Privacy & security
Your saves do not take a detour through us.
Rove is a desktop app with local-first behavior. The important boundaries are simple enough to state plainly.
The short version
What Rove does and does not do.
- Rove does not run a Rove-hosted save server.
- The application does not upload saves anywhere unless you configure a cloud destination.
- Google Drive access is user-authorized from the desktop app.
- OAuth refresh tokens are stored locally using Windows protection.
- Desktop OAuth client configuration is not treated as a private server credential.
- The update system uses signed release artifacts.
We do not promise end-to-end encryption unless that feature is actually implemented. Google Drive and synced-folder privacy also depend on the provider and account you choose.
Open by default
Read the source. Report a problem.
The desktop app is the canonical technical source for behavior and implementation. Review it on GitHub.
For a security concern, use the repository's security reporting guidance rather than posting sensitive details in a public issue. The website repository and desktop app repository are intentionally separate.
Open security guidance ↗