Privacy Policy
DropRoost is an App Store wishlist and price tracker developed by Peter Dongo (“we,” “us”). This policy explains exactly what data the app handles and why. The short version: there are no accounts and we never ask who you are. We store only what is needed to check prices, send you the alerts you asked for, and stop a paid subscription being shared.
What we do not collect
DropRoost has no user accounts and no sign-in. We do not ask for — and never receive — your name, email address, phone number, password, or payment details. There is no analytics SDK, no advertising, no cross-app tracking, and no third-party trackers of any kind. We do not build a profile of you and we never sell or share your data.
What stays on your device and in your iCloud
Your wishlist itself — the apps you save, your categories, notes, ordering, and settings — lives on your device and syncs across your Apple devices through your own private iCloud account (Apple’s CloudKit). This data is stored under your Apple ID, is not visible to us, and is governed by Apple’s privacy policy.
What our server stores, and why
To check prices around the clock and push you a notification when something drops, our server needs to know a few things. This is the complete list of what it holds for your device:
- The items you choose to watch — the public App Store identifiers of the apps, in-app purchases, and subscriptions you added, plus the storefront (region) and the alert rule you set, and whether you muted an item.
- A push notification token — an identifier issued by Apple that lets us deliver alerts to your device. It is not your phone number, Apple ID, or your name — but because it identifies your device, we treat it as personal data.
- Your storefront preference — a two-letter region code (for example,
us) so we fetch prices from the right App Store. - Your platform — whether the device is iOS, iPadOS, or macOS, so notifications are formatted correctly.
- Your notification settings and pending digest — whether you muted everything, whether you chose immediate, daily, or weekly summaries, and — if you chose a digest — the price drops queued for your next summary (item title, old price, new price). The queue is emptied when the summary is sent, so it holds at most one day’s or one week’s worth of drops.
- An App Attest key — when your device attests itself to Apple, we store the resulting key identifier, its public key, and a counter. It is derived from your device’s Secure Enclave and identifies the device. It exists so that a leaked subscription receipt can’t be replayed from somewhere else; it carries no information about you or what you do.
- Subscription entitlement (only if you buy IAP Tracking) — the Apple-signed transaction identifier for your purchase, used solely to confirm your subscription is active and to enforce a limit of 6 devices per subscription. We never see your Apple ID or payment method.
Price history itself belongs to an item, not to a person: one shared, anonymous series per item and region, used by everyone watching it, with no record of who was watching when. The one exception is the digest queue described above — if you choose daily or weekly summaries, the drops waiting to be summarised are stored against your device until that summary is sent.
Legal basis (GDPR)
If you are in the EU/EEA or the UK, we process the data above on these bases:
- Performance of a contract (Art. 6(1)(b)) — your push token, watched items, storefront, platform, notification settings, and subscription entitlement. Without these we cannot deliver the price alerts the app exists to deliver.
- Legitimate interests (Art. 6(1)(f)) — the App Attest key and the 6-device limit per subscription. Our interest is preventing a paid subscription from being shared or replayed by devices that did not pay for it, which is what keeps the service affordable for the people who did. The data used is a device key and a count — nothing about you personally — and you can object using the contact address below.
Your rights
You have the right to access, correct, erase, restrict, and object to our processing of your data, and to receive it in a portable form. In practice:
- Erasure is one tap — Erase everything in the app’s settings, described below. It is immediate and complete.
- Access and portability — your wishlist is exportable from within the app; for what the server holds, email us and we will send it.
- Because there is no account, we can only act on requests we can tie to a device — in practice, requests made from the app itself.
You also have the right to complain to a data protection supervisory authority. Ours is Hungary’s Nemzeti Adatvédelmi és Információszabadság Hatóság (NAIH); if you live elsewhere in the EU/EEA you may complain to your own national authority instead.
Notifications
Push notifications are delivered through Apple’s Push Notification service (APNs). We send Apple the alert and your push token; Apple delivers it to your device. You can turn notifications off at any time in Settings → Notifications → DropRoost (iOS and iPadOS) or System Settings → Notifications → DropRoost (macOS), and you can mute everything, or any individual alert, inside the app.
In-app purchases
All purchases are processed by Apple through StoreKit. When you buy IAP Tracking, your device sends our server an Apple-signed receipt so we can verify the purchase is genuine and active. This verification happens between your device, our server, and Apple — we never handle your card, and we never see your Apple ID.
Deleting your data
You are in control. Removing an item stops it being tracked for you. To erase everything our server holds for your device, use Erase everything in the app’s settings — this immediately deletes your device record, your push token, your storefront and notification settings, your entitlement record, your App Attest key, any queued digest, and all of your watches. Because we hold no account, there is nothing else tied to you to delete.
Deleting the app without erasing first does not itself notify our server — iOS gives us no signal for it. What happens instead is described under retention below. If you want your data gone at a specific moment, use Erase everything before you delete the app, or email us.
Data retention
We keep your watches, push token, and settings until one of these happens:
- You use Erase everything (or ask us by email) — deleted immediately.
- Apple tells us your push token is permanently dead — which happens the next time we try to send you a notification after you have deleted the app. We then delete your device record and everything attached to it. Be aware this depends on there being an alert to send: if nothing you watch ever drops in price, no attempt is made, so nothing triggers the deletion and the record can persist. That is why the erase button, not app deletion, is the reliable way to remove your data.
Queued digest entries are deleted as soon as their summary is sent, and at most one day or one week after they are queued. A subscription’s device slot is freed after 90 days without use. Item price history is kept indefinitely as anonymous, shared catalogue data to power the history charts — it is not linked to any device.
Third parties
DropRoost uses no trackers, no analytics, and no advertising. It relies on these providers:
- Apple (Ireland/USA) — App Store price data, StoreKit purchases, APNs notification delivery, and iCloud sync of your wishlist under your own Apple ID.
- Fly.io (USA; our machines run in Frankfurt, Germany) — runs our server.
- Neon (USA) — the managed Postgres database that actually holds everything listed above.
- Cloudflare (USA) — serves this website. It receives no data from the app.
These are processors acting on our instructions; none of them use your data for their own purposes.
Children’s privacy
DropRoost is not directed at children under 13, and we do not knowingly collect data from them. We never ask any user for a name, email address, or other identifying detail, so the only data we hold about a child user would be the device identifiers described above. If you believe a child’s device data is on our server, email us and we will erase it.
International users and transfers
DropRoost works the same everywhere. Our server machines run in Frankfurt, Germany. The push token and device records described above are personal data, and the providers listed under “Third parties” are US-headquartered companies that may store or access that data outside the EU/EEA; those transfers are covered by the European Commission’s Standard Contractual Clauses in our agreements with them. They act only on our instructions. Apple’s own handling of APNs, StoreKit, and iCloud is governed by Apple’s privacy policy.
The controller for this data is Peter Dongo, Hungary, reachable at the address below.
Changes to this policy
If we update this policy, the new version will be posted at this URL with a revised “Last updated” date. Material changes will be noted in the release notes of the next app update.
Contact
Questions about this policy or about DropRoost in general:
[email protected]