RootCalm logo
    Back to Home

    Privacy Policy

    Version 1.1.0 • Last updated: September 20, 2026

    1. Introduction

    This Privacy Policy describes how RootCalm ("we," "us," or "our") collects, uses, discloses, and safeguards your personal information when you use our anger assessment application (the "Service").

    We respect your privacy and are committed to protecting it through our compliance with this policy. Please read this Privacy Policy carefully to understand our practices regarding your personal data and how we will treat it.

    2. Information We Collect

    2.1 Information You Provide Directly

    Account Registration Information:

    When you create an account, we collect:

    • Email address - Required for account creation and authentication
    • Password - Stored in encrypted form using industry-standard hashing algorithms
    • OAuth credentials - When using third-party sign-in (e.g., Google), we receive limited profile information

    Assessment Response Data:

    When you complete assessments, we collect:

    • Your responses to all assessment questions, including open-ended text responses
    • Anger intensity ratings and trigger selections
    • Emotional state and physical symptom reports
    • Core beliefs, expectations, and action plans you select or create
    • Timestamp data indicating when assessments were started and completed
    • Assessment history and comparison data over time
    • Personal notes you add to your assessment results

    Feedback and Communication:

    • Helpfulness ratings (1-5 scale) for the Service
    • Testimonials and written feedback you provide
    • Recommendations for service improvements
    • Support inquiries and correspondence with us

    2.2 Information Collected Automatically

    Technical and Usage Information:

    When you access the Service, we automatically collect certain information about your device and usage patterns:

    • Device information: Browser type and version, operating system, device type (mobile/desktop)
    • Log data: IP address, access times, pages viewed, time spent on pages
    • Usage patterns: Features used, navigation paths, click-through rates
    • Session data: Session duration, frequency of visits, return visits
    • Performance data: Page load times, error messages, technical issues encountered

    2.3 Cookies and Tracking Technologies

    We use cookies and similar tracking technologies to enhance your experience:

    • Essential cookies: Required for authentication and basic Service functionality
    • Functional cookies: Remember your preferences and settings
    • Analytics cookies: Help us understand how the Service is used
    • Local storage: Stores session information and user preferences locally

    3. How We Use Your Information

    We use the information we collect for the following purposes:

    Service Provision and Maintenance

    • Process your assessment responses and generate personalized results
    • Store your historical assessment data for progress tracking
    • Authenticate your account and manage user sessions
    • Provide access to your assessment history and notes

    Communication

    • Send welcome emails when you create an account
    • Send assessment completion notifications with result summaries
    • Send reminder emails for follow-up assessments (if applicable)
    • Respond to your inquiries and support requests
    • Send important service updates and security notices

    Service Improvement and Analytics

    • Analyze usage patterns to improve Service features and user experience
    • Identify and fix technical issues and bugs
    • Conduct aggregate statistical analysis (anonymized data only)
    • Test new features and improvements

    Security and Fraud Prevention

    • Detect and prevent fraudulent, unauthorized, or illegal activity
    • Monitor for security threats and vulnerabilities
    • Enforce our Terms of Service and other policies
    • Protect the rights, property, and safety of our users and the Service

    Legal Compliance

    • Comply with applicable laws, regulations, and legal processes
    • Respond to lawful requests from public authorities
    • Establish, exercise, or defend legal claims

    4. Email Communications

    4.1 Types of Emails

    Transactional Emails (Cannot Opt Out):

    • Account verification and password reset emails
    • Security alerts and important account notifications
    • Service updates that affect your account

    Optional Emails (Can Opt Out):

    • Welcome emails when you sign up
    • Assessment completion notifications
    • Reminder emails for follow-up assessments
    • Service improvement updates and feature announcements

    4.2 Managing Email Preferences

    You can manage your email preferences in your account settings. Note that even if you opt out of optional emails, we will still send critical transactional and security-related emails that are necessary for account management.

    5. Data Security

    We implement comprehensive technical and organizational security measures to protect your personal information:

    🔐 Encryption

    • All data transmitted between your device and our servers is encrypted using TLS/SSL
    • Passwords are hashed using bcrypt with industry-standard salt rounds
    • Sensitive data at rest is encrypted using AES-256 encryption

    🛡️ Access Controls

    • Strict access controls limit who can access personal data
    • Multi-factor authentication for administrative access
    • Regular access audits and permission reviews
    • Row Level Security (RLS) policies in our database

    🔍 Monitoring and Response

    • 24/7 security monitoring and threat detection
    • Regular security audits and vulnerability assessments
    • Incident response plan for data breaches
    • Regular backups with encrypted storage

    6. Data Sharing and Disclosure

    ✓ What We DON'T Do:

    • ❌ We DO NOT sell your personal information to third parties
    • ❌ We DO NOT trade or rent your data to advertisers
    • ❌ We DO NOT share your assessment responses with third parties for marketing

    6.1 When We May Share Your Information

    We may share your information only in the following limited circumstances:

    With Your Consent

    We will share your information when you explicitly authorize us to do so.

    Service Providers (Sub-Processors)

    We work with trusted third-party service providers ("Operators" under POPIA / "Processors" under GDPR) who assist us in operating the Service:

    • Supabase Inc. - Database hosting and authentication (USA)
    • PayFast (Pty) Ltd - Payment processing (South Africa)
    • Resend Inc. - Email delivery services (USA)
    • YouTube (Google LLC) - Embedded guided meditation videos (USA/Global)
    • Google LLC (via Lovable AI) - AI analysis features (USA/Global)
    • Sumsub (Sum and Substance Ltd) - Identity document and facial-liveness verification for court-mandated programmes (UK/EU)

    These providers are bound by data processing agreements and may only use your data to perform services on our behalf. For complete details, see our Data Processing Information page.

    Legal Requirements

    We may disclose your information if required by law, court order, subpoena, or other legal process, or if we believe disclosure is necessary to protect our rights, your safety, or the safety of others.

    Business Transfers

    In the event of a merger, acquisition, or sale of assets, your information may be transferred. We will notify you via email and/or prominent notice on our Service of any such change.

    Aggregated and Anonymized Data

    We may share aggregated, anonymized data that cannot be used to identify you for research, analytics, or service improvement purposes.

    6A. Identity Verification and Biometric Data (Court-Mandated Programmes)

    This section applies only if you enrol in a court-mandated or compliance programme.

    Identity verification is not used for our free tools, quizzes, blog, or standard Pro subscription.

    6A.1 Why We Verify Identity

    Courts, probation officers, and attorneys must be able to rely on the fact that the person named on a completion certificate is the person who actually completed the work. To make our certificates defensible, participants in court-mandated programmes complete a one-time identity check at enrolment and short facial re-match checks before key assessments.

    6A.2 What Is Collected

    • An image of a government-issued identity document (ID card, passport, or driving licence)
    • A live selfie / short liveness capture
    • A biometric facial template derived from those images, used to confirm a match
    • Verification metadata: date and time, result (approved / rejected), document country and type, and the number of re-match checks passed

    6A.3 Who Processes It

    Identity and biometric processing is carried out by Sumsub (Sum and Substance Ltd), a specialist identity verification provider, acting as our Operator (POPIA) / Processor (GDPR) under a data processing agreement. Your identity document images and biometric templates are held by Sumsub on their secure infrastructure. RootCalm does not store your ID document images or your biometric facial template. We store only the verification outcome and metadata listed in 6A.2, linked to your account.

    6A.4 Lawful Basis and Consent

    Biometric information is special personal information under section 26 of POPIA and a special category of personal data under Article 9 of the GDPR. We process it only on the basis of your explicit, informed and voluntary consent, which is requested on a dedicated screen before any capture begins, and additionally for the establishment, exercise or defence of a legal claim where a certificate is submitted to a court. You may withdraw consent at any time by contacting us; withdrawal means we can no longer issue or maintain a court-verifiable certificate, and you may instead complete the programme on an unverified basis.

    6A.5 Retention

    • ID images and biometric templates: retained by Sumsub for the period required for audit and re-match purposes, and deleted at the end of that period or on verified deletion request
    • Verification outcome and metadata held by RootCalm: retained for 5 years after certificate issue, so that a court, probation officer, or attorney can verify a certificate after the fact
    • If you never complete enrolment, incomplete verification records are deleted within 30 days

    6A.6 Who Can See the Result

    Only you, our authorised administrators, and — where you choose to share a certificate or report — the court, probation officer, or attorney you share it with. They see the outcome (verified / not verified, date, method), never your document images or biometric data.

    6A.7 Your Rights

    You may request access to your verification records, correction of inaccurate details, withdrawal of consent, or deletion of your biometric data by emailing us using the details in section 16. We will action verified requests within 30 days. Automated matching decisions are always reviewable by a human on request.

    7. Data Retention

    7.1 Active Accounts

    We retain your personal information for as long as your account is active and as necessary to provide you with the Service. This includes:

    • Account information: Retained while your account is active
    • Assessment data: Retained indefinitely for progress tracking unless you request deletion
    • Feedback: Retained indefinitely to improve the Service

    7.2 Account Deletion

    When you delete your account:

    • Your account information and assessment data will be permanently deleted within 30 days
    • Some information may be retained for legal, security, or administrative purposes as required by law
    • Anonymized, aggregated data may be retained for analytics purposes
    • Backup copies may exist for up to 90 days before being permanently purged

    7.3 Inactive Accounts

    If your account is inactive for an extended period (typically 3+ years), we may contact you to confirm whether you want to keep your account. If we cannot reach you or you do not respond, we may delete your account and associated data after providing notice.

    8. Your Privacy Rights

    You have the following rights regarding your personal information:

    📄 Right to Access

    You can request a copy of all personal information we hold about you, including your assessment history and responses.

    ✏️ Right to Correction

    You can update or correct your account information and assessment notes at any time through your account settings.

    🗑️ Right to Deletion

    You can request deletion of your account and all associated data. Individual assessments can be deleted from your assessment history page.

    📤 Right to Data Portability

    You can export your assessment data in CSV or JSON format from your assessment history page.

    🚫 Right to Object

    You can object to certain processing of your data, such as optional email communications, through your account settings.

    ↩️ Right to Withdraw Consent

    Where we rely on your consent to process personal information, you have the right to withdraw that consent at any time.

    To exercise any of these rights, please contact us through the feedback mechanisms in the Service or use the data management tools in your account settings. We will respond to your request within 30 days.

    9. Special Privacy Rights (POPIA, GDPR, CCPA)

    9.1 South African Users (POPIA)

    🇿🇦 Protection of Personal Information Act (POPIA)

    If you are a South African resident, your personal information is protected under the Protection of Personal Information Act 4 of 2013 (POPIA). We are committed to full compliance with POPIA.

    Under POPIA, you have the following rights as a data subject:

    • Right to be notified. You have the right to be informed when your personal information is collected and how it will be used
    • Right to access, You can request confirmation of whether we hold your personal information and request access to it
    • Right to correction; You can request correction or deletion of inaccurate, irrelevant, excessive, out-of-date, incomplete, misleading or unlawfully obtained personal information
    • Right to deletion, You can request the destruction or deletion of your personal information
    • Right to object. You can object to the processing of your personal information for direct marketing purposes
    • Right to submit a complaint, You have the right to lodge a complaint with the Information Regulator

    Information Officer

    In terms of POPIA, we have appointed an Information Officer to ensure compliance with data protection requirements:

    • Name: Dr. Elizma van der Smit
    • Email: support@root-calm.com
    • Response time: Within 30 days of receipt of request

    Lodging a Complaint

    If you believe we have violated your privacy rights under POPIA, you may lodge a complaint with the Information Regulator:

    Lawful Basis for Processing (POPIA Section 11): We process your personal information based on: (1) your consent, (2) necessity for performing a contract with you, (3) compliance with legal obligations, (4) protection of your legitimate interests, and (5) pursuing our legitimate interests where your rights are not unduly affected.

    9.2 European Union Users (GDPR)

    If you are located in the European Economic Area (EEA), you have additional rights under the General Data Protection Regulation (GDPR):

    • Right to lodge a complaint with your local data protection authority
    • Right to restrict processing in certain circumstances
    • Right to data portability in a machine-readable format
    • Right to object to automated decision-making

    Legal Basis for Processing: We process your data based on: (1) your consent, (2) performance of a contract with you, (3) compliance with legal obligations, and (4) our legitimate interests in providing and improving the Service.

    9.3 California Users (CCPA)

    If you are a California resident, you have rights under the California Consumer Privacy Act (CCPA):

    • Right to know what personal information is collected, used, shared, or sold
    • Right to delete personal information held by us
    • Right to opt-out of the sale of personal information (we do not sell personal information)
    • Right to non-discrimination for exercising your CCPA rights

    10. International Data Transfers

    Your information may be transferred to and processed in countries other than your country of residence. These countries may have data protection laws that are different from the laws of your country.

    When we transfer data internationally, we ensure appropriate safeguards are in place, such as:

    • Standard Contractual Clauses approved by the European Commission
    • Data processing agreements with third-party providers
    • Compliance with applicable data protection frameworks

    11. Third-Party Services and Links

    11.1 OAuth Providers

    When you use third-party authentication services (e.g., Google OAuth), we receive limited information from these providers according to your privacy settings with them. We encourage you to review the privacy policies of any third-party authentication providers you use:

    11.2 External Links

    The Service may contain links to external websites (e.g., crisis resources, mental health organizations). We are not responsible for the privacy practices or content of these external sites. We encourage you to read the privacy policies of any website you visit.

    12. Children's Privacy (Under 18)

    The Service is generally intended for adults (18 and over). We do not knowingly collect personal information from a person under 18 except through our limited minor pathways described below, and then only with verifiable parent or legal guardian involvement and consent, as required by clause 4.3 of our Terms of Service.

    Permitted minor pathways. A person aged 13–17 may use the following only where a parent or legal guardian is involved, consents, and (for paid programmes) creates or supervises the account:

    • the Teen Anger Quiz and other teen-facing free screening tools;
    • the Teen anger management track, purchased and supervised by the parent or guardian; and
    • the court-directed programme, only where the referring court or officer permits a minor to enrol and the parent or guardian consents.

    What we collect for minors. We collect only the information needed to deliver and document the programme or screening — account details, responses, progress and, where a court report is requested, completion records. We do not use a minor's information for advertising or profiling, and we do not sell it. Identity verification involving biometric comparison (section 6A) is not applied to minors without written guardian consent.

    Guardian rights. A parent or legal guardian may request access to, correction of, or deletion of a minor's information at any time, and may withdraw consent, which ends the minor's use of the Service. If a minor has used the Service outside these pathways, or without the required consent, please contact us and we will delete that information as quickly as possible.

    13. Data Breach Notification

    In the event of a data breach that affects your personal information, we will:

    • Notify affected users within 72 hours of discovering the breach (when required by law)
    • Provide details about what information was compromised
    • Explain the steps we are taking to address the breach
    • Offer guidance on steps you can take to protect yourself
    • Notify relevant data protection authorities as required by law

    14. Do Not Track Signals

    Some web browsers have "Do Not Track" features that signal websites you visit that you do not want your online activity tracked. Currently, there is no universally accepted standard for how to respond to Do Not Track signals. As such, we do not currently respond to Do Not Track browser signals.

    15. Changes to This Privacy Policy

    We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make changes:

    • We will update the "Last updated" date at the top of this policy
    • For material changes, we will provide prominent notice (e.g., email notification)
    • Your continued use of the Service after changes constitutes acceptance of the updated policy

    We encourage you to review this Privacy Policy periodically to stay informed about how we protect your information.

    16. Contact Us

    If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:

    Responsible entities:

    • South Africa (POPIA responsible party): Dr. Elizma van der Smit Inc. — Information Officer Dr. Elizma van der Smit, PhD — support@root-calm.com
    • United States, EU and UK (business / controller): RootCalm, LLC (Delaware) — support@root-calm.com

    Data Protection Inquiries:

    • • Email the address matching your jurisdiction above
    • • Use the feedback form within the application
    • • For urgent privacy matters, mark your communication as "Privacy Request"

    We aim to respond to all privacy-related inquiries within 30 days (45 days for US state privacy requests, extendable once where permitted).

    17. Acknowledgment

    BY USING THE SERVICE, YOU ACKNOWLEDGE THAT YOU HAVE READ AND UNDERSTOOD THIS PRIVACY POLICY AND AGREE TO THE COLLECTION, USE, AND DISCLOSURE OF YOUR PERSONAL INFORMATION AS DESCRIBED HEREIN. IF YOU DO NOT AGREE WITH THIS PRIVACY POLICY, PLEASE DO NOT USE THE SERVICE.

    This Privacy Policy was last updated on September 20, 2026. Please review it periodically for changes.