Last updated: July 15, 2026
Romy's Garage is built to work almost entirely on Your device. This Privacy Policy explains the little information that is processed in connection with the Service, who processes it, and why, and tells You about Your privacy rights.
The words whose initial letters are capitalized have meanings defined under the following conditions. The following definitions shall have the same meaning regardless of whether they appear in singular or in plural.
For the purposes of this Privacy Policy:
Sign-in identifier. When You sign in with Sign in with Apple, Apple issues a stable, app-specific identifier for Your Apple ID (not Your actual Apple ID or email address). This identifier is stored locally in Your Device's Keychain and is also shared with RevenueCat so that Your Pro Subscription can be recognized across reinstalls or additional devices.
Name (optional). Apple lets You choose whether to share Your name the first time You sign in. If You do, it is stored locally in Your Device's Keychain to personalize the Account screen in Settings. It is never transmitted to the Company or any third party.
Email address (optional, not stored). Apple may share Your email address (or a private Apple relay address) with the Application at the moment You sign in. Romy's Garage does not persist this email address and does not transmit it anywhere.
Subscription and purchase status. To unlock Pro features, the Application checks Your subscription status with RevenueCat, which in turn relies on Apple's App Store to validate Your purchase. Neither the Company nor RevenueCat ever receives Your payment card details — those are handled entirely by Apple.
Project Data. See "Project Data Stays on Your Device" below — this data is never sent to Us.
Support correspondence. If You email Us for support, We process the content of Your message and Your email address to respond to You.
We do not collect: location data, contacts, health data, browsing or in-app usage analytics, advertising identifiers, or any data via cookies or web-tracking technologies. Romy's Garage is a native iOS application with no embedded analytics, advertising, or tracking SDKs.
Device permissions. The Application may request access to Your Device's Camera, solely so You can take a photo of a part or Your vehicle directly within the app. Romy's Garage does not request access to Your full Photo Library — the built-in iOS photo picker lets You choose existing photos without granting the app broader library access.
Apple's own diagnostics (optional, controlled by You). If You have enabled "Share With App Developers" under Your Device's Privacy & Security settings, Apple may share anonymized crash and performance data with Us through App Store Connect. This is entirely controlled by You in Your Device settings and governed by Apple's own privacy policy, not by the Application itself.
The Company may use the limited Personal Data described above to:
We do not use Your Personal Data for advertising, profiling, or automated decision-making, and We do not send marketing communications based on Personal Data collected through the Service.
We share Personal Data only in the following situations:
We do not share Personal Data with advertisers, data brokers, or analytics partners, because We do not work with any.
Your vehicle project information — including project names, categories, parts, tasks, milestones, budget entries, journal entries, before/after photo pairs, and any photos You take or import — is stored exclusively on Your Device. Romy's Garage has no backend server, and this Project Data is never transmitted to, or accessible by, the Company or any third party, including RevenueCat or Apple.
If You use the Application's optional "Export data" feature, You create a backup file that You choose where to save or share (for example, via Files, a cloud-storage app of Your choice, AirDrop, or email) using Your Device's standard share sheet. That choice, and any resulting storage of the file, is entirely Yours; the Company never receives or has access to Your exported backup files.
Because Project Data never reaches Us, We cannot access, restore, or delete it on Your behalf — You are always in full and immediate control of it (see "Delete Your Personal Data" below).
The very limited Personal Data described in this Policy (Your sign-in identifier and, if applicable, support correspondence) may be processed by RevenueCat, Inc., which is based in the United States, and by Apple, which operates data centers internationally. Where Personal Data is transferred outside the European Economic Area (EEA) or the United Kingdom (UK) to a country not recognized as providing an adequate level of protection, We and Our Service Providers rely on appropriate safeguards, such as the European Commission's Standard Contractual Clauses (SCCs) or the UK International Data Transfer Agreement, together with supplementary technical measures such as encryption.
If the Company is involved in a merger, acquisition, or asset sale, the very limited Personal Data described in this Policy may be transferred; We will provide notice before it becomes subject to a different Privacy Policy.
The Company may disclose Personal Data if required to do so by law, or in the good-faith belief that such action is necessary to comply with a legal obligation, protect the rights or safety of the Company or others, or investigate wrongdoing in connection with the Service.
Because Your Project Data stays on Your Device rather than on a Company-operated server, it cannot be exposed by a breach of Our systems — We simply do not have it. The security of Project Data on Your Device depends on Your own Device security (passcode, Face ID/Touch ID, and keeping Your operating system up to date), which is Your responsibility. For the limited Personal Data We do process via RevenueCat and Apple, We rely on those providers' security measures; no method of electronic transmission or storage is ever 100% secure, and We cannot guarantee absolute security.
We do not use any analytics, advertising, or crash-reporting SDKs beyond what is described above.
We process the limited Personal Data described in this Policy under the following legal bases:
If You are in the EEA or UK, You have the right to:
To exercise these rights, contact Us using the details below. We may ask You to verify Your identity before responding, and We will generally respond within one month.
This section supplements Our Privacy Policy and applies solely to California residents.
| Category | Examples | Collected? |
|---|---|---|
| A. Identifiers | Sign-in identifier; name and email address (if You choose to share them) | Yes |
| B. California Customer Records (Cal. Civ. Code § 1798.80(e)) | Name | Yes (overlaps with A) |
| C. Protected classifications | Age, race, gender, etc. | No |
| D. Commercial information | Subscription/purchase status (via Apple/RevenueCat) | Yes |
| E. Biometric information | — | No |
| F. Internet/network activity | Browsing history, in-app analytics | No |
| G. Geolocation data | — | No |
| H. Sensory data | Audio/visual recordings | No (Your own photos stay on Your Device and are never received by Us) |
| I. Professional/employment information | — | No |
| J. Education information | — | No |
| K. Inferences | Profiles or predictions about You | No |
| L. Sensitive personal information | Government IDs, financial accounts, precise geolocation, health data, etc. | No |
We do not sell Personal Information for money, and We do not "share" it for cross-context behavioral advertising, because We do not use any advertising or ad-measurement technology.
If You are a California resident, You have the right to: notice of collection; know/access the Personal Information We hold about You; request correction; request deletion (subject to exceptions such as RevenueCat's/Apple's legal retention obligations); opt out of sale or sharing (not applicable, as We do not sell or share); and non-discrimination for exercising these rights.
To exercise these rights, contact Us at the email below. We will verify Your identity before responding and will respond within 45 days (extendable once by 45 days where reasonably necessary).
We do not knowingly collect Personal Information from children under 16, and We do not sell or share Personal Information of any Consumer, regardless of age.
The Service does not respond to Do Not Track (DNT) browser signals. As a native mobile application without cookies or web-tracking technology, Romy's Garage has no tracking activity for a DNT signal to affect.
Romy's Garage does not run its own age-verification check. Eligibility to use the Service is governed by Apple's own account requirements: the Application can only be used with an Apple Account that meets Apple's minimum age for that country, or, for younger children, an Apple Account organized by a parent or guardian through Family Sharing under Apple's own parental controls.
Under data protection laws such as COPPA (US) and the GDPR, We do not knowingly collect Personal Data from children under 13 (or the relevant minimum age under Your local law) outside of what is described above, and We do not knowingly sell or share any child's Personal Data. If You are a parent or guardian and believe Your child has provided Us with Personal Data without appropriate consent, please contact Us so We can address it.
This Privacy Policy links to RevenueCat's and Apple's own privacy policies for Your reference. We have no control over, and assume no responsibility for, the content or privacy practices of those third-party sites.
We may update this Privacy Policy from time to time. We will notify You of material changes by updating the "Last updated" date above and, where appropriate, through a notice within the Application prior to the change taking effect. You are advised to review this Privacy Policy periodically.
If You have any questions about this Privacy Policy, You can contact Us: