Legal
Privacy Policy
Rooted collects the information needed to run the naming workspace, manage purchases, and improve the product. We do not sell personal data.
Last updated: 03/07/2026
What We Collect
| Data | Use | Retention | Legal basis |
|---|---|---|---|
| Email address | Sign-in, account identification, and service messages | Until account deletion, subject to provider logs | Contractual necessity |
| Display name | Optional personalization in the product | Until account deletion | Consent |
| Story answers, including heritage, home languages, family names, surname, sibling names, names to avoid, and naming context | Personalized recommendations, previews, reports, Compare, Ask, and saved decision context | Until account deletion | Contractual necessity |
| Shortlist, Compare, and Ask activity | Saved names, partner matching, invite flows, Ask links, responses, and comments | Until account or owner-led Ask deletion | Contractual necessity and legitimate interest |
| Reports and previews | Paid or premium name context and shareable report links | Until account deletion unless publicly shared | Contractual necessity |
| Payment identifiers | Stripe checkout, App Store purchases, billing, subscriptions, and report purchases | Retained by payment providers according to financial record requirements | Contractual necessity |
| Analytics events | Product quality, funnel analysis, and release-readiness checks | According to PostHog retention settings | Legitimate interest or consent where required |
What We Do Not Collect
- Passwords.
- Baby dates of birth or due dates.
- Location or home address.
- Health or medical data.
- Social media profiles.
- Phone numbers.
How We Use Data
- To authenticate your account through email OTP sign-in.
- To create personalized name matches, previews, and reports.
- To save Shortlist, Compare, and Ask activity.
- To process subscriptions and one-time report purchases.
- To detect errors, understand product usage, and improve the flow.
- To respond to support, deletion, and export requests.
Sensitive Story Context
Story answers may include cultural heritage, home languages, family names, religious or cultural naming preferences, and names you want to avoid. Rooted treats this as sensitive family context. These fields are used only to personalize names, reports, previews, Compare, Ask, and Shortlist context.
You can leave optional Story fields blank, edit your Story, download your account export, or delete your account from Settings.
Service Providers
Rooted uses trusted providers to operate the service: Convex for database, server functions, and authentication; AWS SES for email OTP delivery; Stripe for payments; Vercel for hosting and AI Gateway; PostHog for analytics; and email/support tooling used to respond to user requests.
These providers process data only as needed to provide their services to Rooted. Rooted does not sell personal data.
Cookies And Analytics
Essential cookies are used for sign-in, security, checkout, and app functionality. Analytics cookies are only enabled after you accept analytics. You can change your choice on the Cookie Policy page.
Public Sharing
Ask links and shared Shortlist Reports are designed to be opened by people you choose to send them to. Anyone with a valid share link may be able to view or respond to that shared item, so only share links with people you trust.
Deletion And Export
You can delete your account from Settings. Deletion removes Rooted app data and Convex Auth records tied to your account. If a Stripe billing record exists, Rooted attempts to delete the Stripe Customer or cancel the Stripe subscription before deleting app data. Stripe may retain payment records where required for financial, tax, or legal reasons.
You can download a structured JSON account export from Settings. The export includes Rooted app data such as profile, Story, Shortlist, Compare, Ask, report, preview, subscription mirror, and mobile access metadata. Session token hashes, OTP code hashes, and responder keys are not included.
To ask a privacy question, contact hello@rooted.name.