the fine print · 1 of 3

privacy
policy.

Last updated: July 12, 2026

The honest summary: as a visitor you give up nothing — no public forms, no visitor accounts, no analytics, no cookies to consent to. (There is one private, invitation-only operator console for the founder; it processes no visitor data — see Section 4.) The app keeps your trips on your device, and when you plan it sends the triprequest through our own backend to AI services, runs no ads, no analytics and no trackers, and never sells anything about you. Everything below is the detail behind that sentence.

1. Who is responsible (controller)

roam o'clock is operated by Mark Szegner ("we", "us", the "controller" in the sense of Art. 4(7) GDPR). For every question about your data — including all requests under Section 8 — contact szegnermark@gmail.com. We respond within one month, as Art. 12(3) GDPR requires.

2. What this policy covers

Two things: (a) this website — the public pages are purely informational and collect no visitor data; a private, allowlisted operator console (for the founder only) is described in Section 4 — and (b) the roam o'clock app and watch face (currently in pre-release), described below so you can see exactly how they behave before launch.

3. The website: no cookies, no analytics

This site does not set advertising or analytics cookies and does not fingerprint or track you — which is why there is no cookie banner: there is nothing to consent to. Technical delivery (serving pages over TLS, DDoS protection) is provided by our hosting chain (Lovable as the deployment platform, with Cloudflare in front). Web servers process IP addresses transiently as a technical necessity of the HTTP protocol; our legal basis for that is Art. 6(1)(f) GDPR (legitimate interest in operating a secure website). Client-side error reports (a crash on the page) may be sent to the hosting platform to help us fix bugs; they contain technical error details, not form contents.

4. No waitlist, no newsletter, no visitor forms — by design

There is deliberately no public form on this site that asks for your name, email address, or any other personal detail. We removed the early waitlist precisely to keep it that way (any addresses collected during that brief period have been deleted). The only "processors" involved in serving the public site are its hosting chain — Lovable as the deployment platform with Cloudflare in front — whose transient technical processing is described in Section 3. We hold no database of visitors.

The one exception is a private operator console (a hidden admin area for the founder to manage the service). Signing into it is invitation-only: sign-in links are sent only to email addresses on a fixed internal allowlist; any other address entered is silently discarded and stored nowhere. It holds operational data only — the service's own configuration, plus anonymous, non-identifying app statistics (which cities are planned, review counts) that contain no visitor identity or IP. It contains no personal data about site visitors, and you never interact with it.

5. The app: your data stays on your device

The app requires no account and creates none. The following live exclusively in app-private storage on your phone or watch and are erased when you uninstall or clear storage:

  • Trips and itinerary history
  • Your taste profile (food styles, activities, budget, rhythm, free-text notes)
  • Venue reviews you write (stars + comments) and the credits they earn
  • Credit balance and settings (theme, clock format)
  • An API key, only if you switch to optional bring-your-own-key mode (not the default)

The itinerary syncs to a paired Wear OS watch over Google's local Wearable Data Layer — a direct Bluetooth/on-device link between your phone and watch. It is not routed through our servers.

6. The app: what leaves your device, and when

Data leaves your device when you ask Romi to plan, re-plan, or verify a trip — and, separately, only if you choose to report an AI suggestion (see the end of this section). The planning request contains the city, dates, your taste-profile text, an optional accommodation address if you chose to enter one, and your own past venue ratings for that city. It goes first to our own backend, which then calls the AI providers on your behalf using our keys:

  • Our relay — a small server we operate on Cloudflare Workers. It receives your request, attaches our API keys, and forwards it to the providers below. It is a pass-through: it does not store your trip or attach any account, name, or advertising ID to it.
  • Anthropic (Claude API) — generates the itinerary; requests may use Anthropic's server-side web search to check that venues are current. Under Anthropic's API terms, API inputs are not used to train models.
  • Google (Gemini API with Maps grounding) — cross-checks venue names, ratings, and opening status. It runs server-side through our key as a best-effort step that never blocks your plan.

These requests carry no account ID and no advertising identifier. The legal basis is performance of the service you explicitly trigger (Art. 6(1)(b) GDPR): you tap "plan", we plan. Step counting for the "steps today" card happens entirely on-device and is never transmitted — which is also why the Play Store data safety form lists it as "not collected".

Everydays never leave your device. Days you build by hand — in everydays mode or as manual trip days — involve no AI and no network: they are created, stored, and edited on your phone and synced only to your own paired watch. Nothing about your daily life touches our relay or any AI provider.

The app requests no location permission. Navigation is handed to Google Maps with the venue's coordinates, not yours; from that point Google's own privacy policy applies, as it does for any external link you tap (OpenTable, GetYourGuide, Uber).

Reporting an AI suggestion. Every AI-planned stop has a "report this suggestion" option. If — and only if — you use it, we receive the reason you picked, any note you add, and the stop's venue, area, and city, so we can review and improve what Romi suggests (Google Play requires apps that generate content with AI to offer this). The report carries no account, name, or advertising ID. It is stored on our relay and automatically deleted after 30 days. This is the one piece of app data that uninstalling does not erase, because it is no longer only on your device — please don't include personal details in the note. To have a report removed sooner, email the controller (section 1).

7. What changes at launch (and will be announced first)

  • Purchases: credit packs will be sold through Google Play Billing. Google processes the payment; we never see card numbers — only a purchase token to credit your balance.
  • A credits ledger & abuse checks: our backend (described in Section 6) will add a server-side credits ledger and integrity checks, plus anonymous, non-identifying planning statistics (which cities are planned — no visitor identity, no IP). This policy will be kept current as those go live.
  • Community venue ratings: a future, separately announced opt-in may share anonymized venue ratings (venue, city, stars — not your identity) to improve everyone's plans. It will be off by default.

8. Your GDPR rights

You can, at any time and free of charge:

  • Access the data we hold about you (Art. 15) — which, for this website, is nothing: there is no visitor database
  • Have any data corrected (Art. 16) or deleted (Art. 17)
  • Restrict processing (Art. 18) or object to processing based on legitimate interest (Art. 21)
  • Receive your data in a portable format (Art. 20)
  • Withdraw any consent at any time (Art. 7(3)) without affecting past processing
  • Complain to a supervisory authority (Art. 77), in your own EU member state if you prefer

For app data there is usually nothing for us to hand over or delete: it is on your device, under your control, and uninstalling removes it.

9. Security

The public site is served exclusively over TLS and stores nothing about visitors — there is no visitor database to breach. Operator data (the private console) sits behind allowlisted, single-user authentication with row-level access control; provider API keys live only in the backend relay's encrypted secrets, never in the console or the browser. The app keeps its data in Android app-private storage, isolated by the OS from other apps. No system is perfect — if a breach ever affects your data we will notify the supervisory authority within 72 hours (Art. 33) and, where required, you (Art. 34).

10. Children

Neither the site nor the app is directed at children under 16, and we do not knowingly process their data — which, with no visitor accounts and no public forms, is structural rather than aspirational.

11. Changes to this policy

When the policy changes — for example when the backend or community features launch — the "last updated" date above changes with it, and material changes will be highlighted here and in the app's release notes. Questions, requests, complaints: szegnermark@gmail.com.