Last updated: June 1, 2026
This is a plain-language launch draft for Frontroom. It should be reviewed by counsel before public release. It is based on the current app scope: local-first use, optional account sign-in, optional cloud backup/sync, optional Pro purchases, and import/export tools.
Frontroom stores app data on your device, including system records, members, avatars and picked images, custom fronts, folders, tags, custom fields, fronting and co-fronting history, front notes, journal notes, notes for the next front, private feed posts, comments, reactions, privacy settings, import records, archive records, and local operation history.
The current local database is a SQLite database stored by the app on your device. It is not separately SQLCipher-encrypted in the current build. Frontroom can use your device's local authentication as an optional app lock, but app lock is a device-level convenience, not a separate encrypted vault.
Frontroom can import Simply Plural export files and avatar archives. Data that Frontroom supports may become native app data. Unsupported or unknown import sections may be preserved as read-only archive records so you can keep a more complete migration record.
Frontroom may ask you to pick files for imports, backups, and restores, and may ask you to pick images for avatars or private feed images. The current app does not request camera or microphone permission.
You can use the local core without an account. If you choose Apple or Google sign-in, Frontroom sends sign-in tokens to the Frontroom backend to create or access your account. The backend may receive account identifiers and provider information such as user ID, name, or email, depending on what the sign-in provider returns.
If you use cloud backup or sync, Frontroom uploads encrypted backup bundles and encrypted asset objects, along with metadata needed to operate the feature, such as backup IDs, timestamps, sizes, asset references, local system IDs, and key IDs. Cloud key material is tied to your account so your account can restore backups. This means Frontroom cloud backup is not zero-knowledge.
Access tokens, refresh tokens, and cached cloud key material are stored in the device secure storage when available.
Pro purchases are handled through the app stores and RevenueCat. We may receive purchase status, entitlement status, product identifiers, renewal or expiration dates, app user IDs, and purchase-management links. We do not receive full payment card numbers from the app stores.
If you visit our website or contact support, we may receive information such as your email address, message contents, and ordinary website or server logs. Use arthur@worldbuilders.app for privacy requests.
We use service providers for app distribution, account sign-in, cloud hosting or storage, subscriptions, website hosting, and support. These providers process information needed to provide those services.
Frontroom does not have public profiles, public discovery, followers, or a public social graph in the current launch scope. If you export, share, or upload a backup file somewhere else, that copy is controlled by where you put it.
Frontroom is not directed to children under 13. Account sign-in and cloud features require confirming that you are at least 13 and agreeing to the terms and privacy policy. If we learn that we collected account information from a child under 13 without required consent, we will delete it.
We use practical safeguards such as local-first storage, secure storage for account tokens when available, optional app lock, and encrypted cloud backup uploads. No app, device, backup, or network service can be made perfectly secure. Local backup exports are not encrypted by Frontroom.
We may update this policy as Frontroom changes. If a change meaningfully affects account, cloud, purchase, or data-handling practices, we will update the date above and provide notice where appropriate.