RoastBot — Privacy Policy

Last updated: 29 July 2026 · Effective: on first publication

RoastBot is published by Sycamore Hill Studios. This policy explains exactly what the app collects, why, and how to remove it. It describes the app as built — not a generic template.

The short version. There is no account and no sign-up. We do not ask for your name, email, or phone number. We do not use advertising, analytics, or tracking SDKs. What you type is sent to our server to generate a roast, and is not used to build a profile of you.

1. What we collect

DataWhyHow long we keep it
A random device identifier
A randomly generated UUID created on first launch.
To count your daily free usage and to remember whether you have a subscription. It is not your device's hardware ID, advertising ID, or any other identifier that follows you between apps. Until you delete your data or uninstall the app.
What you type
The description you enter, plus the style, relationship and spice level you choose.
Sent to our server, which passes it to Microsoft Azure OpenAI to generate the roast. Not stored as a record of you. Server logs may retain a truncated copy (first 200 characters) for up to 30 days to diagnose failures.
Subscription status
Whether your subscription is active, in a trial, or lapsed, and when it expires.
To unlock paid features. Verified directly with Google Play. Until you delete your data or the subscription record expires.
Usage counts
How many roasts you have generated today.
To enforce the free daily allowance. Rolling daily counters; removed when you delete your data.
Content reports
If you report a roast: the reason, an optional comment, and an identifier for the reported content.
To review and improve safety filtering. Required by Google Play's AI-generated content policy. 180 days.

2. What we do not collect

3. AI-generated content

Roasts are generated by an artificial intelligence model (Microsoft Azure OpenAI). Output is produced automatically and is not reviewed by a person before you see it. It may occasionally be inaccurate, odd, or not to your taste. Every roast has a Report button; reports are reviewed and used to improve filtering.

RoastBot is designed for consensual comedy about habits and quirks. The server refuses requests that target protected characteristics, minors, or real identifiable individuals, and refuses slurs at every spice level.

4. Who processes your data

We do not sell your data, and we do not share it for advertising.

5. Deleting your data

Open Settings → Delete my data in the app. This removes the usage counters, the subscription mapping, and the device identifier held for you, along with anything saved on the device. It takes effect immediately.

Deleting your data does not cancel a subscription — subscriptions are managed by Google Play. To cancel, use Settings → Manage subscription, or the Subscriptions section of the Play Store app.

You can also email sycamorehillstudios@outlook.com and we will delete anything associated with your device.

6. Children

RoastBot is not directed to children. Its humour is intended for a teen and adult audience, and it is not part of Google Play's Designed for Families programme. We do not knowingly collect data from children under 13. If you believe a child has used the app, contact us and we will remove the associated data.

7. Your rights

Depending on where you live (for example under the UK GDPR, EU GDPR, or the CCPA), you may have the right to access, correct, export, or delete your data, and to object to certain processing. Because we hold no account and no contact details, the fastest route is the in-app deletion above. For anything else, email us — we respond to verified requests within 30 days.

Legal basis, where the GDPR applies: we process this data to perform the contract you enter when you use the app (delivering generations and honouring your subscription), and on the basis of our legitimate interest in preventing abuse and controlling cost.

8. Security

All traffic between the app and our server uses HTTPS. Our server holds no API keys for the AI services; it authenticates using managed workload identity, and the media storage has key-based access disabled entirely. Generated media links are time-limited and expire automatically.

9. Changes

If this policy changes materially, we will update the date at the top and, where the change affects how your data is used, surface a notice in the app.