Legal

Privacy Policy

Rooted collects the information needed to run the naming workspace, manage purchases, and improve the product. We do not sell personal data.

Last updated: 03/07/2026

What We Collect

DataUseRetentionLegal basis
Email addressSign-in, account identification, and service messagesUntil account deletion, subject to provider logsContractual necessity
Display nameOptional personalization in the productUntil account deletionConsent
Story answers, including heritage, home languages, family names, surname, sibling names, names to avoid, and naming contextPersonalized recommendations, previews, reports, Compare, Ask, and saved decision contextUntil account deletionContractual necessity
Shortlist, Compare, and Ask activitySaved names, partner matching, invite flows, Ask links, responses, and commentsUntil account or owner-led Ask deletionContractual necessity and legitimate interest
Reports and previewsPaid or premium name context and shareable report linksUntil account deletion unless publicly sharedContractual necessity
Payment identifiersStripe checkout, App Store purchases, billing, subscriptions, and report purchasesRetained by payment providers according to financial record requirementsContractual necessity
Analytics eventsProduct quality, funnel analysis, and release-readiness checksAccording to PostHog retention settingsLegitimate interest or consent where required

What We Do Not Collect

  • Passwords.
  • Baby dates of birth or due dates.
  • Location or home address.
  • Health or medical data.
  • Social media profiles.
  • Phone numbers.

How We Use Data

  • To authenticate your account through email OTP sign-in.
  • To create personalized name matches, previews, and reports.
  • To save Shortlist, Compare, and Ask activity.
  • To process subscriptions and one-time report purchases.
  • To detect errors, understand product usage, and improve the flow.
  • To respond to support, deletion, and export requests.

Sensitive Story Context

Story answers may include cultural heritage, home languages, family names, religious or cultural naming preferences, and names you want to avoid. Rooted treats this as sensitive family context. These fields are used only to personalize names, reports, previews, Compare, Ask, and Shortlist context.

You can leave optional Story fields blank, edit your Story, download your account export, or delete your account from Settings.

Service Providers

Rooted uses trusted providers to operate the service: Convex for database, server functions, and authentication; AWS SES for email OTP delivery; Stripe for payments; Vercel for hosting and AI Gateway; PostHog for analytics; and email/support tooling used to respond to user requests.

These providers process data only as needed to provide their services to Rooted. Rooted does not sell personal data.

Cookies And Analytics

Essential cookies are used for sign-in, security, checkout, and app functionality. Analytics cookies are only enabled after you accept analytics. You can change your choice on the Cookie Policy page.

Public Sharing

Ask links and shared Shortlist Reports are designed to be opened by people you choose to send them to. Anyone with a valid share link may be able to view or respond to that shared item, so only share links with people you trust.

Deletion And Export

You can delete your account from Settings. Deletion removes Rooted app data and Convex Auth records tied to your account. If a Stripe billing record exists, Rooted attempts to delete the Stripe Customer or cancel the Stripe subscription before deleting app data. Stripe may retain payment records where required for financial, tax, or legal reasons.

You can download a structured JSON account export from Settings. The export includes Rooted app data such as profile, Story, Shortlist, Compare, Ask, report, preview, subscription mirror, and mobile access metadata. Session token hashes, OTP code hashes, and responder keys are not included.

To ask a privacy question, contact hello@rooted.name.