giao diện

Rowa Privacy Policy

Updated: 7 September 2026

In short

Rowa has no accounts, collects no identity, shows no ads and carries no analytics. Your router password and SSH key never leave your device.

What stays on the device

What leaves the device, and why

1. A device identifier — for the 30-day trial

A 32-character hash derived from the identifier the operating system provides (ANDROID_ID on Android; a randomly generated UUID kept in the Keychain on iOS). The raw value never leaves the device — only the hash does.

It serves exactly one purpose: remembering when this device's trial began, so that uninstalling and reinstalling is not a reset button. No name, no email, no location, nothing else. The record is a hash and a timestamp.

Deletion: open Rowa → Settings → Unlock everything → Erase trial data. The server record is deleted immediately.

2. A push token — only if you turn it on

If you enable "Alert me with the app closed", your device's Firebase Cloud Messaging token is registered with our relay, together with an identifier your own router generates and the language you have selected. Turning it off makes the router discard its key, invalidating every registration.

3. Purchases

Handled entirely by the App Store or Google Play. Rowa never sees or stores any payment information.

4. Telegram — only if you turn it on

The bot is yours. You create it in @BotFather, Telegram gives you a token, and the app passes that token down to your router — it stays there, in /etc/config/rowa, and goes nowhere else. Not through our relay, not through any other server. The app does not read it back either: the one thing it asks the router is whether a token is present. The Wi-Fi password and the AdGuard admin password are absent from this page for the same reason — they go straight from your device to your router. This is one of the advanced features, and it stays off until you turn it on.

The alerts, though, really do leave your house — not from the device, but from the router. When the router notices something, the router itself calls api.telegram.org — not the app, not a server of ours. From that moment the text of the alert is in Telegram's hands, under Telegram's policy, and Telegram sees the IP address your router is using to reach the internet.

The message carries the name you gave the router, then, depending on the alert: the name and MAC address of an unknown device that just joined the network, the name of a temperature sensor, a RAM percentage, disk space, battery level. Bug reports mask those things; Telegram alerts do not — masked, an alert would say nothing. "Nothing new leaves the device" would be true to the letter and would mislead you: getting exactly that text into Telegram is the whole of what this feature does.

The bot's replies to the commands described below travel the same way and carry more: how many hours the router has been up, CPU and RAM percentages, how many devices are connected and how many are blocked, the data used today and this month, the SIM's carrier and signal figures, and a six-digit confirmation code when you order a reboot. No MAC addresses and no device names are in that set — the bot answers with counts, not lists.

One request goes the other way. When you tap to find your chats, the router asks Telegram where your bot has been messaged from, and takes exactly three things: the chat id, the chat title — the person's Telegram name or @username — and the chat type. Only private chats are offered: groups and channels are dropped on the router. You can also paste a private chat's id directly and skip this request. The one you pick is kept in the router's configuration so the app can show you where alerts are going. Whatever you switch on, Rowa cannot browse your conversations — Telegram only returns messages sent to that bot — and it can only send to the chat your own bot is already in.

And there is a second direction, and it is not optional: the bot also takes commands. Once Telegram is set up the router stops only speaking and starts listening — there is no separate switch for that half, and an earlier version of this page had one. We dropped it on 9 September 2026: “would you like the bot slow and mute?” has no good answer, and a spare switch only moves the responsibility onto the reader. To make the router stop listening, turn Telegram off — that is the stop, and it stops both directions at once.

An earlier version of this page said the router "does not read, store or display the content of any message". That was true until the command channel existed, and leaving it up would stop it being a description. This is what replaces it.

The router holds a connection open to Telegram and waits there; the moment someone writes to your bot Telegram answers, and if nobody does it closes after fifty seconds and the router opens another. The body of that reply carries the full text of every message sent to your bot in the last twenty-four hours. It passes through the router's memory and is gone when the request ends: not written to disk, not forwarded anywhere, not back to the app and not to any server of ours. From that body the router takes exactly two things. One: the id, title and type of every private chat that has written to the bot — a list of at most ten, held in memory, and it is the list you see when you pick where alerts go; groups and channels are never written into it. Two: message text — but only from the one chat you picked, only from messages sent after the router started listening and no older than one polling interval, and anything that does not begin with a / is dropped before the router reads anything further out of it. A router that restarts resets that "started listening" mark, and so does picking a different destination, so a command sent before it never runs.

Put plainly: the router does read the beginning of messages sent to your bot — a command has to be read to be obeyed. What it does not do is keep them, show them, or send them anywhere. The router's log gets exactly one line, and only for a reboot: that a reboot was ordered. No parameters, no message text.

Two more things worth saying out loud. First, it spends your router's data — measured at about 8 KB per poll, and the router holds each poll open for up to fifty seconds waiting for a message, so on the days nobody writes it comes to about 14 MB a day. That figure sits under the destination card in the app, and the bot messages it to you once when you finish setting it up. Days you type a lot cost more, in proportion to how much you type.

There is no interval picker and no separate on/off switch for the listening half: holding the connection open answers faster and costs less than any way of asking on a schedule, so there is nothing left to choose. On a router running a metered SIM that is a real number, and turning Telegram off is the stop, on that same screen. Second, the bot only takes commands in a private chat, and a reboot on top of that takes a six-digit confirmation good for sixty seconds. What the router recognises is the conversation and not the person — in a group every member could send commands, including someone just added — so groups are excluded both as a destination and as a place the bot listens. The bot's command menu is registered for private chats only, so it does not pile into the command list of other bots in a group.

Disabling: Rowa → Settings → Telegram bot → Turn Telegram off. The router deletes the token and the destination, which stops both directions at once; after that there is nothing left on the router to call Telegram with. To silence the alerts but keep the setup, use the switch under Notifications. Messages already sent stay in Telegram — Rowa cannot delete them.

Rowa is not affiliated with or endorsed by Telegram. Telegram is a trademark of its respective owner.

Bug reports — the app does NOT send them anywhere

The bug report screen writes a diagnostic and shows you all of it. Where it goes is your choice — through your own messaging app, or copied out. The app does not upload it to any server.

The diagnostic also masks Wi-Fi names, device names, MAC addresses, IP addresses and phone numbers before it is displayed.

Permissions

None of the following

No advertising. No behavioural analytics. No cross-app tracking. No location collection. We do not share or sell your data to third parties, and the Rowa app sends nothing to Telegram — if you turn Telegram on, the sender is your own router, straight to Telegram, not through the app and not through a server of ours. The router also reads the commands you send that bot — still direct, still not through us. See section 4.

Contact

tuanlong.sav@gmail.com

© 2026 Rowa · htl·8 · About · Privacy · Support · Terms