PRIVACY POLICY

Last updated: August 1, 2026

Last updated: August 1, 2026

Welcome to ROVA (the "App"). ROVA is owned and operated by ROVA LLC ("we," "us," or "our"). We are committed to protecting your privacy and providing a transparent data architecture.

Our core privacy philosophy is simple: ROVA collects only the information strictly necessary to deliver personalized training, manage your account, track metrics, and synchronize your data across devices. We do not sell your personal data.

Please read this policy carefully to understand how your data is handled. By creating an account or using ROVA, you consent to the practices described below.

Welcome to ROVA (the “App”). ROVA is owned and operated by GR STORES LLC (“we,” “us,” or “our”). We are committed to protecting your privacy and providing a transparent data architecture.

Our core privacy philosophy is simple: ROVA collects only the information strictly necessary to deliver personalized training, manage your account, track metrics, and synchronize your data across devices. We do not sell your personal data.

Please read this policy carefully to understand how your data is handled. By creating an account or using ROVA, you consent to the practices described below.

Welcome to ROVA (the “App”). ROVA is owned and operated by GR STORES LLC (“we,” “us,” or “our”). We are committed to protecting your privacy and providing a transparent data architecture.

Our core privacy philosophy is simple: ROVA collects only the information strictly necessary to deliver personalized training, manage your account, track metrics, and synchronize your data across devices. We do not sell your personal data.

Please read this policy carefully to understand how your data is handled. By creating an account or using ROVA, you consent to the practices described below.

1. Information We Collect and How We Use It

1. Information We Collect and How We Use It

1. Information We Collect and How We Use It

We organize the data we process into distinct, functional categories designed to maximize performance tracking while minimizing data collection footprints.

Account & Authentication Data

To create an account and maintain ecosystem security, we require your name (if provided), email address, and a unique User ID. Passwords are completely encrypted and handled securely by our backend provider, Supabase Authentication. We never see, store, or have access to your raw plaintext password. This data is used solely to create your profile, securely authenticate your logins, facilitate account recovery, and establish secure cloud communication between your device and our servers.

Personal Profile & Onboarding Metrics

To customize your training algorithms, you provide self-reported wellness data during onboarding. This includes your age or date of birth, height, weight, biological sex or gender, personal fitness goals, current experience level, training frequency, workout duration preferences, available gym or home equipment, and preferred units of measurement. We process this information to generate tailored workout programs, calculate pacing parameters, and calibrate automated exercise recommendations.

Performance, Training, & Fitness Logs

This represents your core data footprint inside the App. We log completed workouts, historical training timelines, exercise selections, structured logs of sets, reps, and weight lifted, rest periods, workout feedback ratings, and program progression states. For endurance and aerobic tracking, this data stack includes elapsed time, calculated pace, estimated speed, and active calories burned. We use this information to generate visual progress charts, evaluate historical aerobic capacity, preserve your workout history, and iteratively improve future workout targeting.

Optional Geolocation Tracking

We collect precise GPS routing, live speed, and exact tracking coordinates exclusively to track real-time outdoor runs or cycling routes. This data is collected only if you explicitly grant permission via your device’s system location prompt. If denied, outdoor GPS metrics will be unavailable, but all other features of the App remain fully operational.

Device & Application Diagnostics

We automatically collect technical data necessary to monitor App stability, resolve software bugs, and optimize high-density UI rendering across varied mobile hardware. This data includes your device model, operating system version, App version, unique device identifiers, and system crash or diagnostic logs.

Payment & Subscription Data

To manage premium tiers, we process your subscription status and transaction validation receipts. ROVA does not collect, process, or store credit card numbers or banking information. All premium commerce is handled directly through the Apple App Store or Google Play Store. We receive a digital token confirming your subscription status, but your financial details remain strictly with the platform store.

We organize the data we process into distinct, functional categories designed to maximize performance tracking while minimizing data collection footprints.

Account & Authentication Data

To create an account and maintain ecosystem security, we require your name (if provided), email address, and a unique User ID. Passwords are completely encrypted and handled securely by our backend provider, Supabase Authentication. We never see, store, or have access to your raw plaintext password. This data is used solely to create your profile, securely authenticate your logins, facilitate account recovery, and establish secure cloud communication between your device and our servers.

Personal Profile & Onboarding Metrics

To customize your training algorithms, you provide self-reported wellness data during onboarding. This includes your age or date of birth, height, weight, biological sex or gender, personal fitness goals, current experience level, training frequency, workout duration preferences, available gym or home equipment, and preferred units of measurement. We process this information to generate tailored workout programs, calculate pacing parameters, and calibrate automated exercise recommendations.

Performance, Training, & Fitness Logs

This represents your core data footprint inside the App. We log completed workouts, historical training timelines, exercise selections, structured logs of sets, reps, and weight lifted, rest periods, workout feedback ratings, and program progression states. For endurance and aerobic tracking, this data stack includes elapsed time, calculated pace, estimated speed, and active calories burned. We use this information to generate visual progress charts, evaluate historical aerobic capacity, preserve your workout history, and iteratively improve future workout targeting.

Optional Geolocation Tracking

We collect precise GPS routing, live speed, and exact tracking coordinates exclusively to track real-time outdoor runs or cycling routes. This data is collected only if you explicitly grant permission via your device’s system location prompt. If denied, outdoor GPS metrics will be unavailable, but all other features of the App remain fully operational.

Device & Application Diagnostics

We automatically collect technical data necessary to monitor App stability, resolve software bugs, and optimize high-density UI rendering across varied mobile hardware. This data includes your device model, operating system version, App version, unique device identifiers, and system crash or diagnostic logs.

Payment & Subscription Data

To manage premium tiers, we process your subscription status and transaction validation receipts. ROVA does not collect, process, or store credit card numbers or banking information. All premium commerce is handled directly through the Apple App Store or Google Play Store. We receive a digital token confirming your subscription status, but your financial details remain strictly with the platform store.

We organize the data we process into distinct, functional categories designed to maximize performance tracking while minimizing data collection footprints.

Account & Authentication Data

To create an account and maintain ecosystem security, we require your name (if provided), email address, and a unique User ID. Passwords are completely encrypted and handled securely by our backend provider, Supabase Authentication. We never see, store, or have access to your raw plaintext password. This data is used solely to create your profile, securely authenticate your logins, facilitate account recovery, and establish secure cloud communication between your device and our servers.

Personal Profile & Onboarding Metrics

To customize your training algorithms, you provide self-reported wellness data during onboarding. This includes your age or date of birth, height, weight, biological sex or gender, personal fitness goals, current experience level, training frequency, workout duration preferences, available gym or home equipment, and preferred units of measurement. We process this information to generate tailored workout programs, calculate pacing parameters, and calibrate automated exercise recommendations.

Performance, Training, & Fitness Logs

This represents your core data footprint inside the App. We log completed workouts, historical training timelines, exercise selections, structured logs of sets, reps, and weight lifted, rest periods, workout feedback ratings, and program progression states. For endurance and aerobic tracking, this data stack includes elapsed time, calculated pace, estimated speed, and active calories burned. We use this information to generate visual progress charts, evaluate historical aerobic capacity, preserve your workout history, and iteratively improve future workout targeting.

Optional Geolocation Tracking

We collect precise GPS routing, live speed, and exact tracking coordinates exclusively to track real-time outdoor runs or cycling routes. This data is collected only if you explicitly grant permission via your device’s system location prompt. If denied, outdoor GPS metrics will be unavailable, but all other features of the App remain fully operational.

Device & Application Diagnostics

We automatically collect technical data necessary to monitor App stability, resolve software bugs, and optimize high-density UI rendering across varied mobile hardware. This data includes your device model, operating system version, App version, unique device identifiers, and system crash or diagnostic logs.

Payment & Subscription Data

To manage premium tiers, we process your subscription status and transaction validation receipts. ROVA does not collect, process, or store credit card numbers or banking information. All premium commerce is handled directly through the Apple App Store or Google Play Store. We receive a digital token confirming your subscription status, but your financial details remain strictly with the platform store.

2. Third-Party Data Service Providers

2. Third-Party Data Service Providers

2. Third-Party Data Service Providers

To keep ROVA functional, secure, and synchronized, we disclose specific data categories to trusted operational infrastructure providers. These processors are contractually barred from using your data for any commercial purpose beyond providing services to ROVA.

Supabase, Inc. serves as our primary cloud database, hosting encrypted authentication states, profile configurations, and historical training tables. Apple, Inc. and Google LLC facilitate secure in-app purchase validation, app distribution metrics, and platform performance diagnostics. Firebase Crashlytics processes anonymized technical diagnostic stack traces to help us eliminate application bugs and system crashes. Cloudflare, Inc. manages our web infrastructure, deep-link routing, and network security, processing basic technical data (such as IP addresses and device headers) strictly to deliver web content and defend against malicious traffic.

To keep ROVA functional, secure, and synchronized, we disclose specific data categories to trusted operational infrastructure providers. These processors are contractually barred from using your data for any commercial purpose beyond providing services to ROVA.

Supabase, Inc. serves as our primary cloud database, hosting encrypted authentication states, profile configurations, and historical training tables. Apple, Inc. and Google LLC facilitate secure in-app purchase validation, app distribution metrics, and platform performance diagnostics. Firebase Crashlytics processes anonymized technical diagnostic stack traces to help us eliminate application bugs and system crashes. Cloudflare, Inc. manages our web infrastructure, deep-link routing, and network security, processing basic technical data (such as IP addresses and device headers) strictly to deliver web content and defend against malicious traffic.

To keep ROVA functional, secure, and synchronized, we disclose specific data categories to trusted operational infrastructure providers. These processors are contractually barred from using your data for any commercial purpose beyond providing services to ROVA.

Supabase, Inc. serves as our primary cloud database, hosting encrypted authentication states, profile configurations, and historical training tables. Apple, Inc. and Google LLC facilitate secure in-app purchase validation, app distribution metrics, and platform performance diagnostics. Firebase Crashlytics processes anonymized technical diagnostic stack traces to help us eliminate application bugs and system crashes. Cloudflare, Inc. manages our web infrastructure, deep-link routing, and network security, processing basic technical data (such as IP addresses and device headers) strictly to deliver web content and defend against malicious traffic.

3. Data Retention, Security, and Cloud Sync

3. Data Retention, Security, and Cloud Sync

3. Data Retention, Security, and Cloud Sync

Your data is securely sent over TLS encryption and stored within cloud architecture managed by Supabase. We retain your personal information, profile parameters, and training logs for as long as your user account remains active. If your account is completely idle for more than two consecutive years, we reserve the right to archive or permanently delete your inactive data stack to reduce data footprints.

Your data is securely sent over TLS encryption and stored within cloud architecture managed by Supabase. We retain your personal information, profile parameters, and training logs for as long as your user account remains active. If your account is completely idle for more than two consecutive years, we reserve the right to archive or permanently delete your inactive data stack to reduce data footprints.

Your data is securely sent over TLS encryption and stored within cloud architecture managed by Supabase. We retain your personal information, profile parameters, and training logs for as long as your user account remains active. If your account is completely idle for more than two consecutive years, we reserve the right to archive or permanently delete your inactive data stack to reduce data footprints.

4. California Privacy Rights

4. California Privacy Rights

4. California Privacy Rights

If you reside in California, you are granted specific rights regarding your personal information under the California Consumer Privacy Act (CCPA), as amended by the CPRA.

You have the right to request a clear breakdown of the categories of personal information we collect and the specific entities with whom it is shared. You also maintain the right to modify or amend inaccurate metrics or profile data held within our database. We do not sell your personal data for monetary gain or share it for cross-context behavioral advertising, and exercising your privacy rights will never result in degraded app performance, increased pricing tiers, or a denial of services.

Additionally, ROVA does not track its users over time and across third-party websites to provide targeted advertising, and therefore does not respond to browser or device Do Not Track (DNT) signals.

If you reside in California, you are granted specific rights regarding your personal information under the California Consumer Privacy Act (CCPA), as amended by the CPRA.

You have the right to request a clear breakdown of the categories of personal information we collect and the specific entities with whom it is shared. You also maintain the right to modify or amend inaccurate metrics or profile data held within our database. We do not sell your personal data for monetary gain or share it for cross-context behavioral advertising, and exercising your privacy rights will never result in degraded app performance, increased pricing tiers, or a denial of services.

Additionally, ROVA does not track its users over time and across third-party websites to provide targeted advertising, and therefore does not respond to browser or device Do Not Track (DNT) signals.

If you reside in California, you are granted specific rights regarding your personal information under the California Consumer Privacy Act (CCPA), as amended by the CPRA.

You have the right to request a clear breakdown of the categories of personal information we collect and the specific entities with whom it is shared. You also maintain the right to modify or amend inaccurate metrics or profile data held within our database. We do not sell your personal data for monetary gain or share it for cross-context behavioral advertising, and exercising your privacy rights will never result in degraded app performance, increased pricing tiers, or a denial of services.

Additionally, ROVA does not track its users over time and across third-party websites to provide targeted advertising, and therefore does not respond to browser or device Do Not Track (DNT) signals.

5. Mandatory App-Store Account & Data Deletion

In strict compliance with Apple App Store Review Guideline 5.1.1(v) and Google Play user data mandates, we provide an unhindered, seamless pathway to permanently remove your identity from our systems. Deleting your account means all your profile metrics, saved workouts, and cloud sync tracking data are completely and permanently wiped from our active production database.

To delete your data in-app, navigate to the Settings panel inside the ROVA App, locate your profile information row, select Delete Account, and confirm the prompt. When you use this feature, your account authentication state and associated cloud database records are dropped from our Supabase instance automatically.

Alternatively, you may submit an explicit deletion request via email to support@rovaapp.com from your registered account email. Upon identity verification, your data will be permanently expunged within 30 days.

6. Children's Privacy Mandate

ROVA is a general-audience application designed for individuals who are at least 13 years of age or older. We do not knowingly target, market to, or collect personal data from children under the age of 13. If we discover that a child under 13 has inadvertently provided us with personal information, we will immediately delete that data from our servers.

7. Changes to This Policy

We may periodically update this Privacy Policy to reflect modifications to ROVA's feature set or evolving global data compliance standards. When material updates are made, we will notify you by updating the "Last Updated" date at the top of this document or via a conspicuous in-app system message.

8. Contact Information

For any legal questions, data access requests, or privacy concerns regarding this framework, please contact us directly.

ROVA LLC

Email: support@rovaapp.com