
RoaPilot

RoaPilot — Politique de confidentialité
Last Updated: 03.12.2025
This Privacy Policy explains how ROAPILOT (“we,” “our,” “the App”) collects, uses, shares, and protects user information across all platforms, including iOS, Android, Web, Smart TV platforms, backend services, and integrated third-party APIs (TikTok API, Firebase, RevenueCat, Google APIs, Microsoft APIs, Apple APIs, and other connected services).
By using the App or visiting our website (www.roapilot.com), you agree to the terms of this Privacy Policy.
1. Information We Collect
We collect the following categories of information depending on how you use our App and which login method you choose:
1.1 Account & Authentication Data
Collected through Apple, Google, Microsoft, Email/Password, or TikTok login:
-
Full name
-
Email address
-
Profile photo (if provided)
-
Authentication identifiers (UID)
-
OAuth tokens (stored temporarily)
We do NOT store passwords. All authentication is handled securely by the login provider.
1.2 TikTok API Data (If user logs in with TikTok)
If you choose to authenticate using TikTok Login, we may collect:
-
TikTok open_id
-
TikTok username / display name
-
TikTok profile picture
-
TikTok basic profile metadata
-
Authorized tokens (short-term, not stored permanently)
We do NOT:
-
Post content on behalf of users
-
Access private TikTok data
-
Access videos, messages, analytics, or non-public information
-
Store TikTok access tokens permanently
All data access is strictly limited to permissions granted by the user and compliant with:
TikTok Developer Terms & Policies → https://developers.tiktok.com/terms/
1.3 Automatic Device & Usage Data
Collected automatically through Firebase, Google Analytics, or internal logs:
-
Device type, OS version, device model
-
IP address, region, language
-
App usage logs
-
Crash reports
-
Subscription status (via RevenueCat)
This information helps improve performance, stability, and security.
1.4 Subscription & Payment Information
We use RevenueCat to process subscription verification.
We do NOT collect or store payment card details.
RevenueCat may process:
-
Subscription ID
-
Purchase status
-
Platform (App Store / Google Play)
-
Transaction history
1.5 User-Generated Content (If applicable)
If the user uploads or imports data (e.g., playlists, favorites, custom settings), this data may be stored securely on our servers or locally on the device.
2. How We Use Your Data
We use collected information for:
-
Account creation & authentication
-
Improving app performance and user experience
-
Subscription management and entitlement validation
-
Preventing fraud and unauthorized access
-
Providing personalized features
-
Customer support
-
Debugging and crash analysis
TikTok Login data is only used for the purpose of logging in and identifying the user.
We never use TikTok API data for:
-
Advertising
-
Selling data
-
Publishing content
-
Analytics profile building
3. Data Sharing & Third-Party Services
We may share limited data with trusted service providers:
✔ Firebase (Authentication, Database, Analytics)
✔ Google (Authentication, Analytics)
✔ Apple (Authentication)
✔ Microsoft (Authentication)
✔ TikTok API (Login)
✔ RevenueCat (Subscription verification)
✔ Cloud hosting providers
We DO NOT sell user data to advertisers or third parties.
All third-party services follow strict privacy & security standards.
4. Data Storage & Retention
-
Authentication data is stored securely in Firebase.
-
TikTok access tokens are not stored, only used during the login session.
-
Subscription data is stored by RevenueCat for verification.
-
Device and analytics data may be stored for performance optimization.
-
User data is retained as long as the user’s account remains active.
Users may request account deletion at any time.
5. Data Deletion (User Rights)
You have the right to:
-
Request deletion of your account
-
Request deletion of TikTok login data
-
Request removal of subscription data
-
Request access to the information we hold
Users can request deletion by emailing:
Upon request:
-
TikTok API data is deleted immediately
-
Firebase account & related data are deleted within 48 hours
-
Subscription records are anonymized
-
Logs are purged within 30 days
6. GDPR Compliance (EU Users)
Under GDPR, users have the right to:
-
Access their personal data
-
Request correction
-
Request deletion
-
Limit processing
-
Export their data
-
Withdraw consent
ROAPILOT acts as a Data Controller under GDPR.
7. CCPA Compliance (California Users)
California residents may:
-
Request what personal information is collected
-
Request deletion of their data
-
Opt out of data sharing (we do not sell data)
8. Children’s Privacy
ROAPILOT does not knowingly collect data from children under 13.
If such data is discovered, it is deleted immediately.
9. Security
We use industry-standard security measures:
-
End-to-end encryption
-
Secure HTTPS transmission
-
OAuth2 authentication
-
Encrypted token handling
-
Restricted backend access policies
However, no system is 100% secure; users use the service at their own risk.
10. Changes to This Policy
We may update this Privacy Policy occasionally.
Changes will be posted on this page with a new “Last Updated” date.
11. Contact Us
For questions, data deletion, or privacy concerns: