Rollingin privacy policy
Last updated: 18 September 2026
This policy covers the Rollingin Android application developed by Kshitij Sharma under the Kshitij Works name. Privacy enquiries: contact@kshitijworks.com .
The app is a workplace attendance kiosk administered by the organization using the tablet. That organization controls enrollment, access, optional data transfers, and its operational retention requirements. Ask your workplace administrator about its use of employee records. The developer does not operate a remote account service or automatically receive employee attendance or face data.
Recognition runs on-device. Face data is not automatically uploaded, but administrators can export encrypted backups containing biometric records. Non-biometric employee and attendance information can be synced or shared. Ordinary employee removal retains inactive face profiles and historical attendance and recognition records.
Information stored and used
The app uses the camera for enrollment, face quality checks, recognition, and attendance recording. It stores the following information locally, as applicable to the workplace’s use:
- Employee and workplace records: employee names and IDs, work details and employment history, schedules, holidays, attendance, site information, settings, and generated reports.
- Face profiles: accepted enrollment descriptors, pose-average and aggregate face embeddings, one 128×128 JPEG thumbnail per face-profile version, and model, quality, confidence, pose, and enrollment metadata. Older profiles remain stored but inactive after re-enrollment.
- Recognition audit records: scan embeddings, matched employee identifiers, match distance and margin, vote counts, and applicable quality and liveness metadata.
- Operator accounts: local Super Admin and Manager usernames, roles, creation times, and salted PBKDF2-SHA256 password hashes. Super Admin records also include a recovery email address. Active session metadata is kept in session storage.
- Device/site identity: a local identity record used by the application.
The app does not persist full camera frames, enrollment videos, or an image for every captured frame. A small face-profile thumbnail is the persisted enrollment image.
When information can leave the tablet
Recognition does not require a remote recognition service. The following features can transfer or expose data outside the app’s private storage:
- Cloud Sync: a Super Admin can manually send non-biometric business data to the organization’s configured HTTPS endpoint. This includes employee names/IDs, schedules and holidays, attendance, public holidays, employment history, site information, and app settings. It excludes face data, operator accounts, reset tokens, reports, and device ID.
- Google Drive or document-provider backup: a Super Admin
can manually upload an encrypted
.faceid-cloudbackup containing the same non-biometric Cloud Sync data. It excludes face information and operator credentials. The selected storage provider receives the encrypted backup file. - Full backup: the app can write a passphrase-encrypted
.faceidfile to public device Documents. It contains face embeddings, thumbnails, recognition scans, attendance, reports, and hashed operator credentials. It is not automatically uploaded, but an administrator can copy or share it off-device. - Reports and analysis exports: operators can share attendance text or CSV through WhatsApp, email, or Android’s share sheet. Analysis ZIP files can be saved to public Documents. Recipients and selected services receive the exported information.
- Password recovery: when configured, the organization’s TLS-only SMTP server processes the Super Admin’s recovery email address and a one-time PIN to deliver recovery email.
- Updates: the Super Admin update screen communicates with Google Play to check for and download software updates. The app does not include attendance or face data in this process.
The organization’s servers, selected backup providers, report recipients, and messaging or email services handle information under their own arrangements and policies. The workplace administrator controls these destinations.
Analytics, diagnostics, and automatic backup
The app has no integrated analytics SDK, custom crash-reporting service, Play Integrity check, or runtime licence-validation service. Android automatic cloud backup and device-to-device transfer are disabled.
Google Play, Android, and device services may independently process installation, update, crash, or application-not-responding diagnostics under their own policies and settings. These are separate from app-integrated telemetry.
Security and access
The Android app sandbox protects the local SQLite database, and local roles restrict administrative access. The database itself is not encrypted with SQLCipher. Operator passwords are stored as salted hashes. Full and cloud backup files are encrypted; full exports require a passphrase.
Administrators are responsible for controlling physical access to the tablet, operator access, backup passphrases, and exported copies. Optional Cloud Sync uses HTTPS and configured recovery email uses TLS-only SMTP.
Retention and employee removal
The app does not use a fixed automatic retention period for the records described here. Historical records can remain until the organization takes the relevant removal or reset action.
Delete User is not complete erasure. It deletes enrollment capture descriptors, marks face profiles and current work details inactive, and ends employment. Face-profile embeddings and thumbnails, historical recognition scans, and attendance records are retained. An employee identity row is retained when historical records reference it.
A Super Admin factory reset erases the local database, accounts, settings, and face-engine caches, while preserving the device/site identity record. A cloud restore can also remove local employees absent from the restored roster; restore is a data-replacement operation and should not be treated as a routine deletion request.
Neither operation deletes existing public Documents exports, Google Drive backups, cloud-server copies, shared reports, email, WhatsApp, or copies held by recipients. Those require separate removal by the people or organizations controlling them.
Requests and choices
Employees should contact their workplace administrator to ask about their records, correction, retention, or erasure. The developer cannot remotely delete data stored on an organization’s tablet, servers, or third-party accounts.
For application assistance or privacy questions, email contact@kshitijworks.com . Do not send face images, biometric backup files, passwords, or employee records with an initial enquiry. See the data removal guide for the available controls and their limits.
Policy updates
This page will be updated when the application’s data handling changes. The date above identifies the current policy version.