ROVEPOINT

Privacy Policy

Effective date: [effective date]

Draft — not legal advice, not yet reviewed by counsel.

This page is an AI-drafted starting point describing what ROVEPOINT's systems actually do today. It has not been reviewed by a lawyer and must not be published or relied on as a real privacy policy until it has been — especially given this product is designed to hold passport and visa data. Bracketed fields ([like this]) are placeholders for real legal-entity details that need to be filled in before publishing.

Who we are

ROVEPOINT is operated by [Company legal name], a [company type] registered in [jurisdiction], registered address [registered address]. If you have questions about this policy or your data, contact us at [contact email].

What we collect

  • Your phone number, to sign you in via one-time passcode.
  • Travel documents you choose to store — passports, visas, vaccination records, insurance — including document numbers and expiry dates.
  • Your nationality, if you provide it, to look up visa requirements.
  • Trip details you enter — destinations, dates, titles.
  • Questions you ask the ROVE AI copilot, sent to Anthropic (our AI provider) to generate a response.
  • Your email address, if you join the waitlist.

How we protect it

Document numbers and other sensitive fields are encrypted before they are ever written to our database — our database itself never sees or stores that data in plain text. Every table enforces row-level access control so you can only ever read or write your own records, not another user's. Scanned document images are stored in a private file store, accessible only via a short-lived, single-use link generated at the moment you view them.

When we share it

We do not sell your data. We share it only with the service providers needed to run ROVEPOINT, and never a document itself without your explicit, revocable consent:

  • Supabase — hosts our database and file storage.
  • Twilio — delivers the SMS one-time passcode used to sign in.
  • Anthropic — processes questions you send to the ROVE AI copilot.
  • Resend — delivers account and reminder emails.

If a partner (an airline, hotel, or similar) ever requests access to one of your documents, that access is a specific, logged, time-limited grant you approve — not a standing permission, and it can be revoked at any time.

Your rights

You can view, update, or delete your documents and account data directly within the app at any time. [Add any additional rights required by applicable law — e.g. GDPR/ CCPA data export, right to erasure timelines, regulator contact details.]

Changes to this policy

[Describe how and when this policy will be updated, and how material changes will be communicated to users.]

Draft — not legal advice, not yet reviewed by counsel.

This page is an AI-drafted starting point describing what ROVEPOINT's systems actually do today. It has not been reviewed by a lawyer and must not be published or relied on as a real privacy policy until it has been — especially given this product is designed to hold passport and visa data. Bracketed fields ([like this]) are placeholders for real legal-entity details that need to be filled in before publishing.