Terms of Use · Impressum / Legal Notice · Deutsch
Last updated: September 4, 2026
This privacy policy applies to the Android app RoofWard
(package ID: com.roofward.home).
Robert Peringer
Ittlinger Hauptstraße 17
94315 Straubing
Germany
Email: FsNaviVfr@gmail.com
RoofWard is a tracker for recurring maintenance work on a home. The data you enter (task name, cost, interval, due date, category, and an optional area such as house, flat, garage, cellar or roof) is stored in a local database on your device. A document you attach to a job you have logged — a photo or PDF of a service record, a tradesperson’s invoice or a chimney sweep’s certificate, optionally taken with the camera on the spot — is stored as a file in the app’s private storage on the same device (see Section 3.2). There is no user account, no registration, and no server/backend of our own. The app does not transmit the maintenance data you enter, or the documents you attach, to the developer or to third parties.
Some limited technical data is nevertheless processed by third-party services when you use certain features: Google Play Billing is used to process premium purchases, and the Frankfurter API may be contacted directly from your device to fetch exchange rates when you use the currency conversion feature. Both are described in detail in Section 3. No advertising, analytics, or tracking services are used.
If Android’s Auto Backup feature is enabled on your device, the app’s local database and any documents you have attached may be included in a backup associated with your Google Account. The developer has no access to such backups (see Section 5).
Name, cost, currency, interval, due date, category, and an optional linked area for each maintenance task you add are stored in the app’s local database on your device. This data is used to display your tasks and to schedule local reminder notifications before a due date. It is never uploaded to a server operated by the developer.
Taken together, these entries say something about your home rather than about a service you subscribe to: what it is fitted with, what has recently been serviced and what has not, and — where you have entered dates far ahead — when a tradesperson is expected. Please bear that in mind when deciding what to record and when handing your unlocked device to someone else.
If you pick one of the symbols that ship with the app for an entry, that choice is stored there as well. The symbols are part of the app; no image is uploaded and none is fetched from the internet.
For any job you log you can attach up to ten documents — typically the service record, the tradesperson’s invoice or the chimney sweep’s certificate. There are three ways to do so: an existing photo from your gallery, an existing file from your device storage (a photo or a PDF), or a photo you take with your device camera then and there. The app then makes its own copy in its private storage on your device; photos are scaled down and re-encoded in the process. The metadata embedded in the original does not survive that — including the place the photo was taken and the camera model, where your device had written them. Only the orientation is carried over, so that a receipt photographed upright is not shown lying on its side. Only the file name of that copy is written to the local database, and an original you picked is left untouched.
When you take a photo, the app does not open the camera itself; it hands the capture to the camera app on your device. That app writes the image into a temporary file in RoofWard’s cache, from which the app produces the scaled copy; the temporary file is then deleted. Cancelling the capture deletes it too. Whether the camera app additionally keeps its own copy in your gallery is decided by the camera app alone; RoofWard has no influence over that.
A document is free-form content and can therefore contain more than the fields you type elsewhere in the app — your own name and the address of your home, the name, address and staff of the firm that carried out the work, a customer, order or invoice number, a meter or serial number, or anything else printed on it. The tradespeople named on such a document are data subjects under the GDPR just as you are, and you are attaching their data without their being asked.
The same applies to a photograph you take yourself. A picture of a boiler, a fuse box, a ceiling or a roof is a picture of your home, and it may show rooms, furnishings, other occupants or neighbouring property beyond the thing you meant to record. Please bear all of this in mind when deciding what to attach.
The app does not read, analyse, or interpret what a document contains, and does not upload it to the developer or to any third party. None of the three routes requires an additional Android permission for the app: an existing file is chosen in the Android system’s own photo picker or document picker, which grants the app access to that single file only, and for a capture the camera app asks for whatever permissions it needs itself (see Section 4).
Removing a document from an entry, or deleting the entry itself, also deletes the stored copy from your device. Uninstalling the app or clearing its data removes all stored documents.
Unlike the rest of your data, a document is a file rather than a database row, and it is included in Android’s Auto Backup alongside the database. If Auto Backup is enabled on your device, attached documents can therefore form part of a backup associated with your Google Account (see Sections 5 and 6).
Paid premium features are purchased through Google Play Billing. Payment details (card numbers, billing address, etc.) are processed entirely by Google, which acts as an independent data controller for that processing — RoofWard never sees or receives your payment details.
To determine whether premium features should be unlocked, the app queries your purchase status directly from Google Play each time it starts. This purchase information is not transmitted to the developer — there is no developer-operated server to receive it — and is not stored on your device either; it is only held in memory for the current app session. See Google’s Privacy Policy.
If you use the Insights screen to display totals in a currency other
than the one a task was entered in, the app fetches current
exchange rates from the free, keyless Frankfurter API
(api.frankfurter.app, based on European Central Bank reference
rates) over the internet. The purpose of this request is solely to
convert amounts between currencies for display; no maintenance
data or other personal data is included in or derived from this
request, only the currency codes needed to look up a rate. The
request is sent directly from your device to the Frankfurter API; the
developer does not operate or route this request through its own
server. As with any network request, your device’s IP address is
technically visible to the Frankfurter service as the operator of
that API, as well as to any technical infrastructure providers it
relies on (for example hosting or content-delivery providers). The
developer does not have access to this information and does not
control how long it is retained; this is determined by the
Frankfurter service and its infrastructure providers according to
their own privacy and retention practices. Fetched rates are cached
locally on your device for 24 hours to minimize how often this
request is made.
The app declares and uses the following Android permissions:
| Permission | Purpose |
|---|---|
Notifications (android.permission.POST_NOTIFICATIONS) |
Used to remind you before a maintenance task is due. Reminders are scheduled entirely on your device. On Android 13+, this requires your explicit consent, which the OS will ask for. |
Internet (android.permission.INTERNET) |
Used for Google Play Billing and fetching exchange rates for currency conversion (see 3.3–3.4). This is a standard permission automatically granted at install time, not something you are separately prompted to approve. |
The app does not request access to your contacts, location, camera, microphone, photos, or other sensitive device data.
This includes attaching a document. An existing file is chosen in the Android
system’s own photo picker or document picker, which hands the app a read grant
for the single file you selected and nothing else. The app therefore does not
declare READ_MEDIA_IMAGES or any comparable storage permission.
Taking a document photo does not require a camera permission for the app
either. The picture is taken by the camera app on your device, using its own
permissions; RoofWard merely provides a temporary file for it to write into,
and does not declare android.permission.CAMERA.
The app uses Google Play Billing to process premium purchases, and the Frankfurter API to fetch exchange rates for currency conversion in the Insights screen (see 3.4). No advertising, tracking, or analytics/statistics SDKs are used (e.g. no Google Analytics, Firebase Analytics, or similar).
The app also supports Android’s built-in Auto Backup, which — if enabled on your device — automatically backs up the app’s local database and the document files you have attached, as part of the standard Android OS backup service. The backup is handled by Android and associated with your Google Account; the developer does not operate this backup service and has no access to its contents. See Google’s documentation on Android Auto Backup for details, and Android’s device backup settings to control it.
Maintenance data you enter is stored in the app’s local database on your device, and documents you attach are stored as files in the app’s private storage on the same device. Both remain there until you edit or delete them, or delete the app’s local data. The developer does not operate its own server and does not receive or disclose this data to third parties.
If Android Auto Backup is enabled for RoofWard, this local database and the attached document files may also be included in a backup associated with your Google Account, as described in Section 5.
Under the GDPR, you generally have the right to access (Art. 15), rectification (Art. 16), erasure (Art. 17), and restriction of processing (Art. 18). Where the respective legal requirements are met, you also have the right to data portability (Art. 20) and the right to object to processing based on legitimate interests (Art. 21).
Because the developer does not receive or have access to the maintenance data stored locally on your device, many requests concerning such data can already be fulfilled directly by using the app’s functions to view, edit, or delete it. You may also contact the controller using the details in Section 1 if you wish to formally exercise any of these rights.
Deleting the app or its local data removes this data from your device. If Android Auto Backup is enabled, a backup may remain associated with your Google Account until it is managed or deleted through Android’s backup settings or your Google Account — the developer cannot delete this on your behalf, as it has no access to it (see Section 5).
You also have the right to lodge a complaint with a data protection supervisory authority.
Where the GDPR applies, the legal basis depends on the specific processing activity:
This privacy policy may be updated as needed, for example due to changes in the app’s functionality or legal requirements. The current version is always available via the link provided in the app and in the Play Store listing.
For privacy-related questions, please contact: FsNaviVfr@gmail.com