learnroots

Privacy Policy

Last updated 22 August 2026 ยท version 2026-08-22

Roots (learnroots.app) helps people learn the language their family speaks. This policy explains what we collect, why, how long we keep it, and how you can get it back or get rid of it. It covers the main Roots app, the Roots Volunteers site (where native speakers help verify and voice courses), and the internal admin dashboard we use to run the service. All three share one database.

Roots is run by Daniel Ngabo, sole trader trading as Roots (ABN: 99787748701), based in Australia. For any privacy question, correction, or complaint, email [email protected] and a real person will answer.

Short version: we don't run ads, we don't sell anything about you, and we don't hand your data to anyone outside the infrastructure providers that run the service, which are listed below.

Who Roots is for

Roots is for adults. You need to be 18 or older to hold a Roots account. We ask your age as the first question when you sign up, before we ask for an email address or anything else. If you tell us you're under 18, we stop there: we don't collect your email and we don't create an account.

Your age is stored on your profile and can be set only once. It decides whether the social parts of Roots are available to you, so it is not something you can edit afterwards. If you entered it wrongly, email us and we'll correct it.

Roots does not currently offer accounts or profiles for children. An earlier version of Roots included family profiles for under-13s. That feature is switched off, and all child profiles and the parental-consent records attached to them were deleted in August 2026. If family profiles return in a future version, this policy will be updated before they do, and the consent process described to parents at the time will apply.

Children's privacy

Roots is not directed to children and we do not knowingly collect personal information from anyone under 18. The age question at signup is asked before we collect anything else, and an under-18 answer ends the signup without an email address being collected.

If you believe someone under 18 has created an account, email us and we will delete it and everything attached to it. We will not ask you to prove anything first.

Roots previously supported family profiles for children under 13, with verifiable parental consent collected by the "email plus" method under the US Children's Online Privacy Protection Act. That feature is switched off. In August 2026 we deleted every child profile, every child session, and every parental-consent record, along with the learning activity attached to them.

What we collect from you

Account basics: your email address and username, your age (a number you enter at signup, used to decide whether you can hold an account and to pitch lessons appropriately), and the avatar you build. Your password is handled and hashed by our authentication provider, Supabase. We never see or store it in readable form.

Learning activity: which languages you study, lessons and exercises completed, accuracy, streaks, XP, placement and check-up results, and words you've saved for review. Anything you type into the optional "why are you learning" prompt is stored, and that step is always skippable.

Social features (Connect and Explore): friend connections and friend codes, the preset nudges and kudos you send, and whether you're currently online so friends see a presence dot.

Your Connect card, if you choose to make one: a display name, the city you live in and the place you were born (both chosen from a list, so a city rather than an address), up to two heritages or peoples you identify with, the languages you're learning, your written answers to up to three prompts, and up to three photographs you upload. Your heritage is information about ethnic origin, which European law treats as a special category. We collect it only because you type it in, only to introduce you to people with a shared background, and you can leave it blank or delete your card at any time.

Messages: Roots lets adults send a one-off introduction note and then, once both people accept, free-text direct messages. We store the text of those messages so they can be delivered and shown to you both. We do not read them routinely; admins can access message content only when investigating a report, and message text is checked automatically against a blocked-words filter when it is sent.

Things you send us: feedback, native-speaker verification votes, content reports, reports that a word's pronunciation sounds wrong (the word, and an optional note you type), and reports about another user. These go to our admins only, never to other users.

Notifications: if you allow push notifications, Apple gives us a device token so we can send them. You can turn notifications off in your device settings at any time and the token stops being useful.

If you volunteer on Roots Volunteers: a separate username and PIN, an unverified phone number, audio recordings of you reading course words aloud, and (only if you opt into paid voice work) your payout details, meaning a bank BSB and account number, or a Wise account.

Device-side and technical data: we keep your session and in-progress lesson state in your browser's local storage so the app is fast and stays signed in. We also record app events (which screen, which lesson, when) to understand what's working. If you're not signed in, those events carry a random device identifier rather than anything about you. Our hosting providers keep ordinary server logs including IP addresses, the way essentially every website does.

When you choose a password, we check it against the Have I Been Pwned database of passwords exposed in known breaches, so we can warn you off one that is already public. This check never sends your password. Your device hashes it, sends only the first five characters of that hash, and does the comparison locally.

How we use it

To run the app: save your progress, pick the right lesson, power streaks, friends, check-ups, and the Connect features if you turn them on.

To improve the courses: aggregate native-speaker votes and corrections so we know which words need fixing. A lot of our content is still marked as awaiting verification, and this is how that gets fixed.

To keep people safe: investigate reports of abuse, spam, or misuse, and act on them.

To pay volunteers: if you opt into paid voice work, we use your payout details to pay you manually, outside the app.

To talk to you about your account: confirmation emails, password resets, and important service notices. We keep these separate from any promotional email. If we ever start sending news or marketing, we'll ask you to opt in first, and every such message will have an unsubscribe link.

We do not run ads, sell your data, share it with data brokers or marketers, or use it to train anyone else's AI.

Who can see your data

Friends you connect with can see your username, avatar, streak, XP, current unit, weekly promise and online status. Nothing else: not your email, not your exact age, not your feedback.

If you turn on Connect and build a card, people you have not met can see that card: your display name, city, birthplace, heritages, the languages you're learning, your prompt answers, your photos, and a summary of your progress. That is the point of the feature, but it is worth being clear that this content is shown to strangers rather than only to friends. Connect is off until you switch it on, you can switch it off again at any time, and doing so removes your card from other people's decks.

Leaderboards show your username, avatar and weekly XP to other adults using Connect, either worldwide or within your country. If you would rather not appear, turn Connect off.

A small number of admins (the person who runs Roots and anyone explicitly flagged as an admin) can sign into the admin dashboard to review feedback and reports, look at aggregate usage, and help with support. Admin access is behind a login and is not public.

Recordings and corrections submitted through Roots Volunteers are reviewed by admins for quality before being used in a course. A recording an admin approves is trimmed, cleaned and then published into the course, where anyone using Roots can play it. It is published as the voice for a word, never under your name, and we don't attach your username, email or phone number to it. If you'd rather a recording of yours wasn't published, or want one taken down after it has been, tell us and we'll remove it.

We will disclose personal information if the law genuinely requires it, such as under a court order, and we'll tell you unless we're legally prevented from doing so.

Where your data lives, and who processes it

Supabase: our database, authentication and file storage, including volunteer voice recordings. Our database is hosted in the United Kingdom / European region.

Cloudflare: hosting and delivery for learnroots.app, its server logs, and privacy-friendly page analytics that count visits without cookies or cross-site tracking.

Vercel: hosting for our staging site and its server logs.

Resend: sending transactional email (confirmations, password resets, and account notices).

Apple Push Notification service: delivering push notifications to iOS devices, if you turn them on.

Have I Been Pwned: the breached-password check described above. Only a five-character fragment of a hash is ever sent, never your password or your email address.

These providers process data on our behalf under their own security and privacy commitments; they are not allowed to use it for their own purposes. We do not sell personal information and we do not share it with advertisers, data brokers or analytics companies beyond what is listed here. If we add a provider, we will update this list.

Because our infrastructure is hosted outside Australia, your information is stored overseas. We've chosen established providers with recognised security practices, but you should know that overseas storage is how the service works.

Artificial intelligence, and what it is used for

Roots has no AI features. Nothing you type, say, upload or study is sent to an AI model, at any point, for any purpose. We do not use your data, or anyone else's, to train a model.

Some of the artwork and audio in Roots was generated with AI tools while the courses were being built, then reviewed and committed as ordinary files. That includes the illustrations attached to vocabulary words, the artwork in the Learn My Roots history sections, and the accent samples used in the dialect check. Those accent samples are synthesised speech, not recordings of people, and are labelled as such in the app.

The human voice recordings in the courses themselves are different: those are real recordings made by adult volunteers through the Roots Volunteers site, and they are never synthesised.

How long we keep it

Account details, learning activity, friends and social records: for as long as your account exists. When you delete your account in the app, these are removed straight away. Copies can persist in our provider's encrypted backups for up to 30 days before ageing out.

Connect cards, photos, introduction notes and messages: for as long as your account exists, or until you delete the card or switch Connect off. Deleting your account removes them, including messages you sent, which disappear from the other person's inbox too.

Feedback, content reports and reports about users: up to 24 months, so we can spot repeat problems. If you delete your account, these are detached from your identity rather than destroyed. The report stays useful, but it stops being about you.

App analytics events: up to 13 months, then deleted. On account deletion they're detached from your identity immediately.

Deletion records: we keep a minimal record that a deletion was carried out (the date and a one-way hash of the email address, not names) for 3 years. This is the evidence that we complied, and it's the one thing that outlives a deletion request.

Volunteer voice recordings: for as long as they're used in a course, or until you ask us to remove a specific recording.

Volunteer payment records: 5 years after the payment, because Australian tax law requires us to keep records of money paid.

Server logs held by our hosting provider: their standard retention, around 30 days.

Your rights and choices

Delete your account, in the app: Profile, then Delete my account. This permanently removes your account, your learning data, your Connect card and photos, your messages, your friendships, and your volunteer recordings if you have any. We ask for your password first so nobody holding your unlocked phone can do it by accident.

Turn Connect off, or delete your card: the Connect tab, then edit your card. Your card stops appearing to other people immediately.

Block someone: from their profile, a message thread, or a card. Blocking removes the friendship both ways and stops them finding you again.

Get a copy of what we hold, or correct something that's wrong: email [email protected] and we'll sort it out. We'll respond within a reasonable time and at most 30 days.

Turn off push notifications: your device's notification settings.

Stop volunteering: you can stop at any time and ask us to delete your recordings and payout details separately from your learning account.

If you're in the European Economic Area or the United Kingdom, you have rights of access, correction, erasure, restriction, objection and portability under the GDPR and UK GDPR. We honour all of these for everyone, wherever you live, because running two standards would be silly. Our lawful basis is the contract we have with you for the service, and our legitimate interest in keeping it safe and working. For the heritage information on a Connect card, which is a special category of data under Article 9, our basis is your explicit consent, given by choosing to fill that field in; you can withdraw it by clearing the field or deleting your card.

Security

Passwords are hashed by our authentication provider and never stored in readable form. We also check new passwords against a database of publicly breached passwords and warn you off them.

Our database uses row-level security on every table, so by default the only rows you can read are your own: your progress, your card, your messages, your recordings, your payout details. Volunteer recordings live in private storage that is not publicly readable, and are served through short-lived signed links rather than public URLs.

We maintain a written information security program covering access control, secrets handling, breach response and an annual review. We can describe it to you if you ask.

No system is perfectly secure, and Roots is a small operation run by one person with help from volunteers. If we ever discover a breach that affects you, we will tell you, and where the law requires it we'll notify the Office of the Australian Information Commissioner and, for European users, the relevant supervisory authority within 72 hours.

Cookies and local storage

We use your browser's local storage to keep you signed in and remember things like your active course and lesson progress, and a cookie to remember a friend code you've been given. Words you've asked us not to test you on are also kept there, on your device only, and are never sent to us. We don't use third-party advertising or tracking cookies, and there's no cross-site tracking to opt out of, which is why you won't see a cookie banner.

Changes to this policy

If we change how we handle your data in a meaningful way, we'll update the date and version at the top of this page, show a notice in the app, and, where the change is significant and affects you, ask you to read and accept it before carrying on.

Contact and complaints

Questions, corrections, access requests, deletion requests or privacy complaints: [email protected]. We aim to acknowledge within one business day and resolve within 30 days.

If you're in Australia and you're not happy with how we've handled a privacy complaint, you can take it to the Office of the Australian Information Commissioner at oaic.gov.au. If you're in the EEA or UK, you can complain to your local data protection authority.