Back to Roots

Privacy Policy

LAST UPDATED: 1 SEPTEMBER 2026

Who we are

Roots is operated by Guidance Belgium EUCV, based in Ieper, Belgium. You can reach us at hello@rootsocial.app.

We are the data controller for the personal data described below.

Our approach

Roots is designed to put your privacy first. We do not sell your data, serve ads based on your activity, or use algorithms to manipulate what you see. We don't run ads and don't sell your data. We don't use an algorithm to rank or promote content, and we don't track you for advertising purposes. This policy describes what we collect, why, and what control you have over it.

Digital identity and age verification

Roots does not require government-issued ID, biometric data, or any other intrusive digital identity check to join or use the general network. Because Roots is invite-only, runs no ads, uses no algorithmic feeds, and enforces strict safety rules on public Pages, we do not need to collect identity documents for ordinary operation.

If we ever offered age-restricted spaces (for example, 18+ Pages), we would use a privacy-preserving age-verification method such as Zero-Knowledge Proofs. This would prove only the required age threshold without uploading, storing, or processing a copy of your identity document on our servers.

What we collect

Account information

  • Email address
  • Username and display name
  • Profile photo (optional)
  • Password (if you sign up with email/password) — stored securely and never visible to us in plain text
  • If you sign up with Google, we receive basic profile information (name, email, profile photo) from Google, per your Google account settings

Age verification

  • Date of birth, collected to confirm you meet the minimum age (16) to use Roots
  • You control who, if anyone, can see your birthday: nobody, month and day only, or the full date
  • Requests to change a stored birthdate that would affect age eligibility are reviewed manually before being applied

Content you create

  • Posts, photos, comments, messages, and any other content you post
  • Location tags you choose to add to a post (never collected automatically or in the background)
  • Reactions, room memberships, and similar activity

Community activity

  • Communities you join, your role in them, and content you post there — visible to that community's members and its creator
  • Answers you give on a community's membership application form — visible only to that community's creator and managers
  • Your progress through a community's classroom lessons, if you take courses

Technical information

  • Basic device and browser information needed to operate the service (e.g. for push notifications)
  • We do not use tracking cookies for advertising or cross-site tracking

Payment information (paid features only)

  • Payment card details are collected and processed directly by Stripe, our payment processor. We do not store your full card number.
  • We retain a record of your Roots+ subscription and any paid community memberships: status, billing history, and the amounts charged.
  • If you are a creator receiving payouts, identity and bank details are collected and verified directly by Stripe (Stripe Connect). We receive only the verification status and payout totals, never your bank credentials or identity documents.
  • We keep per-community payment and dispute counts to detect fraud and protect members; these counts are not linked to individual members beyond the transaction record.

Why we collect it

  • To provide and operate Roots (your account, your posts, your conversations)
  • To verify you meet the minimum age requirement
  • To send you notifications you've opted into (messages, calls, friend requests)
  • To process payments for Roots+ subscriptions and paid community memberships, and to pay out creators
  • To prevent payment fraud and handle disputes and chargebacks
  • To keep the platform safe (e.g. reviewing reported content, preventing abuse)

We do not use your data to serve ads, and we do not sell or rent your data to third parties.

Who we share it with

We use a small number of third-party service providers ("processors") to operate Roots. Each only receives the data necessary to perform its specific function:

  • Supabase — hosts our database, authentication, and file storage
  • Resend — sends transactional emails (invites, waitlist confirmations, account notices)
  • Stripe — processes payments for Roots+ and paid community memberships, and verifies creators' identity and bank accounts for payouts (Stripe Connect)
  • Google — provides optional sign-in via Google OAuth, if you choose to use it, and serves the typefaces used across Roots
  • Apple — provides optional sign-in via Sign in with Apple, if you choose to use it
  • Cloudflare — delivers and protects the site (including the strictly necessary __cf_bm bot-protection cookie) and hosts and streams the videos you upload
  • Klipy — powers GIF and sticker search; your search terms are sent to Klipy when you open the picker
  • Google Gemini — text you choose to translate is processed by an AI model (currently Google Gemini) and is not used to train it
  • Push services — if you enable push notifications, your browser's push service (Apple, Google, or Mozilla, depending on your device) delivers them

Some of these providers may process data outside the European Economic Area. Where that's the case, we rely on appropriate safeguards (such as Standard Contractual Clauses) to protect your data.

When you join a community, that community's creator and managers can see your community-scoped display name and avatar, the content you post there, and — if the community gates membership — your application answers. They never see your private network activity, your friends, or your email address unless you share it yourself.

We do not share your data with advertisers, data brokers, or any other third party for marketing purposes.

Cookies and similar technologies

Roots doesn't use cookies for tracking or advertising. We use browser storage (not cookies) to keep you signed in, remember your language and display preferences, and support features like offline drafts — this is strictly functional and never used to build an advertising profile.

One cookie, __cf_bm, is set by Cloudflare, our security provider, for bot protection — this is strictly necessary for the site to function securely and isn't used for tracking.

Some content — video playback (via Cloudflare Stream) and GIF search (via Klipy) — is provided by third parties, whose own cookies or similar technologies may apply according to their own privacy policies.

Your rights

Under the GDPR, you have the right to:

  • Access the personal data we hold about you
  • Correct inaccurate data
  • Delete your account and associated data
  • Export your data — Roots includes a built-in Digital Yearbook feature that lets you download your posts and photos at any time, organized by year
  • Object to or restrict certain processing
  • Lodge a complaint with your national data protection authority (in Belgium, the Gegevensbeschermingsautoriteit / Data Protection Authority)

To exercise any of these rights, contact us at hello@rootsocial.app.

How long we keep your data

We keep personal data only as long as necessary for the purpose we collected it for. Concretely:

  • Active accounts — your profile, posts, photos, and messages are kept for as long as your account is active.
  • Deleted accounts — when you delete your account, your personal data and content are deleted within 90 days. Residual copies in encrypted backups are removed within a further 30 days as backups rotate.
  • Billing records — invoices and transaction records for Roots+ subscriptions and paid community memberships are kept for up to 10 years, as required by Belgian accounting and tax law. Card details are never stored by us (see Stripe, above).
  • Waitlist and invite emails — if you request an invite but never create an account, your email address is deleted within 12 months. Delivery records (bounces, complaints) are kept up to 24 months to protect email deliverability.
  • Safety and abuse records — reports and moderation actions are kept for up to 24 months, or longer where required by law or an ongoing dispute.
  • Server and security logs — kept for up to 12 months, then deleted or anonymised.
  • Message translations — text you choose to translate is processed on demand and is never stored.

Where we keep data longer than the periods above, it's because a legal obligation requires it; we never keep data "just in case".

Children and minors

Roots requires users to be at least 16 years old. We do not knowingly collect data from anyone younger. If we become aware that someone under 16 has created an account, we will take steps to remove it.

Changes to this policy

If we make material changes to this policy, we'll notify you (e.g. via email or an in-app notice) before the changes take effect.

Contact

Questions about this policy or your data: hello@rootsocial.app

Available in English only for now. Translated versions will follow once professionally reviewed.