Privacy & security

Your saves do not take a detour through us.

Rove is a desktop app with local-first behavior. The important boundaries are simple enough to state plainly.

The short version

What Rove does and does not do.

  • Rove does not run a Rove-hosted save server.
  • The application does not upload saves anywhere unless you configure a cloud destination.
  • Google Drive access is user-authorized from the desktop app.
  • OAuth refresh tokens are stored locally using Windows protection.
  • Desktop OAuth client configuration is not treated as a private server credential.
  • The update system uses signed release artifacts.

We do not promise end-to-end encryption unless that feature is actually implemented. Google Drive and synced-folder privacy also depend on the provider and account you choose.

Open by default

Read the source. Report a problem.

The desktop app is the canonical technical source for behavior and implementation. Review it on GitHub.

For a security concern, use the repository's security reporting guidance rather than posting sensitive details in a public issue. The website repository and desktop app repository are intentionally separate.

Open security guidance ↗