Privacy Policy
Last updated
The short version
- Roster Report for Mac reads Messages on your Mac. It syncs message text only for people you put on your roster.
- For everyone else, we get a name, a number or email, and when you last talked. Never what was said.
- Message text is encrypted at rest (AES-256-GCM) and in transit (TLS).
- We use OpenAI’s GPT models, through Vercel AI Gateway, to power the assistant. Nobody trains models on your messages.
- We don’t sell your data, show ads, or share it with data brokers.
- Delete your account and we delete your data within 30 days.
This policy explains how Roster Report (“Roster Report”, “we”, “us”) handles information when you use our website, the Roster Report web app, Roster Report for Mac, and Roster Report over iMessage (together, the “Service”). We’ve tried to write it the way we’d explain it to a friend, because that’s what the product is for.
What we collect
Information you give us
- Account details: your name and email address. If you sign in with a passkey, we store the passkey’s public key. Your fingerprint or face never leaves your device, and we never see it.
- Your roster and notes: the people you add, the names and emoji you give them, and anything you tell Roster Report about them.
- Messages to Roster Report: what you text Roster Report (in your note-to-self thread or, on Pro, to Roster Report’s own number) and what it replies.
- Screenshots you import: if you upload a screenshot of a conversation from a dating app, we process the image to extract the conversation and profile details, and store the extracted text.
- Your work calendar (optional): if you add a private calendar (.ics) link, we fetch it periodically and use event times to spot conflicts.
- Billing: if you subscribe to Pro, Stripe processes your payment. We receive your subscription status and a customer reference, not your full card number.
Information collected automatically
- Device information: for each paired Mac, its name, macOS version, the Roster Report for Mac version, and when it last synced.
- Session and log data: IP address, browser or user agent, and request logs, used for security, debugging and abuse prevention.
What Roster Report for Mac syncs
Roster Report for Mac runs on your Mac and reads the Messages database and your Contacts there, with the Full Disk Access permission you grant. What it sends to us depends on whether someone is on your roster:
| Not on your roster | On your roster | |
|---|---|---|
| Name (from Contacts) | Yes | Yes |
| Phone number or email | Yes | Yes |
| When you last talked, who sent last, message count | Yes | Yes |
| Message text | No | Yes, encrypted |
| Attachments | No | Type or file name only, never the file |
Only one-to-one conversations are included. When you add someone to your roster, Roster Report syncs a limited window of recent history so it has context. Our servers also discard message text for anyone who isn’t on your roster, as a second safeguard.
When you ask Roster Report to send a message, the text is queued on our servers until your Mac picks it up and sends it through Messages.
How we use it
- To run the features you use: your roster, memory, reminders, suggested replies, Tone Control, Name Guard, double-booking and duplicate detection, the excuse tracker, archiving, and the daily report.
- To reply when you text Roster Report, and to send messages you ask it to send.
- To manage your account and subscription, and to keep the Service secure.
- To contact you about your account, security, or changes to these terms. No marketing email without your opt-in.
We don’t read your messages. Access to production data is limited to a small number of people, and only when needed to investigate a problem you report or a security issue. Because message text is encrypted in our database, even that takes deliberate steps; nobody browses it.
AI processing
Roster Report’s assistant, suggestions and memory are powered by OpenAI’s GPT models. We send requests through Vercel AI Gateway. A request includes only what’s needed for the task, for example the recent messages with the person you’re asking about, plus relevant things Roster Report remembers about them.
We don’t train AI models on your messages, and our AI providers don’t either. They process requests to return a response to us under terms that prohibit using that data to train their models.
Where it’s stored and how it’s protected
- The Service is hosted on Vercel, and our database runs on Neon (Postgres), both in the United States.
- Everything travels over TLS.
- Message text is encrypted by our application with AES-256-GCM before it’s written to the database, on top of the storage encryption our providers use. For duplicate and excuse detection we store a keyed hash of each message, which lets us spot repeats without decrypting anything.
- Each paired Mac has its own revocable token. You can unpair it from your dashboard at any time.
- Passkey sign-in means there’s no password to phish or reuse.
No system is perfectly secure. If we ever learn of a breach affecting your data, we’ll tell you promptly.
Who else processes it
We use a small number of service providers (“subprocessors”) to run Roster Report:
| Provider | What for | Location |
|---|---|---|
| Vercel | Hosting, serverless functions, scheduled jobs, logs, AI Gateway | United States |
| Neon | Postgres database | United States |
| OpenAI | AI models (GPT), via Vercel AI Gateway | United States |
| Stripe | Payments and subscriptions (Pro only) | United States |
| Hosted iMessage provider (e.g. Sendblue or Linq) | Roster Report’s own number, only if you turn it on (Pro only) | United States |
If we add or change a subprocessor, we’ll update this list.
What we don’t do
- We don’t sell or rent your data.
- We don’t use your data for advertising, and we don’t share it with data brokers.
- We don’t train AI models on your messages.
We will disclose information if the law requires it, for example in response to a valid court order. Where we’re allowed to, we’ll tell you first. If Roster Report is ever acquired or merged, this policy continues to apply to your data, and we’ll let you know before anything changes.
Retention and deletion
- We keep your data while your account is active.
- Removing someone from your roster deletes their synced message text and what Roster Report remembered about them. Their directory entry (name and last-talked date) stays while that Mac is paired.
- Archiving a thread (manually, or after 47 quiet days) hides it. It doesn’t delete it.
- Deleting your account deletes your data from our live systems within 30 days. Backups roll off within a further 30 days.
- Server logs are kept for up to 30 days. Billing records are kept as long as tax and accounting law requires.
You can also uninstall Roster Report for Mac at any time. It stops syncing immediately.
Your choices and rights
Wherever you live, you can ask us to access, export, correct or delete your data, or to stop processing it. Much of this you can do yourself from your dashboard; for anything else, email privacy@roster.report. We’ll respond within 30 days. Depending on where you live (for example, the EU, UK or California), you may have additional rights, including the right to complain to your local data protection authority. We don’t “sell” or “share” personal information as those terms are defined under California law.
The people you text
The people on your roster didn’t sign up for Roster Report. We process their messages only on your behalf, to provide the Service to you, and we hold ourselves to the same protections described here. You’re responsible for using Roster Report in a way that’s lawful and fair to them; see our Terms of Service.
If you think your messages are being processed through someone’s Roster Report account and you’d like them removed, email privacy@roster.report. We’ll do what we reasonably can.
Cookies
We use cookies that are strictly necessary to keep you signed in and to protect your account. We don’t use advertising or cross-site tracking cookies.
Children
Roster Report is for adults 18 and over. We don’t knowingly collect data from anyone younger. If you believe a minor is using Roster Report, contact us and we’ll delete the account.
Changes to this policy
If we change this policy, we’ll update the date at the top. If a change is significant, we’ll tell you by email or in the app before it takes effect.
Contact
Questions, requests or concerns: privacy@roster.report. A person will answer. Roster Report always texts back, and so do we.