Roundo (“the app”) is a free, ad-free interval and CrossFit-style workout timer for Android phones and Wear OS watches, published by Tomáš Hulek. This policy covers both the phone app and the watch app.
None. Roundo’s developer never receives any data from the app. Roundo does not include analytics SDKs, crash reporters, telemetry, advertising IDs, or any code that sends information about you, your device, or your usage to the developer or to any third party. The only data that ever leaves a device is the optional phone ↔ watch sync described below, which goes end-to-end encrypted to your own other device.
Roundo stores the following on your own device(s) only:
This data is held in Android’s Preferences DataStore in Roundo’s private application directory. Uninstalling Roundo removes all of it. There is no account system and Roundo runs no cloud service of its own.
If you use both the phone app and the Wear OS app on a paired phone and watch, Roundo uses the Wearable Data Layer of Google Play services to sync your presets from phone to watch and your finished-workout log from watch to phone. Google Play services delivers it between your own paired devices: directly over an encrypted Bluetooth channel, or — when Bluetooth isn’t available — through a Google server node, end-to-end encrypted so that neither Google nor Roundo’s developer can read it. Only the same Roundo app, signed with the same key, on your other device can access it. Roundo’s developer never receives this data, and heart-rate readings are never part of it.
After you complete a few workouts, Roundo may ask Google Play to show its standard in-app rating prompt (Google’s In-App Review API). Google decides whether the prompt appears, and any rating you leave goes to Google Play under Google’s own privacy policy. Roundo never learns whether or how you rated it.
No backup includes this data unless your device’s general Android Auto Backup is enabled (a system-wide setting Roundo does not control). On the phone, the workout log is excluded from Auto Backup.
If you turn on heart rate in the watch app’s Settings and grant the permission, Roundo reads your heart rate from the watch’s sensor (through Wear OS Health Services) while a workout is on screen and shows it live on the timer. Heart-rate readings are displayed only: Roundo never stores them, never adds them to the workout log, never syncs them to the phone, and never sends them anywhere. Roundo does not read heart rate in the background. Leave the toggle off or decline the permission and the timer works fully without it.
BODY_SENSORS
on Android 15 and earlier, health.READ_HEART_RATE on Android 16 / Wear
OS 6 and later) — optional, off until you enable heart rate in Settings.
Used only as described under “Heart rate” above.Roundo does not request internet access, location, camera, microphone, contacts, calendar, files, phone, or SMS. It has no network code of its own; apart from the end-to-end encrypted phone ↔ watch sync above, none of the data above leaves your device.
Nothing, with no one. The phone ↔ watch sync only moves your own data between your own devices, end-to-end encrypted; it is not shared with Roundo’s developer or any third party.
Roundo collects no data, so it does not knowingly or unknowingly collect data from anyone, of any age.
Roundo’s Settings contain a “Support development” link that opens the Buy Me a Coffee page in your default browser. Once you tap it you’ve left Roundo and Buy Me a Coffee’s privacy policy applies. Tapping the link sends nothing about you to Roundo’s developer. Donations are optional and unlock nothing.
If Roundo’s data handling ever changes, this policy will be updated at the same URL with a new “Last updated” date, and the change will be called out in the release notes.
For privacy-related questions: tomas@earthbanc.io