Effective date: September 3, 2026 | Developer: Jan Aguja
This Privacy Policy describes how the ROLL app ("the app", "we") handles your information. ROLL is built around a simple premise: everything you put in your vault stays on your device, encrypted, and under your control. We do not operate any servers, and the app has no concept of a user account.
1. Information We Collect
We do not collect anything. ROLL has no backend, no analytics SDK, no crash reporting, and no advertising network. The app cannot identify you, and nothing about your usage of it is ever transmitted anywhere.
2. What's Stored On Your Device
Vault content. Photos, videos, and files you add to a vault are encrypted with AES-256-GCM using a key generated on your device and stored in your device's secure hardware-backed storage (Android Keystore / iOS Keychain). This key never leaves your device and is not accessible to us or to any other app.
Your vault code(s). The codes for your real vault and, if you set one up, your decoy vault are stored as salted, iterated hashes — never in plain text, and never anywhere but your device.
Album names. Folder/album names you create are stored locally in an unencrypted manifest file, since they contain no photo, video, or file content — only the organizational names you choose.
An optional hint. If you set a hint for your real vault's code during setup, it's stored locally on your device and shown only after you long-press the disguise screen's help icon.
3. Local Wi-Fi Import (Optional)
When you open this feature, the app starts a temporary local web server for the sole purpose of receiving the files you drag onto the page it serves. That server stops the moment you close the screen. No data is sent anywhere beyond your own local network, and the transferred files are encrypted into your vault the same way any other import is.
4. Backups
ROLL lets you export a vault to a single password-encrypted file
(.rollbackup) so you can keep a copy somewhere of your choosing —
a cloud drive, external storage, another device. The app itself never uploads
this file anywhere; where it ends up is entirely your decision, made through
your device's own share or save dialog. Restoring a backup requires the
password you set when creating it — we do not store or have access to that
password.
5. Third-Party Services
ROLL does not integrate any third-party analytics, advertising, or tracking SDKs. It does not use Google Sign-In or any other authentication provider, because there is no account to sign in to.
6. Permissions
Photo/media library access. Used only to let you pick photos and videos to add to a vault, and — if you choose to "Unhide" an item — to save it back out. ROLL never scans or accesses your photo library except when you're actively importing or exporting through the app's own picker.
Local network access. Used only for the optional PC/Mac import feature described in Section 3, and only while that screen is open.
7. Data Retention and Deletion
Everything ROLL stores lives in the app's private, sandboxed storage on your device. Deleting an item inside the app removes its encrypted blob immediately. Uninstalling the app, or clearing its data through your device's system settings, removes everything — there is no account or server-side copy for us to delete, because none exists.
8. Children's Privacy
ROLL is not directed at children under 13. We do not knowingly collect personal information from children — in fact, as described above, we do not collect personal information from anyone.
9. Changes to This Policy
We may update this policy from time to time. The effective date at the top of this page will be updated accordingly. Continued use of the app after changes constitutes acceptance of the updated policy.
10. Contact
For any privacy-related questions, contact:
Jan Aguja
[email protected]