Privacy Policy
Last updated July 9, 2026
Rooots Personal helps your household keep its bills, documents, people, and routines in one place. This policy explains what we collect, why, the legal bases we rely on, and the choices and rights you have — including under the GDPR and CCPA. We do not sell your data.
1. Who we are (data controller)
Rooots (“Rooots,” “we,” “us”) is the controller of the personal information processed through Rooots Personal. For any privacy question or request, email support@rooots.net with “Privacy” in the subject line.
2. Information we collect
- Account information: your name, email, and a securely hashed password (or your Google sign-in identifier).
- Household data you enter: bills, income, chores, documents, people (including children and pets), providers, vault entries, calendar dates — you control this content.
- Payment information: processed by Stripe. We never see or store your full card number — only a customer/subscription reference and your plan status.
- Forwarded email: bills you forward to your household address are processed to extract the biller, amount, and due date, then queued in your Bill Inbox.
- Usage and device data: basic logs (IP address, browser type, timestamps) needed to run the service securely.
3. Legal bases for processing (GDPR)
Where the GDPR applies, we rely on:
- Performance of a contract — to provide the household service you signed up for.
- Legitimate interests — to secure, maintain, debug, and improve the service and prevent fraud, balanced against your rights.
- Consent — for optional features and any marketing; you can withdraw consent at any time.
- Legal obligation — to keep records we’re required to keep (e.g. billing/tax).
4. How we use your information
- To provide the service: store and display your data, send reminders, generate your family calendar feed, and power Sterling.
- To process your subscription and prevent fraud.
- To keep the service secure, debug problems, and improve features.
- We do not sell your personal information and do not use your household content to advertise to you.
5. How your data is stored & protected
- Stored with row-level security so only your account can read or write your household’s row.
- Public links you generate (the fridge QR code, the calendar subscription feed) are protected by unguessable tokens — the token is the key, so keep those links private.
- Encryption in transit (HTTPS) and reputable infrastructure providers. Rooots staff do not access your household content except when you request support, when required by law, or to investigate abuse.
6. Sharing & sub-processors
We share data only with the service providers that help us run Rooots (hosting, database, payments, email, and the AI provider that powers Sterling), each under contract and only as needed. See our Sub-processors page for the current list.
We may disclose information if required by law or to protect the rights and safety of our users.
7. Data retention
- Active accounts: we keep your data while your account is active.
- Cancelled accounts: your data is kept in read-only form for 90 days so you can reactivate, then permanently deleted.
- Backups are retained ~30 days for disaster recovery. We may retain data longer where required by law.
8. Your rights
All users can access, correct, delete, or export their data, and opt out of marketing. Additional rights by region:
- EEA / UK / Switzerland (GDPR): access, rectification, erasure, restriction, portability, objection, the right to withdraw consent, and the right to lodge a complaint with a supervisory authority.
- California (CCPA/CPRA): the right to know, delete, correct, opt out of “sale”/“sharing” (we do not sell), limit use of sensitive information, and non-discrimination.
- To exercise any right, email support@rooots.net with “Privacy Request.” We respond within 30 days (45 for complex requests) and may verify your identity first.
9. International data transfers
Your information is processed in the United States. If you use the service from the EEA, UK, or Switzerland, we rely on Standard Contractual Clauses (SCCs) for those cross-border transfers as required by the GDPR.
10. Children
Rooots Personal is a tool for parents and guardians to manage their household, which may include information about their own children. It is not directed to children, and children should not create accounts. You’re responsible for the information you store about members of your household.
11. SMS & text messaging
If you provide a mobile phone number, we may send you SMS text messages related to your household account or the services you request — for example, reminders, confirmations, secure payment links, and service updates. Message frequency varies. Message and data rates may apply. Reply HELP for help or STOP to unsubscribe at any time.
No mobile information will be shared with third parties or affiliates for marketing or promotional purposes. Information sharing with subcontractors who support our services (such as message delivery and payment processing) is permitted solely to deliver the service you requested. All other use-case categories exclude text-messaging originator opt-in data and consent; this information will not be shared with any third parties.
12. Changes & contact
We may update this policy; we’ll change the date above and, for material changes, notify you in the app or by email. Questions or requests: support@rooots.net.