Skip to content
Roost
InstallDocsAlternativesGitHub

Legal

Privacy Policy

This policy explains the information handled by the Roost website and private pre-launch managed service. The managed service has not publicly launched or opened public signup, and its accounts are operator-created.

Last updated September 4, 2026

Information Roost handles

  • Account and contact information: your email address and, when you use Google sign-in, the verified email address, Google subject identifier, and canonical issuerhttps://accounts.google.com. The issuer and subject identify the Google account; Roost does not use email equality alone to link an existing account.
  • Credentials and devices: password hashes if you add a password, browser-generated public keys and their fingerprints, device labels, authorization and revocation records, and sign-in metadata. Browser private keys are designed to remain on your device, and raw passwords are not retained.
  • Service content: the terminal sessions, commands or input, session history, account and dashboard settings, machine information, and other content you send to or create through Roost.
  • Network and security information: IP addresses, request metadata, rate-limit records, authentication and security events, and operational logs used to protect and run the service.
  • Human-verification information: Cloudflare Turnstile responses and validation results when a private pre-launch enrollment requires an anti-abuse check. Roost uses the response to verify the request and does not use it for advertising.
  • Support information: messages you send to support, your reply address, and information you include so the issue can be investigated.

How the information is used

Roost uses this information only as needed to:

  • create and authenticate operator-created accounts, link sign-in methods, and authorize devices;
  • provide terminal, dashboard, synchronization, backup, and related service features;
  • send verification, activation, password-reset, security, and support email;
  • prevent abuse, enforce capacity limits, investigate incidents, and keep the service reliable; and
  • respond to support requests and comply with applicable legal obligations.

Google sign-in

Google sign-in requests only the OpenID Connect openid and email scopes. Roost verifies the returned identity token and keeps the canonical Google issuer, subject identifier, and latest verified email needed to recognize the account. Roost does not call Google data APIs or Gmail, request offline access, or retain Google ID tokens, access tokens, or refresh tokens.

Service providers

Roost shares information with service providers only to operate the service:

  • Google provides optional account authentication.
  • Cloudflare provides DNS, network delivery and protection, tunnels, and Turnstile anti-abuse checks. Cloudflare may process IP addresses and request or device signals under its own terms.
  • Resend delivers transactional account and support-related email.
  • Hosting infrastructure providers process account data, service content, logs, and encrypted backups on the systems used to run Roost.

Roost does not sell personal information, show advertising, or share information for cross-context behavioral advertising. The public marketing site does not run analytics.

Cookies and browser storage

The dashboard uses strictly necessary cookies and browser storage for sign-in transactions, account routing, security receipts, preferences, and device authorization. Roost does not use advertising cookies. A browser may also keep its non-extractable private device key locally so it can prove authorization on later visits.

Retention and deletion

Account identity records, authorized device records, settings, and service content are retained while the account exists. Disabling an account stops its managed access but does not by itself erase its data, so the account can be re-enabled. There is no blanket automatic deletion schedule for all service records.

High-volume terminal input audit records are deleted after the configured retention window, which currently defaults to 90 days. Roost keeps the newest 14 daily encrypted account backup snapshots; older snapshots are removed as that set rotates. Information changed or removed from the live service may therefore remain in a backup until its snapshot rotates out. Short-lived verification and sign-in transaction records expire after their security purpose ends. Security records may be retained longer when needed to investigate abuse or protect accounts.

Support messages are retained as needed to answer the request and preserve an operational support history. To ask about your information or request account deletion, email[email protected]. Some limited records may be kept where required for security, dispute resolution, or legal compliance.

Security

Roost uses access controls, isolated account services, signed device requests, and encrypted backups to protect information. No Internet service can guarantee absolute security. Keep control of your email account and devices, and contact support promptly if you suspect unauthorized access.

Changes and contact

This policy may change as the private pre-launch managed service develops. The date above will be updated when the policy changes. Questions about this policy can be sent to[email protected].

Roost

One self-hosted dashboard for your macOS and Linux machines.

GPL-3.0-only · © 2026 Mihai Mateias

Roost

InstallDocsAlternatives

Project

github.com/cefege/roostLicense (GPL-3.0-only)Issues

Legal & support

PrivacyTermsEmail support

Author

github.com/cefegede.linkedin.com/in/mihai-mateias

No analytics on this site.