Back to DearRoll

DearRoll · Privacy

Privacy Policy

Effective date: 30 August 2026 Reviewed app version: 1.0.0 (versionCode 13)

DearRoll processes photos, videos and the resulting media-library overview locally on the Android device. DearRoll does not operate a proprietary server for this processing, does not require a user account, and contains no advertising, proprietary tracking, analytics SDK or crash-reporting SDK. The optional DearRoll Pro purchase is handled through Google Play.

1. Purpose and basic principle

DearRoll helps users understand, review and consciously clean up photos and videos on an Android device. Media analysis takes place locally on the device. DearRoll does not upload photos, videos, thumbnails, media details or calculated file hashes to a DearRoll service.

No DearRoll account or sign-in is required.

2. Access to photos and videos

DearRoll requests Android access to images and videos only when required for a feature selected by the user. Depending on the Android version, the app uses the applicable storage or media permissions or Android's selected-media access.

DearRoll processes locally, in particular:

  • photos, videos and local thumbnails;
  • media IDs and local content addresses;
  • file names, media types and file sizes;
  • folders or relative media paths;
  • creation, added or capture dates;
  • image width and height and, for videos, duration;
  • SHA-256 hashes calculated locally to identify byte-for-byte identical files.

This information is used to display and group media, calculate storage use, create cleanup suggestions and identify exact duplicates. Android access restricted to selected media is recognised by DearRoll but does not provide a complete overview of the whole media library.

Access can be changed or withdrawn at any time in Android settings.

3. Local storage in the app

DearRoll stores settings and work progress in the app's private storage so that features can continue reliably after a restart. This includes, in particular:

  • completion of the introduction and selected appearance;
  • the app-wide free or unlocked usage state, including the initial library state, decisions already counted, covered media identifiers and stable starter grants;
  • the DearRoll Pro state most recently confirmed by Google Play as a local offline cache;
  • selection and review status for screenshots, photo series, folders, duplicate groups consciously kept and other views;
  • a cached overview containing counts, storage sizes, numbers of months and folders, and the time of the last update; this overview contains no copies of photos or videos;
  • active cleanup tasks with progress and associated media identifiers;
  • pending trash operations;
  • history limited to no more than 30 entries;
  • technical development states only in debug builds.

The complete inventory, active scans, sorting, filters and current navigation are held only temporarily in memory; the overview values and work states listed above remain stored locally. Thumbnails are kept in a limited memory cache. DearRoll does not operate a proprietary cloud database and does not write copies of the media library to proprietary external storage.

Android cloud backup and device transfer are disabled for DearRoll.

4. Trash and deletion of media

DearRoll does not delete media automatically. Media is initially only selected for trash. Before it is handed to Android, the selection can be reviewed and changed.

The actual move takes place only after an additional confirmation in an Android system dialog. Retention, restoration and permanent deletion in the system trash are governed by Android and the relevant gallery or device implementation.

Resetting DearRoll does not alter photos, videos or Android's system trash.

5. DearRoll Pro and Google Play

DearRoll Pro is an optional one-time purchase. Payment and payment data are handled by Google Play and the payment services used by Google. DearRoll does not request or store credit-card or bank-account details.

To display, purchase, acknowledge and restore the product, the app processes through Google Play Billing, in particular:

  • the product identifier and product details;
  • the localised price;
  • purchase and acknowledgement status;
  • a temporary purchase token.

The purchase token is transmitted to Google Play for acknowledgement but is not persistently stored or logged by DearRoll. DearRoll stores locally only whether DearRoll Pro was last confirmed successfully.

In connection with Play Store, purchase and payment, Google may process purchase, account, device, network, security and diagnostic data under its applicable terms. Further information is available in Google's Privacy Policy.

6. Network access and included Google components

DearRoll has no proprietary backend or cloud service. Network access is required for Google Play Billing. The release build also contains Google components required by Billing, including Google Data Transport/CCT, Firebase Encoders and parts of Google Play services.

DearRoll does not use these components for proprietary advertising, analytics, location requests or a proprietary cloud database. The technical, device, purchase or diagnostic data processed by Google components in actual Play operation depends on the final app configuration and Google's current information. These disclosures must match the published app's Google Play Data safety form.

7. Website and support contact

The website and the dearroll@vareldan.com mailbox are provided by STRATO GmbH, Otto-Ostrowski-Straße 7, 10249 Berlin, Germany. STRATO processes personal data as a processor. According to STRATO, its data processing agreement is automatically incorporated into contracts concluded from 18 July 2022 onward, and its data centres are located in Germany.

When this page is accessed, the web server processes technically necessary connection data. This may include the IP address, access time, requested resource, transferred data volume, referrer, browser or operating-system information and HTTP status. STRATO anonymises the IP address in the access logs it makes available to customers. According to STRATO's general privacy information, log and temporary data are often retained for a few days and for no more than 60 to 90 days, depending on security or operational needs. STRATO states that customer access logs are available for the preceding six weeks and error logs for the preceding 24 hours.

Processing serves secure delivery, error analysis and prevention of abuse. The legal basis is Article 6(1)(f) GDPR; the legitimate interest is the secure and reliable operation of the website.

When a message is sent to dearroll@vareldan.com, the information submitted by the sender is processed. This may include the email address, name, message content, attachments and technical headers. Processing serves the handling of support, privacy and other enquiries. Depending on the enquiry, the legal basis is Article 6(1)(b) GDPR for contractual or pre-contractual communication, Article 6(1)(c) GDPR for legal obligations, or Article 6(1)(f) GDPR for general support and secure documentation of communications.

Support messages are deleted once an enquiry has been fully handled and no statutory retention duty or legitimate reason for further retention applies. Where STRATO processes hosting and email data in German data centres, this does not constitute a transfer to a third country. If STRATO or one of its subprocessors processes data outside the EU or EEA in an individual case, the safeguards specified in the data processing agreement apply.

Further information: STRATO privacy information and STRATO data processing agreement.

8. Advertising, analytics, tracking and diagnostics

DearRoll contains no advertising, proprietary tracking, analytics SDK or crash-reporting SDK. The app writes a small number of technical counts and timing values to the local Android system log and does not send them to a DearRoll service.

Depending on device, account, testing and Play Console settings, Android or Google Play may separately process crash, ANR or diagnostic data. Such platform processing is governed by the relevant Google or Android settings and terms.

9. Retention and deletion options

Transient inventory, thumbnail and comparison data is held in memory and removed when the process ends or it is evicted from the cache. Local settings and work progress remain until they are changed, completed, reset, cleared through Android's app-data controls or removed by uninstalling the app.

“Reset DearRoll” removes saved settings, selections, review states, the cached overview, active tasks, pending trash operations, local history and the app cache. The central cleanup entitlement, including free decisions already used, and the DearRoll Pro access most recently confirmed by Google Play are retained so that a reset neither renews the free allowance nor removes a purchase. Photos, videos and Android system trash remain unchanged.

Android's “Clear storage” action or uninstalling the app also removes the local Pro cache. The purchase itself remains associated with the Google Play account and may be queried again through “Restore purchases”.

Because DearRoll has no proprietary account or server-side user profile, the controller cannot view, associate or erase purely local app data remotely. Purchase or account data held by Google must be managed through Google's available procedures.

To the extent that local media processing is legally attributable to the controller, it is carried out to provide the app features expressly requested by the user under Article 6(1)(b) GDPR. Processing related to DearRoll Pro serves performance of the optional purchase contract, also under Article 6(1)(b) GDPR. Records required by law may be processed under Article 6(1)(c) GDPR.

Security, error and support processing may be based on Article 6(1)(f) GDPR. The legitimate interests are secure operation, troubleshooting, prevention of abuse and responding to user enquiries.

DearRoll does not rely on consent as a general legal basis for advertising or tracking because those features are not included. Android media permissions are technical operating-system access decisions and are not automatically equivalent to consent under data-protection law.

11. Recipients and transfers outside the EU/EEA

DearRoll does not transmit photos, videos or local work progress to a proprietary server. External recipients may be involved only in the following contexts:

  • Google Play and Google payment services when retrieving, purchasing, acknowledging or restoring DearRoll Pro;
  • Android system services for permissions and trash operations;
  • website-hosting and email service providers used for the public page and support.

Google or other service providers may process data outside the EU or EEA. The applicable provider privacy and contractual information and any adequacy decisions, standard contractual clauses or other lawful safeguards govern such processing.

12. Children and target audience

DearRoll is not specifically directed at children and contains no advertising, social features, user profiles or child-specific data collection. The app does not rely on a child's consent for tracking or personalised advertising.

The target audience selected in Google Play Console must be consistent with this statement. If DearRoll is specifically directed at children in the future, this policy, the app design, all SDKs and Google Play Families requirements must be reassessed before publication.

13. Data-subject rights

Where the legal requirements are met, individuals have, in particular, rights to:

  • access;
  • rectification;
  • erasure;
  • restriction of processing;
  • data portability;
  • object to processing based on legitimate interests;
  • withdraw consent with effect for the future;
  • lodge a complaint with a data-protection authority.

Requests may be sent to dearroll@vareldan.com. Because DearRoll does not associate local app data with a DearRoll account or transmit it to a proprietary server, the controller cannot remotely identify or erase that local data.

Supervisory authority competent at the controller's establishment:

Berlin Commissioner for Data Protection and Freedom of Information
Alt-Moabit 59–61
10555 Berlin
Germany
Email: mailbox@datenschutz-berlin.de
Website: https://www.datenschutz-berlin.de/

Individuals may also contact another supervisory authority competent under Article 77 GDPR.

14. Controller and contact

The controller responsible for DearRoll is:

Ali Demirkol, trading as “Vareldan Studio”
Ritterlandweg 17
13409 Berlin
Germany

Email: dearroll@vareldan.com
Public version: https://vareldan.com/en/dearroll/privacy/

No data protection officer has been appointed.

15. Changes to this privacy policy

This privacy policy will be updated if features, SDKs, recipients, law or publication requirements change. The current version is available at https://vareldan.com/en/dearroll/privacy/. Material changes will also be indicated in the app where required.