Privacy Policy
RootedWords is operated by HopSavings, LLC.
This Privacy Policy explains how HopSavings, LLC (“we,” “us,” or “our”) collects, uses, and protects information when you use RootedWords, our daily cultural crossword app for iOS and Android (the “App”). RootedWords is operated by HopSavings, LLC, a Georgia limited-liability company.
If you have questions or want to exercise a privacy right, email support@hopsavings.com. This policy is published at https://rootedwords.app/privacy (Vercel; domain registered at Squarespace Domains).
Mailing address for privacy requests (principal office):
HopSavings, LLC
2300 W Park Place Blvd, Ste 146 #674
Stone Mountain, GA 30087
USA
This policy is US-focused. We keep California and other U.S. state-privacy category disclosures. The rights in §8 are offered to all users, wherever they live.
1. The short version
- We collect what we need to run your account, serve puzzles, handle clue reports, and improve puzzle quality.
- The current App has no advertising SDKs, no third-party product-analytics SDKs, and no sale of personal information.
- You can request deletion in the App (Settings / Profile) or by emailing support@hopsavings.com.
- We do not promise an inactive-account purge after 24 months. Accounts stay until you (or we) delete them.
- Crash and error reports are sent to Sentry with PII scrubbing. We do not send email, name, username, user id, session tokens, or clue-report text. See §14.A.
- You must be 13 or older. Sign-up asks for your birth year (not stored) and requires agreement to this policy and the Terms.
2. Information we collect and why
We collect only the categories below. Display name and avatar columns exist in the database but the App does not collect or show them.
| Category (CCPA-style) | Examples | Purpose | Collected? |
|---|---|---|---|
| Identifiers — account | Email; password (hashed by Supabase Auth, never stored by the App); username on email sign-up only | Create and authenticate the account | Yes |
| Identifiers — sign-in providers | Google sign-in identity; Apple Sign-In on iOS (scopes EMAIL + FULL_NAME). Apple full_name may be written to Auth user_metadata on first sign-in and is not shown in the App. |
Sign-in | Yes |
| Identifiers — session | Supabase access / refresh tokens in on-device secure storage (expo-secure-store) |
Keep you signed in | Yes (on device) |
| Identifiers — user ID | Supabase user UUID on profiles and on clue reports when signed in |
Account, reports | Yes |
| Identifiers — device | Android ID or iOS IDFV (not IDFA); web fallback UUID | Attach clue reports and gameplay events to a device; help purge device-keyed rows on deletion | Yes |
| User-generated content | Clue reports: report type, puzzle/clue index, answer text, optional comment. Clue prompt text is not stored. | Investigate and fix clues | Yes |
| App activity / gameplay telemetry | puzzle_events: start, complete, abandon, duration (seconds), device id. No user id on this table. |
Puzzle balance and difficulty | Yes |
| Diagnostics (schema) | client_schema_events: app version, OS (ios/android/web), schema version seen, optional puzzle id. No user id or device id. |
Detect stale clients | Yes |
| Progress and stats | On-device and server puzzle grid progress; server streak counts for daily puzzles; local solve counts | Resume play; streaks | Yes |
| Commercial information | Purchases, payment cards | — | No. No IAP in the current App. |
| Location / contacts / photos / precise advertising IDs | — | — | No. |
| Notification preference | On-device toggle in Settings for the local 9:00 a.m. reminder. Not sent to our servers. | Remind you a daily puzzle is ready | Local only |
| Birth year (age gate) | Four-digit year entered at sign-up. Used only on the device to block under-13 accounts. Not stored and not sent to our servers. | Eligibility | On-device only; discarded after the check |
| Crash diagnostics | Sentry: stack traces, device OS, and app version. No email, name, username, user id, IP, session tokens, or clue-report text. See §14.A. | Reliability | Yes |
Playing the App requires an account. Unauthenticated users are sent to Welcome.
We do not collect data through third-party advertising, MMP, or product-analytics SDKs, because those are not in the client.
3. How we use your information
- Create, secure, and manage your account (including Google and Apple sign-in).
- Save progress and daily streaks.
- Generate and serve puzzles (content generation uses OpenAI on our backend — we do not send your email or name to that provider).
- Review clue reports you submit.
- Improve puzzle quality and difficulty using first-party
puzzle_eventsand aggregates inpuzzle_stats. - Schedule a local daily reminder when you have it enabled.
- Diagnose crashes and client errors via Sentry (§14.A).
- Process account-deletion requests (Firebase function receives your session token and optional device id).
- Protect the App against abuse.
We do not use your information for advertising. We do not sell or rent personal information, and we do not share it for cross-app advertising.
4. Where your data is stored
Your data is stored and processed in the United States. Specifically:
- Supabase (Auth + Postgres) in West US (Oregon), United States: account, profile, progress, reports, telemetry, pending-deletion rows.
- Firebase / Google Cloud in
us-central1: Cloud Functions (including account deletion and the daily purge job), Cloud Logging, Cloud Tasks / Cloud Run for puzzle generation. - On your device: session tokens (secure storage); puzzle progress, caches, settings, and telemetry-dedup keys (AsyncStorage).
- Sentry (US ingest): crash and error reports (§14.A). Treat as an additional US processor.
- Vercel: hosts
rootedwords.appmarketing / legal pages after publication. The domain is registered at Squarespace Domains (registrar only). Vercel may set its own cookies or access logs on the website.
If you use the App from outside the United States, your information is transferred to and processed in the United States (Supabase in Oregon; Firebase/GCP in us-central1).
5. Parties we share data with
We share personal information only with providers that help us operate RootedWords. We do not sell it or share it for advertising.
5.1 Providers that handle player account or device data
| Provider | Role | What they receive |
|---|---|---|
| Supabase (West US / Oregon) | Auth + database | Email, password hash, OAuth/Apple identities, profile, progress, reports, events, pending deletions |
| Sign-in (OAuth via Supabase) | Google account identifiers / email per Google’s OAuth | |
| Apple | Sign in with Apple (iOS) | Email (or Hide My Email relay) and name on first authorization |
Firebase / Google Cloud (us-central1) |
Deletion HTTP function, purge cron, puzzle-ops infrastructure, logs | User JWT + optional deviceId on delete; userId in some error logs |
5.2 Providers that handle operational / content data (generally not player accounts)
| Provider | Role | Your personal information? |
|---|---|---|
| OpenAI | Puzzle generation, clue embeddings | No — we do not send your email, name, or device id |
| Slack | Ops alerts (pool health, error rates) | No user identifiers in alert payloads |
| Vercel | rootedwords.app hosting |
Website visitors only; may set its own cookies or access logs |
5.3 Additional processor (crash reporting)
| Provider | Role | Status |
|---|---|---|
| Sentry | Crash / error reports with PII scrubbing (no email, name, or user id) | In use as of 5 September 2026. Sentry is configured not to store IP addresses. We accepted Sentry’s Data Processing Addendum on 5 September 2026 (HopSavings organization). |
6. How long we keep your data
| Data | Retention |
|---|---|
| Account, profile, progress, username, auth identity | While the account exists. After a deletion request: 30-day grace, then hard-delete by the daily 03:00 America/New_York job. Latency can be 30 days plus up to ~24 hours. |
| Inactive accounts with no deletion request | Kept indefinitely. We do not promise a 24-month inactive purge. |
puzzle_events |
Until a device-keyed purge (only if deviceId was stored on the pending-deletion row) or a future TTL job. |
puzzle_stats |
De-identified aggregates. Survive account deletion. |
client_schema_events |
Kept; not tied to an account. |
clue_reports |
Until user-keyed purge, and device-keyed purge if deviceId was provided. |
| Local cache / tokens / reminder schedule | Until you sign out, delete App data, uninstall, or turn the reminder off. Local puzzle files may remain on the device until then. |
| Sentry crash / error reports | Plan-dependent after ingest (currently 30 days on our Sentry plan; 90 days if we upgrade that plan). Events are scrubbed of email, name, username, user id, IP, tokens, and clue-report text before they leave the device. The Sentry org does not store IP addresses (setting enabled 5 September 2026). |
GCP logs that already recorded a userId |
Vendor default. |
| Legal holds | We may keep limited records longer where required by law or to resolve a dispute. |
7. Deleting your account
You can request deletion at any time:
- In the App: Settings / Profile → Delete account.
- By email: write to support@hopsavings.com from the address on the account (or with enough information for us to verify you). Email requests are fulfilled manually.
What actually happens (in-app path):
- We record a pending-deletion row with
purge_after≈ 30 days. Your Auth user is not disabled. The account is not deactivated. - You are signed out on this device. Local progress is cleared on that device.
- 30-day cancelable grace period: if you sign back in before purge, the pending row is cancelled and the account stays.
- After
purge_after, a daily job permanently deletes profile, progress, user-keyed reports, optional device-keyed reports/events, and the Auth user.
What may survive hard-delete: puzzle_events if no deviceId was stored, or from other devices; puzzle_stats aggregates; client_schema_events; published puzzles; vendor backups retained by Supabase or Google on their own schedules; Apple/Google’s own copies of the identity; local cache and a leftover reminder if you did not turn it off.
8. Your rights and choices
We offer the following rights to all users, wherever you live:
- Access the personal information we hold about you.
- Correct inaccurate personal information. There is no in-app profile-edit screen today. Correction is by email to support@hopsavings.com.
- Delete your account and associated data (§7).
- Opt out of “sale” / “sharing” — we do not sell personal information and do not share it for cross-context advertising.
- Limit use of sensitive personal information — we do not collect SSN, precise geolocation, or similar sensitive categories.
- Appeal a refusal, where the law requires it, by emailing support@hopsavings.com.
To make an access or correction request, email support@hopsavings.com. We may need to verify your identity. We will not require you to create a new account solely to submit a deletion request; the email path is available.
Authorized agents (California): email support@hopsavings.com. We may require proof of authorization and identity.
Do Not Track / GPC: the App does not respond to browser DNT signals.
9. Children’s privacy
RootedWords is a general-audience cultural crossword and is not directed to children under 13. You must be at least 13 to create an account.
At sign-up (email, Google, and Apple), the App asks for your birth year and blocks account creation if that year means you are under 13. You must also check a box agreeing to this Privacy Policy and the Terms of Service (with links to both). We do not store your birth year and do not send it to our servers. Under-13 attempts do not create an account.
If we learn we have collected personal information from a child under 13, we will delete it. Contact support@hopsavings.com.
10. How we protect your data
- Encryption in transit (HTTPS/TLS) between the App and our providers.
- Session tokens in the device’s secure storage (
expo-secure-store). - Passwords handled by Supabase Auth (hashed server-side).
- Release-build client error logs and uncaught crashes are sent to Sentry after PII scrubbing (§14.A). Debug logs stay on-device.
No service is 100% secure. Use a strong, unique password.
11. Notifications
The App can schedule a local daily reminder at 9:00 a.m. on your device. We do not collect a push token and do not operate a push-notification server.
You can turn this reminder on or off in Settings in the App, and you can also disable notifications in your device settings.
12. Changes to this policy
We may update this Privacy Policy. We will change the “Last updated” date and post the new version at https://rootedwords.app/privacy. If we make material changes, we will update that date and, where required, notify you by email or in the App.
13. Contact us
RootedWords is operated by HopSavings, LLC
Email: support@hopsavings.com
Website: https://rootedwords.app
Mail (principal office):
HopSavings, LLC
2300 W Park Place Blvd, Ste 146 #674
Stone Mountain, GA 30087
USA
14. Crash reporting
14.A Primary (current practice) — Sentry with PII scrubbing
The App sends crash and error reports to Sentry so we can fix bugs. This has been in place since 5 September 2026.
How it is configured:
- We send stack traces, device OS, and app version.
- We do not attach your account to crash reports, and we do not send Sentry default personal-information fields.
- We do not send email, name, username, user id, IP address, session tokens, or clue-report text. Sentry’s default data scrubbing is on. Sentry is configured not to store IP addresses (enabled 5 September 2026).
- Session replay is not enabled (sample rates 0%).
- Crash ingest is in the United States (
ingest.us.sentry.io). - Not used for advertising or tracking across apps.
Sentry is an additional processor under §5.3. We accepted Sentry’s Data Processing Addendum on 5 September 2026. Retention of error events is described in §6.