Legal
Privacy Policy
What Rootmates knows about you, why, who else touches it, and how to get it deleted.
Effective
Who we are
Rootmates is operated by Tamir Tzion Heyman, an individual sole proprietor established in Israel ("Rootmates", "we", "us", "our"). We decide why and how personal data is used in Rootmates, which makes us the data controller for it. If the developer name shown on the App Store or on Google Play is written differently, it refers to the same person.
You can reach us about anything in this policy at feedback@root-mates.com. This is the same address we use for support and for safety reports, and it is monitored.
What this policy covers
This policy applies to the Rootmates mobile app on iOS and Android, the Rootmates web app at root-mates.com, the accounts and backend behind them, and these public pages. It does not cover anything you do inside another company's product - if you tap a link out of Rootmates, or share a day stamp into WhatsApp, that service has its own policy.
What we collect, and what each thing is for
Everything below either comes from you or is produced by the app while you use it. We do not buy personal data, we have no advertising or analytics SDKs, and we do not track you across other apps or websites.
| What we hold | Why we hold it |
|---|---|
| Email address | To create your account, sign you in, and reach you about your account. |
| Authentication identifiers - your Rootmates user ID, and the identifier Apple or Google gives us if you sign in with them | To recognise you on each sign-in and keep your data attached to you and nobody else. |
| Display name | To name you to your squadmates, on the shared streak and in chat. |
| Avatar photo (optional) | To show your face next to your name in a squad. |
| The habits you create and your daily completion logs | To run the core product - your day, your history, your progress. |
| Streaks, levels, freezes, challenge participation and squad membership | To keep score, to show a squad its shared streak, and to put you in the right squad. |
| Notes and comments you write on habits | To show them where you wrote them. Task notes are visible to your squadmates. |
| Squad chat messages, and photos you send in chat | To deliver them to the squad you sent them to. |
| Journal entries | To provide the private journal. These are for you. |
| Uploaded photos, including private progress photos | To store and show you the photo feature you chose to use. |
| Push notification tokens | To deliver the reminders, nudges and chat pings you turned on. |
| Abuse and moderation reports - what was reported, by whom, about whom, and what we did | To protect users, to enforce the rules, and to be able to show our working if a decision is challenged. |
Crashes and diagnostics, and why they are not on that list
Rootmates contains no crash reporter and no analytics SDK. The app does not collect your device model, your operating-system version or a record of what you tap, and when it breaks it does not send us a report. If a screen crashes, the app shows you the error and offers you a way out - and that is the end of it. Nothing about the crash leaves your phone for us.
What we can see is what Apple and Google show every developer of every app. App Store Connect publishes crash reports and Google Play Console publishes Android vitals, and both are built from data that Apple and Googlecollect - from people who turned on sharing analytics or diagnostics with developers in their own device settings, under Apple's and Google's privacy policies, not ours. It reaches us through their dashboards rather than from your device, it is aggregated across everyone using the app, and it does not identify you to us. Whether it is collected from you at all is a setting on your phone, not a setting in Rootmates.
What your squadmates see, and what stays private
Your squadmates can see your display name and avatar, the habits and check-offs you share with the squad, your streak and level, the notes and comments you write on habits, your squad chat messages, any photo you post into a squad chat, and your challenge activity.
Your journal entries and your private progress photos are not shown to squadmates. They are stored for you, under access rules that only let your own account read them. Nothing on the internet is absolutely secure, but this is not a setting you have to find - it is how those two features are built.
Our legal bases (GDPR)
If you are in the EU or the EEA, the GDPR applies to us because we offer this service to people there. These are the bases we rely on.
| Data | Legal basis |
|---|---|
| Email, authentication identifiers, display name, avatar | Art. 6(1)(b) - performance of our contract with you |
| Habits, completion logs, streaks, levels, freezes, challenges, squad membership | Art. 6(1)(b) - contract |
| Notes, comments, chat messages, journal entries, uploaded photos | Art. 6(1)(b) - contract |
| Push tokens, for the transactional notifications you enabled | Art. 6(1)(b) - contract. Any promotional or marketing push would need your Art. 6(1)(a) consent, and we would ask for it separately. |
| Abuse reports and moderation records | Art. 6(1)(f) - our legitimate interest, and that of the people using Rootmates, in a service that is safe to be in; and Art. 6(1)(c) where the law requires us to act or to keep a record |
Where we rely on legitimate interests, we have weighed them against your rights, and you can object - see Your rights below.
Sensitive information you choose to enter
Rootmates does not connect to Apple Health, Google Health Connect or any medical service, and we do not diagnose, score or infer anything about your health.
You do not need to provide medical or other sensitive information to use Rootmates. If you voluntarily enter information that reveals your health, religious beliefs, sexual life or other special-category information - in a habit name, a journal entry, a note or a photo - you explicitly consent to our processing that information solely to provide the feature in which you entered it. You may withdraw this consent at any time by deleting the relevant content or your account. Withdrawing does not affect anything we lawfully did before you withdrew.
Who else touches your data
We do not sell your personal data and we do not hand it to advertisers or data brokers. We do use a small set of named service and platform providers to run Rootmates, and your data passes through them:
- Supabase - authentication, database hosting and file storage. Our database and your uploaded files live here, in the EU (Frankfurt) region.
- Expo / EAS - application infrastructure, including the push notification relay and over-the-air update delivery.
- Apple Push Notification service (APNs) and Google Firebase Cloud Messaging (FCM) - delivery of the notifications you turned on, to your device.
- Vercel - hosting for the Rootmates web app and API.
- Apple and Google - optional identity providers, if you choose Sign in with Apple or Google Sign-In. They tell us the account information you authorise them to share, and they also process information under their own terms and privacy notices.
Where a service provider processes personal data on our behalf, we require appropriate contractual, confidentiality and security protections and require the provider to process the information consistently with our instructions and applicable data-protection law.
We may also disclose personal data where we are legally required to, or where it is genuinely necessary to investigate abuse, protect someone from harm, or establish or defend a legal claim.
International transfers
Rootmates is established in Israel. The European Commission recognises Israel as providing an adequate level of protection for personal data, so personal data reaching us in Israel is covered by that adequacy framework.
Some of our service providers, or their own subprocessors, may process information in the United States or in other countries. Where EU or EEA personal data is transferred to a country that does not benefit from an adequacy decision, we rely on an appropriate transfer mechanism - such as the European Commission's Standard Contractual Clauses and supplementary safeguards where required, or another legally recognised transfer mechanism. You may contact us for information about the safeguards that apply to a particular transfer.
How long we keep things
| Category | Retention |
|---|---|
| Account and profile information | Kept while your account is active. Deleted when you delete your account. |
| Habits, completion history, streaks, journal entries, notes, comments, chat messages and uploaded photos | Kept until you delete the content or your account, other than the narrow exceptions in this table. |
| Push notification tokens | Kept while they are needed to deliver notifications you enabled. Removed when the token is invalidated by the platform, when you turn notifications off, or when the account is deleted. |
| Crash reports and performance data in the App Store Connect and Play Console dashboards | Not ours to keep, and not ours to delete. We store no diagnostic records of our own, so there is no window of ours to state. How long these reports stay in Apple's and Google's consoles is set by Apple and Google under their own policies. |
| Abuse reports and moderation records | Up to 12 months after the report is closed, where that is necessary to protect users, to document an enforcement decision, or to meet a legal obligation. A record can outlive the reported account, because a record that vanishes with the offender is not a safety record. |
| Encrypted database backups | Our database is on Supabase, which takes an automatic daily backup and keeps up to 7 days of them. Point-in-time recovery is not enabled. So 7 days is the outer edge of how long a deleted row can survive in a backup. |
What deletion actually means, stated honestly. When you delete something - a photo, a message, your whole account - it is removed from our live systems immediately. It may still exist in an encrypted disaster-recovery backup until that backup expires on its normal rotation, which is at most 7 days. Those backups are isolated from ordinary use of the product, and if we ever had to restore one, we would reapply the deletions. Uploaded files are a separate store that is not part of those database backups, so deleted photos are gone at deletion.
Deleting your account
You can delete your Rootmates account yourself, without contacting anyone, and it takes effect immediately.
- In the app: Settings / Profile → Delete account.
- On the web: root-mates.com/delete-account, which can delete your account for you after you sign in, and also tells you how to ask us to do it by email if you no longer have the app installed.
Deleting your account removes your account and the personal data attached to it from our live systems: your profile, your habits and completion history, your private journal, your notes and comments, your chat messages, and every photo you uploaded. If you are the owner of a squad, ownership is handed to another member so the squad does not die with your account; if you were the only member, the squad is deleted with you. The exceptions are the ones already named above - moderation records where we need them, and encrypted backups until they expire.
Your rights
Subject to applicable law, you may ask us to give you access to the personal data we hold about you; correct information that is wrong; delete it; restrict how we process it; or give you a portable copy of the information you provided. You may object to processing we base on legitimate interests. Where we rely on your consent, you may withdraw it at any time, without affecting the lawfulness of what we did before you withdrew.
Most of these you can exercise yourself inside the app: edit your profile and your content, and delete your account outright. For anything else, email feedback@root-mates.com and we will answer within one month, as the GDPR requires. We may need to confirm you are the account holder before we act, which is a protection for you.
If you are in the EU or EEA and you think we have got this wrong, you have the right to lodge a complaint with the data-protection supervisory authority in the country where you live, where you work, or where you believe the infringement happened. If you are in Israel, you may contact the Privacy Protection Authority. We would rather you told us first, but that right does not depend on it.
No automated decision-making
Rootmates does not use personal data to make decisions about you that produce legal or similarly significant effects through solely automated processing. Enforcement decisions about content and accounts are made by a person.
Children
Rootmates is intended for people aged 13 and older. We do not knowingly allow anyone under 13 to hold a Rootmates account, and we do not design features to attract them. If we learn that an account belongs to someone under 13, we will suspend it and delete the account and its personal information, unless the processing is lawfully authorised by a verified parent or guardian.
If you believe a child under 13 is using Rootmates, tell us at feedback@root-mates.com and we will act on it.
Security
Data moving between the app and our servers travels over TLS. Data at rest is encrypted by our hosting providers, including database backups. Access to your rows is enforced in the database itself with row-level security, not only in the app - so a bug in a screen cannot hand your journal to somebody else. Access to production systems is limited to the operator. No service can promise perfect security, and we do not.
California and other US state privacy rights
Rootmates is a small independent app and does not currently meet the thresholds that make an operator a "business" under the California Consumer Privacy Act. We provide the following anyway, to everyone, not only Californians.
We do not sell personal information, and we do not share personal information for cross-context behavioural advertising. There are no advertising SDKs, no analytics SDKs and no ad identifiers in Rootmates.
You may ask us to tell you what personal information we hold about you, to correct it, or to delete it - see Your rights and Deleting your account above. We will not treat you differently for exercising any of this.
Do Not Track.Some browsers can send a "Do Not Track" signal. There is no common standard for what a service must do when it receives one, and our services do not currently respond to browser Do Not Track signals. We do not track you across third-party websites or apps in the first place.
Changes to this policy
This version is effective 31 August 2026. If we change it in a way that matters, we will update the effective date at the top and tell you in the app before the change takes effect. Continuing to use Rootmates after that means the new version applies to you.
Contact
Tamir Tzion Heyman, sole proprietor, Israel - operating as Rootmates.
feedback@root-mates.com
See also the Terms of Use and the Community Guidelines.