Privacy Policy

Last updated 12 August 2026

The short version

1. Who we are

Roastish is operated by Roastish Technologies Pvt. Ltd., 221B, MG Road, Bengaluru, Karnataka 560001, India ("we", "us"). We are the data controller for the information described here.

This policy covers the Roastish mobile app and https://roastish.com.

2. What we collect

Information you give us

DataWhy
Email address and Google account IDTo create and sign you into your account
Username (handle), bio, profile photoYour public identity in the app
Photos you post, and their captions and categoriesThey are the content of the app
Roasts you writeShown anonymously to other users
Reports and messages you send usTo investigate and reply
A roast written through a "roast me" link, if you use one without an account To show it on that post. No account, name or email is asked for or stored — see section 4.

Information collected automatically

DataWhy
Which posts you view, laugh at, share and follow To rank your feed and count views. This shapes what you are shown.
Approximate location — city, state and country, and coordinates if you grant location permission To surface posts from near you. Optional: deny the permission and the app works, with a less local feed.
Device push tokenTo send you notifications
IP address and the endpoint called Rate limiting and abuse prevention. Kept briefly, then expired.
Crash reports — device model, OS version, stack trace To find and fix crashes. Via Firebase Crashlytics.
Recordings of your screen as you use the app, and where you tap and scroll To see where the app confuses people. Via Microsoft Clarity. Two screens are excluded — see section 4.
That you installed the app, opened it, signed up, posted or roasted — and a device advertising identifier To measure which advert brought you here, and to stop paying for adverts that bring nobody. Via Meta (Facebook).
Your device's advertising ID, rough location from your IP address, device type, and how you interact with the adverts you are shown To choose which advert to show you in the feed, and to count when one is seen or tapped. Via Google AdMob. Never your name, email, handle or anything you posted.

We show adverts. They appear in the feed, between posts, and every one of them is marked Sponsored. They are supplied by Google AdMob, which is what keeps Roastish free to use — nothing in the app is for sale and there is no subscription.

To choose which advert to show you, AdMob reads your device's advertising ID — a resettable identifier Android gives every app for this purpose — along with your rough location from your IP address, your device type, and how you interact with the adverts themselves. We never send AdMob your name, your email, your handle or anything you have posted. What Google does with what it collects is covered by Google's own policy, and you can reset or delete your advertising ID at any time in Android Settings → Privacy → Ads.

Meta's measurement kit is included so we can tell which of our adverts, on Facebook and Instagram, brought people here — it reports what you did in the app to Meta, and Meta may use that for its own advertising. If that is not a trade you want, section 8 explains how to limit it.

We do not collect your contacts, your calendar, your photo library beyond the single image you choose to post, your precise background location, or any payment information.

3. How we use it

We do not use your content to train machine-learning models of our own, and we do not sell personal information.

4. What "anonymous" means here — read this one

Roasts are anonymous to other users. The server strips the author from every roast before it is sent to any device. There is no screen, API response or export in which one user can see who wrote a roast — not even the person who was roasted.

Roasts are not anonymous to us. Our database records which account wrote which roast. We need that link to remove abusive content, enforce the one-roast-per-post rule, and respond to a valid legal request. Anyone telling you an app like this is anonymous end-to-end is describing something we have not built.

Practically: if you write something that violates our Terms or the law, being anonymous to other users will not keep it anonymous from us or from a court.

Your posts are never anonymous. Your handle and profile photo are attached to every post, which is the point of the app.

Roasts written through a "roast me" link are different, and more anonymous than the rest. If you share an invite link, anyone who opens it can roast that post in a browser without an account. When they do, there is no account for us to record, because there was never one — so the paragraph above does not apply to those roasts. We store the roast text, the post it was written on, and which invite link it came through. We do not ask for a name, an email or a sign-in, and we do not store the visitor's IP address with the roast.

The trade-off is honest rather than accidental: those roasts are checked by the same automated moderation as every other roast and can be removed or reported in the same way, but there is no account behind them for us to suspend. That is why an invite link is limited in how many roasts it accepts, expires on its own, and can be turned off at any time by the person who shared it.

If you are the one sharing the link: turning it off stops new roasts immediately. Roasts already written stay on your post until you delete them or the post.

Screen recording never covers the box you write a roast in. We record screens to find confusing parts of the app, and a recording of someone typing a roast would be a record of who wrote it — anonymity that held in the app but not in our analytics would not be anonymity at all. The roast box and the reply box are blanked out of every recording.

The photo editor is blanked out too. Everything on that screen is a photo you have not posted yet, and backing out of it is you deciding not to publish. That decision should not put the photo in an analytics tool.

5. Who we share it with

We share data only with the service providers that make the app run. Each processes it on our instructions.

ProviderWhat it receivesWhy
Google Firebase (Authentication, Cloud Messaging, Crashlytics) Account identifier, email, device push token, crash diagnostics Sign-in, notifications, crash reporting
Amazon Web Services (S3) The images you upload Storing and serving photos
OpenAI The text of captions and roasts, at the moment you post them Automated moderation before publication. No account identifier is sent with the text.
Microsoft (Clarity) Recordings of your screen and your taps, minus the roast box, the reply box and the photo editor. A random identifier, not your handle or email. Finding parts of the app that do not work as people expect
Google AdMob Your advertising ID, IP address, device type and how you interact with adverts in the feed. Not your handle, email, photos, captions or roasts. Choosing and measuring the adverts shown between posts. Google may use what it collects for its own advertising, under its own policy.
Meta Platforms (Facebook, Instagram) That the app was installed and opened, and when you sign up, post or roast. A device advertising identifier where your device allows one. Not your handle, email, photos, captions or roasts. Measuring which of our adverts works. This is the one entry in this table where the recipient may also use the data for its own purposes rather than only ours.
Our hosting provider All application data Running the servers and database

We may also disclose information where we are legally required to, or where it is necessary to investigate a credible threat to someone's safety.

If the business is ever sold or merged, your information may transfer with it. We will tell you in the app before that happens.

Where the GDPR or India's DPDP Act applies, we rely on:

7. How long we keep it

DataRetained
Account, posts, roastsUntil you delete them or close your account
Deleted posts Marked deleted immediately and hidden everywhere; purged after 30 days, so reports filed just beforehand can still be reviewed
Abuse reports and moderation records Up to 12 months after the matter is resolved
Rate-limit records (IP)Hours — they expire automatically
Crash reportsPer Firebase Crashlytics' own retention, currently 90 days
Screen recordings Per Microsoft Clarity's own retention, currently 30 days
Advert measurement events Held by Meta under its own policy, which we do not control

8. Your rights and choices

Depending on where you live you may have the right to access, correct, export, or delete your personal data, to object to or restrict processing, and to withdraw consent. In the app you can already:

Limiting advert measurement and screen recording

Both of these are device-level controls rather than app settings, because that is where they actually take effect — an in-app toggle that the operating system can override would be theatre.

None of this affects the app working. Nothing here is behind a wall.

For anything else, email privacy@roastish.com from your registered address. We respond within 30 days. If you are unhappy with our response you may complain to your local data protection authority.

9. Deleting your account

Settings → Delete account, in the app. This removes your profile, your posts and your roasts.

Two honest exceptions. Aggregate counts that no longer identify you — a post's total view count, for instance — remain. And where we are required to keep records of a reported safety incident, we retain the minimum needed for as long as the law requires.

If you cannot reach the app, email privacy@roastish.com from the address on the account.

10. Children

Roastish is for people aged 13 and over. We do not knowingly collect information from anyone younger. If you believe a child has an account, email privacy@roastish.com and we will remove it.

11. Security

Traffic is encrypted in transit with HTTPS. Sign-in tokens are held in the device's secure keystore, not in ordinary app storage. Only one device can be signed into an account at a time — signing in elsewhere ends the earlier session. Access to production data is limited to people who need it.

No system is perfectly secure. If a breach affects you we will notify you and the relevant authority as the law requires.

12. International transfers

Our providers operate globally, so your data may be processed outside your country — including in the United States. Where required we rely on Standard Contractual Clauses or an equivalent safeguard.

13. Changes

If we change this policy we will update the date at the top, and for anything significant we will tell you in the app before it takes effect.

14. Contact

Privacy: privacy@roastish.com
Anything else: hello@roastish.com
Post: Roastish Technologies Pvt. Ltd., 221B, MG Road, Bengaluru, Karnataka 560001, India