RootedWords

Privacy Policy

RootedWords is operated by HopSavings, LLC.

Effective date / last updated: 5 September 2026

This Privacy Policy explains how HopSavings, LLC (“we,” “us,” or “our”) collects, uses, and protects information when you use RootedWords, our daily cultural crossword app for iOS and Android (the “App”). RootedWords is operated by HopSavings, LLC, a Georgia limited-liability company.

If you have questions or want to exercise a privacy right, email support@hopsavings.com. This policy is published at https://rootedwords.app/privacy (Vercel; domain registered at Squarespace Domains).

Mailing address for privacy requests (principal office):

HopSavings, LLC
2300 W Park Place Blvd, Ste 146 #674
Stone Mountain, GA 30087
USA

This policy is US-focused. We keep California and other U.S. state-privacy category disclosures. The rights in §8 are offered to all users, wherever they live.

1. The short version

  • We collect what we need to run your account, serve puzzles, handle clue reports, and improve puzzle quality.
  • The current App has no advertising SDKs, no third-party product-analytics SDKs, and no sale of personal information.
  • You can request deletion in the App (Settings / Profile) or by emailing support@hopsavings.com.
  • We do not promise an inactive-account purge after 24 months. Accounts stay until you (or we) delete them.
  • Crash and error reports are sent to Sentry with PII scrubbing. We do not send email, name, username, user id, session tokens, or clue-report text. See §14.A.
  • You must be 13 or older. Sign-up asks for your birth year (not stored) and requires agreement to this policy and the Terms.

2. Information we collect and why

We collect only the categories below. Display name and avatar columns exist in the database but the App does not collect or show them.

Category (CCPA-style) Examples Purpose Collected?
Identifiers — account Email; password (hashed by Supabase Auth, never stored by the App); username on email sign-up only Create and authenticate the account Yes
Identifiers — sign-in providers Google sign-in identity; Apple Sign-In on iOS (scopes EMAIL + FULL_NAME). Apple full_name may be written to Auth user_metadata on first sign-in and is not shown in the App. Sign-in Yes
Identifiers — session Supabase access / refresh tokens in on-device secure storage (expo-secure-store) Keep you signed in Yes (on device)
Identifiers — user ID Supabase user UUID on profiles and on clue reports when signed in Account, reports Yes
Identifiers — device Android ID or iOS IDFV (not IDFA); web fallback UUID Attach clue reports and gameplay events to a device; help purge device-keyed rows on deletion Yes
User-generated content Clue reports: report type, puzzle/clue index, answer text, optional comment. Clue prompt text is not stored. Investigate and fix clues Yes
App activity / gameplay telemetry puzzle_events: start, complete, abandon, duration (seconds), device id. No user id on this table. Puzzle balance and difficulty Yes
Diagnostics (schema) client_schema_events: app version, OS (ios/android/web), schema version seen, optional puzzle id. No user id or device id. Detect stale clients Yes
Progress and stats On-device and server puzzle grid progress; server streak counts for daily puzzles; local solve counts Resume play; streaks Yes
Commercial information Purchases, payment cards — No. No IAP in the current App.
Location / contacts / photos / precise advertising IDs — — No.
Notification preference On-device toggle in Settings for the local 9:00 a.m. reminder. Not sent to our servers. Remind you a daily puzzle is ready Local only
Birth year (age gate) Four-digit year entered at sign-up. Used only on the device to block under-13 accounts. Not stored and not sent to our servers. Eligibility On-device only; discarded after the check
Crash diagnostics Sentry: stack traces, device OS, and app version. No email, name, username, user id, IP, session tokens, or clue-report text. See §14.A. Reliability Yes

Playing the App requires an account. Unauthenticated users are sent to Welcome.

We do not collect data through third-party advertising, MMP, or product-analytics SDKs, because those are not in the client.

3. How we use your information

  • Create, secure, and manage your account (including Google and Apple sign-in).
  • Save progress and daily streaks.
  • Generate and serve puzzles (content generation uses OpenAI on our backend — we do not send your email or name to that provider).
  • Review clue reports you submit.
  • Improve puzzle quality and difficulty using first-party puzzle_events and aggregates in puzzle_stats.
  • Schedule a local daily reminder when you have it enabled.
  • Diagnose crashes and client errors via Sentry (§14.A).
  • Process account-deletion requests (Firebase function receives your session token and optional device id).
  • Protect the App against abuse.

We do not use your information for advertising. We do not sell or rent personal information, and we do not share it for cross-app advertising.

4. Where your data is stored

Your data is stored and processed in the United States. Specifically:

  • Supabase (Auth + Postgres) in West US (Oregon), United States: account, profile, progress, reports, telemetry, pending-deletion rows.
  • Firebase / Google Cloud in us-central1: Cloud Functions (including account deletion and the daily purge job), Cloud Logging, Cloud Tasks / Cloud Run for puzzle generation.
  • On your device: session tokens (secure storage); puzzle progress, caches, settings, and telemetry-dedup keys (AsyncStorage).
  • Sentry (US ingest): crash and error reports (§14.A). Treat as an additional US processor.
  • Vercel: hosts rootedwords.app marketing / legal pages after publication. The domain is registered at Squarespace Domains (registrar only). Vercel may set its own cookies or access logs on the website.

If you use the App from outside the United States, your information is transferred to and processed in the United States (Supabase in Oregon; Firebase/GCP in us-central1).

5. Parties we share data with

We share personal information only with providers that help us operate RootedWords. We do not sell it or share it for advertising.

5.1 Providers that handle player account or device data

Provider Role What they receive
Supabase (West US / Oregon) Auth + database Email, password hash, OAuth/Apple identities, profile, progress, reports, events, pending deletions
Google Sign-in (OAuth via Supabase) Google account identifiers / email per Google’s OAuth
Apple Sign in with Apple (iOS) Email (or Hide My Email relay) and name on first authorization
Firebase / Google Cloud (us-central1) Deletion HTTP function, purge cron, puzzle-ops infrastructure, logs User JWT + optional deviceId on delete; userId in some error logs

5.2 Providers that handle operational / content data (generally not player accounts)

Provider Role Your personal information?
OpenAI Puzzle generation, clue embeddings No — we do not send your email, name, or device id
Slack Ops alerts (pool health, error rates) No user identifiers in alert payloads
Vercel rootedwords.app hosting Website visitors only; may set its own cookies or access logs

5.3 Additional processor (crash reporting)

Provider Role Status
Sentry Crash / error reports with PII scrubbing (no email, name, or user id) In use as of 5 September 2026. Sentry is configured not to store IP addresses. We accepted Sentry’s Data Processing Addendum on 5 September 2026 (HopSavings organization).

6. How long we keep your data

Data Retention
Account, profile, progress, username, auth identity While the account exists. After a deletion request: 30-day grace, then hard-delete by the daily 03:00 America/New_York job. Latency can be 30 days plus up to ~24 hours.
Inactive accounts with no deletion request Kept indefinitely. We do not promise a 24-month inactive purge.
puzzle_events Until a device-keyed purge (only if deviceId was stored on the pending-deletion row) or a future TTL job.
puzzle_stats De-identified aggregates. Survive account deletion.
client_schema_events Kept; not tied to an account.
clue_reports Until user-keyed purge, and device-keyed purge if deviceId was provided.
Local cache / tokens / reminder schedule Until you sign out, delete App data, uninstall, or turn the reminder off. Local puzzle files may remain on the device until then.
Sentry crash / error reports Plan-dependent after ingest (currently 30 days on our Sentry plan; 90 days if we upgrade that plan). Events are scrubbed of email, name, username, user id, IP, tokens, and clue-report text before they leave the device. The Sentry org does not store IP addresses (setting enabled 5 September 2026).
GCP logs that already recorded a userId Vendor default.
Legal holds We may keep limited records longer where required by law or to resolve a dispute.

7. Deleting your account

You can request deletion at any time:

  • In the App: Settings / Profile → Delete account.
  • By email: write to support@hopsavings.com from the address on the account (or with enough information for us to verify you). Email requests are fulfilled manually.

What actually happens (in-app path):

  1. We record a pending-deletion row with purge_after ≈ 30 days. Your Auth user is not disabled. The account is not deactivated.
  2. You are signed out on this device. Local progress is cleared on that device.
  3. 30-day cancelable grace period: if you sign back in before purge, the pending row is cancelled and the account stays.
  4. After purge_after, a daily job permanently deletes profile, progress, user-keyed reports, optional device-keyed reports/events, and the Auth user.

What may survive hard-delete: puzzle_events if no deviceId was stored, or from other devices; puzzle_stats aggregates; client_schema_events; published puzzles; vendor backups retained by Supabase or Google on their own schedules; Apple/Google’s own copies of the identity; local cache and a leftover reminder if you did not turn it off.

8. Your rights and choices

We offer the following rights to all users, wherever you live:

  • Access the personal information we hold about you.
  • Correct inaccurate personal information. There is no in-app profile-edit screen today. Correction is by email to support@hopsavings.com.
  • Delete your account and associated data (§7).
  • Opt out of “sale” / “sharing” — we do not sell personal information and do not share it for cross-context advertising.
  • Limit use of sensitive personal information — we do not collect SSN, precise geolocation, or similar sensitive categories.
  • Appeal a refusal, where the law requires it, by emailing support@hopsavings.com.

To make an access or correction request, email support@hopsavings.com. We may need to verify your identity. We will not require you to create a new account solely to submit a deletion request; the email path is available.

Authorized agents (California): email support@hopsavings.com. We may require proof of authorization and identity.

Do Not Track / GPC: the App does not respond to browser DNT signals.

9. Children’s privacy

RootedWords is a general-audience cultural crossword and is not directed to children under 13. You must be at least 13 to create an account.

At sign-up (email, Google, and Apple), the App asks for your birth year and blocks account creation if that year means you are under 13. You must also check a box agreeing to this Privacy Policy and the Terms of Service (with links to both). We do not store your birth year and do not send it to our servers. Under-13 attempts do not create an account.

If we learn we have collected personal information from a child under 13, we will delete it. Contact support@hopsavings.com.

10. How we protect your data

  • Encryption in transit (HTTPS/TLS) between the App and our providers.
  • Session tokens in the device’s secure storage (expo-secure-store).
  • Passwords handled by Supabase Auth (hashed server-side).
  • Release-build client error logs and uncaught crashes are sent to Sentry after PII scrubbing (§14.A). Debug logs stay on-device.

No service is 100% secure. Use a strong, unique password.

11. Notifications

The App can schedule a local daily reminder at 9:00 a.m. on your device. We do not collect a push token and do not operate a push-notification server.

You can turn this reminder on or off in Settings in the App, and you can also disable notifications in your device settings.

12. Changes to this policy

We may update this Privacy Policy. We will change the “Last updated” date and post the new version at https://rootedwords.app/privacy. If we make material changes, we will update that date and, where required, notify you by email or in the App.

13. Contact us

RootedWords is operated by HopSavings, LLC
Email: support@hopsavings.com
Website: https://rootedwords.app
Mail (principal office):
HopSavings, LLC
2300 W Park Place Blvd, Ste 146 #674
Stone Mountain, GA 30087
USA

14. Crash reporting

14.A Primary (current practice) — Sentry with PII scrubbing

The App sends crash and error reports to Sentry so we can fix bugs. This has been in place since 5 September 2026.

How it is configured:

  • We send stack traces, device OS, and app version.
  • We do not attach your account to crash reports, and we do not send Sentry default personal-information fields.
  • We do not send email, name, username, user id, IP address, session tokens, or clue-report text. Sentry’s default data scrubbing is on. Sentry is configured not to store IP addresses (enabled 5 September 2026).
  • Session replay is not enabled (sample rates 0%).
  • Crash ingest is in the United States (ingest.us.sentry.io).
  • Not used for advertising or tracking across apps.

Sentry is an additional processor under §5.3. We accepted Sentry’s Data Processing Addendum on 5 September 2026. Retention of error events is described in §6.