Skip to content
Rova
How it worksWhat Rova protectsExploreSupport
HomePrivacyTermsSupport

Privacy Policy

How Rova handles your photos, designs, device information and choices.

Effective: August 11, 2026

On this pageOverviewInformation we processProcessing mapPhotos and AI processingHow we use informationService providersRetentionYour choices and rightsChildrenContact

1. Overview

This Privacy Policy explains how Maydora Teknoloji ve Ticaret A.Ş. ("Maydora", "we", "us" or "our") processes information when you use the Rova mobile application, the rovadesign.com website and related support services (together, the "Services"). Maydora, based in Türkiye, is the operator of Rova and the controller of personal data described here unless a service provider acts as an independent controller.

Rova is designed without a conventional named profile or email sign-in. The app creates pseudonymous random technical identifiers so it can provide free allowances, protect subscriptions, operate generation securely and support account deletion.

In plain language: when you choose to generate a design, Rova sends the photo, any reference and your design instruction to third-party AI processing services solely to handle that request and related safety, security and support. Rova's application backend does not currently write those images to its server database or cloud file storage. Projects you save are stored on your device, subject to your Apple backup settings.

2. Information we process

Photos, prompts and design choices

When you ask Rova to create or edit a design, we process the source photo, any reference image, your written instruction, selected space type, style, palette, preservation mode and related design choices. We need this content to produce the proposal you requested.

Pseudonymous account and device information

Our backend authentication provider creates a pseudonymous account identifier. Rova also creates a random device identifier stored in the iOS Keychain, which may survive app deletion. We use these identifiers for authentication, free-proposal limits, fraud prevention, subscription binding, service security, account deletion and support. We do not require your name, email address or phone number to use the app.

Subscription and transaction information

Apple processes App Store purchases. Our subscription-management provider gives Rova pseudonymous customer identifiers, product and entitlement status, purchase and renewal events, storefront-related details and technical information needed to activate and restore Rova Pro. We do not receive your full payment-card details.

Usage, diagnostics and attribution

Rova records limited product events such as onboarding steps, paywall interactions, generation success or failure categories and app lifecycle information. These events may include a pseudonymous app identifier, app version, device/operating-system information, timestamps, coarse network information and subscription context. Rova does not send your photos or prompt text to product-analytics providers.

Our subscription-management and advertising-attribution providers may process pseudonymous attribution identifiers and purchase events to measure advertising. If you permit tracking through Apple's App Tracking Transparency prompt, this may include the advertising identifier (IDFA). If you decline, Rova does not receive permission to access the IDFA; privacy-preserving attribution and non-IDFA identifiers may still be used where permitted.

Website and support information

Our website hosting, content-delivery and security providers may process IP address, browser, device, security and request metadata when they deliver this website. The website does not provide a generation tool, user account, contact form or advertising cookie. If you email us, we and our communications or support providers receive the address, message and attachments you choose to send.

Processing map

This table connects each category with how it is collected, why it is used, the legal basis generally relied on where applicable, the recipients and transfer context, and the retention criteria. A legal basis can differ by jurisdiction; where a stated basis is unavailable, we rely only on another basis permitted by applicable law.

Data categoryCollection, purpose, basis, recipients and retention
Design contentCollected: directly from you when you take or select a source photo, add a reference, enter an instruction or choose design settings and submit a generation request.
Purpose: generate and return the requested design; apply safety, abuse-prevention, reliability and support controls.
Legal basis: performance of the requested service or contract; your direction or consent where required for disclosure to AI providers; legitimate interests in security and reliability; legal obligations where applicable.
Recipients and transfers: AI/model-hosting/inference and cloud/backend/security providers. Processing may occur in Türkiye, the EEA, the United States or other provider locations under the safeguards in section 5.
Retention: Rova's backend handles content in transit and working memory and does not currently persist it; providers may apply limited operational, security, debugging or legal retention; saved projects remain locally on your device and in any Apple backup until removed under your settings.
Pseudonymous account, device and security informationCollected: generated automatically by the app, iOS Keychain and backend services when you install, authenticate or use Rova.
Purpose: authenticate access, enforce free and paid allowances, bind entitlements, verify app integrity, prevent fraud, delete account data and provide support.
Legal basis: performance of the service or contract; legitimate interests in security, fraud prevention and service administration; legal obligations where applicable.
Recipients and transfers: cloud/backend/security, app-platform and subscription-management providers, with international processing under section 5 where necessary.
Retention: while the pseudonymous account and relevant allowance or entitlement relationship operate, and afterward only as needed for deletion completion, security, fraud, support, disputes or legal requirements. The Keychain identifier may survive app deletion until removed through the in-app deletion process or device controls.
Subscription and transaction informationCollected: from Apple and our subscription-management provider when you view, start, renew, restore, cancel or seek support for a purchase.
Purpose: activate and restore Rova Pro, administer entitlements, prevent purchase fraud, provide billing support and meet accounting or legal duties.
Legal basis: performance of the subscription contract; legitimate interests in entitlement administration and fraud prevention; legal obligations.
Recipients and transfers: Apple, subscription-management and relevant cloud/backend providers, which may process data internationally under section 5.
Retention: for the active subscription and as afterward needed for restoration, transaction support, fraud prevention, accounting, consumer claims and legal obligations. Apple independently controls its transaction records.
Usage and diagnosticsCollected: automatically from app interactions, lifecycle events, versions, device/operating-system context, timestamps and success or failure categories.
Purpose: understand feature use, measure reliability, troubleshoot failures, protect the Services and plan improvements. Photo content and prompt text are not sent to product analytics.
Legal basis: legitimate interests in operating, securing and improving Rova; consent where required by applicable law.
Recipients and transfers: analytics, diagnostics, cloud/backend and security providers, potentially in international locations under section 5.
Retention: for the configured period reasonably needed to compare releases, investigate reliability or security issues and measure product performance, then deleted or de-identified where appropriate.
Advertising and attribution informationCollected: from app, subscription and attribution events and device-permitted identifiers. IDFA is accessed only when Apple's tracking permission has been granted.
Purpose: attribute installs and subscription events, measure campaigns and detect attribution fraud.
Legal basis: consent where required for tracking or advertising identifiers; otherwise legitimate interests or another basis permitted for privacy-preserving measurement in the relevant jurisdiction.
Recipients and transfers: attribution, advertising and subscription-management providers, potentially in international locations under section 5.
Retention: for the configured period needed to measure the applicable campaign, reconcile attribution and investigate fraud or disputes, then deleted or de-identified where appropriate.
Website and support informationCollected: website request and security metadata is collected automatically; email address, message and attachments are collected directly from you when you contact us.
Purpose: deliver and secure the website, respond to questions, investigate issues and maintain necessary support records.
Legal basis: legitimate interests in website security and communications; performance of a requested service; consent or legal obligations where applicable.
Recipients and transfers: website hosting/content-delivery/security and communications/support providers, potentially in international locations under section 5.
Retention: website records for operational security and troubleshooting needs; support material until the matter and reasonable follow-up are complete, with longer retention only for security, disputes or legal recordkeeping.

3. Photos and AI processing

Rova checks your entitlement or free allowance before uploading a photo. When you tap the generation control, you direct Rova to transmit the source photo, optional reference image and structured instruction over encrypted connections to our secured application backend and to one or more third-party AI, model-hosting or inference providers. Those providers process the content to generate the requested result and may perform related safety, abuse-prevention, reliability and legal-compliance processing.

  • Rova's application backend does not currently write source photos, reference photos or generated images to its server database, cloud file storage or persistent server disk. The content is handled in transit and working memory for the request.
  • We do not currently use your photos or prompts to train a model of our own, publish them, or make them available to other Rova users.
  • AI and infrastructure providers may keep limited request, response, safety or technical records under the provider terms and settings applicable to Rova, including for security, abuse prevention, debugging and legal compliance. Retention and processing locations can vary by provider, service tier and region.
  • We select and configure providers for business/API use and require protections consistent with this Policy and applicable law. If we propose using private photo or prompt content to train or improve a general-purpose model, we will first clearly disclose that use and request opt-in consent.
  • Generated images returned to the app are saved locally only when the app can create your project. Your local Rova documents may be included in your Apple device or iCloud backup according to your Apple settings.

Avoid uploading photos you do not have permission to use, or photos containing sensitive documents, private information or identifiable people where processing is unnecessary.

4. How and why we use information

  • Provide the Services: authenticate the app, generate proposals, save projects locally and restore subscription access.
  • Perform our contract: deliver requested designs and Rova Pro benefits.
  • Protect the Services: enforce fair-use limits, prevent fraud, verify app integrity, troubleshoot failures and secure systems.
  • Improve Rova: understand feature use and reliability through limited analytics that do not include photo content or prompt text.
  • Measure marketing: attribute app installs and subscription events, subject to your device choices and applicable law.
  • Meet legal duties: maintain transaction-related records, respond to lawful requests and enforce our terms.
  • Support you: answer messages and investigate account or subscription problems.

Depending on where you live, our legal bases may include performance of a contract, legitimate interests in operating and securing Rova, consent for tracking where required, and compliance with legal obligations.

We do not sell personal data for money. Some advertising-attribution disclosures may be considered "sharing", "targeted advertising" or a similar term under certain laws. You can deny or change tracking permission in iOS Settings.

5. Service providers and disclosures

We use third-party processors and platforms only for defined operational purposes. We require providers that receive data from Rova to protect it to the same or an equivalent standard required by this Policy and applicable law, subject to their independent legal obligations. Providers may change as technology and the Services develop; the categories of processing are described below.

  • AI, model-hosting and inference providers: process photos, references and instructions to create requested images and support model safety and reliability.
  • Cloud hosting, backend and security providers: provide pseudonymous authentication, app-integrity verification, server functions, quota and entitlement records, network delivery, logging, fraud prevention and operational security.
  • App-store and device-platform providers: distribute the app, process purchases, manage subscriptions, provide app attestation and permissions, and provide optional device or cloud backup.
  • Subscription-management providers: maintain pseudonymous customer records, subscription and entitlement status, purchase restoration and related attribution integrations.
  • Analytics and diagnostics providers: process limited product-use, performance and reliability events. We do not send photo content or prompt text to these providers for product analytics.
  • Advertising and attribution providers: measure installs and subscription events using identifiers allowed by your device settings and applicable law, including an advertising identifier only when permission has been granted where required.
  • Website, communications and support providers: deliver and protect the website and help us receive, manage and respond to support messages.

Our current technology stack includes Apple services for app distribution and purchases; cloud and backend services for app authentication, integrity checks and request handling; business/API AI services for image generation; and specialist providers for subscription management, analytics, attribution and website delivery. We assess new or replacement providers before they process personal data and update our disclosures when a change materially affects how your data is used or protected.

We may also disclose information when required by law, to protect rights and safety, in connection with a corporate transaction, or with your direction. Providers may process information in Türkiye, the European Economic Area, the United States and other countries. Where required, we use recognised transfer safeguards, such as adequacy decisions or contractual protections, and apply supplementary measures where appropriate. To request information about the safeguard relevant to your data, or a copy where one can legally be provided, email info@maydora.com with the subject "Rova transfer safeguards". We may provide a summary or redact confidential and third-party information where necessary without obscuring the substance of the protection.

6. Retention and deletion

We keep personal data only for the period reasonably necessary for the stated purpose, then delete or de-identify it unless a longer period is required or permitted for law, security, fraud prevention or dispute resolution. We determine that period by considering whether the request is complete, whether an account, entitlement or allowance remains operational, the time reasonably needed to investigate failures or misuse, provider configuration and deletion controls, and applicable transaction, accounting, consumer-protection and legal-record duties.

InformationTypical retention
Source and reference images in Rova's application backendProcessed in transit and working memory for the generation request; not currently stored in Rova's server database or cloud file storage.
AI-provider request dataFor the time needed to generate and return the result, plus the provider's limited period for configured security, abuse monitoring, debugging, deletion operations or legal compliance.
Saved projects and generated imagesOn your device until you delete a project, delete all projects or delete the account and data. Device and cloud backup copies follow your Apple settings and retention.
Pseudonymous account, quota and run recordsWhile the account and relevant allowance cycle operate, and afterward only as reasonably needed to complete deletion, investigate failures or misuse, prevent fraud, support you, resolve disputes or meet legal requirements.
Subscription and entitlement recordsFor the active subscription and afterward as needed for restoration, fraud prevention, transaction support, accounting, consumer claims and legal obligations. Account deletion does not cancel or erase the app-store platform's transaction record.
Analytics and attribution eventsFor the configured period reasonably needed to compare releases or campaigns, measure reliability and attribution, and investigate security, fraud or disputed events; then deleted or de-identified where appropriate.
Support communicationsUntil the request and reasonable follow-up are complete, and longer only where needed for security, disputes or legal and business recordkeeping.

In Rova, open Settings → Delete account & data to delete the pseudonymous app account, app-owned account records, device binding and local projects. This action does not cancel an App Store subscription; use Apple's subscription management separately. Some transaction, entitlement, fraud-prevention, security or legal records may remain where deletion is not technically controlled by Rova or where retention is required or permitted by law.

7. Your choices and rights

  • Choose whether Rova may access the camera or photo library in iOS Settings.
  • Choose whether to allow tracking through Apple's App Tracking Transparency control.
  • Delete individual projects, all local projects, or your pseudonymous account and data inside Rova.
  • Manage or cancel a subscription through your Apple account settings.
  • Contact us to request access, correction, deletion, restriction, objection, portability, withdrawal of consent or an appeal where applicable.

Withdrawing consent

Where processing relies on consent, you may withdraw it at any time through the relevant iOS permission or tracking setting, an in-app control where available, or by emailing us. Withdrawal applies to future processing and does not make processing carried out lawfully before withdrawal unlawful. A feature that requires the withdrawn permission or disclosure may no longer work, but we will not treat withdrawal as permission to use the data for a new purpose.

How to make a rights request

Email info@maydora.com with the subject "Rova privacy request" and describe the right you want to exercise. Because Rova does not require a named profile, include only information reasonably helpful to locate the relevant pseudonymous account, such as the in-app identifier or transaction/support reference available to you. Do not send an identity document unless we specifically explain why it is necessary.

We may ask for information reasonably necessary to verify that you control the relevant account, device, transaction or email address. We use verification information only to handle the request and protect data from unauthorised disclosure. If we cannot verify a request or an exception applies, we will explain the decision where permitted. We will respond within the period required by the law that applies to the request. If that law permits an extension, we will tell you that an extension is needed and why.

If applicable law gives you a right to appeal our decision, reply to the decision email with the subject "Rova privacy appeal" and explain why you believe it should be reconsidered. The appeal will be reviewed by someone able to reconsider the original outcome, and we will respond within the legally applicable period. You may also lodge a complaint with the competent data-protection authority.

Rights differ by jurisdiction and may be subject to verification and lawful exceptions. Residents of Türkiye may have rights under the Law on the Protection of Personal Data (KVKK); residents of the EEA or United Kingdom may have rights under applicable data-protection law; and residents of certain US states may have additional privacy rights.

8. Security

We use safeguards appropriate to the nature of the data, including encrypted transport, pseudonymous authentication, app- and device-integrity checks, access controls, secret-managed credentials, limited backend storage and provider security measures. No security method is perfect, and we cannot guarantee absolute security.

9. Children's privacy

Rova is not directed to children under 13, and we do not knowingly collect personal data from children under 13. If you believe a child has provided information improperly, contact us so we can investigate and delete it where appropriate.

10. Changes to this policy

We may update this Policy when Rova, our providers, security practices or legal requirements change. We will post the revised Policy here and update the effective date. If a change materially affects how we collect, use, retain or disclose personal data, we will provide prominent or in-app notice before the change takes effect where reasonably possible and obtain consent where required by law. We will not apply a materially different new purpose to information already collected without an appropriate legal basis and required notice.

11. Contact

Maydora Teknoloji ve Ticaret A.Ş.
Türkiye
Email: info@maydora.com

Please include "Rova privacy request" in the subject and avoid sending photos or sensitive information unless we specifically request it.

Rova
PrivacyTermsSupport

Rova is operated by Maydora Teknoloji ve Ticaret A.Ş.