Rooted Privacy Notice
The short version
- We ask for a lot, because matching on heritage needs it. Where your people are from, the languages you speak, your faith if you choose to say. You decide what appears on your profile and you can hide or change any of it.
- Your data lives in the EU (Ireland).
- We never sell your data. Not to advertisers, not to anyone.
- We do not show anyone that you read their message. No read receipts, ever.
- You can delete your account from Settings. You get 14 days to change your mind, then it is gone.
- You can ask us for a copy of everything we hold, or ask us to correct or delete it.
The rest of this page is the detail. It is long because being honest about this is worth more than being brief.
Who we are
Nexus-Sectech Ltd (company number 17126982), trading as Rooted, is the controller of your personal data. That means we decide what is collected and why, and we are responsible for looking after it.
- Registered address: 71–75 Shelton Street, Covent Garden, London, WC2H 9JQ, United Kingdom
- ICO registration number: ZC120755
- Contact about privacy: privacy@joinrooted.love
- Data protection lead: the founder, reachable at privacy@joinrooted.love
What we collect, and why
Things you tell us
| What | Why | Our lawful basis |
|---|---|---|
| Email and password | To create and secure your account | Performance of our contract with you |
| Name, date of birth, city, country | To run your profile. We show your age, never your date of birth | Contract |
| Gender, height, occupation, education, interests, prompt answers | Your profile, and matching | Contract |
| Whether you have children, and what you are looking for | Matching, and so people can make informed choices | Contract |
| Relationship structure, and for polygyny the two disclosures | Shown on your profile so others can decide openly | Contract, and our legitimate interest in member safety |
| Photos and videos | Your profile | Contract |
| Heritage: nations, ethnic groups, languages | The heart of how Rooted matches people | Your explicit consent |
| Faith, if you choose to give it | Matching, and shown only if you want it shown | Your explicit consent |
Heritage and faith are what the law calls special category data. We ask for your explicit consent at sign-up, we record when you gave it, and you can change your mind. Everything in that group is optional except your nation of heritage, and you can hide any of it from your profile while still using it for matching, or remove it entirely.
Things we collect as you use Rooted
| What | Why | Our lawful basis |
|---|---|---|
| Likes, passes, matches, and who you blocked | To run the product, and to keep people you blocked away from you | Contract, and legitimate interests |
| Messages you send | To deliver them | Contract |
| Which profiles you were shown, and what you did with them | To make your recommendations better | Legitimate interests |
| Conversation patterns, such as who started a chat and whether it was replied to | Match quality, and spotting abuse and ghosting patterns | Legitimate interests |
| Your sign-up IP address, device, browser and where you came from | Fraud and abuse prevention, including catching banned people making new accounts | Legitimate interests |
| Approximate location, derived from your city | Distance sorting | Contract |
We do not collect your GPS location. Distance is worked out from the city you typed, fuzzed to an approximate point. We never know precisely where you are.
Things we collect to keep people safe
| What | Why | Our lawful basis |
|---|---|---|
| A live selfie at verification | To confirm you are a real person, in real time | Explicit consent, and substantial public interest in preventing fraud |
| Automated scans of every photo and video | To detect illegal content and content that breaks our rules, before anyone sees it | Legal obligation, and substantial public interest |
| Reports you make or that are made about you, including a snapshot of the reported message | So we can investigate fairly | Legitimate interests, and legal obligation |
| Records of moderation decisions and staff access to sensitive data | To keep our own team accountable | Legal obligation, and legitimate interests |
Special category data, in plain terms
Some of what we hold is more sensitive: your ethnicity, your faith, the biometric check at verification, and the fact that using a dating service says something about your orientation.
- We keep heritage in a separate, more tightly locked part of the database than the rest of your profile.
- We ask for explicit consent for heritage and faith, separately from agreeing to the terms.
- For the safety scanning and moderation work, we rely on a legal basis for preventing unlawful acts and protecting people, and we keep a written policy explaining how we handle that data. You can ask us for a copy.
- Your verification selfie is not stored by us. Our verification provider captures and holds it. We receive only the result: verified, or not.
How matching works, and the part that is automated
Rooted picks a small set of people to show you each day. That ranking uses things you have told us and things you have done here: shared heritage, languages, faith, intent, interests, age, and who you have liked before. Verified profiles are shown first.
Three things we want to be straight about:
- We show you the reason. Every card carries the reason it was chosen, such as "You're both Akan" or "Both marriage-minded". If we cannot explain a match in a sentence, we should not be making it.
- You control how much heritage counts. There is a setting for it, and you can turn it down to nothing.
- Nothing here decides anything legal or similarly significant about you. It decides the order of some profiles. A human, you, makes every actual decision.
Moderation decisions that affect your account, such as a suspension, are made by a person, not automatically. Automated scanning can flag content and hold it back from being published, and you can appeal any decision and have it looked at again by a human.
Who we share it with
We do not sell your data and we do not share it for advertising. We use these companies to run Rooted, and they may only act on our instructions:
| Who | What they do | Where |
|---|---|---|
| Supabase | Database, file storage and log-in | EU (Ireland) |
| Vercel | Hosting and running the website | EU (Ireland) region, US company |
| Stripe | Identity verification, and payments if we introduce them | US, with EU options |
| Mistral AI | The scam check, when you ask for it | France (EU) |
| Resend | Sending account emails, such as confirmation and password reset | Ireland (EU) |
| Cloudflare | Blocking bots at sign-up | Global |
| Arachnid Shield (Canadian Centre for Child Protection) | Scanning uploads for child sexual abuse material | Canada |
| Sightengine | Scanning uploads for nudity, violence and other prohibited content | France (EU) |
The scam check is worth explaining. When you tap "Check this message", we send only the text of that message. No name, no profile, no account identifier, nothing that ties it to you or to the person who sent it. Our provider keeps it for up to 30 days to detect misuse of their own service, does not use it to train anything, and hosts it in the EU.
We will also share information where the law requires it, or where we must to report illegal content, most importantly child sexual abuse material, which we report to the appropriate authorities.
Where your data is held
Your data is stored in the European Union (Ireland).
Some of the companies above are based outside the UK and EU, or may access data from outside it. Where that happens we rely on the approved safeguards for international transfers. Specifically: certification under the UK Extension to the EU–US Data Privacy Framework where the supplier holds it, and otherwise the UK International Data Transfer Addendum together with the EU Standard Contractual Clauses, built into our contract with that supplier. Canada, where our child-safety scanning partner is based, is covered by a UK adequacy decision. If you want the specific safeguard for a specific supplier, ask us at privacy@joinrooted.love.
How long we keep things
| What | How long |
|---|---|
| Your profile, photos, messages and matches | For as long as your account exists |
| Your account after you delete it | 14 days, so you can change your mind, then permanently deleted |
| Sign-up IP and device details | 18 months |
| Conversation and engagement patterns | 18 months |
| Photo scan results | 90 days, unless the photo is flagged — then the outcome becomes a moderation record |
| Records of moderation decisions and staff access | 6 years from the decision, see the note below |
| Payment records, if you ever pay us | As long as accounting law requires |
Your rights
You can ask us to:
- Give you a copy of what we hold about you.
- Correct anything wrong. Most of it you can edit yourself in the app.
- Delete your account and data. Settings, Danger Zone, and you have 14 days to change your mind.
- Restrict or object to how we use it, particularly anything we do on the basis of legitimate interests.
- Take your data elsewhere, in a portable format.
- Withdraw consent for heritage, faith or verification at any time. Withdrawing does not undo anything we did lawfully beforehand, and some of it is needed for the service to work at all.
We will respond within one month. It is free.
One honest limit. Our records of moderation decisions and of staff access to sensitive data cannot be deleted by anyone, including us. They are deliberately append-only, because a safeguarding log that can be edited is not a safeguarding log. If you ask us to erase everything, those records stay, and we rely on the exemption that allows keeping data for legal obligations and for legal claims. Everything else goes. Those records are kept for six years from the decision — the period during which a legal claim about it could still be brought — and then deleted.
If you are unhappy with how we have handled your data, please tell us first so we can put it right. You also have the right to complain to the Information Commissioner's Office (ico.org.uk), or to your local data protection authority.
Cookies and what we store on your device
We do not use advertising or tracking cookies, and there is no third-party analytics.
What we do store:
- Log-in cookies, so you stay signed in. Strictly necessary.
- A bot-protection check at sign-up, from Cloudflare. Strictly necessary.
- Your display preferences, saved in your browser: your theme, evening mode, background and which admin scope you last used. These never leave your device.
Because all of it is strictly necessary or purely your own preferences, we do not show a cookie banner. If that ever changes, we will ask you properly first.
Children
Rooted is for adults, 18 and over. We check date of birth at sign-up and verification helps confirm it. If you think someone here is under 18, please report them. We treat those reports urgently.
Changes to this notice
If we change how we use your data in a way that affects you, we will tell you in the app before it takes effect, not quietly in a footer.
Last updated: 11 August 2026.