logic.
Stays on your device
- Your entire save: character, class, level, stats, run history, inventory, abilities, titles, currencies, and achievement flags.
- The save file is AES-GCM encrypted at rest, using a key generated on your device and held in your Keychain.
- The display name you type for your character. It is stored locally, never sent to Game Center, and never shown to other players.
- Display preferences and tutorial flags.
- A save that fails its integrity check is quarantined locally rather than deleted, so nothing is lost silently.
What can leave your device
- Game Center (optional). Scores and achievements go to Apple only if you are signed in. Decline and the game plays exactly the same without leaderboards.
- Purchases. Apple processes payment. We never see your card details.
- Your own iCloud (optional). The encrypted save blob and its key sync through your iCloud key-value store and iCloud Keychain so your progress follows you between your devices. Because the blob is encrypted with a key only you hold, the synced data is unreadable without your device.
The game contains no analytics, no crash reporter, no advertising, and no tracking prompt. It sells consumable in-app currency and includes a randomized draw mechanic that spends that currency. Deleting the app removes the local save, but the iCloud copy and Keychain key persist in your Apple account until you clear them there.
18.5 VitalQuest: Ascend
VitalQuest: Ascend is in development and has not been released. When it ships, this section will describe exactly what it collects, before it is available to download. It will display no advertisements.
18.6 Triage
Triage is built to keep your money data on your device. Your accounts, balances, and transactions are stored locally in an encrypted database. RoxyKovu does not receive, store, or have access to your financial data. There is no Triage account and no Triage server.
- Platforms
- Mac, iPhone, and iPad
- Account
- None. No sign-in of any kind.
- Ads
- None.
- AI
- On-device by default. Optional cloud AI is off unless you connect your own provider key.
Stays on your device
- Everything you enter or import: accounts, balances, transactions, budgets, promotional balances, and rules.
- On-device AI. Triage runs locally using Apple's Foundation Models or a local model you choose to install. Prompts and responses never leave your device on this path.
What can leave your device
- Optional cloud AI (off by default). If you turn it on and connect a third-party provider with your own API key, Triage sends redacted data to the provider you chose, under that provider's terms. For categorizing transactions that is transaction text: merchant or payee, amount, date, category, and last four digits. For the AI assistant it also includes a working summary of your finances: account names, balances and APRs, totals, income and spending by category, top merchants, recent transactions, and promotional balances. Full account, card, routing, Social Security, and IBAN numbers are removed first. That redaction is best effort and not guaranteed, and some providers, especially free tiers, may retain or train on what you submit. You can disable cloud AI and remove your key at any time.
- Exchange rates. If you hold balances in more than one currency, Triage downloads public exchange-rate data from the European Central Bank to estimate cross-currency totals. That request fetches rates only. It sends none of your accounts, balances, or transactions.
- Widgets and Live Activities (optional). A short financial summary, such as net worth, cash, debt, and the next payment or promotion, is shared with the widget so it can be drawn. It stays on your device, but it can appear on your Home Screen or Lock Screen where anyone who can see your screen can read it.
- Siri and Shortcuts (optional). Your spoken or typed request is processed by Apple's Siri under Apple's terms. The figure itself is read from data already on your device.
- Optional iCloud sync (off by default). Your data syncs through your own iCloud using Apple's CloudKit. The sensitive money fields are end-to-end encrypted, so neither Apple nor RoxyKovu can read them.
- Your device and its backups. Your data lives on this device, so anyone with access to your unlocked device or your device backup can see it. App Lock with Face ID or Touch ID and idle locking helps protect it.
- Exporting or sharing. If you export your data or use a share feature, you control where it goes and these protections no longer apply.
- Purchases. Apple processes payment. We never receive your card details.
- Connecting a provider or installing a model. Signing in to a provider or downloading a local model sends only connection information to that service, never your financial data.
RoxyKovu operates no Triage server and keeps no copy of your data, so in none of these cases does your financial data reach us. Triage contains no analytics, telemetry, advertising, or third-party tracking SDKs.
18.7 Vianta
Vianta brings AI to your Apple HomeKit smart home, entirely on your device. There is no account and no sign-in. Vianta collects no personal data, and it never transmits your home data to RoxyKovu or to any third party.
- Platforms
- Mac, iPhone, and iPad
- Account
- None. No sign-in of any kind.
- Ads
- None.
- AI
- Runs on your device. It makes no network calls.
Stays on your device
- Your HomeKit data, including accessory names, rooms, zones, scenes, and device states, is read and processed on your device only.
- The built-in assistant runs on Apple's on-device Foundation Models. Your requests and its responses are processed locally.
- The local interface. Vianta exposes a small interface that AI tools and scripts on the same Mac can use, including through the open Model Context Protocol. It is bound to localhost, active only while the app is open, and requires a secret token. It is not reachable from your network or from the internet.
What can leave your device
- Optional in-app feedback. If you choose Settings, then Send feedback, the text you type plus basic app and device information (app version, build, OS version, and device model) is sent over HTTPS to RoxyKovu so we can improve the app. This is the only outbound data Vianta sends. If you never send feedback, nothing leaves your device.
Vianta has no analytics, no advertising, and no third-party SDKs that collect data.
18.8 Naval Letter Builder
Naval Letter Builder drafts, formats, and exports correspondence entirely on your device. The only data that ever leaves is feedback you type and choose to send, plus any file you export yourself. There is no account and no server-side copy of your drafts.
- Platforms
- iPhone and iPad
- Account
- None. Optional Face ID or Touch ID app lock is local to your device.
- Ads
- None.
- AI
- The writing critics run on your device using Apple Intelligence, and can be switched off.
Stays on your device
- Every draft, stored in the app's private storage with iOS file protection applied. Drafts are not exposed to the Files app.
- Your saved defaults: letterhead and command lines, SSIC, originator, signer name, signature variant, your drawn signature image, and font and classification preferences.
- Dictation. Speech recognition is forced to on-device mode, and if your device cannot do on-device recognition the app reports an error rather than sending your audio to a server.
- Camera scans and photo imports. Text recognition runs locally through Apple's Vision framework.
- AI critic activity. Suggestions and rationale live in a short in-memory buffer that is never written to disk. Accept and skip counts stay in local settings and are never transmitted.
- Document generation. Word and PDF files are produced by an export engine bundled inside the app and run offline.
- Clipboard copies are marked local-only, so they do not travel to your other Apple devices through Universal Clipboard.
What can leave your device
- Feedback you send. The message you type goes to a RoxyKovu service in the US East region. The app warns you before sending. Do not paste classified or controlled unclassified information into the feedback box.
- Files you export or share. Once you export a document or hand it to another app, you control where it goes and this policy no longer governs it.
Naval Letter Builder has no analytics, crash reporting, advertising, or attribution SDKs, and no third-party packages at all. It does not disable Apple's system-wide Writing Tools or system keyboard dictation, so if you route text through those OS features, Apple's terms govern that text rather than ours.
18.9 EDEN
EDEN is professional clinical software, and it works differently from the rest of our apps: it is a client for an electronic health record, so clinical data is stored on RoxyKovu's secured infrastructure rather than only on the device. Speech recognition and the Eden assistant still run entirely on the device. EDEN is licensed to healthcare practices, not sold to consumers.
- Platforms
- iPhone, iPad, and Mac
- Account
- Required. Issued by your practice, with multi-factor authentication supported.
- Ads
- None.
- AI
- Inference runs on your device. There is no third-party or cloud AI provider.
Stays on the device
- Speech recognition. Dictation and the wake word are forced to on-device mode, so raw audio is not sent to Apple or to us.
- Wake-word detection and its personalization, which use a bundled model retrained locally. Voice enrollment samples never leave the device.
- The Eden assistant's reasoning, which runs on Apple's on-device Foundation Models. There is no OpenAI, Anthropic, Google, or other external model provider in the app.
- Document scanning, scanned-lab text extraction, and before-and-after photo comparison, all processed locally.
- Conversation memory with Eden, written to an encrypted local file that is excluded from device backups.
- Sign-in tokens, held in the device Keychain, marked device-only so they never sync to iCloud. Passwords are never stored on the device.
- Recently viewed and open charts, cached per device and never synced to the server.
- When the app is backgrounded or locked, caches, temporary files, and the pasteboard are cleared.
What leaves the device
- Clinical data, by design. Patients, encounters, problems, allergies, medications, orders, labs, prescriptions, billing, scheduling, messages, and tasks live on RoxyKovu's AWS infrastructure in the US East region, encrypted in transit and at rest. This is what an EHR is; the record has to outlive any one device.
- Sign-in. Credentials and multi-factor codes are sent over TLS to the EDEN authentication service.
- Ambient scribe output. The encounter transcript and the generated note, suggested codes, and draft summary are uploaded and attached to the encounter. The audio itself is never uploaded; the text is.
- Files and images. Clinical photos, encounter photos, insurance cards, intake signatures, lab images, chat attachments, and documents upload to RoxyKovu's private storage.
- Audit trail. Every access to protected health information is logged with who, what, and when, as HIPAA requires.
EDEN carries no analytics, crash reporting, attribution, or advertising SDKs, and no tracking prompt. Clinical data in EDEN is not end-to-end encrypted: the service can process stored records, which is what makes server-side search, auditing, and practice-wide access possible. Section 5.6 covers how we handle clinical health data and HIPAA obligations.
18.10 Clara
Clara holds the people you track, their details, your gift ideas, and your never-give rules on your device and in your own private iCloud. The AI runs on your device, there are no analytics or advertising SDKs, and no RoxyKovu server stores your records. Clara has not been released yet; this section describes the app as built and will be updated at launch.
- Platforms
- iPhone, iPad, and Mac
- Account
- None. Your own iCloud account is the only identity.
- Ads
- None.
- AI
- Runs on your device using Apple Intelligence. No cloud AI provider, no API key.
Stays on your device
- Everything you record: people, relationships, birthdays and occasions, profile fields, gift ideas, notes, reminders, budgets, gift history, circles, and household tasks, written to encrypted local storage.
- Never-give rules and dislikes, which are enforced locally.
- Photos, avatars, and mood-board images you add.
- Contacts import reads only the single contact you tap. Clara never reads through your address book.
- All AI prompting and generation, using Apple's on-device Foundation Models with plain non-AI fallbacks when Apple Intelligence is unavailable. Anything the assistant proposes to change requires your explicit confirmation first.
- Reminders and occasion alerts, scheduled locally on your device.
What can leave your device
- Your own iCloud (on by default, switchable off). Your records sync to your own private iCloud so they follow you between your devices. This is your Apple account, not a RoxyKovu server, and no other person can read it. Clara uses standard CloudKit protection rather than app-level end-to-end encryption, so whether it is end-to-end encrypted depends on your iCloud Advanced Data Protection setting.
- Sharing with another person (off by default). When you turn sharing on, only the profile fields you wrote about yourself and your own avatar become readable by the people you invite. Your gift planning, ideas, notes, and activity stay private to you. That surprise-protection boundary is enforced in code and covered by tests. Inviting someone sends their email address to Apple so it can resolve their iCloud account.
- Beta diagnostics (TestFlight builds only, on by default with an opt-out in Settings). During the beta we upload roughly once a day: a random per-install identifier, app version, platform, OS version, device model, and events. Be aware that AI events include the exact text of your Ask Clara request, up to 2,000 characters, along with a first name when that name appears in what you typed. If you type "add a Kindle for Mom's birthday," that sentence reaches our storage. Non-AI events carry shape only, never names or field values. This is switched off in Settings under Diagnostics, and it does not exist in App Store builds.
- Feedback you send. The category, your message (up to 4,000 characters), a random per-install identifier, app version, and platform. None of your records are attached.
- Discover product search. Search terms go to a RoxyKovu service that queries a merchant catalog on your behalf. Terms come either from what you typed or from a person's interests, with the person's name stripped and never-give conflicts removed before the request. Interest keywords leave the device; names and profile records do not.
- Product images and merchant links. Product thumbnails load directly from merchant image servers, so those servers see your IP address. Tapping a product opens the merchant's page in your browser as an ordinary web visit.
- Voice input. Speech recognition prefers on-device transcription but does not require it, so on some devices and languages Apple's speech service transcribes the audio under Apple's terms.
Clara links no third-party SDKs at all. There is no advertising, attribution, or crash-reporting library, and no affiliate redirect service is currently in use.
18.11 PatchShepherd
PatchShepherd is a Windows desktop utility that finds outdated software on your PC and helps you update it. It has no analytics and no telemetry: it never reports your activity, and it never sends your list of installed applications to us. The only information that reaches RoxyKovu is feedback you choose to type and send.
- Platforms: Windows 10 and newer, through the Microsoft Store.
- Account: none with RoxyKovu. There is no sign-in and no license key. Pro is a one-time purchase, and your entitlement is checked through Microsoft Store licensing using the Microsoft account you are already signed in to.
- Ads: none.
- Analytics and telemetry: none. There is no analytics, telemetry, or crash-reporting component in the app, and nothing is sent automatically to report how you use it.
Stays on your device
- Your scanned software inventory, available updates, health scores, and update history.
- Your settings, including theme, language, scheduled scans, and the record that you accepted the terms. These live in the Windows registry under your user account and in the app's own folder in your local application data.
- A local activity log, kept on your PC, that records the package-manager commands the app ran and the applications it detected.
- PatchShepherd does not collect your computer name, your Windows username, your domain, or a hardware inventory.
What can leave your device
- Feedback you send. If you open Settings and send feedback, we receive the message you typed, a randomly generated identifier for your installation (not tied to you or to your hardware), the app version, your Windows version, and a timestamp. It is handled by our own Amazon Web Services endpoint in the US East (Ohio) region, which also sees your IP address as part of the connection.
- The optional diagnostic log attached to that feedback. The feedback dialog offers to attach a copy of the local activity log, and that box is ticked by default. If you leave it ticked, the log is encrypted and uploaded with your message. It contains recent app activity, including the commands PatchShepherd ran and the applications it detected on your PC. Untick the box if you would rather not send it.
- Version lookups for .NET tools. During a scan, including a scheduled one, PatchShepherd asks nuget.org for the current version of each .NET global tool you have installed. Only the package name is sent, but nuget.org sees your IP address.
- Windows Update checks. When Windows Update scanning is enabled, the Windows Update agent contacts Microsoft in the normal way.
- Package manager traffic. To find and install updates, PatchShepherd runs the package managers already on your PC, such as WinGet, the Microsoft Store, Chocolatey, Scoop, PowerShell Gallery, npm, and pip. Each contacts its own official repositories directly and sends whatever it normally sends, which includes the names of the packages being checked. We do not route or copy that traffic.
- Installing a package manager. If you ask PatchShepherd to set up Chocolatey or Scoop for you, it downloads and runs that project's official install script from that project's own website.
- Optional AI access, off by default. PatchShepherd can expose your update list, installed software, and update history to an AI assistant running on the same PC, through a local interface. It is off until you turn it on, and where that assistant then sends the information is governed by whichever assistant you chose.
- Pro purchase. Microsoft processes the payment and the entitlement check. We never see your card details.
PatchShepherd needs administrator rights to install updates. That is a consequence of what the app does, not a way of collecting information about you.
19. Contact us
If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:
- Email: Support@roxykovu.com
- Website: roxykovu.com/contact-us
- Company: RoxyKovu LLC, Charlotte, North Carolina, USA
We aim to respond to all privacy inquiries within 30 days. For requests under specific privacy laws (GDPR, CCPA, etc.), we will respond within the timeframes required by applicable law.