Privacy at Room of Days

Last updated August 23, 2026

Your device is the source of truth. Room of Days works without an account, advertising, or analytics.

Data on your device

Your quests, goals, progress, journal text, preferences, and space are stored locally. Room of Days does not upload journal photos to its cloud backup or shared spaces. Your operating system may include local app data in device backups you choose to enable.

Cloud backup and optional account

Cloud backup is off by default. If you turn it on, Room of Days creates an anonymous Firebase session and mirrors your save to Cloud Firestore. That save can include your quests, goals, journal writing, game progress, and workout or other activity progress; it does not include journal photos. Publishing a shared space, keeping one in your Circle, or sending a preset support signal may also create an anonymous Firebase session, but merely opening a room code does not. None of these actions turns on full-save backup. If you create an account, Firebase Authentication stores your email and links the cloud save to your sign-in so it can follow you across devices. Firebase Authentication may process an IP address and basic app/device metadata to secure authentication and operate the service. Firebase acts as a service provider. Room of Days does not sell data, derive location from that metadata, or use it for ads or tracking.

Health and wellness

Room of Days offers general fitness and wellness guidance. It is not a medical device and does not diagnose, treat, cure, or prevent any medical condition. If you enable cloud backup, your save may include quest or goal titles and completion records about exercise, sleep, meals, medication, stress, or other routines you choose. Room of Days does not read HealthKit, Health Connect, heart-rate or body-sensor data, or location. Device tilt, when available, only changes visual depth and is not stored or uploaded. Consult a qualified healthcare professional for medical advice, diagnosis, or treatment.

Schedule, locations, and optional Google place search

Room of Days does not request or access your current location. Manual schedule and location details stay on your device and remain outside Cloud Firestore, including saved names, routing text, buildings, and room numbers.

Place search is optional, off by default, and starts only after you choose Search places with Google and accept its local consent prompt. For an active search, Room of Days sends your typed search query, a random search-session token, the app language, and, after you choose a result, the selected Google provider place ID to Google through a protected Room of Days service. Room of Days does not send your manual schedule fields or current location with these requests.

Accepted place search creates or reuses a Firebase identity and uses a retained random installation ID for service abuse and cost controls. The installation ID is app-generated and is not a hardware or device ID. The per-identity and per-installation abuse counters are marked to expire 35 days after the last update for security and abuse prevention and cost control. Firestore deletes expired documents asynchronously afterward.

Firebase App Check also protects these requests. It uses Play Integrity on Android, App Attest with DeviceCheck fallback on Apple platforms, and reCAPTCHA v3 on the web. The platform provider and Firebase process app or device attestation material to issue an App Check attestation token. The app sends that token with the callable request for security and abuse prevention, not advertising or analytics.

Google’s returned display name and address are transient, are shown only while you are using the editor, and are not persisted by Room of Days. A saved selection keeps only the provider, provider place ID, your exact typed query as its saved name, and any routing, building, or room text you write yourself. Room of Days does not use place-search queries for advertising or analytics.

Use Me → Your account → Turn off place search to withdraw place-search consent on this device, including while using linked-account or cloud-backup features. The app checks the cacheless consent record before and after every provider request, so this stops future requests from another open browser tab and discards a provider result if consent is withdrawn while that request is in flight. Another tab may continue to show a previously rendered transient result until you next interact with it. You can accept again later. Withdrawing consent clears the local consent choice, but does not delete your Firebase account or retained installation ID, and it does not immediately delete existing abuse counters.

In a place-search-enabled installed build, after the owner-only room cleanup rules are active, a separate remove private service identity control appears under Me → Your account when backup is off and the current identity is anonymous. It is not shown in the web app. Before deleting that Firebase Auth identity or its save document, a protected callable creates or refreshes a service identity deletion tombstone for the Firebase UID. Firestore and Storage rules use that tombstone to block new save, shared-room, media, Spark, and Circle writes from other open app instances and late Firebase tokens. The app then uses an owner-only server lookup to find shared rooms carrying that immutable identity. For each confirmed room, a server deletion lock prevents new room updates and new private Spark and Circle receipts while the existing receipts are cleared from the server; the room and lock are then deleted together. The app repeats the server lookup until no owned room remains. If App Check, tombstone creation, the lookup, server deletion lock, cleanup, or identity check cannot be confirmed, the identity is kept so you can retry while place search stays off. This removes only rooms the server lookup can authoritatively identify as owned by that identity.

This separate removal does not delete your on-device Daybook, progress, manual or saved locations, map preference, or journal media. The retained installation ID stays on your device. The service identity deletion tombstone remains after Auth deletion and is marked to expire 35 days after it is created or refreshed; Firestore deletes the expired document asynchronously afterward. Abuse counters associated with that ID remain marked for expiration based on their last update and Firestore deletes them asynchronously.

Shared spaces, visitor pages, and Discover

Sharing is optional. A shared space contains your level, an app-generated build title, preset room appearance, and broad app-generated activity signals. The room itself is generated-only: it does not publish your private Me display name, profile-card text, goals, Journal writing, season writing, or photos to visitors. Shared spaces also exclude quest details, streak history, email, sign-in credentials, and account-profile details. The visitor-readable room carries an opaque keeper key. A separate private ownership record carries the Firebase owner ID so security rules can restrict changes; visitors never receive that raw ID. Anyone with the room link can view the generated room until you stop sharing from the same controls that show your code.

A visitor page is a separate, optional publication. You choose which bounded cards to publish and choose an audience for them. Anyone who opens the exact room code, including someone arriving from Discover, can see only your Anyone cards. Mutuals cards are added only after both people have independently kept each other in Circle; a block in either direction removes that access. Only me cards are never sent to a visitor. Your public name is included for an audience only when that audience can see at least one selected card. Visitor-page projections carry the selected, bounded card content and an opaque owner key, never your raw Firebase UID. Journal photos remain private.

Discover is a separate opt-in. Turning on Make my space discoverable adds a small directory card containing the room code used to open the shared space, an optional public name that you enter separately, app-generated title and level, preset room appearance, a randomizing bucket, an opaque stable keeper key derived from the anonymous owner ID, and update and expiration times. The keeper key is not shown in the interface; it lets a block continue to hide the same keeper if their room code changes. It is not used for advertising or analytics. The directory never contains visitor-profile card text. Quests, Journal pages, streaks, private Me cards, email, and account details are never copied into it.

Opening Discover creates or reuses an anonymous Firebase session and retrieves a small, shuffled handful of unexpired directory cards. Tapping a card then retrieves that shared room. A listing is marked to expire 30 days after it is created or refreshed, and Firestore deletes expired listings asynchronously. Turning Discover off or stopping sharing removes the listing immediately when the request succeeds.

A public name is optional, may be cleared, and is separate from the name on your private Me page. Public names and visitor-card content are normalized and filtered; links and contact details are prohibited. The protected services limit how quickly public names can change and use Firebase App Check for abuse prevention. People can block a keeper on their device or privately report inappropriate visible content, impersonation, or another safety problem. Relationship and block data remain private. A report stores the reporting Firebase identity, room and owner identifiers, category, relevant visible-content snapshot, and timestamps needed for human review. Reports are not shown to the reported keeper and are retained only as needed to investigate abuse, enforce the rules, and protect the service. See the community rules and safety guide.

If you keep someone else’s room in your Circle or send a preset support signal, Firestore stores a fixed, text-free receipt with a timestamp and your anonymous Firebase user ID. Only that room’s owner can read or clear it. No custom message, profile text, or contact information is attached.

Deletion and control

You can export or reset your data from Me → Your save is yours. A reset removes prior on-device data, journal photos, the local usage log, any shared space, and the old cloud save. A signed-in account stays signed in and receives a fresh blank cloud save; a guest backup deletes its old anonymous Firebase identity before starting a fresh blank guest. If the network interrupts cleanup, the app keeps the old guest credential and opaque room code only long enough to retry, rather than leaving shared data behind with no owner able to remove it. Signed-in users can permanently delete their account from Me → Your account → Delete account. Linked-account deletion removes the Firebase sign-in, cloud save, and the currently known shared room, clears on-device app data as the confirmation warns, turns cloud backup off, and leaves the app device-only. If you cannot access the app, the account deletion guide provides a direct email request path.

Permissions

Photo and camera access is used only when you choose to attach media to a journal entry. Notification permission is used only when you enable local reminders. Room of Days does not track you across apps or websites.

Get support.

Terms of use.