1. Who we are
Roastish is operated by Roastish Technologies Pvt. Ltd., 221B, MG Road, Bengaluru, Karnataka 560001, India ("we", "us"). We are the data controller for the information described here.
This policy covers the Roastish mobile app and https://roastish.com.
2. What we collect
Information you give us
| Data | Why |
|---|---|
| Email address and Google account ID | To create and sign you into your account |
| Username (handle), bio, profile photo | Your public identity in the app |
| Photos you post, and their captions and categories | They are the content of the app |
| Roasts you write | Shown anonymously to other users |
| Reports and messages you send us | To investigate and reply |
| A roast written through a "roast me" link, if you use one without an account | To show it on that post. No account, name or email is asked for or stored — see section 4. |
Information collected automatically
| Data | Why |
|---|---|
| Which posts you view, laugh at, share and follow | To rank your feed and count views. This shapes what you are shown. |
| Approximate location — city, state and country, and coordinates if you grant location permission | To surface posts from near you. Optional: deny the permission and the app works, with a less local feed. |
| Device push token | To send you notifications |
| IP address and the endpoint called | Rate limiting and abuse prevention. Kept briefly, then expired. |
| Crash reports — device model, OS version, stack trace | To find and fix crashes. Via Firebase Crashlytics. |
| Recordings of your screen as you use the app, and where you tap and scroll | To see where the app confuses people. Via Microsoft Clarity. Two screens are excluded — see section 4. |
| That you installed the app, opened it, signed up, posted or roasted — and a device advertising identifier | To measure which advert brought you here, and to stop paying for adverts that bring nobody. Via Meta (Facebook). |
| Your device's advertising ID, rough location from your IP address, device type, and how you interact with the adverts you are shown | To choose which advert to show you in the feed, and to count when one is seen or tapped. Via Google AdMob. Never your name, email, handle or anything you posted. |
We show adverts. They appear in the feed, between posts, and every one of them is marked Sponsored. They are supplied by Google AdMob, which is what keeps Roastish free to use — nothing in the app is for sale and there is no subscription.
To choose which advert to show you, AdMob reads your device's advertising ID — a resettable identifier Android gives every app for this purpose — along with your rough location from your IP address, your device type, and how you interact with the adverts themselves. We never send AdMob your name, your email, your handle or anything you have posted. What Google does with what it collects is covered by Google's own policy, and you can reset or delete your advertising ID at any time in Android Settings → Privacy → Ads.
Meta's measurement kit is included so we can tell which of our adverts, on Facebook and Instagram, brought people here — it reports what you did in the app to Meta, and Meta may use that for its own advertising. If that is not a trade you want, section 8 explains how to limit it.
We do not collect your contacts, your calendar, your photo library beyond the single image you choose to post, your precise background location, or any payment information.
3. How we use it
- To run the app — show your feed, deliver roasts, keep counts accurate.
- To rank your feed — your interests, the categories you engage with, and your location influence what appears.
- To keep it safe — automated moderation before publication, plus reports, blocking and rate limits.
- To notify you — a roast on your post, a laugh, a new follower. You can turn these off in Settings.
- To fix problems — crash reports and error logs.
We do not use your content to train machine-learning models of our own, and we do not sell personal information.
4. What "anonymous" means here — read this one
Roasts are anonymous to other users. The server strips the author from every roast before it is sent to any device. There is no screen, API response or export in which one user can see who wrote a roast — not even the person who was roasted.
Roasts are not anonymous to us. Our database records which account wrote which roast. We need that link to remove abusive content, enforce the one-roast-per-post rule, and respond to a valid legal request. Anyone telling you an app like this is anonymous end-to-end is describing something we have not built.
Practically: if you write something that violates our Terms or the law, being anonymous to other users will not keep it anonymous from us or from a court.
Your posts are never anonymous. Your handle and profile photo are attached to every post, which is the point of the app.
Roasts written through a "roast me" link are different, and more anonymous than the rest. If you share an invite link, anyone who opens it can roast that post in a browser without an account. When they do, there is no account for us to record, because there was never one — so the paragraph above does not apply to those roasts. We store the roast text, the post it was written on, and which invite link it came through. We do not ask for a name, an email or a sign-in, and we do not store the visitor's IP address with the roast.
The trade-off is honest rather than accidental: those roasts are checked by the same automated moderation as every other roast and can be removed or reported in the same way, but there is no account behind them for us to suspend. That is why an invite link is limited in how many roasts it accepts, expires on its own, and can be turned off at any time by the person who shared it.
If you are the one sharing the link: turning it off stops new roasts immediately. Roasts already written stay on your post until you delete them or the post.
Screen recording never covers the box you write a roast in. We record screens to find confusing parts of the app, and a recording of someone typing a roast would be a record of who wrote it — anonymity that held in the app but not in our analytics would not be anonymity at all. The roast box and the reply box are blanked out of every recording.
The photo editor is blanked out too. Everything on that screen is a photo you have not posted yet, and backing out of it is you deciding not to publish. That decision should not put the photo in an analytics tool.
5. Who we share it with
We share data only with the service providers that make the app run. Each processes it on our instructions.
| Provider | What it receives | Why |
|---|---|---|
| Google Firebase (Authentication, Cloud Messaging, Crashlytics) | Account identifier, email, device push token, crash diagnostics | Sign-in, notifications, crash reporting |
| Amazon Web Services (S3) | The images you upload | Storing and serving photos |
| OpenAI | The text of captions and roasts, at the moment you post them | Automated moderation before publication. No account identifier is sent with the text. |
| Microsoft (Clarity) | Recordings of your screen and your taps, minus the roast box, the reply box and the photo editor. A random identifier, not your handle or email. | Finding parts of the app that do not work as people expect |
| Google AdMob | Your advertising ID, IP address, device type and how you interact with adverts in the feed. Not your handle, email, photos, captions or roasts. | Choosing and measuring the adverts shown between posts. Google may use what it collects for its own advertising, under its own policy. |
| Meta Platforms (Facebook, Instagram) | That the app was installed and opened, and when you sign up, post or roast. A device advertising identifier where your device allows one. Not your handle, email, photos, captions or roasts. | Measuring which of our adverts works. This is the one entry in this table where the recipient may also use the data for its own purposes rather than only ours. |
| Our hosting provider | All application data | Running the servers and database |
We may also disclose information where we are legally required to, or where it is necessary to investigate a credible threat to someone's safety.
If the business is ever sold or merged, your information may transfer with it. We will tell you in the app before that happens.
6. Legal bases
Where the GDPR or India's DPDP Act applies, we rely on:
- Contract — to provide the account and the app you asked for.
- Legitimate interests — safety, moderation, abuse prevention and product improvement.
- Consent — location and push notifications, both optional and both withdrawable in your device settings at any time.
- Legal obligation — where we must retain or disclose data.
7. How long we keep it
| Data | Retained |
|---|---|
| Account, posts, roasts | Until you delete them or close your account |
| Deleted posts | Marked deleted immediately and hidden everywhere; purged after 30 days, so reports filed just beforehand can still be reviewed |
| Abuse reports and moderation records | Up to 12 months after the matter is resolved |
| Rate-limit records (IP) | Hours — they expire automatically |
| Crash reports | Per Firebase Crashlytics' own retention, currently 90 days |
| Screen recordings | Per Microsoft Clarity's own retention, currently 30 days |
| Advert measurement events | Held by Meta under its own policy, which we do not control |
8. Your rights and choices
Depending on where you live you may have the right to access, correct, export, or delete your personal data, to object to or restrict processing, and to withdraw consent. In the app you can already:
- Edit your handle, bio and photo — Settings → Edit profile.
- Delete any post or roast you made.
- Turn notifications off — Settings, or your device's app settings.
- Revoke location access — your device's app permissions.
- Delete your account and everything on it — Settings → Delete account.
Limiting advert measurement and screen recording
Both of these are device-level controls rather than app settings, because that is where they actually take effect — an in-app toggle that the operating system can override would be theatre.
- Android: Settings → Privacy → Ads → Delete advertising ID. Apps, including this one, then have no advertising identifier to report.
- iPhone: Settings → Privacy & Security → Tracking, and turn off Allow Apps to Request to Track. Roastish does not ask for tracking permission at all today, so on iPhone the advertising identifier is already withheld.
- Screen recording: Microsoft lets you opt out for every app that uses Clarity at clarity.microsoft.com/opt-out. You can also email us and we will exclude your account.
None of this affects the app working. Nothing here is behind a wall.
For anything else, email privacy@roastish.com from your registered address. We respond within 30 days. If you are unhappy with our response you may complain to your local data protection authority.
9. Deleting your account
Settings → Delete account, in the app. This removes your profile, your posts and your roasts.
Two honest exceptions. Aggregate counts that no longer identify you — a post's total view count, for instance — remain. And where we are required to keep records of a reported safety incident, we retain the minimum needed for as long as the law requires.
If you cannot reach the app, email privacy@roastish.com from the address on the account.
10. Children
Roastish is for people aged 13 and over. We do not knowingly collect information from anyone younger. If you believe a child has an account, email privacy@roastish.com and we will remove it.
11. Security
Traffic is encrypted in transit with HTTPS. Sign-in tokens are held in the device's secure keystore, not in ordinary app storage. Only one device can be signed into an account at a time — signing in elsewhere ends the earlier session. Access to production data is limited to people who need it.
No system is perfectly secure. If a breach affects you we will notify you and the relevant authority as the law requires.
12. International transfers
Our providers operate globally, so your data may be processed outside your country — including in the United States. Where required we rely on Standard Contractual Clauses or an equivalent safeguard.
13. Changes
If we change this policy we will update the date at the top, and for anything significant we will tell you in the app before it takes effect.
14. Contact
Privacy: privacy@roastish.com
Anything else: hello@roastish.com
Post: Roastish Technologies Pvt. Ltd., 221B, MG Road, Bengaluru, Karnataka 560001, India