Privacy Policy
This Privacy Policy explains how QuietRoots ("we", "our", "us") collects, uses, and protects your personal information when you use the QuietRoots mobile app and website (together, the "Service").
Draft v1.0. This is a starter version intended for review by qualified counsel before public launch. GDPR, CCPA, and COPPA disclosures require legal review.
1. Information We Collect
We collect only what we need to run the Service:
- Account information — email address, display name, password hash (if you register with email), or provider identifier (if you sign in with Apple or Google).
- Service usage — which passages you read, practice logs you create, preferences you choose (language, theme, notification times). This data is tied to your account and used to personalise your experience.
- Device data — device type, operating system version, app version, a device token used to deliver push notifications (only if you opt in). We do not track your location.
- Support correspondence — if you email us, we retain the conversation to help you and improve the Service.
2. How We Use Information
- To provide and improve the Service;
- To deliver notifications and service emails (password reset, invitations);
- To detect abuse, fraud, and security incidents;
- To comply with legal obligations.
We do not use your data to serve advertising and we do not sell your data to third parties.
3. Legal Bases (GDPR)
If you are in the EU or UK, we process your personal data on these bases:
- Contract — to provide the Service you asked for (account, subscriptions, notifications you enabled);
- Legitimate interests — to keep the Service secure, prevent abuse, analyse aggregate usage;
- Consent — for optional features such as push notifications or marketing emails (only where you explicitly opted in);
- Legal obligation — where law requires retention or disclosure.
4. Sharing With Third Parties
We share limited data with vetted service providers who process it on our behalf:
- Apple & Google — app distribution and subscription billing;
- Stripe — payment processing for direct subscriptions (if applicable);
- Firebase (Google) — push notifications, crash reporting;
- Cloudflare — content delivery, DDoS protection, email routing;
- Hetzner — server hosting (EU data centre).
Each provider is bound by confidentiality obligations and only receives the data strictly needed to perform their function.
5. Cookies & Local Storage
The website uses a small number of cookies / local storage values:
- Language preference (so your next visit lands on the right locale);
- Session cookie (if you log in on the web);
- Security / anti-bot token issued by Cloudflare.
We do not use third-party advertising cookies or cross-site trackers.
6. Your Rights
You have the right to access, correct, export, or delete your personal data. If you are in the EU, UK, or California, you also have the right to object to processing and to lodge a complaint with your local supervisory authority.
To exercise any of these rights, email [email protected]. We respond within 30 days.
7. Data Retention
We retain account data for as long as your account is active. When you delete your account we remove your personal data within 30 days, except items we must retain for legal reasons (for example, transaction records for tax compliance). Backups are rotated out within 90 days.
8. Children Under 13
The Service is not directed at children under 13. If we learn that a user is under 13 we delete their account and data promptly. If you believe a child has given us data, please contact [email protected].
9. International Transfers
Our primary hosting is in the European Union. Some providers (Apple, Google, Stripe, Firebase) may process data in the United States or other countries under Standard Contractual Clauses or equivalent safeguards.
10. Security
We use industry-standard measures: encryption in transit (TLS), encryption at rest for sensitive fields, password hashing with modern KDF, role-based access controls, and audit logging. No system is perfectly secure — if we learn of a breach affecting your data we will notify you as required by law.
11. Changes to This Policy
We may update this Privacy Policy. Material changes will be notified through the Service or by email. The "Last updated" date at the top reflects the current version.
12. Contact
Privacy questions, data requests, or complaints: [email protected].