The short version. Rootio stores the links, notes and images you save, the account they belong to, and the workspaces you share them with. We do not sell your data and we do not show you advertising. We do not train AI models on your library ourselves, but if you use the assistant, what it sends to Google may be used by Google to improve its products — section 5 explains exactly what is sent. Everything below says the same thing in more detail.
1. Who we are
Rootio ("Rootio", "we", "us") is a bookmark manager for individuals and teams, available as a mobile app for iOS and Android and served by an API at rootio.site. This policy explains what personal information we collect when you use it, why, and what you can do about it.
The data controller is GYMTROX Technologies, of 499 D Block, Punjab, Sargodha, Sargodha - 40100, Pakistan. You can reach us at any time at support@rootio.site.
2. What we collect
2.1 Account information
When you create an account we store:
- your name and email address;
- a hash of your password, if you set one — we use bcrypt, and the original password is never written to disk or to a log;
- your profile picture, if you choose one — or, if you sign in with Google, the picture URL from your verified Google ID token;
- your accent colour, your plan, and which workspace you last had open.
2.2 Sign in with Google or Apple
If you sign in with Google or Apple, we receive an identity token from that provider and verify it against the provider's published keys. From it we store your provider account identifier, your email address, your name and (Google only) your profile picture URL. We never receive your password for those accounts, and we do not request access to your Google Drive, contacts, calendar or any other Google or Apple service.
2.3 The content you save
This is the substance of the product: the Roots, Shelves and Links you create, including URLs, titles, notes, tags, and any images you upload. We also store the small amount of bookkeeping that makes the app work — counts per Root and Shelf, which link you last opened, and whether a link's URL last responded.
2.4 Workspace and team information
Workspace names, memberships and roles; invitations you send, including the email address of the person you invited and a hash of the invitation code; roots shared with a workspace and requests to share them; and the activity timeline — who saved, moved, shared or deleted what, and any replies left on an entry.
2.5 Device and technical information
- Push notification tokens for each device you sign in on, and the platform that issued them;
- Server logs — for each request, a generated request identifier, the method and path, the response status and the time it took. We deliberately do not log request bodies, because they carry passwords and tokens;
- Session records — refresh tokens, stored hashed, so a signed-in device can stay signed in and a stolen token can be detected and revoked.
2.6 Analytics
The app uses Firebase Analytics (which reports into Google Analytics 4) to record which screens are opened and a small, fixed set of product events — a link saved, a root created, an invitation sent, and similar. Every parameter on those events is deliberately low-cardinality: a boolean or a short category, never a link URL, a note, a question you asked the assistant, a name or a record identifier. Your account identifier is attached so that a session can be counted once rather than many times.
2.7 What we never collect
We do not collect your location, your contacts, your camera roll (beyond the single image you pick), your browsing history outside the app, or any advertising identifier. There are no third-party advertising or tracking SDKs in Rootio.
3. How we use it
- To run the service — store your library, sync it, and show it to the people you shared it with.
- To authenticate you, keep you signed in, and detect a stolen session token.
- To answer your questions with the assistant, and to flag duplicate or dead links.
- To send you the messages described in section 9.
- To enforce plan limits, and to process a subscription if you buy one.
- To keep the service secure and available — rate limiting, abuse prevention, and diagnosing failures.
- To understand which parts of the app are used, in aggregate, so we know what to improve.
We do not sell personal information, we do not share it with data brokers, and we do not use it for advertising or profiling.
4. Legal bases (UK / EU users)
| What | Basis under the GDPR |
|---|---|
| Your account, your library, sharing and sync | Performance of our contract with you (Art. 6(1)(b)) |
| Security, rate limiting, abuse prevention, logs | Our legitimate interests in a service that stays up and is not abused (Art. 6(1)(f)) |
| Analytics and product measurement | Consent where required, otherwise legitimate interests (Art. 6(1)(a) / (f)) |
| Push notifications | Consent — granted through your device's permission prompt (Art. 6(1)(a)) |
| Billing and tax records | Legal obligation (Art. 6(1)(c)) |
5. The AI assistant
When you ask the assistant a question, the question and the relevant entries from your own library are used to produce an answer. Depending on how the service is configured, that processing happens either entirely on our own servers or through Google as a model provider.
Where a model provider is used, your question and the library entries needed to answer it are sent to that provider so it can return an answer. Rootio uses the Gemini API on its free tier, and under Google's terms for that tier your prompts and the responses may be used by Google to provide, improve and develop its products, services and machine-learning technologies. Human reviewers at Google may read and annotate that material; Google states that it disconnects the material from our account, API key and project before a reviewer sees it. If we move to the paid tier this stops applying, and we will update this policy and the date on it.
What is sent is only what answering needs: for the links in question, the title, address, site, tags, description and any notes you wrote, together with the names of the Root and shelves they sit on. The sign-in address and the card details you can record against a link are never sent to a model provider. Because your own notes are included, treat a note as something a reviewer could read if you use the assistant.
We record the number of questions you ask each month so we can apply your plan's allowance; we do not retain the question text for any other purpose.
When you ask a question from inside one of your Roots, the assistant is given only that Root's shelves and links. Nothing from your other Roots is sent, so an answer there cannot draw on them.
The assistant answers from your library and cites the link it came from. It can still be wrong or incomplete — see clause 9 of the Terms & Conditions.
6. Who we share it with
We share personal information only with the service providers that Rootio needs to run, and each receives only what its function requires. Each acts as our processor under a data processing agreement, with one exception: on the Gemini API's free tier Google may also use what it receives for its own products, as clause 5 explains.
| Provider | What it does | What it receives |
|---|---|---|
| Google (Sign-In, Firebase) | Social sign-in, analytics, Android push delivery | Account identifier, device token, screen and event names |
| Apple | Sign in with Apple, iOS push delivery | Provider account identifier, device token |
| Expo | Push notification delivery to both platforms | Device token, notification title and body |
| Google (Gemini API) | The AI assistant, where configured. On the free tier Google may use this material to improve its own products (clause 5) | Your question, and the titles, addresses, tags, descriptions and notes of the links it needs to answer it |
| Google (Gmail SMTP) | Password resets and workspace invitations | Recipient email address and the message body |
| Hostinger | Servers, database and file storage | All data stored by the service, at rest |
We may also disclose information where we are legally required to, or where it is necessary to establish or defend a legal claim. If Rootio is ever acquired or merged, your information may transfer to the acquirer, and you will be told before that happens.
7. Workspaces and other people
A workspace is a shared space, and that is the point of it. Anyone who is a member of a workspace can see the Roots, Shelves and Links in it, the activity timeline for it, and the name, email address and profile picture of every other member. Sharing a Root with a workspace makes that Root, its shelves and its links visible to every member of that workspace.
If you invite someone by email, we store the address you entered and send them a message with an invitation code. Only invite people who expect to hear from you.
The workspace owner and its admins can remove members and can restructure Roots shared with the workspace. If you were invited into a workspace by an organisation, that organisation may have its own privacy policy governing what it does with what you put there.
8. Images and file links
Worth knowing. Pictures you upload — a profile photo, a Root's image — are served from an unguessable but unauthenticated URL. The filename is sixteen random bytes, and anyone holding the exact URL can open the file without signing in. This is the same arrangement used by essentially every avatar hosted on a CDN, including the Google profile picture that sits beside it, and it is what lets the app display an image without attaching a login token to every image request.
The practical consequence: do not upload anything to Rootio as an image that you would not be willing to have seen by someone who obtained the link.
9. Push notifications and email
Push notifications tell you what your team did — a link shared, an invitation accepted, a suggestion waiting. They are sent only after you grant the permission on your device, and you can turn them off at any time in the app's settings or in your device settings. Declining is a normal answer and nothing else in the app stops working.
Email is transactional only: password resets, and workspace invitations you or a teammate send. We do not send marketing email, and there is no mailing list to unsubscribe from.
10. Retention and deletion
| What | How long |
|---|---|
| Your account and library | Until you delete it, or you ask us to |
| Deleted Roots, Shelves and Links (the trash) | Recoverable for your plan's retention window, then permanently removed |
| Archived links | Until you restore or delete them — they never expire on their own |
| Password reset tokens | Minutes — they expire quickly and are single-use |
| Workspace invitation codes | Until accepted, revoked, replaced by a resend, or expired |
| Refresh tokens (sessions) | Until they expire, you sign out, or the family is revoked |
| Server logs | A short operational window, then discarded |
| Billing records | As long as tax and accounting law requires |
Deleting your account removes your account record, your library and your device tokens. Content you contributed to a shared workspace — a link you saved onto a shared Shelf, an entry on a team's timeline — may remain visible to that workspace, because it is part of a record other people rely on. Tell us at support@rootio.site if you would like that reviewed.
How to delete your account sets out the whole process — how to ask without the app installed, exactly what is removed, what happens to a workspace you own, and how long we take.
11. Security
- All traffic between the app and the API runs over TLS.
- Passwords are stored as bcrypt hashes and are never logged.
- Refresh tokens are hashed at rest, single-use, and rotated. Presenting a token that has already been rotated is treated as a theft signal and revokes the whole session family.
- Every request is scoped to your active workspace on the server. A record belonging to a workspace you are not a member of answers as if it does not exist.
- Requests are rate limited, and the API refuses request shapes it does not expect.
No system is perfectly secure. If you believe you have found a vulnerability in Rootio, please write to support@rootio.site before disclosing it publicly, and we will work with you.
12. Your rights
Depending on where you live, you have some or all of the following rights:
- Access — a copy of the personal information we hold about you.
- Correction — most of it you can edit yourself in the app.
- Deletion — of your account and its contents.
- Portability — any Root exports as clean Markdown from inside the app, at any time, without asking us.
- Objection and restriction — to processing based on legitimate interests.
- Withdrawing consent — for push notifications and analytics, at any time.
Write to support@rootio.site and we will respond within 30 days. If you are in the UK or the EU and you are not satisfied with our response, you may complain to your local supervisory authority.
California residents. We do not sell or share personal information as those terms are defined by the CCPA/CPRA, and we do not offer financial incentives in exchange for it. The rights above cover the CCPA rights to know, delete and correct.
13. International transfers
Rootio and its providers operate internationally, so your information may be processed in a country other than your own, including the United States. Where information leaves the UK or the EEA we rely on the European Commission's Standard Contractual Clauses, the UK International Data Transfer Addendum, or an adequacy decision, as applicable.
14. Children
Rootio is not directed at children and is not for anyone under 13, or under the minimum age of digital consent in your country if that is higher. We do not knowingly collect personal information from children. If you believe a child has given us information, write to us and we will delete it.
15. Changes to this policy
We will update this page when what we do changes, and the date at the top will change with it. If a change materially affects how we handle your information, we will tell you in the app or by email before it takes effect.
16. Contact
support@rootio.site
GYMTROX Technologies, 499 D Block, Punjab, Sargodha, Sargodha - 40100, Pakistan