Privacy Policy
Last updated: August 16, 2026
This Privacy Policy explains how Hamid Keshmiri (“Routindo”, “we”, “us”) collects, uses, and protects your information when you use the Routindo mobile and web application (the “Service”). If you have questions, contact us at contact@mail.routindo.app.
Information we collect
Account information
- Email and name. When you create an account with email and password, we store your email address and a display name derived from it. Passwords are stored only as a salted hash — we never store them in plain text.
- Sign in with Google or Apple. If you sign in with a social provider, we receive your email address and basic profile information (including a profile photo, if available) from that provider.
- Anonymous use. You can use Routindo without an account. In that case we create a device-scoped anonymous session that holds no email or identity; if you later sign up, your existing data is carried over to your new account.
Content you create
- Your routines, their schedules and reminders, and your completion history (which routines you marked done and when).
- Your preferences — such as which day your week starts on, which days count as your weekend, app and widget theme, and your device time zone.
- Home-screen widget (Android). A snapshot of today’s routines is stored on your device so the widget can render offline. We also record a count of how many Routindo widgets you have installed, tied to your account, so we can decide whether to suggest adding one.
Technical information
- IP address and server logs. Our servers process your IP address to operate the Service, prevent abuse, and rate-limit requests. Logs are kept for a limited period.
- Your device time zone, so reminders resolve to the correct local day.
- Sessions and devices. Each time you sign in we keep a session record holding your IP address and your device’s user agent — which identifies the app or browser and the broad type of device. Where a plan limits how many devices an account may use, we also record a device identifier, so that we can apply the limit and show you which devices are signed in. You can end a session at any time by signing out.
Advertising (free version only)
- Advertising identifier. On Android, your device’s Advertising ID. On iOS, the Identifier for Advertisers (IDFA) — and only if you allow tracking when the system asks you.
- Ad delivery information. Our advertising partner receives your IP address (from which approximate location can be derived), device and app information, and how you interact with the ads it serves.
We do not sell your personal data for money. The free version does show third-party advertising, which means sharing the information above with our advertising partner — see Advertising and your choices. We never share your routines, completion history, or anything else you create with advertisers.
How we use your information
- To provide, maintain, and sync the Service across your devices.
- To authenticate you and keep your account secure.
- To apply the features and limits of the plan you are on.
- To send transactional emails you request or that are essential to your account — email verification codes, password-reset codes, and an account-deletion confirmation. We do not send marketing email without your consent.
- To suggest an icon when you create a routine. The routine’s name — and nothing else — is sent to OpenAI, which returns a few emoji that suit it. Your email, your account, and your device are not sent, and the request is made by our servers rather than by the app, so OpenAI does not receive your IP address.
- To display and measure advertising in the free version of the app, and to prevent ad fraud.
- To prevent fraud, abuse, and security incidents.
- To comply with legal obligations.
Our legal basis for using your data
If you are in the European Economic Area or the United Kingdom, the law requires us to have a legal reason for every use of your personal data, and to tell you which one applies. Ours are:
- To perform our contract with you. Storing your account, your routines, your completion history and your preferences, syncing them across your devices, sending you the transactional emails described above, and applying the features and limits of your plan. This is not optional extra processing — it is the Service itself, and we cannot provide Routindo without it.
- Our legitimate interests. Keeping the Service secure and available: processing IP addresses and server logs to rate-limit requests, prevent abuse, and investigate security incidents; recording how many Routindo widgets you have installed so we can decide whether suggesting one is useful to you; and sending a routine’s name to OpenAI to suggest an icon for it, so that naming a routine is quicker than searching a list of emoji. We rely on this only where your rights and freedoms do not override it, and you can object at any time — see Your rights.
- Your consent. Personalized advertising, wherever consent is required. You can decline, and you can withdraw consent at any time, without losing access to the app — see Advertising and your choices. Withdrawing does not affect anything we did before you withdrew.
- To comply with a legal obligation. Responding to lawful requests, and keeping records the law requires us to keep.
Service providers we share data with
We use a small number of third-party processors to run the Service. They may process your data only on our instructions:
- Cloud hosting & database — Railway and its managed PostgreSQL database store your account and app data.
- Backup storage — Cloudflare R2 holds encrypted backups of that database.
- Email delivery — Resend sends the transactional emails described above.
- Sign-in providers — Google and Apple, if you choose to sign in with them.
- App updates — Expo delivers over-the-air updates to the app. Each time your device checks for one, Expo receives your IP address, your platform, and which version of the app you are running.
- Content delivery — routine icons are standard emoji images your device fetches from a public CDN (jsDelivr).
- Icon suggestions — OpenAI receives a routine’s name in order to suggest emoji for it, and nothing else about you. We keep the suggestion so the same name does not have to be sent again; see retention below.
Our advertising partner is different, and we want to be clear about it: Google AdMob does not act only on our instructions. It uses what it receives for its own purposes as an independent controller — selecting and measuring ads, and detecting ad fraud — under Google’s own privacy terms.
Advertising and your choices
The free version of Routindo is supported by ads served by Google AdMob. A paid plan, where offered, removes them. Ads are the only reason any of your information reaches a company that isn’t running the Service for us.
- Personalized vs non-personalized ads. Where consent is required — including the EEA, the UK, and Switzerland — we ask before any personalized advertising. You can decline and keep using the app; you’ll see non-personalized ads instead.
- Under 18. We do not show personalized ads to users we understand to be under 18, whether or not consent has been given.
- Android. You can reset or delete your Advertising ID under Settings → Privacy → Ads.
- iOS. Tracking happens only with your permission via the system prompt, and you can change it later under Settings → Privacy & Security → Tracking.
- United States. See “Do not sell or share” under Your rights.
Data retention and deletion
We keep your information for as long as your account exists. You can delete your account at any time from within the app (Account → Delete account). Deletion is immediate and permanent: it erases your account and all associated data — routines, completion history, preferences, sessions, and linked sign-in providers.
Encrypted database backups are one exception, and we let them expire rather than edit them. A backup is deleted 30 days after it is taken if it is a daily one, and 180 days after it is taken if it is a monthly one, so a deleted account’s records can persist inside a backup until it reaches that age. We do not restore a deleted account from a backup. Server logs holding IP addresses are kept by our hosting provider for a limited period set by its platform, and are not used to rebuild anything about you.
Icon suggestions are the other exception, and a smaller one. When a routine name is sent to OpenAI, we store that name with the emoji that came back, so nobody has to wait for the same answer twice. That record is not linked to you — it holds no account, no device, and no way to tell who typed it — and it is deleted 90 days after the last time it was used. Because it is not linked to you, deleting your account does not remove it; it simply expires. OpenAI also keeps what it receives for a period set by its own policy, which we do not control.
Information our advertising partner has already received is held under its own retention policy; deleting your Routindo account does not recall it, so use the advertising choices above if that matters to you.
Your rights
Depending on where you live (including under the GDPR and CCPA/CPRA), you may have the right to access, correct, delete, or export your data, and to object to or restrict certain processing. You can exercise deletion directly in the app; for other requests, contact contact@mail.routindo.app. You may also lodge a complaint with your local data-protection authority.
Do not sell or share (United States). We do not sell your personal information for money. Serving personalized ads does count as “sharing” for cross-context behavioral advertising under California’s CCPA/CPRA and comparable state laws. To opt out, decline personalized ads in the app, or email contact@mail.routindo.app with the subject “Do Not Sell or Share”. We honor opt-out preference signals, including Global Privacy Control, where we are required to.
International transfers
Your account and app data are stored and processed in the United States (our hosting provider’s US West region), whichever country you use Routindo from. Our sign-in and advertising partners operate globally, so ad-related information may be processed elsewhere too. Where required, we rely on appropriate safeguards (such as Standard Contractual Clauses) for these cross-border transfers.
Because the data is held in the United States, it is subject to US law, and US courts or authorities may be able to compel access to it through lawful process.
Security
We protect your data with measures including encryption in transit, hashed passwords, and access controls. No method of transmission or storage is completely secure, but we work to protect your information.
Children and teenagers
Routindo is intended for people aged 13 and over, or the minimum age required in your country.
Routindo is not directed to children under 13, we do not knowingly collect their personal data, and we do not knowingly serve them personalized advertising. If you believe a child has given us personal data, contact us and we will delete it.
Changes to this policy
We may update this policy from time to time. We will post the new version here and update the “Last updated” date; significant changes will be communicated in-app or by email where appropriate.
Contact
Hamid Keshmiri
contact@mail.routindo.app