legal

Privacy

Torollo is local-first on purpose. The app's usage telemetry is opt-in. The website uses cookieless, aggregate Plausible analytics without a consent prompt. Both are described below.

This website

This site sets no cookies and has no accounts or tracking pixels. We use Plausible, a cookie-free analytics service, to count page views and outbound clicks in aggregate, without personal identifiers. If the store opens, clicks on buy buttons, completed checkouts, or copies of an install command are counted the same way. Purchase events carry the product name. Copy events carry the command and button placement. Nothing identifies you.

The application

The app works fully offline apart from pulling Docker images. Your projects, containers, progress and terminal history stay in ~/.torollo and in your local Docker daemon. There is no account and no sign-in.

Opt-in usage telemetry

The app can send anonymous usage events so we can see where a first run breaks and where roadmaps lose people. It asks once, on the home screen. Until you accept, and if you decline, the app makes no telemetry request at all, not even the local check of whether Docker is running that the first events describe.

When enabled, these are the only events sent:

Every event also carries the app version and a random installation id generated on your machine after you accept. The id is not derived from your hardware, your account (there is none) or your network. Events never contain your name, email, code, project names, container contents, file paths, terminal input or error messages. You can inspect every request in your browser's network tab; the full list, with the properties of each event, is in the project README.

Events are sent to Plausible, the same analytics service as this website, under thetorollo.app site. Plausible stores no cookies and no IP addresses in its reports. Self-hosters and forks can point the app at their own endpoint or disable telemetry entirely at build time.

Changing your mind. Click the activity icon in the home-screen header, or clear the torollo_telemetry_consent key from the browser's local storage. Turning telemetry off also deletes the installation id, so enabling it again later starts a new anonymous identity that cannot be linked to the previous one. Because the id is random and stored only on your machine, we cannot identify which events were yours; deletion requests therefore apply to the id you send us, if you still have it.

Purchases

Payments are processed by Stripe; we never see your card details. We receive your email address in order to deliver your purchase, re-issue download links, tell you when a newly included scenario is available, and handle refunds. It is not used for marketing without your consent and is never sold.

Contact

For any privacy question or deletion request: othmane@torollo.app.