Roost Privacy Policy
Effective date: 2026-09-28
Roost is a macOS application made by an independent developer (“we”, “us”). This policy explains what Roost does with your data, what it does not do, and what happens on the website at https://roost.afceda.com. The short version: Roost has no servers, no accounts and no analytics. Your data goes to exactly two places, both chosen by you: the on-device model on your Mac and the AI providers you configure.
1. What Roost is
Roost runs a local server on your Mac that receives requests from AI applications you use and routes each request either to Apple Intelligence on your Mac or to an external AI provider you have configured. Which one is used depends on the mode you select and, in the Smart and Private modes, on an assessment made by the on-device model.
2. Data we collect
We collect no personal data through the app. Roost does not create accounts, does not send usage statistics, crash reports or telemetry to us, and does not contain advertising or third-party analytics. We have no server that the app talks to.
Apple may provide us with aggregated, anonymous statistics about downloads and usage of the app through App Store Connect, if you have allowed this in your device settings. That data comes from Apple, not from Roost, and is governed by Apple’s privacy policy.
3. Data processed on your Mac
The following stays on your Mac and is under your control:
- Settings: port, network interface, mode, provider list (names, addresses, model names), routing options. Stored in the app’s preferences.
- API keys for providers: stored in the macOS Keychain, read only when a request or a connection check is sent, never written to logs, settings files or responses.
- Decision log: for each request, the time, the destination (on-device or which provider), the reason, the assessment flags, the duration and a short preview of the last message (up to 120 characters). Kept in memory (the last 200 entries) and, only if you enable it in Settings, appended to a log file on your Mac. Answers are not logged. You can clear the log and delete the file at any time.
- Requests and answers pass through Roost in memory and are not stored by it.
Apple Intelligence processes requests routed to the on-device model on your Mac. How Apple handles on-device processing is described in Apple’s documentation and privacy policy; Roost does not add any processing of its own.
4. Data sent to AI providers you configure
If you add an external provider (for example a cloud service such as OpenAI, Anthropic, Google or DeepSeek, or a server you run yourself such as llama.cpp or Ollama) and select a mode that uses it, Roost sends the following to that provider:
- The content of requests routed to it: the messages your application sent, including any system prompt and conversation history, forwarded as your application sent them, together with your API key for that provider.
- Connection checks: while Roost is running, it asks each enabled provider for its list of models every thirty seconds and when you use Test connection. These checks carry your API key and no request content.
Which requests are routed to a provider depends on the mode:
- On-device: none.
- Smart and Private: only requests that the on-device model has assessed as containing
no private data (and, in Smart, that it judged too hard or too time-sensitive to answer
itself). The assessment is performed by a language model and may make mistakes. The decision
feed and the
X-Roost-*response headers show, for every request, where it went. - Full: every request, without assessment.
Providers process this data under their own terms and privacy policies. We do not control them, do not receive anything from them and do not act as an intermediary between you and them: you hold the account, the key and the contract. Review a provider’s privacy policy before adding it, in particular whether it uses submitted content for training and how long it retains it. Servers you run yourself are subject to your own configuration.
If you open the server to your local network in Settings, other devices on that network can send requests through Roost and therefore through your providers. Roost has no authentication; use this option only on networks you trust.
5. Data we receive when you contact us
The website has a contact form instead of a published email address. When you send a message through it, we receive the email address you enter, your name and WhatsApp number if you choose to give them, the topic you picked and the text of your message. With the message our server records the page you sent it from, the country and city estimated from your IP address using the GeoLite2 database, and the browser and operating system family reported by your browser. The IP address itself is not stored.
We use this only to answer you. We keep a message as long as needed for that and delete it when you ask us to. Please do not send API keys or private conversations.
The form asks you to type digits from a picture to keep out spam. The check runs on our server and stores nothing in your browser.
6. The website
The website at https://roost.afceda.com is a static site served by our own server. To understand how many people visit it and which parts they read, the site runs its own analytics. No third-party analytics service is involved, and nothing is shared with anyone.
What the site records for each page view: the page, the section of the page that scrolled into
view, the address of the site you came from (only its host name), campaign parameters in the
link you followed (utm_*), the browser and operating system family, the type of device, the
screen width in broad ranges, and the preferred language reported by your browser. The country,
region and city are estimated from your IP address using the GeoLite2 database on our server;
the IP address itself is not stored and does not appear in our logs.
Visits are counted with a short-lived hash built from the IP address, the browser identification string and a random value that changes every day and is then discarded. The hash cannot be turned back into an IP address and does not link one day’s visits to another’s. The site sets no cookies and stores nothing in your browser for this purpose.
Raw analytics records are kept for 180 days and then deleted. Daily totals without any per-visit detail are kept indefinitely. The Cookie Notice at https://roost.afceda.com/cookies describes the cookies used on this site.
7. Legal bases and your rights
Where data protection laws such as the GDPR or the UK GDPR apply to you, the processing described in section 5 (contact form) and section 6 (website analytics) is based on our legitimate interest in answering your request and in understanding how the website is used; the processing described in sections 3 and 4 happens on your device or between you and a provider you chose, and we do not process that data.
You have the right to ask what personal data we hold about you, to have it corrected or deleted, and to object to or restrict its processing. Because we hold no data except messages sent through the contact form and anonymous website statistics, such requests will usually be answered by deleting those messages. Send your request through the contact form and choose the topic “Privacy request”. You also have the right to lodge a complaint with a supervisory authority in your country.
8. Children
Roost is not directed to children and we do not knowingly collect data from anyone under the age at which they can consent to data processing in their country. The app has no accounts and collects no data, so there is nothing for us to delete; providers you configure apply their own age rules.
9. Security
Keys are stored in the macOS Keychain. Connections to cloud providers use the TLS encryption provided by macOS. The local server accepts connections only from your Mac unless you change the interface setting. No data is transmitted to us, so there is no data of yours for us to lose.
10. Changes to this policy
We may update this policy when Roost changes. The effective date at the top tells you which version you are reading, and material changes will be noted in the app’s release notes. Continued use of Roost after a change means you accept the updated policy.
11. Contact
Contact form: https://roost.afceda.com/support#contact https://roost.afceda.com