legal
Privacy
Torollo is local-first on purpose. The app's usage telemetry is opt-in. The website uses cookieless, aggregate Plausible analytics without a consent prompt. Both are described below.
This website
This site sets no cookies and has no accounts or tracking pixels. We use Plausible, a cookie-free analytics service, to count page views and outbound clicks in aggregate, without personal identifiers. If the store opens, clicks on buy buttons, completed checkouts, or copies of an install command are counted the same way. Purchase events carry the product name. Copy events carry the command and button placement. Nothing identifies you.
The application
The app works fully offline apart from pulling Docker images. Your projects, containers, progress and terminal history stay in ~/.torollo and in your local Docker daemon. There is no account and no sign-in.
Opt-in usage telemetry
The app can send anonymous usage events so we can see where a first run breaks and where roadmaps lose people. It asks once, on the home screen. Until you accept, and if you decline, the app makes no telemetry request at all, not even the local check of whether Docker is running that the first events describe.
When enabled, these are the only events sent:
- App start and Docker readiness. The app loaded; it checked whether Docker was reachable; the check succeeded or failed. A failure carries one reason code out of a fixed list:
backend_unreachable,timeout,socket_not_found,permission_denied,connection_refusedorunknown. The socket path and the error message stay on your machine. - Image download failed. A node could not be created because its Docker image did not download, with the node type (for example
redis), never the name you gave the node. - Roadmap progress. Roadmap started, first validation ever run on this install, step validated, step failed, roadmap completed, roadmap abandoned at a given step. Each carries the roadmap id and step id from the public catalogue.
Every event also carries the app version and a random installation id generated on your machine after you accept. The id is not derived from your hardware, your account (there is none) or your network. Events never contain your name, email, code, project names, container contents, file paths, terminal input or error messages. You can inspect every request in your browser's network tab; the full list, with the properties of each event, is in the project README.
Events are sent to Plausible, the same analytics service as this website, under thetorollo.app site. Plausible stores no cookies and no IP addresses in its reports. Self-hosters and forks can point the app at their own endpoint or disable telemetry entirely at build time.
Changing your mind. Click the activity icon in the home-screen header, or clear the torollo_telemetry_consent key from the browser's local storage. Turning telemetry off also deletes the installation id, so enabling it again later starts a new anonymous identity that cannot be linked to the previous one. Because the id is random and stored only on your machine, we cannot identify which events were yours; deletion requests therefore apply to the id you send us, if you still have it.
Purchases
Payments are processed by Stripe; we never see your card details. We receive your email address in order to deliver your purchase, re-issue download links, tell you when a newly included scenario is available, and handle refunds. It is not used for marketing without your consent and is never sold.
Contact
For any privacy question or deletion request: othmane@torollo.app.