Privacy Policy
Effective Date: August 21, 2026
Last Updated: August 21, 2026
Rooted App, LLC (“Rooted,” “we,” “us,” or “our”) respects your privacy. This Privacy Policy explains how we collect, use, disclose, retain, and protect personal information when you use the Rooted mobile application for iOS or Android, visit rootedapp.faith, or otherwise interact with services that link to this Privacy Policy (collectively, the “Services”).
Rooted App, LLC is a Missouri limited liability company based in the United States. Rooted may be available internationally, subject to applicable law and platform availability. Rooted is not currently offered in the European Economic Area (EEA), the United Kingdom, or Russia.
If you have questions about this Privacy Policy or our privacy practices, contact us at:
1. Information We Collect
The information we collect depends on how you use Rooted and the features you choose to use.
A. Account and Profile Information
A Rooted account is required to use Rooted.
We may collect:
- Your name;
- Your chosen display name or username;
- Email address;
- Profile photo;
- Gender;
- Internal account or user identifiers;
- Referral or Mission Partner codes;
- Ministry Codes;
- Challenge or group membership; and
- Other information associated with your account and use of Rooted.
Your display name may be different from your legal or personal name.
We do not require a phone number, date of birth, or precise geographic location to create a Rooted account.
B. Authentication Information
Rooted uses Supabase Auth to manage account authentication.
Depending on the sign-in method you select, you may create or access an account using:
- Email-based authentication;
- Sign in with Apple; or
- Sign in with Google.
When you use Apple or Google to sign in, Rooted may receive information authorized by you and the applicable authentication provider, such as your name, email address, provider user identifier, and profile photo.
Apple, Google, and Supabase may separately process information as described in their own privacy policies and applicable terms.
C. Journals, Prayers, Gratitude, and Other Private Content
Rooted allows you to create and store personal content such as:
- Journal entries;
- Prayers;
- Gratitude entries;
- Answered-prayer records; and
- Other information you voluntarily enter into these private features.
This content is stored in Rooted's backend systems, including our Supabase database.
Your private journals, prayers, gratitude entries, and answered-prayer content are not visible to other Rooted users, challenge participants, challenge administrators, churches, ministries, Mission Partners, or impact partners merely because they use or participate in Rooted.
Rooted does not routinely review your private journals, prayers, gratitude entries, or similar private content.
Access to this content is restricted. Authorized Rooted personnel or contractors may access private content only when reasonably necessary to:
- Provide support you request;
- Operate or maintain the Services;
- Diagnose or resolve technical issues;
- Maintain security or investigate suspected misuse;
- Protect Rooted, our users, or others;
- Comply with applicable law or valid legal process; or
- Perform another function reasonably necessary to provide or protect the Services.
Rooted does not:
- Sell your private journal, prayer, or gratitude content;
- Provide that content to advertisers for targeted advertising;
- Use that content for third-party targeted advertising;
- Send that content to generative artificial intelligence providers;
- Perform sentiment or mood analysis on that content; or
- Make that content publicly available.
Rooted may process private content as necessary to provide functionality you request, such as enabling you to search your own saved content.
D. Bible Reading, Faith, and Activity Information
Rooted may collect and store information about how you use faith-related features, including:
- Bible reading history;
- Chapters or books marked as read;
- Books completed;
- Reading-plan participation;
- Reading-plan progress;
- Devotional activity;
- Active Days;
- Prayer activity;
- Gratitude activity;
- Challenge participation;
- Impact milestones and totals; and
- Other progress or activity information associated with Rooted.
Because Rooted is a Christian faith-based service, certain information that you voluntarily provide or generate through Rooted may reveal or relate to religious or philosophical beliefs.
We treat this information as sensitive and do not sell it or use it for targeted advertising.
Where applicable privacy law requires a particular legal basis, explicit consent, or other additional protection for information revealing religious or philosophical beliefs, Rooted will apply the requirements applicable to that processing.
E. Challenges and Community Features
Rooted allows users to participate in shared challenges and community features.
When you participate in a challenge, other members of that challenge may be able to see limited participant information, including:
- Your name and/or display name;
- Your profile photo; and
- The date you joined the challenge.
Challenge members may also see aggregate group statistics, such as the group's overall books read, reading progress, and other shared group-level metrics.
Ordinary challenge members cannot see another individual member's personal reading progress or individual impact contribution.
Challenge administrators may see additional limited information about individual challenge participants, including:
- Active Days; and
- Number of books read.
Challenge administrators cannot see an individual's personal contribution to Rooted's impact metrics, including that person's individual trees, meals, or clean-water contribution.
Neither ordinary challenge members nor challenge administrators may view your private:
- Journal entries;
- Prayers;
- Gratitude entries; or
- Answered-prayer content.
F. Challenge Comments and Messages
Rooted may allow users to post comments, messages, or other content within challenges.
Unlike your private journal, prayer, and gratitude features, content you intentionally post within a challenge is intended to be shared with the participants of that challenge.
Challenge content may include:
- Comments;
- Messages;
- Text;
- Reactions or similar interactions; and
- Information associated with the post, such as your display name, profile photo, or time of posting.
You should not post information in a challenge that you do not want other participants in that challenge to see.
Rooted may process challenge content as reasonably necessary to operate the feature, maintain security, enforce our Terms of Service, respond to reports or support requests, investigate misuse, or comply with applicable law.
Rooted provides reporting and blocking tools for community features and may use automated filtering and manual moderation. If you submit a report, Rooted may process the reported content, account identifiers, report details, and related contextual or technical information as reasonably necessary to review the report, enforce our Terms, protect users, and maintain the safety and integrity of the Services.
G. Ministry Codes
Rooted may allow users to enter a Ministry Code associated with a participating church, ministry, organization, or challenge.
Using a Ministry Code may:
- Associate your participation with the ministry's shared impact metrics;
- Automatically enroll you in an associated Rooted challenge; and
- Allow activity to contribute to shared or aggregate challenge statistics.
Entering a Ministry Code does not, by itself, provide the ministry with your email address or a separate list of personally identifiable information about users who redeemed the code.
However, if using a Ministry Code automatically enrolls you in an associated challenge, the limited participant information described in the Challenges and Community Features section may become visible to participants or administrators of that challenge.
Ministry Codes may expire, be discontinued, or be invalidated by Rooted, including where Rooted reasonably believes a code is being used fraudulently, improperly, or contrary to the Terms of Service.
H. Mission Partner and Referral Codes
Rooted may allow users to enter referral or Mission Partner codes.
Mission Partners or referral partners may receive aggregate information regarding use or conversion associated with their codes.
Rooted does not provide Mission Partners with the names, email addresses, or usernames of individual users merely because those users entered or redeemed a Mission Partner or referral code.
I. Subscription and Purchase Information
Rooted subscriptions and in-app purchases are processed through the Apple App Store or Google Play. Rooted uses RevenueCat to manage subscription products and entitlement status.
Rooted or RevenueCat may process information such as:
- An internal Rooted user identifier;
- Subscription product or tier;
- Purchase date;
- Renewal or expiration date;
- Transaction identifier; and
- Subscription or entitlement status.
Rooted does not receive or store your full credit card number, bank-account information, or full payment-card details from Apple or Google.
When Rooted communicates with RevenueCat regarding your subscription, we use an internal database identifier rather than intentionally sending your cleartext name or email address for entitlement management.
Apple and Google process payment information under their own terms and privacy policies.
J. Usage and Analytics Information
Rooted uses Firebase Analytics to understand how people use the Services and to improve Rooted.
Analytics may include information such as:
- App opens;
- Screens or tabs viewed;
- Buttons and features used;
- Session and engagement information;
- Reading-related interactions;
- Challenge interactions;
- Subscription-related events; and
- Whether certain Rooted features are used.
Rooted does not intentionally send the text of your private prayers, journal entries, or gratitude entries to Firebase Analytics.
Google Signals, advertising identifiers, and ad-personalization features are not enabled by Rooted for Firebase Analytics.
Analytics information may be associated with pseudonymous app, device, or installation identifiers used by the analytics service.
Rooted uses this information for product analytics, reliability, troubleshooting, and improvement—not for targeted advertising.
K. Crash, Diagnostic, and Server Information
Rooted uses Sentry for crash reporting and technical error diagnostics.
Diagnostic information may include:
- App and software version;
- Device or operating-system information;
- Technical error information;
- Time of an error;
- Technical circumstances surrounding a failure; and
- Other information reasonably necessary to diagnose or correct the issue.
Rooted's backend API may also generate server logs for debugging, reliability, security, and fraud-prevention purposes.
Rooted does not intentionally include the contents of private journal entries, prayers, or gratitude entries in analytics or diagnostic events.
L. Push Notifications
If you enable notifications, Rooted may collect and store a push notification token and your notification preferences.
Rooted uses Expo Notifications to facilitate push notifications. Expo may route notifications through services such as Apple Push Notification Service (“APNs”) and Firebase Cloud Messaging (“FCM”), depending on your device.
Rooted may send:
- Bible reading reminders;
- Account-related notifications;
- Challenge or community updates;
- Impact celebrations;
- Monthly impact video announcements;
- Service announcements; and
- Similar Rooted communications.
Rooted does not intentionally use push notifications to disclose sensitive private activity in notification text, such as telling you or someone viewing your device how long it has been since you prayed.
You can disable push notifications through your device settings or available Rooted notification settings.
M. Email and Communications
Rooted may use Resend to send email communications.
These communications may include:
- Authentication codes;
- Account and security emails;
- Welcome emails;
- Monthly impact communications;
- Challenge communications;
- Subscription-related emails;
- Inactivity or engagement communications;
- Product or service announcements; and
- Marketing communications where permitted by applicable law.
If you contact Rooted by email or through a support feature, we may collect your:
- Name;
- Email address;
- Message contents;
- Attachments; and
- Other information you voluntarily provide.
Certain support features may simply open your device's native email application. In that situation, Rooted does not receive your message unless you choose to send it.
You may unsubscribe from marketing emails using the unsubscribe mechanism provided in those messages or by contacting us.
Opting out of marketing does not prevent Rooted from sending necessary authentication, security, transaction, subscription, legal, or account-related communications.
N. Profile Photos and Photo Library Access
If you choose to upload a profile photo, Rooted may request access to a photo you select from your device.
Rooted processes selected images before uploading them to Supabase Storage. Images are resized and compressed, and embedded EXIF metadata, including location information contained in that metadata, is removed through Rooted's image-processing workflow.
Rooted does not currently require access to your contacts, microphone, precise location, health data, motion/activity data, Bluetooth, calendar, or clipboard for the functionality described in this Privacy Policy.
O. App Store Ratings and Reviews
Rooted may use Apple's or Google's native in-app review functionality.
If you submit a rating or review through an app store, Apple or Google processes that rating under its own privacy practices. Rooted does not directly collect your rating through its servers merely because a native review prompt is displayed.
2. How We Use Personal Information
Rooted may use personal information to:
- Create and maintain your account;
- Authenticate users and protect accounts;
- Provide Bible reading, journaling, prayer, gratitude, reading-plan, challenge, and community features;
- Store and synchronize your content;
- Enable you to search your own content;
- Track reading progress, Active Days, achievements, and milestones;
- Administer challenges and community features;
- Manage Ministry Codes, Mission Partner codes, and referrals;
- Calculate and display aggregate challenge and impact information;
- Manage subscriptions and determine access to paid features;
- Provide customer support;
- Send notifications and communications;
- Diagnose technical problems;
- Monitor reliability and performance;
- Protect against fraud, abuse, security threats, and violations of our Terms;
- Understand how users interact with Rooted;
- Improve the functionality, design, reliability, and user experience of the Services;
- Maintain and substantiate Rooted's reported real-world impact;
- Comply with legal, accounting, regulatory, and tax obligations;
- Establish, exercise, or defend legal claims; and
- Send marketing communications where permitted by applicable law.
Rooted does not use your personal information for third-party targeted advertising.
3. Real-World Impact
Rooted may fund or carry out real-world impact activities, including initiatives involving trees, meals, clean water, or other impact programs.
An impact milestone represents Rooted's commitment to fund or carry out the stated impact.
Rooted memberships are purchases of Rooted's app and membership services. They are not charitable donations, and membership payments are not funds donated or earmarked by an individual user for a particular charitable purpose.
Rooted may support impact through vetted nonprofit partners or through initiatives Rooted funds or carries out directly.
When information is provided to nonprofit or other impact partners for purposes such as funding, verification, or reporting, Rooted uses aggregate information and does not identify an individual user as personally funding a specific meal, tree, clean-water activity, or other impact item.
4. Sensitive and Religious Information
Rooted is a Christian faith-based application.
Depending on how you use Rooted, information concerning Bible reading, prayers, journals, Ministry Code participation, or other faith-related activities may reveal information about religious or philosophical beliefs.
Certain jurisdictions provide additional legal protections for sensitive information of this kind.
Where applicable law treats information processed by Rooted as specially protected or sensitive personal data, Rooted will process that information only where an appropriate legal basis and any additional legally required condition apply.
Where Rooted relies on explicit consent to process specially protected information, you may withdraw that consent as permitted by law. Withdrawal does not affect processing that was lawful before consent was withdrawn.
Rooted does not sell sensitive religious information, use it for targeted advertising, or disclose private journal, prayer, or gratitude content to advertisers.
5. How We Disclose Personal Information
Rooted does not sell personal information.
We may disclose personal information in the following circumstances.
A. Service Providers
Rooted uses trusted third-party service providers to help operate, secure, maintain, and improve the Services. These providers may process personal information on Rooted’s behalf or as otherwise necessary to provide their services.
These service providers may include:
- Cloud hosting, database, authentication, and storage providers that help operate Rooted’s infrastructure, manage user accounts, and store information such as profile information, private content, reading activity, challenge information, and application data.
- Analytics, crash-reporting, and diagnostic providers that help us understand how the Services are used, monitor performance, identify errors, prevent abuse, and improve functionality.
- Subscription and payment infrastructure providers that help manage purchases, subscriptions, entitlements, billing status, and related transaction information.
- Email and communications providers that help us send account-related, transactional, service, support, and permitted marketing communications.
- Push-notification and application infrastructure providers that help deliver notifications and support application functionality.
- Identity and authentication providers that allow users to create accounts or sign in using supported third-party authentication methods.
- Application marketplace and platform providers that process app downloads, purchases, subscriptions, payments, notifications, and related platform services.
- Content and technology providers that help provide Scripture, search, reading, or other functionality available through the Services.
We disclose personal information to these providers only as reasonably necessary for them to perform services for Rooted or as otherwise permitted or required by law. We require service providers that process personal information on our behalf to maintain privacy and security protections consistent with this Privacy Policy, applicable law, and applicable platform requirements.
B. Challenge Participants and Administrators
Rooted shares only the challenge-related information described in this Privacy Policy.
Challenge participants may see participant identity information such as name/display name, profile photo, and date joined, together with aggregate group statistics.
Challenge administrators may additionally see limited individual activity information such as Active Days and books read.
Challenge participants and administrators do not receive access to private journals, prayers, gratitude entries, answered-prayer content, or individual impact contributions.
C. Challenge Content
Comments, messages, or other content that you intentionally post in a challenge may be disclosed to participants in that challenge.
D. Ministries and Mission Partners
A ministry does not receive a separate set of personally identifiable information merely because you redeem its Ministry Code.
However, where a Ministry Code automatically enrolls you into a challenge, the challenge visibility rules described above apply.
Mission Partners may receive aggregate conversion statistics but do not receive individual referral names, usernames, or email addresses merely because a code was redeemed.
E. Impact Partners
Rooted may share aggregate or de-identified impact information with nonprofit partners, service providers, vendors, or organizations involved in carrying out or documenting impact.
User identity is not provided to impact partners for the purpose of identifying a particular individual as having personally funded a specific impact activity.
F. Legal, Security, and Safety Purposes
Rooted may disclose information where reasonably necessary to:
- Comply with applicable law;
- Respond to valid legal process or lawful governmental requests;
- Protect the rights or property of Rooted or others;
- Protect users or the public;
- Detect, investigate, or prevent fraud or security incidents;
- Enforce our Terms of Service; or
- Establish, exercise, or defend legal claims.
G. Business Transactions
If Rooted is involved in a merger, acquisition, financing, restructuring, sale of assets, bankruptcy, or similar transaction, information may be transferred in connection with the transaction subject to applicable law and appropriate protections.
6. Advertising, Sale of Data, and Tracking
Rooted does not currently include an advertising SDK.
Rooted does not:
- Sell personal information;
- Share personal information with advertisers for targeted advertising;
- Use your Rooted behavior to target advertisements to you across unrelated apps or websites; or
- Use your private religious activity to build advertising profiles.
Rooted does not currently request Apple's App Tracking Transparency permission because Rooted does not currently engage in cross-app or cross-site tracking that requires such permission.
If these practices materially change, we will update this Privacy Policy and obtain any permission or consent required by applicable law or platform rules.
7. Subscriptions and Payments
Paid Rooted subscriptions are purchased through the Apple App Store or Google Play.
Apple or Google processes your payment credentials. Rooted does not receive your complete payment-card number or bank-account information.
RevenueCat assists Rooted in verifying and managing subscription status using an internal Rooted user identifier.
Deleting your Rooted account does not necessarily cancel an active subscription through Apple or Google. You may need to separately cancel or manage your subscription through your applicable app-store account.
8. Data Retention
Rooted retains personal information only for as long as reasonably necessary for the purposes for which it was collected and as otherwise permitted or required by applicable law.
Retention periods depend on the type of information and the purpose for which it is processed.
Ordinary account information and user content generally remain in Rooted's active systems until you delete the content or your account.
Rooted may retain limited records after account deletion where reasonably necessary for purposes including:
- Legal or regulatory compliance;
- Accounting, tax, and financial recordkeeping;
- Fraud prevention;
- Security investigations;
- Subscription, transaction, refund, or payment disputes;
- Enforcement of agreements or protection against misuse;
- Establishment, exercise, or defense of legal claims; and
- Verification, documentation, accounting, or substantiation of Rooted's reported real-world impact.
Where continued retention of personally identifiable information is not reasonably necessary, Rooted may delete or de-identify information while retaining non-identifying records necessary for these purposes.
Apple, Google, RevenueCat, and other third-party providers may separately retain transaction or other information according to their legal obligations and retention policies.
Analytics or diagnostic information may also remain in pseudonymous, aggregated, or de-identified form in accordance with applicable provider settings and retention practices.
9. Account and Data Deletion
You may delete your Rooted account from within the app using the Delete Account option in Settings.
Rooted also provides an external account-deletion method or resource where required by applicable platform rules.
When you complete account deletion, ordinary personal information and user content associated with your active Rooted account are immediately deleted from Rooted's live database and active storage systems, subject to the limited retention exceptions described in this Privacy Policy.
This generally includes:
- Account name and email information;
- Profile information;
- Journal entries;
- Prayers;
- Gratitude entries;
- Profile photos;
- Reading history;
- Challenge membership; and
- Other ordinary account content.
Challenge comments, messages, and similar community content associated with a deleted account are deleted from Rooted's live database and active storage systems when account deletion is completed, subject only to the limited legal, security, fraud-prevention, and other retention exceptions described in this Privacy Policy.
Certain limited records may remain where reasonably necessary for legal compliance, accounting, fraud or security prevention, subscription disputes, transaction records, impact substantiation, or legal claims.
Although information is removed from Rooted's active systems when account deletion is completed, copies may temporarily remain in secure encrypted database backups for up to 30 days before being overwritten through Rooted's regular backup lifecycle.
Backup copies are maintained for disaster recovery and security purposes and are not treated as active user accounts.
Apple, Google, RevenueCat, and other independent providers may retain transaction records or other information in accordance with their own legal requirements and privacy practices.
10. Your Privacy Rights
Depending on where you live and applicable law, you may have rights concerning your personal information.
These rights may include the ability to:
- Access personal information Rooted maintains about you;
- Obtain a copy or export of certain personal information;
- Correct inaccurate information;
- Request deletion;
- Restrict certain processing;
- Object to certain processing;
- Withdraw consent where processing is based on consent;
- Opt out of marketing communications; and
- Lodge a complaint or appeal where provided by applicable law.
Rooted provides an account data export mechanism.
You may also submit privacy requests by contacting:
We may take reasonable steps to verify your identity before completing a request.
11. Canada
If Canadian privacy law applies to Rooted's processing of your information, you may have rights that include requesting access to personal information we hold about you and requesting correction of inaccurate or incomplete information.
You may contact us regarding a Canadian privacy request or concern at:
Where applicable, you may also have the right to make a complaint to an applicable federal or provincial privacy regulator.
12. California and Other U.S. State Privacy Rights
Residents of California and certain other U.S. states may have additional rights under applicable privacy laws.
Depending on which law applies to Rooted and your information, those rights may include rights to:
- Access or know about personal information;
- Correct inaccurate personal information;
- Delete personal information;
- Obtain a portable copy of certain information;
- Obtain information about certain disclosures;
- Opt out of the sale of personal information;
- Opt out of certain targeted advertising or sharing; and
- Exercise rights regarding sensitive personal information.
Rooted does not sell personal information and does not share personal information for cross-context behavioral advertising.
Rooted does not use private religious, journal, prayer, gratitude, or Bible-activity information for targeted advertising.
To submit an applicable privacy request, contact:
We will not unlawfully discriminate against you for exercising rights granted under applicable privacy law.
13. International Data Transfers
Rooted App, LLC operates from the United States, and Rooted's primary database infrastructure is located in the United States.
Because Rooted may be available outside the United States, personal information from users outside the United States may be transferred to, stored in, or processed in the United States or other jurisdictions where our service providers operate.
These countries may have privacy laws that differ from those in your country.
Where applicable law requires specific safeguards or transfer mechanisms for international transfers, Rooted will implement appropriate measures required for the applicable processing.
You may contact [email protected] for additional information regarding applicable international-transfer safeguards.
14. Security
Rooted uses administrative, technical, and organizational safeguards designed to protect personal information.
These safeguards include, as applicable:
- HTTPS/TLS encryption for data transmitted between the app, backend API, and database infrastructure;
- Encryption at rest provided by our infrastructure;
- Authenticated database access;
- Supabase Row Level Security;
- Access controls;
- Restricted administrative access;
- Credentials and private API keys stored outside application source code;
- Logging and technical monitoring;
- Error monitoring;
- Database backups; and
- Limiting employee and contractor access according to legitimate job responsibilities.
Rooted personnel and contractors with database access are expected to have access only to the extent reasonably necessary for their responsibilities.
No electronic system can be guaranteed to be completely secure, and Rooted cannot guarantee absolute security.
15. Children and Minimum Age
Rooted is not directed to children under 13.
You must be at least 13 years old to create a Rooted account.
If you are under the age of legal majority where you live, you must have permission from a parent or legal guardian to use Rooted.
Where applicable law requires a higher minimum age, consent from a parent or legal guardian, verified parental authorization, or another age-related requirement, those requirements apply.
Rooted does not currently provide parent-managed child-account functionality.
App Store or Google Play content or age ratings do not change the minimum account eligibility requirements stated in this Privacy Policy.
If Rooted learns that personal information was collected from a child in violation of applicable law, Rooted will take reasonable steps to delete the information and address the account.
16. Artificial Intelligence
Rooted does not currently use generative artificial intelligence to analyze or process users' private journal entries, prayers, gratitude entries, or similar private content.
If Rooted introduces a feature that materially changes how personal information is processed using artificial intelligence, we will update our disclosures and obtain additional consent where required by law.
17. Changes to This Privacy Policy
Rooted may update this Privacy Policy from time to time.
If we make material changes, we may notify users through appropriate means, which may include:
- Email;
- An in-app notice;
- A notice within the Services; or
- Another method appropriate under applicable law.
Where applicable law requires consent before a materially different use of previously collected information, Rooted will obtain that consent.
The “Last Updated” date at the beginning of this Privacy Policy indicates when it was most recently revised.
18. Contact Us
For questions, privacy requests, concerns, complaints, or other matters relating to this Privacy Policy, contact:
Rooted App, LLC
Missouri, United States
Email: [email protected]
Where applicable law gives you the right to contact a privacy or data-protection regulator, you may also submit a complaint to the supervisory authority responsible for your jurisdiction.