Privacy Policy
Effective date: September 2, 2026
RoamFolio is an iOS app developed by Nossa ("Nossa," "we," "us," or "our") that helps you collect passport-style stamps for real-world cities and landmarks you visit, connect with friends, and send postcards. This Privacy Policy explains what information the app accesses, how it's used, and the choices you have. RoamFolio has no user accounts of its own outside of Sign in with Apple, and most of what it does happens almost entirely on your device or inside your own iCloud account, using Apple's own frameworks (CoreLocation, Photos, Contacts, CloudKit, Vision). For two optional, narrowly-scoped features — your generated avatar and the in-app coin balance used for optional postcard-delivery upgrades — RoamFolio talks to small services Nossa operates and hosts itself, described below.
1. Information We Collect
Location data
RoamFolio asks for location access ("while using the app") to show which stamping stations are nearby and to verify you're within range of one before letting you collect its stamp. Location is read live on your device to power this proximity check and the map views; RoamFolio does not track your location in the background, does not build a location history beyond the stamps you actually collect, and does not sell or share raw location data with anyone.
Photos
RoamFolio can read photo metadata in a few different ways, depending on the feature:
- Adding a past trip ("Retro-Add"): when you pick a photo from your library (via Apple's system photo picker, which does not grant RoamFolio ongoing library access) or share one in from Google Photos, Files, or another app, RoamFolio reads that single photo's embedded GPS coordinate and capture date to match it against nearby stamping stations. The photo's image data itself is never decoded, stored, or uploaded — only the location/date metadata is used, momentarily, to find a match.
- Sending a postcard, and viewing "Photos From This Trip": to help you pick a photo taken near a stamp — either while composing a postcard, or when browsing the photos your library has near a stamp you've already collected — RoamFolio requests broader photo library access for these features (iOS only offers a combined read/write permission level here; RoamFolio only ever reads your photos and never modifies or deletes them). It scans your library's location metadata to surface nearby matches; a photo you actively choose for a postcard is cropped on-device (Apple's Vision framework picks the most visually interesting area to keep, entirely on-device) and becomes part of a postcard you send — see "Sign in with Apple, Friends, and Postcards" below for how that's stored and shared.
Camera
The camera is used only to scan a friend's RoamPost QR code so you can connect with them. RoamFolio does not otherwise access the camera and does not store camera frames or images from this scan.
Contacts (optional)
RoamFolio can help you find friends who already use the app, entirely opt-in:
- Making yourself discoverable: if you turn on "Let Friends Find You by Phone Number," RoamFolio hashes your own phone number on your device (a one-way SHA-256 hash) and stores only that hash — never your actual phone number — so other users can find you. Turning the toggle back off deletes the stored hash.
- Finding friends from your contacts: if you tap "Find Friends from Contacts," RoamFolio requests access to your device's Contacts, hashes each contact's phone number the same way on your device, and checks those hashes against other users who've opted in above. Your contacts' names and raw phone numbers are never uploaded — only these one-way hashes ever leave your device, and only to check for a match.
Stamps, badges, and friend activity you generate
The stations you've stamped and the dates you collected them, your unlocked badge progress, and your friend connections and postcards are stored on your device and backed up to your own private iCloud account (via Apple's CloudKit) so they sync across your own devices. This data is private to your iCloud account — RoamFolio has no server that stores or has access to it.
Name, avatar, and status
Your display name defaults to the name Apple shares with RoamFolio the first time you sign in (only ever provided on that first authorization, and only if you choose to share it); if you don't share a name, or want to change it later, you can set or edit it anytime from Account. It's used for your in-app greeting and shown to any friends you connect with. Your profile picture is a generated avatar (not a photo) rendered from your display name by a small image-rendering service Nossa operates and hosts itself — see "Third-Party and Nossa-Operated Services" below. You can also set a short status line under your dashboard greeting ("What are you up to?") at any time; unlike your locally-stored stamps, this status is synced to your public RoamFolio profile record so any friend you're connected with can see it on the Friends screen — see "Sharing With Other Users" below.
Sign in with Apple, Friends, and Postcards
RoamFolio has no separate account system of its own — Sign in with Apple, completed once during setup, is how you get an identity in the app at all, and there's currently no way to finish setup without it. What stays optional afterward is whether you actually use RoamPost, the social side built on top of that identity: connecting with friends and sending postcards. We store the opaque identifier Apple provides, plus a randomly generated friend code, in Apple's CloudKit — not on a RoamFolio server. Adding a friend (by entering their code, scanning their QR code, or a contacts match) sends that person a request in CloudKit; the connection only becomes active once they accept it, and either side can remove the connection or block the other person afterward. When you send a postcard, its artwork (built from your chosen photo and stamp) and any short personal message you add are stored in a private, per-recipient CloudKit share that only you and that specific friend can access. Signing in also lets RoamFolio verify you for the optional coin wallet described next, and you can sign out again anytime from Account — your already-collected stamps keep working locally and via iCloud either way, since they don't depend on being signed in.
Coins and couriers (optional)
RoamFolio has an optional in-app currency ("coins") you can earn — for example, by collecting your first stamp, sending your first postcard, or referring friends who accept your requests — and spend on optional upgrades, like a faster courier (Pony or Pigeon instead of the default Postman) to speed up postcard delivery, or extra passport pages. This only applies if you've signed in with Apple; coins are not required to collect stamps or fill your passport. To stop a coin balance from being edited by tampering with the app's local storage, your balance and the history of how you earned or spent it are tracked in a small ledger Nossa operates and hosts itself (a Cloudflare Worker and database, not a third party), keyed only to the opaque, per-app identifier Apple's Sign in with Apple provides — the same identifier used for Friends/Postcards, not your name, email, or Apple ID itself. This ledger never sees your stamps, photos, postcards, or contacts, and RoamFolio does not currently offer any way to buy coins with real money.
Notifications (optional)
Once you've signed in with Apple, RoamFolio will ask for permission to send notifications so it can let you know when a postcard is delivered to you, when a friend request arrives, and when a postcard you sent reaches its recipient. This uses a silent CloudKit push to wake the app so it can prepare that alert — the push itself carries no postcard content or message text, only enough to tell the app something needs checking. RoamFolio also sends an immediate, on-device notification whenever you earn bonus coins (e.g. your first stamp or first postcard) — this one doesn't involve a network push at all, it just reports something that already happened locally. Beyond the system-level permission, RoamFolio's own Notifications settings screen lets you turn postcard alerts and friend-request alerts on or off independently (the coins-earned notification doesn't have its own toggle yet). You can decline or later disable notifications entirely anytime in iOS Settings → Notifications → RoamFolio without affecting any other feature.
Usage analytics
We use TelemetryDeck, a privacy-focused analytics service, to understand how people use RoamFolio — which screens are visited, how many stamps are collected and from which flow, whether nearby stations were found during a search, aggregate friend-discovery activity (e.g. that a code was submitted or a contacts search ran, not who was found), and non-identifying error events when something fails. TelemetryDeck does not use advertising identifiers, does not track you across other apps or websites, and does not require an App Tracking Transparency prompt because it doesn't perform cross-app tracking.
2. How We Use Information
- To show you stamping stations near your current location and let you collect them.
- To match a photo's embedded location/date against nearby stations for retro-adding stamps, and to surface nearby photos for postcards or your stamp's photo gallery.
- To back up and sync your collected stamps, badges, friend connections, and postcards across your own devices via iCloud.
- To power RoamPost's optional social features — friend requests, badge and status sharing between friends, and postcard delivery — for the parts of the app you actually choose to use beyond the required sign-in.
- To notify you, if you allow it, when a postcard or friend request arrives, or a postcard you sent has been delivered.
- To match opted-in phone number hashes so you can find, or be found by, friends already using RoamFolio.
- To render a generated avatar image from your display name, via our own self-hosted service.
- To track and update your optional coin balance and courier purchases, via our own self-hosted coin-wallet service, for signed-in users who use that feature.
- To carry out a full account deletion when you request one — removing your profile, stamps, badges, connections, postcards, and coin balance from every place RoamFolio stored them.
- To understand aggregate app usage and fix errors, via TelemetryDeck.
We do not use your information to serve third-party ads, and we do not sell your personal information.
3. Data Storage and Syncing
RoamFolio does not operate a general-purpose backend server for your data. Data that needs to persist beyond your device — collected stamps, badge progress, friend connections, and postcards — is stored using Apple's CloudKit, inside your own iCloud account:
- Your private database: your collected stamps sync only to your own devices, tied to your Apple ID.
- A shared, per-recipient record: a postcard you send, including any message you add, is placed in a CloudKit share scoped to you and the one friend you sent it to — not a public or queryable database.
- Public profile and connection records: a small profile record (your friend code, display name, unlocked-badge list, and status line — used so friends can see them), friend requests/connections, an opted-in phone-number hash (if you enabled discovery), and a pointer used to notify a recipient that a postcard is waiting are stored in CloudKit's public database, scoped to the RoamFolio app — containing only what's needed to make matching, connecting, or delivery work, never postcard photo content or your raw phone number.
The one exception is the optional coin wallet described above: your coin balance and a log of how you earned or spent coins live in a small database Nossa runs itself, separate from iCloud, keyed to Apple's opaque per-app identifier rather than your name or Apple ID.
If iCloud is unavailable or you're signed out, RoamFolio's core stamp-collecting features keep working fully offline using on-device storage; only cross-device sync and the optional Friends/Postcards features require iCloud.
4. Third-Party and Nossa-Operated Services
| Service | Purpose | What it sees |
|---|---|---|
| Apple CloudKit / iCloud | Stores collected stamps, badges, friend connections, and postcards | Whatever is described in "Data Storage and Syncing" above, governed by Apple's own privacy policy |
| Apple Sign in with Apple | Required identity, set up once during onboarding; also underlies the optional Friends/Postcards and coin-wallet features | An opaque user identifier; no profile data is requested |
| Apple Vision (on-device) | Frames the photo you pick for a postcard | Runs entirely on your device; nothing is transmitted |
| Nossa Avatar Service (self-hosted, not a third party) | Renders your generated profile avatar | Your display name (used as a rendering seed) and the resulting image size; operated by us on our own infrastructure, not shared with any outside company |
| Nossa Coin Wallet Service (self-hosted, not a third party) | Tracks your optional coin balance and courier/passport-page purchases | Apple's opaque per-app identifier (verified via a signed Sign in with Apple token), your coin balance, and a log of earn/spend events; never your name, stamps, photos, postcards, or contacts |
| TelemetryDeck | Privacy-conscious usage analytics | Anonymous, aggregate usage signals (see "Usage analytics" above) |
5. Sharing With Other Users
RoamFolio has no public profiles, social feed, or searchable directory of users. Information is only shared with another person when you take a deliberate action to connect with them, or once they're already your accepted friend:
- Sharing your friend code or QR code shares that code (not your location or stamp history) with whoever you show it to.
- Sending or accepting a friend request shares your display name, avatar, status line, and unlocked badge progress with that friend, for as long as you're connected.
- Sending a postcard shares that specific postcard's artwork, any message you wrote, the stamped station's name, the date, and your display name with the one friend you sent it to.
- Opting in to phone-number discovery only ever shares a one-way hash of your number, checked only against other opted-in users — never your name, raw number, or stamp history.
6. Your Choices and Controls
- Permissions: Location, Photos, Camera, Contacts, and Notifications access can each be reviewed or revoked anytime in iOS Settings → Privacy & Security, or Settings → RoamFolio. Declining a permission simply disables the feature that needs it (e.g., without location access, nearby stations won't be found; without notifications, you just won't get an alert for postcards and friend requests).
- Phone number discoverability: "Let Friends Find You by Phone Number" is off by default and can be turned off anytime, which deletes your stored hash immediately.
- Sign-in: Sign in with Apple is a required, one-time step during setup — there's currently no way to use RoamFolio, including basic stamp collecting, without completing it once. What's optional is everything built on top of it: you're never required to add a friend, send a postcard, or use the coin wallet, and you can sign out again anytime from Account (your already-collected stamps keep syncing via iCloud regardless of sign-in status). You can also decline any friend request, and remove or block a friend at any time from the Friends screen.
- Deleting your account: from Account → Delete Account, you can permanently delete your RoamPost profile, friend code, friend connections and requests, contact discoverability, collected stamps, badges, sent and received postcards, and your coin balance — from CloudKit, our coin-wallet database, and your device, in one flow. This is separate from, and more thorough than, simply deleting the app.
- Deleting the app: uninstalling RoamFolio removes all locally stored data. Because your stamps, badges, connections, and postcards live in your own iCloud account, you can also remove that data separately via iOS Settings → [your name] → iCloud → Manage Account Storage; using the in-app account deletion above is the only way to also remove your coin-wallet record.
7. Children's Privacy
RoamFolio is not directed at children under 13, and we do not knowingly collect personal information from children under 13. If you believe a child has provided us with personal information, please contact us using the details below so we can address it.
8. Data Retention
Stamps, badges, friend connections, and postcards persist for as long as your iCloud account retains them, or until you delete the app / remove that data from iCloud yourself. Your optional coin balance and its transaction log persist until you delete your account, at which point they're removed from our coin-wallet database. A phone-number hash used for friend discovery is deleted as soon as you turn its toggle off. Analytics signals sent to TelemetryDeck are anonymous and are not linked back to an individual identity we control.
9. Security
Because most of RoamFolio's data lives in your own iCloud account rather than a RoamFolio-operated server, it inherits Apple's iCloud security and encryption protections. Postcards are stored in per-recipient CloudKit shares rather than a publicly queryable database, so only the intended recipient can access them. Phone numbers used for friend discovery are one-way hashed (SHA-256) on your device before they ever leave it — the original number cannot be recovered from the stored hash. The coin-wallet service verifies your Sign in with Apple token cryptographically against Apple's own published keys before issuing it a session, and that session token is the only credential used for wallet requests afterward.
10. Changes to This Policy
If RoamFolio's data practices change materially — for example, if a future feature adds a new kind of data collection — we'll update this page and revise the effective date above.
11. Contact Us
Questions about this policy or how RoamFolio handles your data? Reach out at support@nossaapp.com.