๐ŸŒฑ
ROCKROOTED

Privacy Policy

Last updated: 30 May 2026

This Privacy Policy explains how RockRooted ("we", "us", "our") collects, uses, stores, and protects the personal data of users of the RockRooted iOS application and the website at rockrooted.com (together, the "Service"). We aim to use clear, plain English. If anything is unclear, email support@rockrooted.com.

Contents
  1. Who we are
  2. What this app does
  3. Data we collect
  4. How we use your data
  5. Legal basis (UK / EU)
  6. Third-party services
  7. International data transfers
  8. How long we keep your data
  9. Your rights
  10. Deleting your account
  11. Children's data
  12. Sensitive content
  13. Security
  14. Sign in with Apple
  15. Push notifications
  16. AI Coach
  17. Subscriptions
  18. Analytics & error reporting
  19. Cookies
  20. Changes to this policy
  21. Contact

1. Who we are

RockRooted is the trading name of the team that operates the RockRooted identity-coaching app. For the purposes of UK and EU data protection law, we act as the data controller for the personal data described in this policy.

Contact for privacy questions: support@rockrooted.com
General contact: hello@rockrooted.com

2. What this app does

RockRooted is an identity-first personal coaching application. It offers journaling, mood check-ins, structured coaching tools, an AI-assisted coach, and an optional faith-rooted content mode. It is a personal development tool โ€” not a medical, therapeutic, or psychiatric service. Section 12 explains how we treat the sensitive nature of some of the content you create with it.

3. Data we collect

We only collect what we need to operate the Service and personalise it for you. The data falls into three categories.

3a. Identity data

FieldSource
NameYou provide it during onboarding.
Email addressYou provide it at sign-up (email/password) or via Sign in with Apple (which may be an Apple-relayed address).
Archetype selectionYou choose one of five identity archetypes during onboarding.
Faith Mode & Grace Mode preferencesYou toggle these in onboarding or Settings.
Profile pictureOptional. Stored locally on your device only โ€” not uploaded to our servers.

3b. Content you create

FieldSource
Journal entries (rich text)Notes you write inside the Journal.
Mood check-insEmotion selection (1โ€“5 scale) and optional note when you check in.
Tool session dataInputs you make in the structured coaching tools (3T Method, CBT Reset, etc.).
AI Coach messagesYour conversation with the AI Coach. Stored in your current session.

3c. Technical data

FieldSource
Account ID (Supabase auth UUID)Generated when you create an account.
Push notification tokenIssued by Apple if you enable notifications.
Subscription statusSynced from RevenueCat when you subscribe.
Free-message countCounter used to enforce the free AI Coach tier.
App preferencesDark mode, accent colour, notification time, push categories.
Streak & last check-in dateDerived from your check-in activity.

4. How we use your data

We do not sell your personal data. We do not share it with advertisers. We do not use your journal entries or AI Coach conversations to train any AI model.

5. Legal basis for processing (UK & EU users)

For users in the United Kingdom and the European Economic Area, our processing is based on the following grounds under UK GDPR and EU GDPR Article 6:

6. Third-party services we use

The Service depends on the following providers. Each handles the data described and is bound by its own privacy policy.

ProviderWhat it touchesWhy
AppleApple ID, name and email (Sign in with Apple), App Store payment dataAuthentication and subscription billing
Supabase (US)All account data, journal, mood history, tool progress, push tokensDatabase, authentication, server-side functions
Anthropic (US)AI Coach messages, archetype, first name, mode flagsGenerating AI Coach responses (Claude model)
RevenueCat (US)Account ID, subscription receipts, entitlement stateSubscription state management across devices
Resend (US)Email address, name, subscription metadataSending transactional email
Expo PushPush token, notification payloadDelivering notifications via Apple's APNs

Links to each provider's privacy policy: Apple ยท Supabase ยท Anthropic ยท RevenueCat ยท Resend ยท Expo.

7. International data transfers

RockRooted's backend (Supabase) is hosted in the United States. Anthropic, RevenueCat, and Resend are also US-based. When you use the Service from anywhere in the world, your data is transferred to and processed in the United States.

For users in the UK and the European Economic Area, these transfers rely on appropriate safeguards including the European Commission's Standard Contractual Clauses or equivalent UK transfer mechanisms where required by our providers. By using the Service you acknowledge this transfer.

8. How long we keep your data

9. Your rights

Wherever you live, we honour the following rights for all users where applicable. To exercise any of them, email support@rockrooted.com with the account email address you signed up with. We respond within 30 days.

UK & EU (UK GDPR / EU GDPR)

California (CCPA / CPRA)

All other users

We honour the same effective rights globally. Email us with your request.

10. Deleting your account

You can delete your account from inside the app at any time:

  1. Open the app and tap Settings
  2. Scroll to the Data section
  3. Tap Delete Account
  4. Confirm twice when prompted

What happens when you confirm:

Apple subscription: if you have an active subscription, deleting your account does not automatically cancel it. You must cancel in iPhone Settings โ†’ Your Name โ†’ Subscriptions. We are unable to cancel an Apple subscription on your behalf โ€” only Apple can.

11. Children's data

The Service is intended for users aged 18 and over. You confirm you are 18 or older when you accept the disclaimer during onboarding. We do not knowingly collect personal data from anyone under 18. If a parent or guardian becomes aware that a minor has used the Service, contact support@rockrooted.com and we will delete the account immediately.

12. Sensitive content

Some content you create โ€” journal entries, mood notes, AI Coach messages โ€” may reveal information about your emotional state. We treat this content with extra care:

Crisis safeguarding: a background process scans new journal entries for keywords associated with crisis or self-harm. If a threshold is reached, a record is created so our team can review and ensure appropriate resources are made available inside the app. This is a safety measure โ€” not a clinical intervention.

13. Security

We use industry-standard measures appropriate to the sensitivity of the data:

No system is perfectly secure. If you believe your account has been compromised, contact us immediately.

14. Sign in with Apple

If you choose Sign in with Apple, we receive a stable user identifier and, if you grant them, your name and email. The email may be a private relay address generated by Apple โ€” that is your choice and we do not see your real address unless you provide it. We do not receive any other data from your Apple ID.

15. Push notifications

Push notifications are optional. If you enable them we store an Expo push token on your account so we can send reminders. Notification categories include daily nudges, weekly reflections, and broadcasts. You can disable notifications in iPhone Settings โ†’ RockRooted โ†’ Notifications or in-app under Settings โ†’ Notifications.

16. AI Coach

When you message the AI Coach, your message text is sent through our backend to Anthropic's Claude API (in the United States) along with your first name, archetype, and Faith / Grace mode flags. The response is returned to your device. Conversations are scoped to your account.

Per Anthropic's published API policy at the time of writing, customer API data is not used to train Anthropic's models. We do not use your AI Coach conversations to train any model either. Anthropic's privacy policy: anthropic.com/legal/privacy.

17. Subscriptions

Subscriptions are processed by Apple. We never see your payment-card details. RevenueCat is a third-party subscription management service that receives a non-personal subscriber ID linked to your account, so we can keep your premium status synchronised across devices. Cancellation is handled in iPhone Settings โ†’ Your Name โ†’ Subscriptions.

Subscription pricing, free trial details, and cancellation terms are set out in the Terms of Service.

18. Analytics & error reporting

At the time of this policy's effective date, RockRooted does not integrate third-party product analytics or error-reporting services. If we add such services in future (for example to monitor crashes or measure feature usage), this policy will be updated and, where required by law, your consent will be requested before we begin collecting that data.

19. Cookies

The RockRooted iOS app is a native application โ€” it does not use browser cookies. The web pages at rockrooted.com use no analytics or marketing cookies. Standard server access logs may record IP addresses for security and abuse-prevention purposes only.

20. Changes to this policy

We may update this policy from time to time. The "Last updated" date at the top will change. For material changes that affect how we process your data, we will notify you in-app and, where required, ask you to acknowledge the change before continuing to use the Service.

21. Contact

Email support@rockrooted.com for any question about this Privacy Policy, to exercise your rights, or to report a concern.

UK users have the right to complain to the Information Commissioner's Office at ico.org.uk. EU users have the right to complain to their local supervisory authority.