Terms of Service

Last updated 16 September 2026

This is the agreement between you and Rollbird. It is written to be read, not to be survived. If something here is unclear, email [email protected] and ask before you subscribe.

Four things worth knowing before the numbered part.

Your code stays yours. Rollbird only gets the permission it needs to store your bundles and hand them to your app.

There is no service level agreement. No uptime percentage is promised, and no credits are owed if Rollbird is down. Section 10 says what that means in practice.

Rolling back is always free, and going over a plan limit never deletes anything you have already shipped.

Who you are contracting with

Rollbird is operated by KODEN LABS LTDA, a company registered in Brazil under CNPJ 65.648.167/0001-09. "Rollbird", "we" and "us" mean that entity. "You" means the person or company using the service, and if you are using it for a company you confirm you are allowed to accept these terms on its behalf.

Rollbird is a small operation — at the time of writing, one person. That is not a disclaimer, it is context for the promises below, which are deliberately modest and deliberately kept.

What Rollbird does

Rollbird is a hosted over-the-air update service for React Native apps. You install the CLI and the SDK, wrap your app, and publish JavaScript bundles to Rollbird. Rollbird stores each bundle, and your app asks Rollbird on launch whether there is a newer one for its platform, channel and app version. If there is, the app downloads it and runs it next time it starts.

What Rollbird does not do: it does not replace the app stores. Native code changes still need a store submission. It also does not review, test or approve what you publish — if you ship a broken bundle, it goes out.

Apple and Google both place limits on what an app may change after review. Staying inside those limits is your responsibility, not ours.

Your account

You sign in with an email address and a six-digit code sent to it. There is no password. That means access to your Rollbird account is exactly as protected as access to your email, so use an email account you control and secure.

Your work lives in an organization. You can invite others to it and give them a role, and anyone you invite acts with the permissions that role carries. API tokens you issue are credentials — treat them like passwords, scope them to the narrowest thing that works, and revoke them the moment a pipeline stops needing them.

You are responsible for what happens under your account and under tokens issued from it. If you think a token or an email account has been compromised, revoke the token in the dashboard and email [email protected].

You must be old enough to enter into a contract where you live. Rollbird is a developer tool and is not directed at children.

Plans and prices

Rollbird is sold on a free plan and three paid plans — Indie, Team and Studio. Each has its own limits on apps, organizations, team members, storage and release history.

The price of each plan, and what each one includes, is whatever is published on the pricing page at the moment you subscribe. That page is the authoritative list; nothing in this document overrides it, and we have deliberately not restated the numbers here so the two can never disagree. Published prices are in US dollars and exclude any tax that applies where you are. Customers checking out from Brazil may instead be charged the corresponding fixed price in Brazilian reais; Stripe shows the exact amount and currency before you subscribe.

Paid plans can be billed monthly or annually. Annual billing is charged once for the year at the rate shown on the pricing page.

Rollbird does not price on monthly active users. Plans scale on apps, storage, seats and release history. How many people use your app does not change your bill, and it is not a number Rollbird measures. That is a product commitment, not just marketing copy — see the privacy policy for what we do and do not count.

Billing and renewal

Payments are handled by Stripe. Card details go to Stripe directly and Rollbird never sees or stores a card number. By subscribing you also accept Stripe's terms for the payment itself.

A subscription renews automatically at the end of each billing period — every month for monthly plans, every year for annual ones — at the price then published, until you cancel. If a published price changes, the new price applies from your next renewal, and we will email you before that renewal so you can cancel first if you would rather not pay it.

If a payment fails, Stripe will retry it. If it keeps failing we may email you and, after a reasonable chance to fix it, move the organization to the free plan. Moving to the free plan does not delete anything: your live releases keep serving, and you keep access to your data.

Changing plan mid-period is handled through Stripe, and Stripe works out what that costs or credits you before you confirm it.

Cancellation and refunds

You can cancel at any time from the billing page in the dashboard, which opens the Stripe customer portal. Cancelling stops the next renewal. It does not end the plan immediately: you keep everything the plan includes until the period you have already paid for runs out, and then the organization moves to the free plan.

Refunds: if Rollbird is not what you expected, email [email protected] within 14 days of a charge and we will refund that charge in full. This applies to your first payment on a plan and to any annual renewal.

After those 14 days we do not refund part of a month or part of a year. Cancel instead, and use what you have paid for until it ends.

None of this limits any refund or cancellation right you have under consumer law where you live. Where that law gives you more, it wins.

Plan limits

Every plan has limits, and they work by refusal rather than by deletion. When you are at a limit, the action that would exceed it is refused with an error telling you which limit you hit. What already exists keeps working:

  • Limits never delete your data. Going over a limit, downgrading, cancelling or letting a payment fail does not remove your bundles, releases or projects.
  • Live releases keep serving. Apps already in your users' hands keep receiving the release you last published, whatever your plan is doing.
  • Rollback is always free. Rolling back to a previous bundle is never counted against a release quota and is never blocked by a plan limit or a billing problem. If a bad release is out, you can always pull it back.

Storage and release limits are there to keep a flat price honest, not to create an upsell moment in an incident.

Your content

The bundles you upload, and everything in them, are yours. Publishing to Rollbird does not transfer any ownership, and we claim no rights in your code beyond the ones in the next paragraph.

To run the service at all, we need your permission to hold your bundles and hand them out. So you grant Rollbird a non-exclusive, worldwide, royalty-free licence to store, copy, transmit and distribute the content you publish, only for the purpose of operating Rollbird for you: storing it, serving it to your app, showing it back to you in the dashboard and CLI, and keeping the backups that storing it implies. That licence exists solely to deliver the service, ends when the content is deleted, and covers nothing else. We do not use your code to train anything, and we do not look at it except where we have to in order to fix a problem you have asked us to fix, or where the law requires it.

You are responsible for having the right to publish what you publish, and for it not infringing anyone else's rights.

Rollbird keeps production bundles for as long as your account exists. Unfinished uploads expire after 24 hours, and preview bundles beyond the history included with your plan are automatically pruned while their release records remain. If you want other content removed, see how to ask for deletion.

Acceptable use

Do not use Rollbird to:

  • Distribute malware, spyware, or code that takes actions on a device that the person using it has not agreed to.
  • Ship an update that deliberately evades App Store or Google Play review — for example, changing an app into something materially different from what was reviewed.
  • Break the law, infringe someone's rights, or distribute content you have no right to distribute.
  • Publish someone else's app without their permission, or use an app identifier you do not control.
  • Attack the service: probing for vulnerabilities without asking first, attempting to reach other customers' data, deliberately overwhelming the API, or working around plan limits, rate limits or billing.
  • Resell Rollbird as your own OTA service, or share a single account across organizations that should each be paying for their own.

Found a security problem? Email [email protected] and give us a reasonable chance to fix it before telling anyone else. Reports made in good faith are welcome and will not be treated as a breach of this section.

Availability, and the absence of an SLA

There is no service level agreement. Rollbird does not promise a percentage of uptime, does not promise a response time, and does not offer service credits when it is unavailable. Anyone claiming otherwise on Rollbird's behalf is wrong.

What we will actually do: run the service carefully, keep it up as much as we reasonably can, and fix things when they break. Maintenance and outages happen, and a one-person operation sleeps and occasionally takes a holiday.

What this means for your app: design for Rollbird being unreachable. The SDK is built so that an app whose update check fails keeps running the bundle it already has — an outage should mean "no new update right now", not a broken app. Do not build a launch path that requires the update check to succeed.

Support is best-effort by email at [email protected], on every plan including the free one. We aim to reply within a couple of working days and usually do, but that is an intention, not a contractual commitment.

Security and your responsibilities

Bundles are stored in Cloudflare R2 and served over HTTPS. Each project gets a signing key; the private half is encrypted before it is stored, and the SDK verifies a bundle's signature on the device before installing it. Session cookies are HttpOnly and Secure. API tokens are hashed at rest and shown to you exactly once.

What we do not claim: Rollbird holds no security certification. There is no SOC 2 report, no ISO 27001, no independent audit, and no penetration test to show you. If your procurement process needs one of those, Rollbird is not ready for you yet, and we would rather tell you that now.

On your side: keep your email account secure, scope and rotate your API tokens, and do not put secrets in a JavaScript bundle. Anything you ship in a bundle is on your users' devices and should be treated as public.

Suspension and termination

You can stop using Rollbird whenever you like. Cancel the subscription in the dashboard, and email [email protected] if you also want the data removed — see section 8 and the privacy policy.

We may suspend or close an account that breaks section 9, that is being used to harm other people, or where the law requires it. Except where the problem is serious or ongoing, we will email you first and give you a chance to put it right. If we close a paid account for a reason that is not your breach, we will refund the unused part of what you have paid.

If Rollbird as a service were ever to shut down, we would give you at least 60 days' notice by email, keep the service serving updates during that time, and not bill you for a renewal that falls inside the notice period.

Warranties and liability

Rollbird is provided as it is. To the extent the law allows, we make no warranties of any kind about it — not that it will be uninterrupted, not that it will be error-free, and not that it will fit a particular purpose you have in mind.

To the extent the law allows, neither side is liable to the other for indirect or consequential loss, or for lost profits, lost revenue, lost data or lost business, however it arises.

Rollbird's total liability to you for everything arising out of these terms, taken together, is limited to the amount you actually paid Rollbird in the 12 months before the event that caused the claim. On the free plan, where you have paid nothing, that limit is US$100.

Nothing here excludes liability that cannot legally be excluded — for example for death or personal injury caused by negligence, or for fraud. If you are a consumer, your statutory rights are untouched by this section.

Changes to the service and to these terms

Rollbird will change. Features get added, and occasionally one gets removed. If we remove something you are relying on, or change it in a way that materially reduces what a paid plan gives you, we will email you at least 30 days beforehand, and you can cancel and get back the unused part of what you paid.

We may update these terms. The date at the top of this page always says when it last changed. For a material change we will email account holders at least 30 days before it takes effect; for a correction or a clarification we will simply update the page. Carrying on using Rollbird after a change takes effect means you accept it. If you do not, cancel — and if the change lands mid-period, tell us and we will refund the unused part.

Governing law

These terms are governed by the laws of the Federative Republic of Brazil, and any dispute goes to the courts of the Comarca de Itajaí, Santa Catarina. If you are a consumer, this does not take away the protections of the law where you live, or your right under the Brazilian Consumer Protection Code to bring a claim where you are domiciled.

If you are a consumer, this does not take away the protection of the mandatory laws of the country you live in, or your right to bring a case in your local courts.

If any part of these terms turns out to be unenforceable, the rest still stands. Not enforcing something once does not mean giving it up. These terms, together with the privacy policy and the pricing page, are the whole agreement between us about Rollbird.

Contact

Everything — support, billing, security, legal notices, deletion requests — goes to [email protected]. A person reads it.

Notices to Rollbird, including legal ones, should go to that address. If you need a postal address for a formal notice, ask and we will provide one.