ROOST

Privacy Policy

Effective Date: August 13, 2026

For users aged 18 and over

Privacy Contact: service@roost.pet


1. Introduction and Scope

1.1 About this Privacy Policy

This Privacy Policy explains how Roost collects, uses, stores, protects, shares, and otherwise processes personal information when you access or use the Roost mobile application and any related websites, features, content, or services that link to this Privacy Policy, collectively referred to as the "Services."

Roost is a social communication service designed for users aged 18 and over. Its primary features include discovering recommended users, initiating one-to-one video calls, participating in random video matching, following other users, and exchanging text messages.

1.2 Who Is Responsible for Your Information

For the purposes of applicable data protection laws, the developer or legal entity identified as the provider of Roost in the applicable app store listing is responsible for the processing of personal information described in this Privacy Policy.

Questions, requests, or complaints concerning this Privacy Policy may be submitted to:

Email: service@roost.pet

1.3 Application of This Privacy Policy

This Privacy Policy applies to personal information processed through the Services, regardless of the country or region from which you access Roost. Certain supplemental notices or regional provisions may apply based on your place of residence.

If a regional provision conflicts with a general provision of this Privacy Policy, the regional provision will apply to the extent required by applicable law.

1.4 Separate Consent

Your use of Roost does not automatically constitute consent to every type of data processing. Where applicable law requires consent, Roost will request it separately through an appropriate notice, permission request, or affirmative action.

You may decline an optional permission or withdraw consent where permitted by law. However, certain features may not function properly without access to the information necessary to provide them.

1.5 Third-Party Services

This Privacy Policy does not govern independent websites, applications, or services operated by third parties, even if they are accessible through Roost. Third parties process information according to their own privacy policies and legal obligations.

2. Adult Eligibility, Children, and Age Restrictions

2.1 Adults-Only Service

Roost is intended exclusively for individuals who are at least 18 years old. You may not create an account, access the Services, or submit personal information if you are under 18.

By creating an account or using Roost, you confirm that you are at least 18 years old and legally permitted to use the Services in your jurisdiction.

2.2 Age Information

Roost may request your date of birth, age range, or confirmation that you are at least 18 years old. This information may be used to:

 Enforce the adults-only eligibility requirement.

 Prevent minors from creating or maintaining accounts.

 Support trust and safety investigations.

 Comply with applicable laws and platform requirements.

 Restrict access when age information appears inaccurate or inconsistent.

Providing false age information may result in account suspension or termination.

2.3 Information Concerning Minors

Roost does not knowingly permit individuals under 18 to use the Services or knowingly collect personal information directly from them.

If Roost reasonably determines that an account belongs to an individual under 18, Roost may restrict, suspend, or terminate the account and delete associated personal information, subject to limited retention required for legal compliance, safety investigations, abuse prevention, or the protection of users.

A parent, legal guardian, or other person who believes that a minor has provided information to Roost may contact service@roost.pet. The request should contain sufficient information to help Roost identify the relevant account without unnecessarily disclosing additional information about the minor.

2.4 Child Sexual Abuse and Exploitation

Roost strictly prohibits any content or conduct involving Child Sexual Abuse and Exploitation, referred to as "CSAE." Prohibited conduct includes, without limitation:

 Sexual exploitation or abuse of a child.

 Grooming a child for sexual purposes.

 Sextortion involving a child.

 Soliciting or facilitating sexual contact with a child.

 Trafficking a child for sexual exploitation.

 Creating, possessing, requesting, distributing, or promoting Child Sexual Abuse Material, referred to as "CSAM."

 Using Roost to endanger, exploit, or facilitate harm to a child.

When Roost becomes aware of suspected CSAE or CSAM, it may remove relevant content, restrict or terminate accounts, preserve relevant records, and report information to competent law enforcement authorities, child protection organizations, or other legally authorized bodies where required or permitted by law.

2.5 Safety-Related Retention

Information associated with a suspected underage account or child safety incident may be retained for a limited period when reasonably necessary to:

 Complete an investigation.

 Prevent repeated account creation.

 Protect users or potential victims.

 Respond to lawful requests.

 Establish, exercise, or defend legal claims.

 Meet mandatory reporting or record-preservation obligations.

Such information will not be retained longer than reasonably necessary for these purposes.

3. Information You Provide to Roost

3.1 Account and Registration Information

When you create or manage a Roost account, you may provide information such as:

 Your display name or username.

 Your email address or telephone number.

 Your date of birth or age confirmation.

 Your password or other authentication credentials.

 Authentication tokens provided through an authorized third-party sign-in service.

 Your language, country, or region.

 Your account preferences and settings.

If you use a third-party sign-in method, Roost may receive limited account information from that provider according to your settings and the provider's authorization notice. Roost does not receive the password used for an independent third-party account.

3.2 Profile Information

You may choose to add information to your profile, including:

 Profile photographs.

 A biography or self-description.

 Gender or other identity information.

 Interests, hobbies, or conversation preferences.

 Country, region, or general location.

 Languages spoken.

 Other information you voluntarily make available through your profile.

Profile information may be visible to other Roost users according to the nature of the Services and your available privacy settings. You should not include home addresses, government identification numbers, financial details, passwords, or other highly sensitive information in your public profile.

3.3 Social and Connection Information

Roost processes information created through your interactions with other users, including:

 Users you follow or unfollow.

 Users who follow you.

 Video call invitations and responses.

 Random matching history.

 Connection preferences.

 Accounts you block, mute, hide, or report.

 The time and status of social interactions.

 Other actions used to organize or manage your social experience.

This information may be used to provide social features, maintain user preferences, prevent unwanted interactions, improve recommendations, and support trust and safety functions.

3.4 User-Generated Content

Roost may collect and process content that you create, upload, send, publish, or submit through the Services, referred to as "User-Generated Content" or "UGC." UGC may include:

 Profile photographs and profile descriptions.

 Text messages.

 Images, media, or attachments sent through supported features.

 Comments or other social content, if available.

 Reports, complaints, and supporting evidence.

 Feedback, survey responses, and communications sent to Roost.

 Information you choose to share during your use of the Services.

Depending on the feature and your settings, UGC may be visible to selected users, people you follow, people with whom you communicate, or a broader audience within Roost.

Do not upload or share personal information belonging to another person unless you have the lawful right and appropriate permission to do so.

3.5 Support and Safety Communications

When you contact Roost, submit a report, appeal an enforcement action, or request assistance, Roost may collect:

 Your contact information.

 The content of your request.

 Relevant account identifiers.

 Screenshots, images, message excerpts, or other evidence you submit.

 Information about the reported account or interaction.

 Records of Roost's response and follow-up communications.

Roost may use this information to respond to you, investigate potential violations, enforce applicable rules, prevent abuse, and maintain records of safety or compliance actions.

3.6 Information About Other People

If you submit information concerning another person, including through a report or safety complaint, you are responsible for ensuring that the submission is relevant, accurate to the best of your knowledge, and not made for harassment, retaliation, impersonation, or another unlawful purpose.

4. Information Collected Automatically

4.1 Device and Network Information

When you use Roost, certain technical information may be collected automatically, including:

 Device manufacturer and model.

 Operating system and operating system version.

 App version.

 Device language, time zone, and regional settings.

 Internet Protocol address.

 Mobile network or internet service provider.

 Connection type and network performance.

 Device or app identifiers permitted by the operating system.

 Push notification tokens.

 General device configuration and capability information.

Roost does not intentionally use persistent hardware identifiers, such as an IMEI, IMSI, or SIM serial number, for advertising or combine such identifiers with sensitive personal information in a manner prohibited by applicable platform policies.

4.2 Usage and Interaction Information

Roost may collect information about how you interact with the Services, such as:

 Pages, profiles, and features you access.

 Buttons, menus, and controls you use.

 Search, filter, or discovery actions.

 Profiles displayed in the recommendation feed.

 Video call invitations, acceptances, declines, and durations.

 Random matching events.

 Follows, unfollows, blocks, and reports.

 Dates and times of sessions.

 Session duration and frequency of use.

 App installation, update, and referral information.

This information may be associated with your account to operate the Services, understand feature performance, improve recommendations, prevent fraud, and investigate misuse.

4.3 Video Call and Communication Metadata

To establish and maintain video calls and messaging functions, Roost may process technical metadata such as:

 The accounts participating in a call or conversation.

 Call invitation, connection, and termination times.

 Call duration.

 Connection status.

 Network quality, latency, and diagnostic information.

 Message delivery status.

 Safety actions associated with a call or conversation.

Call metadata is different from the audio or video content of a call. Audio and video are processed as necessary to transmit live communications and provide the feature initiated by the user.

Roost does not routinely record or retain the content of private video calls. If a future recording, review, or safety feature processes call content beyond real-time transmission, Roost will provide an appropriate notice and obtain any permission or consent required by law before that processing begins.

4.4 Log, Diagnostic, and Crash Information

Roost and its authorized service providers may automatically collect server logs, crash reports, performance data, and diagnostic events. This information may include:

 Error messages.

 Crash timestamps.

 App state at the time of an error.

 Device and operating system information.

 Network diagnostics.

 Security-related events.

 Technical identifiers associated with a session.

This information is used to maintain stability, troubleshoot technical problems, secure the Services, and improve performance.

4.5 Security and Integrity Information

Roost may collect signals used to identify spam, fraud, harassment, account compromise, automated access, policy violations, or other harmful conduct. These signals may include:

 Unusual login or interaction patterns.

 Repeated account creation attempts.

 Device and network risk indicators.

 Report and enforcement history.

 Suspected use of unauthorized software.

 Signals indicating manipulation of the Services.

 Information necessary to verify the authenticity of a request.

Security information may be combined with account, device, usage, and report information when reasonably necessary to protect users and the Services.

5. Location Data and Device Permissions

5.1 Approximate Location

Roost may infer an approximate location, such as a country, region, or city-level area, from your Internet Protocol address, device language, time zone, or regional settings.

Approximate location information may be used to:

 Display relevant users or content.

 Support regional recommendation functions.

 Apply region-specific legal or safety requirements.

 Detect suspicious access or account compromise.

 Localize language and service settings.

 Analyze service availability and performance.

An Internet Protocol address generally does not provide an exact street address or precise real-time location.

5.2 Precise Location

The core video calling and text messaging features of Roost do not require continuous background access to precise GPS location.

If Roost offers a feature that requires precise location, the App will explain the relevant purpose and request permission through the device operating system before accessing that information. Roost will not collect precise location for an undisclosed purpose.

You may decline or revoke precise location permission through your device settings. Doing so may limit or disable location-based features but should not prevent access to features that do not require precise location.

5.3 Camera Permission

Roost requests access to your camera when necessary to:

 Participate in a video call.

 Capture or upload a profile photograph.

 Create supported visual UGC.

 Submit visual evidence with a safety report, if that feature is available.

Camera access is used only when required for a feature you initiate or enable. Roost does not activate your camera for undisclosed background surveillance.

5.4 Microphone Permission

Roost requests microphone access to transmit your voice during a video call or another audio-enabled feature that you initiate.

You may disable microphone access through your device settings. If microphone permission is disabled, other users will not be able to hear you during a video call, and certain communication features may not function.

5.5 Photo and Media Permission

If you choose to upload a profile photograph, send supported media, or attach evidence to a report, Roost may request access to selected photographs, videos, or media files.

Where supported by the operating system, Roost will request access only to the specific media you select rather than requesting unrestricted access to your entire media library.

5.6 Notification Permission

With your permission, Roost may send notifications concerning:

 Video call invitations.

 Random match activity.

 New followers.

 Text messages.

 Account and security alerts.

 Safety or moderation notices.

 Service updates.

You may manage or disable notifications through the App or your device settings.

5.7 Managing Permissions

You can review, grant, restrict, or revoke device permissions through your operating system settings. Revoking a permission does not delete information previously collected while the permission was active.

If you wish to request deletion of previously collected information, you may use the available account deletion function or contact service@roost.pet, subject to the retention exceptions described in this Privacy Policy.

6. Video Calls, Text Messages, and Communications

6.1 Real-Time Video and Audio Processing

When you initiate or accept a video call, Roost processes and transmits video and audio data to establish and maintain the communication. This processing is necessary to provide the live one-to-one video feature requested by the participating users.

Video and audio data may be temporarily buffered, routed, encoded, decoded, or otherwise technically processed to:

 Establish the call connection.

 Synchronize audio and video.

 Adapt quality to network conditions.

 Reduce latency and connection failures.

 Diagnose technical problems.

 Detect or prevent security and safety threats.

Camera and microphone data are accessed only after the relevant device permissions have been granted.

6.2 Recording and Retention of Video Calls

Roost does not routinely record or permanently store the content of private video calls.

Limited call-related content may be preserved when:

 A user intentionally submits a screenshot, recording, or other evidence through a safety report.

 A disclosed safety feature detects and preserves evidence of a suspected serious violation.

 Preservation is reasonably necessary to investigate fraud, threats, abuse, CSAE, CSAM, or another serious safety incident.

 Roost is required to preserve or disclose information under applicable law or a valid legal process.

 Users are provided with clear notice and any legally required consent before a separate recording feature is activated.

Where call-related content is preserved for a safety investigation, access will be limited to authorized personnel and service providers with a legitimate need to review it.

6.3 Text Messages

Roost may store text messages and supported attachments as necessary to:

 Deliver messages to the intended recipient.

 Synchronize conversations across authorized devices.

 Display conversation history.

 Maintain message status and delivery information.

 Detect spam, fraud, harassment, or prohibited content.

 Investigate reports and enforce applicable rules.

 Comply with legal obligations.

Messages may remain stored until they are deleted by the user, the relevant account is deleted, the applicable retention period expires, or Roost determines that continued storage is no longer necessary.

Deleting a message from your own interface may not remove copies already delivered to another user or information retained for a legitimate safety, security, legal, or compliance purpose.

6.4 Information Shared With Communication Partners

When you participate in a video call or send a message, certain information is necessarily disclosed to the other participant. This information may include:

 Your display name.

 Your profile photograph.

 Information visible on your profile.

 Your live video and audio during an active call.

 Messages and attachments you send.

 Call or message status information.

 Other information you voluntarily disclose during the interaction.

You control what you say, show, or send during a communication. Roost cannot control how another user remembers, records, screenshots, copies, or rediscloses information that you voluntarily share.

You should not disclose passwords, financial details, government identification numbers, home addresses, intimate images, or other highly sensitive information during a call or conversation.

6.5 Reports and Supporting Evidence

If you report a video call, message, or user, Roost may ask you to submit relevant information or evidence. Depending on the reporting feature, this may include:

 The reported account identifier.

 Call or conversation metadata.

 Message excerpts.

 Screenshots or recordings submitted by you.

 A description of the incident.

 The time and approximate date of the interaction.

 Other information reasonably necessary to evaluate the report.

Roost may share limited report information with the reported user when necessary to explain or review an enforcement decision. Roost will seek to avoid revealing the reporting user's identity unless disclosure is necessary, legally required, or unavoidable based on the circumstances of the report.

6.6 Communication Security

Roost applies reasonable technical safeguards to protect communications during transmission, including encryption in transit where technically appropriate.

Unless Roost expressly identifies a feature as end-to-end encrypted, you should not assume that a communication is protected by end-to-end encryption. Authorized processing may still occur for message delivery, abuse prevention, moderation, legal compliance, and technical support.

6.7 User Responsibility

You are responsible for ensuring that content you communicate through Roost complies with applicable law, Roost's Community Guidelines, and the rights of other people.

You must not record, distribute, or commercially exploit another user's private communication without the authorization required by applicable law.

7. User-Generated Content and Content Governance

7.1 Collection and Processing of UGC

Roost collects and processes User-Generated Content when you create, upload, publish, transmit, or submit content through the Services.

UGC may be stored and processed to:

 Display your profile.

 Deliver messages and media to intended recipients.

 Operate social and discovery features.

 Maintain conversation history.

 Respond to reports or support requests.

 Detect prohibited or harmful content.

 Enforce Roost's rules.

 Improve the security, reliability, and usability of the Services.

 Comply with legal requirements.

The visibility of UGC depends on the feature through which it is submitted, your settings, and the audience you select.

7.2 Ownership and Limited License

As between you and Roost, you retain any copyright and other intellectual property rights that you lawfully hold in your UGC.

By submitting UGC, you authorize Roost to host, store, reproduce, process, adapt for technical formatting, transmit, display, and otherwise use the content only as reasonably necessary to:

 Provide and operate the Services.

 Make the content available to the audience you select.

 Maintain technical compatibility across devices.

 Protect users and enforce applicable rules.

 Investigate reports and legal claims.

 Meet applicable legal obligations.

This authorization is non-exclusive, worldwide, and limited to the purposes described in this Privacy Policy and any applicable Terms of Service. It ends when the content is deleted from Roost's active systems, except to the extent that continued processing is required for backups, safety, security, legal compliance, or content previously shared with others.

7.3 Rights in Submitted Content

You must have all rights, licenses, permissions, and consents necessary to submit UGC to Roost.

You may not upload or distribute content that:

 Infringes copyright, trademark, privacy, publicity, or other rights.

 Contains another person's private information without lawful authorization.

 Impersonates another person or misrepresents its source.

 Was obtained through unauthorized access or recording.

 Violates a contractual, professional, or legal duty.

 Is unlawful in the jurisdiction where it is created, uploaded, or accessed.

Roost may respond to valid intellectual property complaints and may remove or restrict allegedly infringing content while a complaint is reviewed.

7.4 Content Moderation

Roost may use automated systems, trained reviewers, user reports, and other safety processes to identify UGC that may violate applicable law, the Terms of Service, or Community Guidelines.

Moderation may involve:

 Analyzing text, images, account behavior, and technical signals.

 Reviewing content submitted through a report.

 Restricting the visibility or distribution of content.

 Issuing warnings.

 Temporarily limiting access to features.

 Suspending or terminating accounts.

 Preserving evidence of serious violations.

 Reporting unlawful content or conduct to competent authorities where required or permitted.

Moderation systems may not identify every violation and may occasionally make mistakes. Where available, users may appeal eligible enforcement decisions through the method described in the relevant notice or by contacting service@roost.pet.

7.5 Prohibited and Harmful Content

Roost may remove, restrict, or report UGC involving:

 CSAE or CSAM.

 Non-consensual intimate content.

 Sexual content involving or appearing to involve a minor.

 Grooming, sextortion, trafficking, or sexual solicitation of a minor.

 Credible threats, violence, terrorism, or criminal activity.

 Harassment, stalking, hate, or targeted abuse.

 Fraud, impersonation, scams, or deceptive conduct.

 Disclosure of private personal information.

 Copyright or intellectual property infringement.

 Malware, spam, or unauthorized commercial activity.

 Any other content prohibited by applicable law or Roost's rules.

Roost may take action based on the content itself, the surrounding context, account history, user reports, and the seriousness of the potential harm.

7.6 Deletion of UGC

You may delete certain UGC through the available product controls. You may also request deletion by contacting service@roost.pet.

Following deletion, UGC may remain temporarily in backups, logs, or restricted safety systems. Roost may retain limited copies when necessary to:

 Investigate a reported violation.

 Prevent repeated abuse.

 Protect the rights or safety of another person.

 Comply with a legal preservation obligation.

 Establish, exercise, or defend a legal claim.

 Maintain evidence relating to CSAE, CSAM, fraud, or another serious violation.

UGC already copied, downloaded, recorded, or redistributed by another user may remain outside Roost's control.

7.7 Public and Shared Content

Content displayed on a profile or shared with other users may be viewed, captured, or redistributed by those users. Privacy settings can reduce the intended audience but cannot guarantee that a recipient will not copy or share the content.

You should consider the sensitivity of information before making it visible to others.

8. Sensitive Personal Information

8.1 Types of Sensitive Information

Depending on how you use Roost, personal information may reveal or relate to:

 Racial or ethnic origin.

 Religious or philosophical beliefs.

 Political opinions.

 Trade union membership.

 Physical or mental health.

 Sex life or sexual orientation.

 Gender identity or expression.

 Precise location.

 Government identification information.

 Biometric information.

 Information concerning alleged or actual criminal conduct.

Roost does not require you to publicly disclose sensitive personal information to use its core video and messaging features.

8.2 Voluntary Disclosure

You may voluntarily reveal sensitive information through your profile, messages, video calls, reports, or other UGC. Where you choose to make such information visible to another user, that person may be able to view, record, or redistribute it.

Your voluntary disclosure does not authorize another user to misuse the information or violate applicable law.

8.3 Purposes of Processing

Roost will process sensitive personal information only when reasonably necessary for a disclosed purpose, such as:

 Providing a feature you requested.

 Applying your discovery or communication preferences.

 Protecting users from fraud, abuse, discrimination, or safety threats.

 Investigating a report.

 Verifying age or identity, if such a feature is offered.

 Complying with applicable law.

 Establishing, exercising, or defending legal claims.

Where applicable law requires explicit consent, Roost will request that consent separately.

8.4 Advertising and Profiling Restrictions

Roost does not use sensitive personal information to infer sensitive characteristics for targeted advertising without legally valid consent.

Roost does not sell personal or sensitive user data in exchange for monetary consideration. Roost also requires service providers handling such data on its behalf to use it only for authorized and disclosed purposes.

8.5 Government Identification Information

If Roost introduces an age or identity verification process involving a government-issued identification document, Roost will provide a specific notice explaining:

 The information required.

 Whether Roost or a verification provider processes it.

 The verification purpose.

 Whether an image of the document is retained.

 The applicable retention period.

 The available user rights and choices.

Users should not submit government identification documents through ordinary profiles, messages, or support channels unless specifically requested through an authorized verification process.

8.6 Data Minimization

Roost seeks to limit the collection of sensitive personal information to what is reasonably necessary for the relevant feature, safety function, or legal obligation.

Where possible, Roost may use a verification result, age range, risk indicator, or other limited confirmation instead of retaining the underlying sensitive document or data.

9. Biometric Data, Age Assurance, and Automated Safety Tools

9.1 Photographs Are Not Automatically Biometric Data

Profile photographs, video streams, and voice communications may contain physical or behavioral characteristics. Roost does not treat ordinary media as biometric identification data unless it is processed through technology designed to identify or verify a person based on unique biological characteristics.

9.2 No Undisclosed Biometric Identification

Roost does not use facial geometry, voiceprints, or similar biometric templates to uniquely identify or authenticate users unless:

 The feature is clearly disclosed before collection.

 The processing is reasonably necessary and legally permitted.

 Any consent required by law is obtained.

 Appropriate retention and deletion rules are established.

 Users receive information about available alternatives where required.

Roost will not introduce undisclosed facial recognition or voice recognition for advertising purposes.

9.3 Age and Identity Assurance

To enforce its adults-only requirement or address suspected impersonation, Roost may use age or identity assurance methods. Depending on the method offered, this may involve:

 Confirming a date of birth.

 Reviewing account information.

 Evaluating age-related risk signals.

 Requesting a selfie, short video, or identification document.

 Using an authorized verification service provider.

 Conducting a manual review in limited cases.

Before collecting a selfie, identification document, or biometric identifier for verification, Roost will provide an additional notice describing the specific processing.

9.4 Automated Safety Analysis

Roost may use automated technologies to help detect:

 Spam and automated accounts.

 Fraud and impersonation.

 Harassment or threatening language.

 Nudity or sexually explicit content.

 Suspected underage users.

 CSAE or CSAM indicators.

 Malicious links or files.

 Repeated violations and account evasion.

 Unusual activity suggesting account compromise.

These systems may evaluate content, metadata, behavioral patterns, and technical signals. Any temporary frames or safety signals generated during automated analysis will be retained only as reasonably necessary for the safety purpose, investigation, or applicable legal obligation.

9.5 Human Review

Authorized personnel or service providers may review flagged information when reasonably necessary to:

 Evaluate a user report.

 Confirm or correct an automated detection.

 Make or review an enforcement decision.

 Respond to an appeal.

 Protect a person from serious harm.

 Meet legal or platform obligations.

Access to reviewed information will be limited according to role, purpose, and confidentiality requirements.

9.6 Automated Decisions

Automated tools may assist with recommendations, spam prevention, risk scoring, content restriction, or account security. Roost may take temporary action automatically when necessary to prevent immediate harm or abuse.

Where applicable law grants a right not to be subject to a decision based solely on automated processing that produces legal or similarly significant effects, Roost will provide an appropriate method to request human review.

10. Cookies, Mobile SDKs, and Similar Technologies

10.1 Technologies Used

Roost and its authorized service providers may use:

 Cookies on websites associated with Roost.

 Mobile software development kits, referred to as "SDKs."

 Local device storage.

 Pixels or similar measurement technologies.

 App instance identifiers.

 Push notification tokens.

 Session identifiers.

 Other technologies necessary to recognize a device or maintain a session.

These technologies may collect device, network, usage, diagnostic, and interaction information described in this Privacy Policy.

10.2 Essential Technologies

Certain technologies are necessary to:

 Authenticate users.

 Maintain account sessions.

 Remember settings.

 Route video and message communications.

 Protect account security.

 Prevent fraud and abuse.

 Balance network traffic.

 Maintain the reliability of the Services.

Disabling essential technologies may prevent Roost from functioning correctly.

10.3 Analytics and Performance

Roost may use analytics and performance technologies to understand:

 How users navigate the Services.

 Which features are used.

 Where errors or crashes occur.

 How video call quality varies.

 Whether a product update performs as intended.

 How the Services can be improved.

Analytics data may be aggregated or pseudonymized where reasonably possible.

10.4 Attribution and Advertising Technologies

If Roost uses advertising, promotional attribution, or campaign measurement technologies, the relevant providers may process resettable advertising identifiers, Internet Protocol addresses, device information, and interaction events.

Where legally required, Roost will request consent before activating non-essential advertising or tracking technologies. Roost will honor applicable device settings and legally recognized opt-out mechanisms.

Roost will not permit an advertising or attribution provider to sell personal and sensitive user data obtained from the App or use that data for undisclosed purposes.

10.5 Third-Party SDK Providers

Roost may engage SDK providers for functions such as:

 Authentication.

 Cloud hosting.

 Video and audio communications.

 Push notifications.

 Crash reporting.

 Analytics.

 Fraud prevention.

 Content moderation.

 Customer support.

 Age or identity verification, if implemented.

 Advertising or attribution, if implemented.

SDK providers may process information on Roost's behalf or, in limited circumstances, for their own disclosed purposes. Roost is responsible for evaluating whether integrated SDKs operate consistently with applicable law, Google Play requirements, and Roost's disclosures.

10.6 User Controls

Depending on your device and region, you may be able to control cookies and similar technologies by:

 Adjusting in-app privacy settings.

 Changing operating system permission settings.

 Resetting or deleting a mobile advertising identifier.

 Limiting advertising personalization.

 Blocking or deleting browser cookies.

 Withdrawing consent through an available consent management tool.

Your choices may not affect technologies that are strictly necessary for security, authentication, or core service operation.

10.7 Do Not Track Signals

Some browsers transmit "Do Not Track" signals. Because there is no universally accepted technical standard for responding to every such signal, Roost may not respond to all Do Not Track settings.

Where required by applicable law, Roost will recognize supported browser-based or device-based opt-out preference signals, such as the Global Privacy Control, for the processing activities to which those signals legally apply.

11. How Roost Uses Personal Information

11.1 Providing the Services

Roost uses personal information to provide the features and functions you request, including to:

 Create, authenticate, and maintain your account.

 Display and manage your profile.

 Present recommended users.

 Operate random matching.

 Establish and maintain one-to-one video calls.

 Deliver text messages and supported attachments.

 Enable follows, blocks, reports, and other social actions.

 Save your settings and preferences.

 Provide customer support.

 Process account deletion and privacy requests.

Certain information is necessary to provide the Services. If you do not provide that information, Roost may be unable to create your account or provide the relevant feature.

11.2 Personalizing Your Experience

Roost may use account, profile, location, language, social interaction, and usage information to:

 Organize the recommendation feed.

 Suggest users who may be relevant to you.

 Apply your discovery preferences.

 Reduce repeated or unwanted recommendations.

 Display content in an appropriate language.

 Remember your preferred settings.

 Adapt the Services to your device and region.

Personalization may involve automated processing, as further described in Section 12.

11.3 Operating Video and Messaging Features

Roost processes communication and technical information to:

 Route video and audio streams.

 Establish call connections.

 Deliver messages.

 Display delivery or call status.

 Adjust video quality to network conditions.

 Diagnose failed calls or message delivery.

 Maintain communication history where applicable.

 Prevent unauthorized access to communications.

11.4 Safety, Security, and Abuse Prevention

Roost may use personal information to protect users, Roost, and the public, including to:

 Detect and prevent spam, scams, fraud, and impersonation.

 Identify suspicious logins or account compromise.

 Detect underage users.

 Investigate harassment, threats, stalking, or other abuse.

 Detect and respond to CSAE and CSAM.

 Enforce the Terms of Service and Community Guidelines.

 Restrict repeated account creation following a serious violation.

 Protect the rights, property, and safety of users or other people.

 Maintain evidence relating to safety incidents or legal claims.

 Improve moderation and risk detection systems.

Safety investigations may involve combining account, device, usage, communication metadata, reports, and relevant UGC.

11.5 Service Improvement and Research

Roost may use information to understand, maintain, and improve the Services, including to:

 Measure feature usage and performance.

 Identify technical errors and crashes.

 Evaluate video and audio quality.

 Understand how users navigate the Services.

 Test new features and interface changes.

 Improve recommendation and matching systems.

 Develop safety and anti-abuse technologies.

 Conduct internal research and statistical analysis.

 Forecast infrastructure and support requirements.

Where reasonably possible, Roost will use aggregated or de-identified information for research and analytics.

11.6 Communicating With You

Roost may use your contact information and account data to send:

 Authentication and verification messages.

 Security alerts.

 Video call and message notifications.

 Information about followers or social activity.

 Customer support responses.

 Safety and moderation notices.

 Account enforcement or appeal decisions.

 Administrative and service-related announcements.

 Notices concerning material changes to the Services or policies.

 Promotional communications where permitted by law.

You may opt out of promotional communications through the unsubscribe method provided in the message or through available settings. You may continue to receive non-promotional communications that are necessary for account security, service operation, or legal compliance.

11.7 Legal and Compliance Purposes

Roost may use personal information to:

 Comply with applicable laws and regulations.

 Respond to valid legal requests.

 Fulfill mandatory reporting obligations.

 Maintain required business and compliance records.

 Exercise or defend legal rights.

 Investigate suspected unlawful activity.

 Resolve disputes.

 Respond to regulatory or law enforcement inquiries.

 Enforce agreements and policies.

11.8 Aggregated and De-Identified Information

Roost may aggregate or de-identify information so that it cannot reasonably be used to identify you. Roost may use such information for analytics, research, reporting, safety measurement, product development, and other lawful business purposes.

Roost will not attempt to re-identify properly de-identified information except when necessary to test whether the de-identification process is effective or as otherwise permitted by law.

11.9 Purpose Limitation

Roost will not use personal information for a materially different purpose without providing additional notice or obtaining consent where required by law.

12. Recommendations, Random Matching, and Personalization

12.1 Information Used for Recommendations

Roost may use the following information to organize recommendations and facilitate matching:

 Age eligibility and age range.

 Country, region, language, and time zone.

 Profile information and stated interests.

 Discovery and communication preferences.

 Prior follows, unfollows, blocks, and reports.

 Video call invitations, acceptances, declines, and durations.

 Random matching activity.

 Recent activity and technical availability.

 Accounts or content you have already viewed.

 Safety, integrity, and enforcement signals.

 Device and network information needed to maintain call quality.

Roost will not use precise location for recommendations unless the relevant feature is clearly disclosed and you have granted the required permission.

12.2 Recommendation Feed

The recommendation feed may rank or filter profiles based on relevance, availability, preferences, safety signals, and predicted likelihood of a meaningful interaction.

The order in which profiles appear does not represent an endorsement, verification, popularity ranking, or guarantee of compatibility.

12.3 Random Matching

Random matching is intended to create spontaneous one-to-one video connections. A random match may still be limited or adjusted according to:

 User availability.

 Language or regional compatibility.

 Technical connection quality.

 Age eligibility.

 User-selected preferences.

 Block lists.

 Prior interactions.

 Safety restrictions.

 Applicable legal requirements.

Accordingly, random matching may not be mathematically uniform or based solely on chance.

12.4 Safety-Based Ranking and Exclusions

Roost may reduce the visibility of, exclude, or delay matching for accounts associated with:

 Credible reports.

 Suspected fraud or automation.

 Repeated unwanted behavior.

 Possible underage use.

 Account compromise.

 Technical abuse.

 Previous enforcement actions.

 Other indicators of risk.

A safety-related restriction does not necessarily mean that Roost has conclusively determined that the user violated a rule.

12.5 Sensitive Information

Roost does not use sensitive personal information to infer sensitive traits for advertising purposes without legally valid consent.

If a user voluntarily selects a sensitive preference for a discovery feature, Roost will use that preference only for the disclosed function and other legally permitted purposes, such as safety or compliance.

12.6 User Controls

Depending on the version and region of the Services, you may be able to influence recommendations by:

 Editing your profile and preferences.

 Changing language or regional settings.

 Following or unfollowing users.

 Blocking or hiding an account.

 Reporting inappropriate behavior.

 Clearing or changing available discovery settings.

 Withdrawing optional permissions.

 Contacting Roost about a recommendation or restriction.

Some safety and integrity processing cannot be disabled because it is necessary to protect the Services and other users.

12.7 No Guarantee Regarding Other Users

Recommendations and matches are generated from available information and automated signals. Roost does not guarantee:

 The identity or background of another user.

 The accuracy of another user's profile.

 Compatibility between users.

 The intentions or conduct of another user.

 That a recommended user will accept a call.

 That a random match will result in a positive interaction.

 Continuous availability of recommendations or matches.

Users should exercise independent judgment and use available blocking and reporting tools when necessary.

13. Legal Bases for Processing

13.1 Application of This Section

This section applies where data protection law requires Roost to identify a legal basis for processing personal information, including in the European Economic Area, the United Kingdom, Switzerland, and other jurisdictions with similar requirements.

The legal basis depends on the information involved, the feature used, and the purpose of the processing.

13.2 Performance of a Contract

Roost processes personal information when necessary to perform its agreement with you or take steps at your request before entering into that agreement.

This basis may apply to:

 Registering and authenticating your account.

 Maintaining your profile.

 Providing recommendations and random matching.

 Establishing video calls.

 Delivering messages.

 Managing follows and social connections.

 Providing customer support.

 Processing account deletion.

 Enforcing applicable service terms.

If required information is not provided, Roost may be unable to perform the relevant service.

13.3 Legitimate Interests

Roost may process personal information when necessary for its legitimate interests or the legitimate interests of another person, provided those interests are not overridden by your rights and interests.

Relevant legitimate interests may include:

 Protecting users from fraud, harassment, and abuse.

 Securing accounts and infrastructure.

 Detecting underage use.

 Preventing unauthorized or automated access.

 Improving performance and reliability.

 Understanding how features are used.

 Providing non-promotional service communications.

 Establishing, exercising, or defending legal claims.

 Preventing repeated violations.

 Maintaining the integrity of recommendations and matching.

Before relying on legitimate interests, Roost will consider the nature of the information, the reasonable expectations of users, potential effects on users, and available safeguards.

13.4 Consent

Roost relies on consent when required for particular processing, which may include:

 Accessing precise location.

 Accessing the camera, microphone, or selected media through device permissions.

 Sending certain promotional communications.

 Activating non-essential advertising or tracking technologies.

 Processing optional sensitive profile information.

 Conducting biometric processing, if such a feature is introduced.

 Using information for another purpose that requires consent.

Consent must be given through a clear affirmative action. You may withdraw consent at any time through available settings or by contacting service@roost.pet.

Withdrawal does not affect the lawfulness of processing completed before the withdrawal.

13.5 Legal Obligations

Roost may process personal information when necessary to comply with a legal obligation, including to:

 Respond to a binding legal request.

 Preserve evidence required by law.

 Report CSAE, CSAM, or other conduct subject to mandatory reporting.

 Comply with court orders.

 Meet regulatory, accounting, or recordkeeping obligations.

 Respond to lawful requests from data protection authorities.

13.6 Vital Interests

Roost may process or disclose personal information when reasonably necessary to protect the life, physical safety, or vital interests of you or another person.

This basis may apply in urgent circumstances involving suicide or self-harm threats, credible threats of violence, missing persons, trafficking, CSAE, or another serious and immediate danger.

13.7 Public Interest and Legal Claims

Where permitted by law, Roost may process sensitive personal information when necessary for reasons of substantial public interest, the prevention or detection of unlawful acts, safeguarding, or the establishment, exercise, or defense of legal claims.

13.8 Questions About Legal Bases

You may contact service@roost.pet if you would like additional information about the legal basis applicable to a particular processing activity.

14. How Roost Shares and Discloses Information

14.1 Sharing With Other Users

Roost shares information with other users when necessary to provide social and communication features.

Depending on the feature and your settings, other users may receive or view:

 Your display name and profile photograph.

 Your profile description and other visible profile information.

 Your general region or language.

 Your follower or following relationship.

 Your video and audio during a live call.

 Messages and attachments you send.

 Call invitations and communication status.

 Other UGC you choose to share.

You should review your profile and available settings before making information visible to others.

14.2 Sharing at Your Direction

Roost may share information when you direct or authorize it, including when you:

 Send a message or media to another user.

 Initiate or accept a video call.

 Connect a third-party account.

 Use a sharing function.

 Submit information to a third-party service.

 Request that Roost disclose information to another person.

Third parties receiving information at your direction may process it under their own privacy policies.

14.3 Service Providers

Roost shares information with authorized service providers that perform functions on its behalf, as described in Section 15.

Service providers may receive only the information reasonably necessary for the service they provide and must process it according to applicable contractual and legal restrictions.

14.4 App Stores and Authentication Providers

If you download Roost through an app store or use a third-party authentication provider, that provider may process information relating to:

 App installation and updates.

 Device and account identifiers.

 Authentication.

 Purchases, if offered.

 Subscription status, if applicable.

 Crash or performance information.

 Compliance with platform rules.

These providers may act as independent data controllers for certain processing and apply their own privacy policies.

14.5 Legal Requests

Roost may disclose information in response to a subpoena, court order, search warrant, regulatory demand, or other valid legal process.

Where legally permitted and reasonably practical, Roost may:

 Review whether the request is valid and properly authorized.

 Limit disclosure to information reasonably required.

 Challenge requests that appear unlawful or excessive.

 Notify the affected user unless notice is prohibited or could create a risk of harm.

Roost may preserve relevant information while evaluating or responding to a legal request.

14.6 Safety and Protection

Roost may disclose information when it reasonably believes disclosure is necessary to:

 Protect a person from death or serious physical harm.

 Investigate or report CSAE or CSAM.

 Prevent trafficking, sextortion, stalking, or credible violence.

 Locate or assist a person in an emergency.

 Detect or prevent fraud or account compromise.

 Protect the rights, property, or security of Roost or another person.

 Enforce applicable agreements and policies.

Disclosures may be made to law enforcement authorities, emergency services, child protection organizations, regulators, or other appropriate recipients.

14.7 Corporate Affiliates

If Roost is operated with corporate affiliates under common ownership or control, information may be shared among those affiliates for service operation, security, support, compliance, and internal administration.

Any affiliate receiving personal information must process it consistently with this Privacy Policy and applicable law.

14.8 Business Transactions

If Roost or its relevant assets are involved in a merger, acquisition, financing, restructuring, bankruptcy, sale of assets, or similar transaction, personal information may be disclosed to advisers, counterparties, and successors as part of evaluating or completing the transaction.

Roost will require appropriate confidentiality protections during the transaction process. If the transaction materially changes how personal information is processed, affected users will receive notice where required by law.

14.9 Aggregated or De-Identified Information

Roost may share aggregated or de-identified information that cannot reasonably identify an individual. Such information may be shared for analytics, research, safety reporting, product development, or business planning.

Roost will not permit recipients to attempt to re-identify properly de-identified information except where permitted for testing the effectiveness of de-identification safeguards.

14.10 No Sale of Personal and Sensitive User Data

Roost does not sell personal and sensitive user data in exchange for monetary consideration.

Certain privacy laws define "sale," "sharing," or "targeted advertising" more broadly. Where those definitions apply, Roost will provide any legally required notices and opt-out rights for relevant processing.

15. Service Providers and Data Processors

15.1 Categories of Service Providers

Roost may engage service providers for:

 Cloud hosting and data storage.

 Content delivery and network infrastructure.

 Video and audio communication technology.

 Message delivery.

 Authentication.

 Push notifications.

 Analytics and crash reporting.

 Customer support.

 Fraud prevention and account security.

 Content moderation and trust and safety.

 Age or identity verification, if implemented.

 Legal, audit, and compliance services.

 Advertising and attribution, if implemented.

 Payment or subscription processing, if offered.

The particular providers used may change as Roost's technology and business needs evolve.

15.2 Information Available to Providers

A service provider may receive account, device, network, usage, communication, content, support, or safety information only to the extent reasonably necessary to perform its assigned function.

For example:

 A communication provider may process call connection data and real-time audio or video streams.

 A cloud provider may store account records, messages, and UGC.

 An analytics provider may process device and feature usage events.

 A moderation provider may review reported content.

 A support provider may access the information included in a support request.

 A verification provider may process age or identity information submitted for verification.

15.3 Contractual Controls

Where a provider acts on Roost's behalf, Roost requires appropriate contractual commitments concerning:

 Confidentiality.

 Information security.

 Purpose limitation.

 Data minimization.

 Assistance with user rights requests.

 Incident notification.

 Retention and deletion.

 Restrictions on unauthorized disclosure.

 Compliance with applicable privacy requirements.

Service providers may not use personal information received from Roost for their own unrelated purposes unless a separate legal basis and appropriate notice apply.

15.4 Independent Controllers

Certain third parties may independently determine how and why they process information. These parties may include:

 App store operators.

 Third-party sign-in providers.

 Payment processors.

 Regulatory authorities.

 Law enforcement authorities.

 Services you intentionally connect to Roost.

Their processing is governed by their own privacy notices and legal responsibilities.

15.5 Subcontractors

A service provider may use approved subcontractors to perform part of its services. Where required, Roost will require the primary provider to impose appropriate privacy and security obligations on those subcontractors.

15.6 Provider Assessment

Roost may evaluate service providers based on factors such as:

 The nature and sensitivity of the information involved.

 The provider's security controls.

 Data storage and transfer locations.

 Retention practices.

 Incident response capabilities.

 Relevant certifications or independent assessments.

 Compliance with Google Play and other platform requirements.

 The provider's ability to support user rights and deletion requests.

Roost may restrict, replace, or discontinue a provider that cannot meet applicable requirements.

15.7 Additional Information

Where required by applicable law, Roost will provide additional information about relevant service providers or international data transfer mechanisms.

Requests for such information may be submitted to service@roost.pet.

16. International Data Transfers

16.1 Global Operation of the Services

Roost is intended for users around the world. To operate the Services, personal information may be transferred to, stored in, accessed from, or processed in countries or regions other than the country in which you live.

These countries may have privacy and data protection laws that differ from the laws of your jurisdiction. In some cases, local laws may provide a different level of protection or allow access to information by courts, law enforcement authorities, or regulatory bodies.

16.2 Transfer Safeguards

When Roost transfers personal information across borders, it will use safeguards required by applicable law. Depending on the countries involved, these safeguards may include:

 A decision by a competent authority that the destination provides an adequate level of protection.

 Standard Contractual Clauses approved by the European Commission.

 The United Kingdom International Data Transfer Addendum or another approved United Kingdom transfer mechanism.

 Contractual clauses approved by another competent regulator.

 Binding corporate rules, if applicable.

 Participation in a legally recognized data transfer framework.

 Your explicit consent, where permitted and appropriate.

 A legal exception necessary to perform a contract, protect vital interests, establish legal claims, or satisfy another lawful purpose.

16.3 European Economic Area, United Kingdom, and Switzerland

For transfers of personal information from the European Economic Area, the United Kingdom, or Switzerland to a country that has not been recognized as providing adequate protection, Roost will use an applicable legal transfer mechanism.

Where required, Roost will also assess whether the laws and practices of the destination country could affect the effectiveness of the selected safeguards and will implement supplementary technical, contractual, or organizational measures where appropriate.

16.4 Supplementary Measures

Depending on the nature and sensitivity of the information, supplementary measures may include:

 Encryption during transmission.

 Encryption or pseudonymization during storage.

 Separation of account identifiers from certain activity data.

 Restricted administrative access.

 Role-based access controls.

 Contractual limits on government access requests.

 Policies for reviewing and challenging excessive legal demands.

 Data minimization and limited retention.

 Security monitoring and audit records.

16.5 Service Provider Locations

Roost's service providers may process information from multiple locations to provide cloud hosting, video communications, message delivery, customer support, security, moderation, analytics, and other services.

Roost evaluates the locations and transfer practices of relevant providers as part of its privacy and security review process.

16.6 Information About Transfer Mechanisms

Where required by law, you may request additional information about the safeguards used for an international transfer. Certain commercial terms or security details may be redacted where necessary to protect confidential information or the security of the Services.

Requests may be sent to service@roost.pet.

17. Data Storage and Retention

17.1 General Retention Principles

Roost retains personal information only for as long as reasonably necessary to:

 Provide the Services.

 Maintain your account.

 Complete the purpose for which the information was collected.

 Protect users and investigate violations.

 Prevent fraud and repeated abuse.

 Resolve disputes.

 Enforce agreements.

 Comply with legal, regulatory, tax, accounting, or reporting obligations.

 Establish, exercise, or defend legal claims.

The retention period depends on the type of information, its sensitivity, the processing purpose, user expectations, technical requirements, and applicable law.

17.2 Target Retention Periods

Unless a different period is disclosed for a specific feature or a longer period is required or permitted by law, Roost applies the following target retention periods:

 Account and profile information: Retained while the account is active. Following account deletion, information will generally be removed from active systems within 90 days.

 Follow, block, and preference information: Retained while necessary to maintain your account settings and social experience. Following account deletion, it will generally be removed from active systems within 90 days.

 Text messages and UGC: Retained while available through your account or until deleted. Deleted content will generally be removed from active systems within 90 days, subject to safety, legal, and recipient-copy exceptions.

 Video call content: Roost does not routinely record or permanently store private call content. Content preserved through a safety report is retained according to the applicable investigation and safety period.

 Video call metadata: Generally retained for up to 12 months for service operation, quality analysis, fraud prevention, and safety. Metadata connected to a report or enforcement action may be retained longer.

 Device, usage, and diagnostic information: Generally retained for up to 24 months, unless a shorter period is sufficient or a longer period is necessary for security or legal purposes.

 Customer support records: Generally retained for up to 3 years after the request is closed to maintain service history, improve support, and resolve disputes.

 Reports and enforcement records: Generally retained for up to 5 years after the matter is closed when necessary to prevent repeated abuse, maintain safety, or defend an enforcement decision.

 Age or identity verification information: Verification documents or images will be retained for the shortest period reasonably necessary to complete verification, unless longer retention is required for fraud prevention, safety, or law. A limited verification result may be retained for the life of the account and for up to 90 days after deletion.

 Consent and privacy request records: Retained for the period necessary to demonstrate compliance and respond to related claims.

 Legal preservation records: Retained for the duration of the applicable legal hold, investigation, proceeding, or limitation period.

 CSAE and CSAM records: Retained and disclosed as required or permitted by applicable child safety, evidence preservation, and reporting laws.

 Aggregated or de-identified information: May be retained for an extended or indefinite period when it can no longer reasonably identify an individual.

17.3 Backup Retention

Information deleted from active systems may remain in encrypted or access-restricted backups for up to 180 days.

Backup copies are maintained for disaster recovery, security, and service continuity. They are not used for ordinary product functions and will be deleted or overwritten according to the backup schedule.

If a backup must be restored, Roost will take reasonable steps to ensure that previously completed deletion requests are reapplied.

17.4 Legal and Safety Exceptions

Roost may retain limited information beyond the ordinary retention period when reasonably necessary to:

 Comply with a legal preservation obligation.

 Respond to a valid government request.

 Investigate fraud, abuse, or a serious safety incident.

 Prevent a suspended user from immediately creating another account.

 Protect a person from harm.

 Resolve a dispute.

 Enforce agreements.

 Establish, exercise, or defend legal claims.

Information retained under an exception will be restricted from ordinary use and deleted when the exception no longer applies.

17.5 De-Identification Instead of Deletion

In some cases, Roost may permanently de-identify information instead of deleting it. De-identified information must not reasonably identify you and may be used only in accordance with applicable law.

18. Information Security

18.1 Security Program

Roost uses reasonable administrative, technical, and organizational measures designed to protect personal information against:

 Unauthorized access.

 Unlawful disclosure.

 Accidental loss.

 Destruction.

 Alteration.

 Misuse.

 Account compromise.

 Unauthorized copying or transmission.

Security measures are selected based on the nature and sensitivity of the information, the potential risks, available technology, and the cost and feasibility of implementation.

18.2 Technical Safeguards

Technical safeguards may include:

 Encryption during transmission using current industry-standard protocols.

 Encryption at rest where appropriate.

 Secure authentication mechanisms.

 Password hashing and credential protection.

 Role-based access controls.

 Network security controls.

 Logging and monitoring of administrative access.

 Detection of suspicious activity.

 Rate limits and anti-automation protections.

 Vulnerability management.

 Secure software development and testing practices.

 Backup and recovery controls.

 Segmentation of systems and information where appropriate.

Roost does not store account passwords in readable plain text.

18.3 Organizational Safeguards

Organizational measures may include:

 Limiting access to personnel with a legitimate business need.

 Confidentiality obligations.

 Privacy and security training.

 Incident response procedures.

 Service provider assessments.

 Internal policies for handling user information.

 Access reviews.

 Data retention and deletion procedures.

 Escalation processes for serious safety incidents.

 Procedures for responding to user rights requests.

18.4 Access to Personal Information

Authorized personnel and service providers may access personal information only when reasonably necessary for their assigned responsibilities, such as:

 Customer support.

 Security and fraud prevention.

 Content moderation.

 Legal compliance.

 System maintenance.

 Incident investigation.

 Privacy request processing.

Access may be logged, reviewed, and revoked when no longer necessary.

18.5 Security Testing and Monitoring

Roost may conduct or commission:

 Vulnerability scanning.

 Penetration testing.

 Code and configuration reviews.

 Access-control reviews.

 Infrastructure monitoring.

 Incident simulations.

 Service provider security reviews.

 Remediation tracking.

The frequency and scope of testing may vary according to risk and operational needs.

18.6 Security Incidents

If Roost becomes aware of a security incident affecting personal information, it will take reasonable steps to:

 Contain and investigate the incident.

 Identify affected systems and information.

 Mitigate ongoing risk.

 Restore the security of the Services.

 Preserve relevant evidence.

 Notify service providers, authorities, or affected users where required.

 Implement reasonable measures to reduce the risk of recurrence.

A notification may be delivered through the App, email, a website notice, or another legally permitted method.

18.7 No Absolute Security Guarantee

No internet transmission, storage system, or security measure is completely secure. Roost cannot guarantee that unauthorized access, loss, misuse, or alteration will never occur.

You should use a unique password, protect your device, avoid sharing authentication codes, and notify Roost promptly if you suspect unauthorized account access.

18.8 Reporting a Security Concern

If you believe that your account or personal information has been compromised, contact service@roost.pet promptly.

Do not use a compromised account to send sensitive information. Roost may request information necessary to verify account ownership and investigate the incident.

19. Your Privacy Rights and Choices

19.1 Rights Available to You

Depending on your jurisdiction, you may have the right to:

 Confirm whether Roost processes your personal information.

 Access personal information held about you.

 Obtain a copy of certain personal information.

 Correct inaccurate or incomplete information.

 Delete personal information.

 Restrict certain processing.

 Object to processing based on legitimate interests.

 Withdraw consent.

 Request data portability.

 Opt out of certain targeted advertising, sale, or sharing.

 Request human review of certain automated decisions.

 Appeal the denial of a privacy request.

 Submit a complaint to a competent data protection authority.

 Receive equal service without unlawful discrimination for exercising a privacy right.

These rights may be subject to conditions, limitations, and exceptions under applicable law.

19.2 Access and Data Copies

You may access certain account and profile information directly through Roost.

You may request a copy of additional personal information by contacting service@roost.pet. Where required by law, Roost will provide the information in a structured, commonly used, and machine-readable format when technically feasible.

A response may omit or redact information where disclosure would adversely affect another person's rights, reveal confidential security information, interfere with an investigation, or violate applicable law.

19.3 Correction

You may correct certain profile and account information through the App.

If information cannot be corrected through available controls, you may submit a correction request to service@roost.pet. Roost may retain a record of the previous information where necessary for fraud prevention, safety, or legal compliance.

19.4 Deletion

You may delete certain content through the App and may request deletion of your account and associated information as described in Section 20.

The right to deletion is subject to limited exceptions, including information that must be retained for legal compliance, security, fraud prevention, safety, or legal claims.

19.5 Restriction and Objection

Where applicable law provides these rights, you may request that Roost restrict processing or object to processing based on legitimate interests.

Roost may continue processing when it demonstrates compelling legitimate grounds that override the request or when processing is necessary for legal claims.

19.6 Withdrawal of Consent

You may withdraw consent through applicable device settings, in-app controls, consent management tools, or by contacting service@roost.pet.

Withdrawal applies to future processing and does not affect processing lawfully completed before withdrawal.

If a feature depends on the withdrawn permission or consent, that feature may no longer be available.

19.7 Marketing Choices

You may opt out of promotional email by using the unsubscribe link provided in the message. Push notifications may be controlled through the App or your device settings.

Opting out of marketing does not prevent Roost from sending account, security, safety, transaction, policy, or other non-promotional service communications.

19.8 Verification of Requests

Before completing a privacy request, Roost may need to verify your identity and authority. Verification may involve:

 Confirming access to the registered email address or telephone number.

 Requesting information associated with the account.

 Confirming recent account activity.

 Requesting additional evidence when reasonably necessary.

Roost will request only the information reasonably necessary to verify the request.

If identity cannot be verified, Roost may deny or limit the request and explain the reason where required by law.

19.9 Authorized Agents

Where permitted by law, you may appoint an authorized agent to submit a request on your behalf.

Roost may require evidence of the agent's authority and may contact you directly to confirm the request. An agent's request may be denied if the required authorization cannot be verified.

19.10 Response Time and Appeals

Roost will respond within the period required by applicable law. If additional time is legally permitted and reasonably necessary, Roost will notify you of the extension.

If Roost denies a request, the response will explain the reason and any available appeal method where required.

Privacy requests and appeals may be sent to service@roost.pet.

19.11 Complaints to Authorities

You may have the right to complain to a data protection authority in the country or region where you live, work, or believe a violation occurred.

Roost encourages you to contact service@roost.pet first so that it can attempt to address your concern, but doing so does not limit your right to contact an authority.

20. Account Deletion and Data Deletion

20.1 How to Request Account Deletion

If Roost allows account creation, it will provide a readily discoverable method to initiate account deletion:

 Through the account or privacy settings within the App.

 Through an external account deletion webpage linked from the applicable app store listing.

 By contacting service@roost.pet when another method is unavailable.

Roost will not require you to reinstall the App solely to request deletion if an external deletion method is available.

20.2 Verification

Roost may verify that the deletion request was submitted by the account owner or an authorized representative.

Verification is intended to prevent another person from fraudulently deleting your account. If Roost cannot reasonably verify the request, it may request additional information or decline to complete the deletion.

20.3 Effect of Account Deletion

Account deletion generally results in:

 Loss of access to the account.

 Removal of the public profile.

 Termination of active sessions.

 Removal from ordinary recommendations and matching.

 Deletion of follow relationships and preferences.

 Deletion or de-identification of account information.

 Deletion of messages and UGC from Roost's active systems, subject to applicable exceptions.

 Cancellation of access to account-specific features.

Account deletion is permanent after any disclosed cancellation period expires. Deleted accounts may not be recoverable.

20.4 Deletion Is Different From Deactivation

Temporary deactivation, logging out, uninstalling the App, revoking a device permission, or disabling an account does not constitute account deletion.

To delete your account and associated information, you must use an account deletion method described in Section 20.1.

20.5 Information That May Be Retained

Following account deletion, Roost may retain limited information when reasonably necessary to:

 Complete the deletion process.

 Maintain restricted backups.

 Comply with law.

 Respond to a legal hold or valid legal request.

 Prevent fraud or repeated abuse.

 Preserve block relationships needed to protect another user.

 Investigate or document a serious safety incident.

 Address CSAE or CSAM.

 Establish, exercise, or defend legal claims.

 Demonstrate compliance with a privacy request.

Retained information will not be used to reactivate the deleted account or for ordinary personalization and marketing.

20.6 Messages and Content Held by Other Users

Deleting your account may not remove:

 Messages already delivered to another user's account.

 Screenshots or recordings created by another user.

 Content copied or shared outside Roost.

 Information another person submitted in a report.

 Information that another user is legally entitled or required to retain.

Roost may remove or anonymize your account identifier from retained conversation records where reasonably possible.

20.7 Deletion Schedule

Roost will begin processing a verified deletion request without undue delay.

Information will generally be removed from active systems within 90 days. Encrypted or access-restricted backup copies may remain for up to 180 days before being overwritten or deleted, subject to legal and safety exceptions.

20.8 Third-Party Services

Deleting your Roost account does not automatically delete information independently maintained by an app store, authentication provider, payment processor, or another third-party service.

You may need to contact those providers or use their account controls separately.

20.9 Cancellation of a Deletion Request

If Roost offers a short cancellation period, the applicable interface will disclose its duration. After that period expires, the deletion process may be irreversible.

Roost will not use a cancellation period to create unreasonable obstacles to deletion.

20.10 Confirmation and Questions

Where technically feasible and legally appropriate, Roost will confirm that a verified account deletion request has been completed.

Questions concerning deletion may be sent to service@roost.pet.

21. Regional Privacy Disclosures

21.1 General Application

Privacy rights vary by country, state, province, and region. Roost will provide the rights required by the law applicable to your personal information.

If this section provides a right that conflicts with another provision of this Privacy Policy, this section will apply to the extent required by applicable law.

21.2 European Economic Area, United Kingdom, and Switzerland

If you are located in the European Economic Area, the United Kingdom, or Switzerland, you may have the right to:

 Obtain confirmation that Roost processes your personal information.

 Access your personal information.

 Correct inaccurate or incomplete information.

 Request deletion of personal information.

 Restrict certain processing.

 Object to processing based on legitimate interests.

 Withdraw consent at any time.

 Receive certain information in a portable format.

 Object to direct marketing.

 Request human intervention for certain significant automated decisions.

 Submit a complaint to a competent supervisory authority.

Where Roost relies on legitimate interests, you may request information about the balancing considerations relevant to that processing.

You may lodge a complaint with the supervisory authority in the country where you live, work, or believe an infringement occurred. You are not required to contact Roost before submitting a complaint, although Roost encourages you to contact service@roost.pet so that it can attempt to resolve the concern.

If Roost is required to appoint a representative or Data Protection Officer for a particular jurisdiction, the relevant contact details will be made available through the Services or an applicable supplemental notice.

21.3 California Privacy Notice

This subsection applies to California residents to the extent Roost is subject to the California Consumer Privacy Act, as amended by the California Privacy Rights Act.

Roost may collect the following categories of personal information:

 Identifiers, such as account identifiers, email addresses, telephone numbers, Internet Protocol addresses, and device identifiers.

 Personal records information, such as profile details and contact information.

 Characteristics protected under California or federal law, such as age, gender, or other information voluntarily disclosed by a user.

 Commercial information, such as subscription or transaction status, if purchases are offered.

 Internet or electronic network activity, such as feature usage, interactions, and diagnostic information.

 Geolocation information, including approximate location and precise location when separately authorized.

 Audio, electronic, visual, or similar information, including live video and audio communications and uploaded media.

 Professional or education information voluntarily included in a profile or communication.

 Inferences derived from activity and preferences for recommendations, security, or personalization.

 Sensitive personal information, such as account credentials, precise location, message content, or information voluntarily revealing sensitive characteristics.

Roost obtains this information from:

 You.

 Your device and use of the Services.

 Other users.

 App stores and authentication providers.

 Service providers.

 Safety reports.

 Public authorities or other legally authorized sources.

Roost uses and discloses these categories for the purposes described in Sections 11 through 15. Retention is governed by Section 17.

Subject to applicable exceptions, California residents may have the right to:

 Know the categories and specific pieces of personal information collected.

 Know the categories of sources, purposes, and recipients.

 Request correction.

 Request deletion.

 Obtain a portable copy.

 Opt out of the sale or sharing of personal information.

 Limit certain uses and disclosures of sensitive personal information.

 Receive equal service without unlawful discrimination.

 Use an authorized agent.

Roost does not sell personal information in exchange for monetary consideration. If Roost engages in processing that qualifies as a "sale" or "sharing" under California law, Roost will provide a legally required opt-out method and recognize applicable opt-out preference signals.

Roost will not discriminate against you for exercising a California privacy right. However, exercising a right may affect a feature that depends on the information covered by the request.

21.4 Other United States State Privacy Rights

Residents of certain United States states may have rights to:

 Access personal information.

 Correct inaccuracies.

 Delete personal information.

 Obtain a portable copy.

 Opt out of targeted advertising.

 Opt out of certain sales of personal information.

 Opt out of profiling that produces legal or similarly significant effects.

 Appeal the denial of a request.

Roost will provide the rights required by the law applicable to the requester. Instructions for appealing a denied request will be included in the response where required.

21.5 Brazil

If Brazil's Lei Geral de Protecao de Dados Pessoais, referred to as the "LGPD," applies to the processing of your personal data, you may have the right to:

 Confirm that processing occurs.

 Access personal data.

 Correct incomplete, inaccurate, or outdated data.

 Request anonymization, blocking, or deletion of unnecessary or unlawfully processed data.

 Request portability where legally and technically available.

 Obtain information about recipients.

 Obtain information about the consequences of refusing consent.

 Withdraw consent.

 Request deletion of data processed based on consent, subject to legal exceptions.

 Object to unlawful processing.

 Request review of certain automated decisions.

 Submit a petition to the Autoridade Nacional de Protecao de Dados, referred to as the "ANPD."

Roost may process personal data under the legal bases permitted by the LGPD, including consent, performance of a contract, compliance with legal obligations, protection of life or physical safety, exercise of legal rights, and legitimate interests.

LGPD requests may be sent to service@roost.pet.

21.6 Canada

If Canadian privacy law applies, you may have the right to:

 Request access to personal information.

 Challenge the accuracy or completeness of information.

 Request correction.

 Withdraw consent, subject to legal and contractual limitations.

 Ask questions about Roost's privacy practices.

 Submit a complaint to the Office of the Privacy Commissioner of Canada or an applicable provincial authority.

Withdrawal of consent may affect Roost's ability to provide a feature that requires the relevant information.

21.7 Australia and New Zealand

If Australian or New Zealand privacy law applies, you may request access to or correction of personal information and may submit a privacy complaint to Roost.

Roost will investigate eligible complaints and respond within a reasonable period. If you are not satisfied with the response, you may have the right to contact the Office of the Australian Information Commissioner, the Office of the Privacy Commissioner of New Zealand, or another competent regulator.

21.8 Other Countries and Regions

Users in other jurisdictions, including Japan, South Korea, Singapore, and other countries or regions, may have additional rights under local law.

Roost will honor legally applicable access, correction, deletion, consent withdrawal, objection, portability, and complaint rights. Requests may be submitted to service@roost.pet.

22. Child Safety and CSAE Standards

22.1 Adults-Only Platform

Roost is exclusively intended for users aged 18 and over. An individual under 18 may not create an account, access video matching, participate in communications, or submit personal information through Roost.

The adults-only designation does not reduce Roost's responsibility to prevent, detect, report, and address risks involving children.

22.2 Published Child Safety Standards

Roost maintains standards prohibiting Child Sexual Abuse and Exploitation, referred to as "CSAE," and Child Sexual Abuse Material, referred to as "CSAM."

These standards apply to all accounts, profiles, video calls, text messages, uploaded media, links, and other activity conducted through the Services.

The standards may be included in Roost's Community Guidelines, Child Safety Standards page, Terms of Service, and this Privacy Policy. They must remain publicly accessible and reference Roost by name.

22.3 Prohibited CSAE Conduct

Roost prohibits:

 Creating, uploading, requesting, possessing, distributing, promoting, or facilitating CSAM.

 Grooming or attempting to groom a child.

 Sexual communication with a child.

 Sextortion involving a child.

 Sexual trafficking or exploitation of a child.

 Arranging or facilitating sexual contact with a child.

 Sharing links, instructions, or tools intended to locate or distribute CSAM.

 Sexualizing a person known or reasonably suspected to be under 18.

 Impersonating a minor for sexual exploitation.

 Encouraging, normalizing, or assisting CSAE.

 Threatening or coercing a child to provide sexual content.

 Using Roost to conceal or coordinate child exploitation.

An account may be suspended or terminated based on credible evidence of prohibited conduct, even if the conduct began outside Roost.

22.4 In-App Reporting Mechanism

Roost will provide an in-app mechanism through which users can report child safety concerns without leaving the App.

A report may include:

 The reported account.

 The type of suspected violation.

 Relevant messages or media.

 Call or interaction metadata.

 A description of the concern.

 Supporting screenshots or other evidence.

Users should not download, reproduce, or redistribute suspected CSAM for reporting purposes. A report should identify the account or content through the available reporting tools without creating unnecessary additional copies.

Urgent danger should be reported directly to the appropriate local emergency or law enforcement authority.

22.5 Review and Enforcement

When Roost receives or identifies a credible child safety concern, it may:

 Restrict access to relevant content.

 Preserve relevant information.

 Suspend affected features.

 Temporarily lock an account.

 Terminate an account.

 Prevent repeated account creation.

 Conduct automated and human review.

 Engage a qualified service provider.

 Notify an authorized child protection organization.

 Submit a legally required report.

 Cooperate with a lawful investigation.

Roost may act without advance notice when notice could increase risk, compromise an investigation, or facilitate deletion of relevant evidence.

22.6 CSAM Reporting and Cooperation

Where required or permitted by law, Roost may report apparent CSAM or suspected CSAE to:

 Competent law enforcement authorities.

 Legally authorized child protection organizations.

 Applicable national or regional reporting centers.

 Regulatory authorities.

 Emergency services.

 Other organizations legally authorized to receive such reports.

A report may include account information, technical identifiers, content, communication metadata, safety reports, and other information reasonably relevant to the suspected violation.

22.7 Preservation of Child Safety Information

Information connected to suspected CSAE or CSAM may be preserved beyond ordinary retention periods when necessary to:

 Prevent the destruction of evidence.

 Complete an investigation.

 Fulfill a mandatory reporting obligation.

 Respond to a lawful preservation request.

 Protect a child or another person.

 Prevent repeated violations.

 Support a legal proceeding.

 Demonstrate compliance with child safety obligations.

Access to preserved information will be restricted to authorized personnel and providers with a legitimate need.

22.8 Confidentiality and User Notice

Roost may be legally prohibited from notifying a user about a child safety report, preservation request, investigation, or disclosure.

Where notice is legally permitted, Roost may still delay or withhold it when reasonably necessary to avoid endangering a child, compromising an investigation, enabling retaliation, or facilitating evidence destruction.

22.9 Child Safety Point of Contact

Roost's designated contact for child safety concerns, CSAE standards, and related compliance inquiries is:

Email: service@roost.pet

This contact may be used by users, regulators, law enforcement authorities, child protection organizations, and Google Play representatives.

22.10 False or Abusive Reports

Users must not knowingly submit false child safety reports or misuse reporting tools to harass, retaliate against, or intimidate another person.

Roost may take action against accounts that intentionally submit fabricated or abusive reports. A good-faith report will not result in action merely because an investigation does not confirm the concern.

22.11 Continuous Compliance

Roost may update its child safety procedures to reflect changes in law, platform requirements, safety risks, and industry practices.

Roost will maintain procedures designed to:

 Publish standards against CSAE.

 Provide an in-app reporting mechanism.

 Address CSAM appropriately.

 Comply with applicable child safety laws.

 Maintain a child safety point of contact.

23. Third-Party Links and External Services

23.1 Links Shared by Users

Users may share links to third-party websites, applications, files, or services through profiles, messages, or other features.

Roost does not control the privacy, security, accuracy, or legality of user-shared third-party links. You should use caution before opening a link or providing information to an external service.

23.2 Integrated Third-Party Services

Roost may allow you to use third-party services for authentication, payment, media selection, sharing, or other functions.

When you choose an integrated service:

 Roost may send information necessary to complete your request.

 The provider may send authorized information to Roost.

 The provider may independently collect device or usage information.

 The provider's own privacy policy may apply to its processing.

You should review the provider's privacy notice and available settings before connecting an account.

23.3 App Stores

Your use of an app store is governed by the app store operator's own terms and privacy policy. The operator may independently process information about downloads, installations, updates, subscriptions, payments, device configuration, and app performance.

Roost does not control information processed independently by an app store.

23.4 External Websites

This Privacy Policy does not apply after you leave Roost and access an independent website or service.

A link from Roost does not mean that Roost endorses the linked service or guarantees its privacy or security practices.

23.5 Malicious or Inappropriate Links

Links may be used for phishing, malware, scams, harassment, or prohibited content. Do not enter passwords, payment details, or authentication codes on an unfamiliar website.

You may report suspicious links through Roost's reporting tools or by contacting service@roost.pet.

Roost may block, remove, or restrict links that appear unsafe or violate applicable rules.

23.6 Third-Party Actions

Roost is not responsible for the independent privacy practices of another user or third party. However, Roost may investigate conduct involving an external service when it is connected to fraud, abuse, CSAE, threats, or another violation involving Roost.

24. Changes, Notices, and Contact Information

24.1 Changes to This Privacy Policy

Roost may update this Privacy Policy to reflect:

 New or modified features.

 Changes in data practices.

 New service providers or technologies.

 Legal or regulatory developments.

 Platform policy changes.

 Security and safety improvements.

 Organizational or business changes.

 Feedback from users or regulators.

The updated policy will display a revised effective date.

24.2 Notice of Material Changes

If a change materially affects how Roost collects, uses, stores, or shares personal information, Roost will provide notice appropriate to the nature of the change.

Notice may be delivered through:

 An in-app notice.

 Email.

 A website announcement.

 A notification displayed when you next access the Services.

 Another method permitted by applicable law.

Where legally required, Roost will obtain consent before applying a material change to information previously collected.

24.3 Review of Updates

You should review this Privacy Policy periodically. Continued use of the Services after an update does not replace consent where applicable law requires separate consent.

The version of the policy in effect when information is processed will apply, subject to applicable legal requirements.

24.4 Privacy Contact

Questions, concerns, complaints, and requests concerning this Privacy Policy or Roost's processing of personal information may be sent to:

App: Roost

Privacy Email: service@roost.pet

Child Safety Email: service@roost.pet

Developer: The developer or legal entity identified as the provider of Roost in the applicable app store listing.

24.5 Information to Include in a Request

To help Roost respond efficiently, your request should include:

 A clear description of the request.

 The email address or telephone number associated with the account.

 Your country or region.

 The privacy right you wish to exercise, if applicable.

 Relevant account or incident information.

 Any accessibility or communication needs.

Do not send passwords, full payment card numbers, unnecessary identification documents, or unrelated sensitive information by email.

24.6 Complaint Handling

Roost will review privacy complaints in good faith and may:

 Confirm receipt.

 Request information necessary to understand or verify the complaint.

 Investigate relevant systems and records.

 Consult service providers.

 Explain the outcome.

 Take reasonable corrective action where appropriate.

 Provide information about an appeal or regulatory complaint right where required.

24.7 Accessibility

Roost seeks to present this Privacy Policy in a clear and accessible form. If you require the policy in an alternative format because of a disability or accessibility need, contact service@roost.pet.

24.8 Language

Roost may provide translations of this Privacy Policy for convenience. If a translation conflicts with the English version, the English version will control to the extent permitted by applicable law.

24.9 Entire Privacy Notice

This Privacy Policy, together with any applicable regional notice, in-app disclosure, permission notice, cookie notice, or feature-specific privacy notice, describes Roost's processing of personal information.

If a feature-specific notice provides more detailed or protective terms for a particular processing activity, that notice will apply to that activity.