Roots

Privacy Policy

Last updated: July 2026

Introduction

This Privacy Policy explains how Roots ("Roots," "we," "our," or "us") collects, uses, discloses, retains, and protects personal information when you use the Roots mobile application and website at useroots.app (collectively, the "Service").

Roots is currently operated by its two co-founders (the "Founders"). We intend to transfer operation of the Service to Root Labs LLC, a Delaware limited liability company we plan to form at or before public launch. In this Privacy Policy, "Roots," "we," "our," and "us" refer to the Founders until that transfer occurs, and to Root Labs LLC after it occurs. You can reach us at dan.rohin.crm@gmail.com. We will update this policy — including adding the Founders' full legal names and business address — to reflect the Root Labs LLC transfer when it happens.

Where Roots Is Available

Roots is currently available only to users in the United States. This policy reflects that scope. If we expand to other countries or regions, we will update this policy and add any additional disclosures or rights required by law in those places before making the Service available there.

Information We Collect

Information you provide directly

  • Account information: your first and last name and email address when you create an account
  • Relationship data: names, phone numbers, birthdays, locations, notes, interaction history, and other personal details you voluntarily enter about people in your life
  • Contact form submissions: your name, email, and message if you contact us through our website

Information collected automatically

  • Push notification tokens: if you grant notification permission, we store a device token to deliver reminders to your device
  • Authentication session data: we use Supabase to manage secure authentication sessions
  • Basic operational data such as device type, app version, and request logs, generated automatically by our infrastructure providers as part of running the Service

Information from your device (with your permission)

  • Contacts: if you grant access, we read your device contacts solely to help you add people you already know to Roots. Roots does not upload or store your full address book. When you select a contact to import, only the specific fields you confirm (such as name, phone number, or birthday) are transmitted to and stored in your Roots account as a relationship record. We do not continuously access or sync your contacts in the background, contact the people you import, send them invitations on your behalf, or match contacts across Roots accounts.

We do not currently use any analytics, crash-reporting, or advertising SDKs. If that changes, we will update this policy and our App Store privacy disclosures before any such tool goes into production.

How We Use Your Information

We use the information we collect solely to provide and improve the Roots service:

  • To create and maintain your account
  • To store and display your relationship data within the app
  • To send you push notifications and email reminders about people you want to stay in touch with (only if you enable these features)
  • To respond to your support requests
  • To maintain the security and integrity of the Service

We do not use your data for advertising, analytics sold to third parties, or any purpose beyond operating the Service for you.

Information About People Who Aren't Roots Users

Roots lets you record information about people in your life — such as names, birthdays, or notes — who may not themselves be Roots users and may never see this policy. That information is provided by the Roots account holder, is stored as part of their account, and is used only to help them stay in touch with the people they care about. It is never visible to anyone besides the account holder. If you are not a Roots user but believe someone has stored information about you in Roots and have a question or request about it, contact us at dan.rohin.crm@gmail.com.

Third-Party Services

Roots uses the following third-party services to operate. Each has its own privacy policy, and each may process limited technical data (such as IP addresses or request logs) as part of providing their service to us:

  • Supabase (supabase.com) — database and authentication. Your data is stored on Supabase's servers with row-level security policies designed to prevent one user's account from accessing another's records.
  • Expo / EAS (expo.dev) — mobile app build and delivery infrastructure, and delivery of push notifications. Expo's push service receives your device's push token and the content of the notification in order to deliver it.
  • Resend (resend.com) — email delivery for weekly digest emails (if enabled)
  • Mapbox (mapbox.com) — location search and autocomplete when adding location information for your contacts. Mapbox receives the text of your search query to return suggestions.
  • Vercel (vercel.com) — website and API hosting

We do not sell your data to any third party. We do not share your data with advertisers.

Your Privacy Rights

We extend the following rights to all users of Roots:

  • The right to know what personal information we collect and how it is used (described in this policy)
  • The right to delete your personal information, at any time, from Settings → Delete Account
  • The right to correct inaccurate information you have entered
  • The right to opt out of the sale of personal information — we do not sell personal information, and have not sold personal information in the preceding 12 months
  • The right to non-discrimination for exercising any of these rights

If we expand outside the United States in the future, we will update this policy to reflect the additional rights and legal bases applicable to users in those regions before making the Service available there.

Data Storage and Security

Your data is stored in the United States on Supabase's infrastructure. We use technical and organizational safeguards designed to protect your data, including database access controls (row-level security) intended to prevent one user from accessing another user's records, encrypted data transmission, and restricted administrative access. Authorized personnel and service providers may access information when reasonably necessary to operate, secure, support, or troubleshoot the Service, or to comply with legal obligations. No method of electronic storage or transmission is 100% secure, and we cannot guarantee absolute security.

In the event of a data breach affecting your personal information, we will notify affected users without undue delay via email and/or an in-app notice, as required by applicable law.

Data Retention

We retain your data for as long as your account is active. When you delete your account, we delete your relationship data, notes, interactions, tags, and settings from our active production systems immediately. We do not currently maintain automated backups of this data. If we enable database backups in the future for disaster-recovery purposes, any residual copies in those backups will be isolated from normal use and fully overwritten within 14 days. We do not restore or reactivate a deleted account from a backup except as necessary to comply with a legal obligation. We may retain limited records beyond this period where required for security, fraud prevention, dispute resolution, or legal compliance.

Your Rights and Choices

  • Access and export: you can export all of your data at any time from the Settings screen in the app as a JSON file
  • Correction: you can edit any information you have entered at any time within the app
  • Deletion: you can delete your account and all associated data at any time from Settings → Delete Account
  • Notification preferences: you can disable push notifications and email reminders at any time from Settings → Notifications or from your device settings

Mobile App Specific Disclosures

Contacts permission: Roots may request access to your device contacts to help you add people you already know. This permission is optional, and you can add people manually without granting it. You can revoke this permission at any time from your iPhone Settings → Roots.

Push notifications: If you grant notification permission, Roots stores a push token on our servers to deliver reminders. You can revoke this permission at any time from your iPhone Settings → Notifications → Roots.

Location: Roots does not access your device's GPS or location services. Location information in the app (city/region for your contacts) is entered manually by you or selected from Mapbox search suggestions.

Sensitive Information

Roots' notes fields let you write freely, but they are not designed to securely store highly sensitive data. Please do not use Roots to store passwords, government identification numbers, payment card information, or detailed medical records. Please also avoid recording intimate or highly sensitive details about another person without their permission.

Age Requirement and Children's Privacy

Roots is intended for use by adults and is not directed at children. You must be at least 18 years old to use the Service. We do not knowingly collect personal information from anyone under 18. If you believe someone under 18 has created an account or provided us with personal information, please contact us at dan.rohin.crm@gmail.com and we will delete it promptly.

Business Transfers

If Roots is involved in a merger, acquisition, financing, reorganization, or transfer of assets — including the anticipated transfer of operations to Root Labs LLC once formed — your information may be transferred as part of that transaction. We will provide notice before your information becomes subject to a different privacy policy or controller as a result.

Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of significant changes by email or an in-app notice before the change takes effect. Where a change materially expands how we use your information, we will ask for your acknowledgment before it applies to you.

Contact Us

Email: dan.rohin.crm@gmail.com
Website: useroots.app/contact