Back to Roots

Privacy Policy

LAST UPDATED: 10 AUGUST 2026

Who we are

Roots is operated by Guidance Belgium EUCV, based in Ieper, Belgium. You can reach us at hello@rootsocial.app.

We are the data controller for the personal data described below.

Our approach

Roots doesn't run ads and doesn't sell your data. We don't use an algorithm to rank or promote content, and we don't track you for advertising purposes. This policy describes what we collect, why, and what control you have over it.

What we collect

Account information

  • Email address
  • Username and display name
  • Profile photo (optional)
  • Password (if you sign up with email/password) — stored securely and never visible to us in plain text
  • If you sign up with Google, we receive basic profile information (name, email, profile photo) from Google, per your Google account settings

Age verification

  • Date of birth, collected to confirm you meet the minimum age (16) to use Roots
  • You control who, if anyone, can see your birthday: nobody, month and day only, or the full date
  • Requests to change a stored birthdate that would affect age eligibility are reviewed manually before being applied

Content you create

  • Posts, photos, comments, messages, and any other content you post
  • Location tags you choose to add to a post (never collected automatically or in the background)
  • Reactions, room memberships, and similar activity

Technical information

  • Basic device and browser information needed to operate the service (e.g. for push notifications)
  • We do not use tracking cookies for advertising or cross-site tracking

Payment information (Roots+ subscribers only)

  • Payment card details are collected and processed directly by Stripe, our payment processor. We do not store your full card number.
  • We retain a record of your subscription status, billing history, and the amount charged.

Why we collect it

  • To provide and operate Roots (your account, your posts, your conversations)
  • To verify you meet the minimum age requirement
  • To send you notifications you've opted into (messages, calls, friend requests)
  • To process payments for Roots+ subscriptions
  • To keep the platform safe (e.g. reviewing reported content, preventing abuse)

We do not use your data to serve ads, and we do not sell or rent your data to third parties.

Who we share it with

We use a small number of third-party service providers ("processors") to operate Roots. Each only receives the data necessary to perform its specific function:

  • Supabase — hosts our database, authentication, and file storage
  • Resend — sends transactional emails (invites, waitlist confirmations, account notices)
  • Stripe — processes payments for Roots+ subscriptions
  • Google — provides optional sign-in via Google OAuth, if you choose to use it, and serves the typefaces used across Roots
  • Apple — provides optional sign-in via Sign in with Apple, if you choose to use it
  • Cloudflare — delivers and protects the site (including the strictly necessary __cf_bm bot-protection cookie) and hosts and streams the videos you upload
  • Klipy — powers GIF and sticker search; your search terms are sent to Klipy when you open the picker
  • Google Gemini — text you choose to translate is processed by an AI model (currently Google Gemini) and is not used to train it
  • Push services — if you enable push notifications, your browser's push service (Apple, Google, or Mozilla, depending on your device) delivers them

Some of these providers may process data outside the European Economic Area. Where that's the case, we rely on appropriate safeguards (such as Standard Contractual Clauses) to protect your data.

We do not share your data with advertisers, data brokers, or any other third party for marketing purposes.

Cookies and similar technologies

Roots doesn't use cookies for tracking or advertising. We use browser storage (not cookies) to keep you signed in, remember your language and display preferences, and support features like offline drafts — this is strictly functional and never used to build an advertising profile.

One cookie, __cf_bm, is set by Cloudflare, our security provider, for bot protection — this is strictly necessary for the site to function securely and isn't used for tracking.

Some content — video playback (via Cloudflare Stream) and GIF search (via Klipy) — is provided by third parties, whose own cookies or similar technologies may apply according to their own privacy policies.

Your rights

Under the GDPR, you have the right to:

  • Access the personal data we hold about you
  • Correct inaccurate data
  • Delete your account and associated data
  • Export your data — Roots includes a built-in Digital Yearbook feature that lets you download your posts and photos at any time, organized by year
  • Object to or restrict certain processing
  • Lodge a complaint with your national data protection authority (in Belgium, the Gegevensbeschermingsautoriteit / Data Protection Authority)

To exercise any of these rights, contact us at hello@rootsocial.app.

How long we keep your data

We keep your data for as long as your account is active. If you delete your account, we delete your personal data and content within 90 days, except where we're required to retain certain records (e.g. billing records) for legal or accounting purposes.

Children and minors

Roots requires users to be at least 16 years old. We do not knowingly collect data from anyone younger. If we become aware that someone under 16 has created an account, we will take steps to remove it.

Changes to this policy

If we make material changes to this policy, we'll notify you (e.g. via email or an in-app notice) before the changes take effect.

Contact

Questions about this policy or your data: hello@rootsocial.app

Available in English only for now. Translated versions will follow once professionally reviewed.