This Privacy Policy explains what personal information Rootwork collects, how we use it, and the choices you have. It applies to Rootwork’s marketing site and application.
What we collect
- Account information — email address, name, and hashed password when you sign up.
- Content you create — projects, clients, tasks, time entries, invoices, and files you upload. This is your data; we hold it on your behalf.
- Billing information — for Pro subscriptions, we store a Stripe customer ID and plan status. Card details are stored by Stripe, not by us.
- Usage information — basic server logs (IP address, browser, request paths) used for security, debugging, and rate limiting.
How we use it
- To operate and improve the service.
- To bill Pro subscribers and manage subscriptions.
- To communicate about your account (password resets, billing, material product changes).
- To detect and prevent abuse.
We do not sell your personal information. We do not run behavioral ad tracking.
AI processing
When you use Clear Scope or other AI features, the content you submit is sent to our AI provider (currently Anthropic) to generate the response. That provider processes the content on our behalf under a data-processing agreement and does not train on your data.
Subprocessors
Rootwork relies on the following service providers:
- Neon — Postgres database hosting.
- Vercel — application hosting.
- Stripe — payment processing.
- Anthropic — AI scoping.
Where your data lives
Data is stored in the United States on infrastructure operated by our hosting providers. By using Rootwork you consent to this transfer and storage.
Your choices
- Access and export — you can view all your data in the app; export features are available from the Settings page.
- Correction — you can edit your account information and content at any time.
- Deletion — you can delete your account at any time. We remove your data within 30 days, except where retention is required by law.
Security
Passwords are stored using bcrypt. Traffic is encrypted in transit via HTTPS. We follow common web-security practices (CSP-friendly headers, HSTS, brute-force protection on the login endpoint). No system is perfectly secure, so we recommend using a strong, unique password.
Children
Rootwork is not intended for children under 16.
Changes
We’ll post any changes to this Policy here. Material changes will be communicated to active subscribers by email.
Contact
Questions or requests? Email hello@rootwork.co.