Back
RootedLegal

Privacy Policy

BeyondBible Rooted · Last updated: 28 July 2026 · downloadrooted@gmail.com

1. Who we are

Rooted ("Rooted", "the App") is operated by BeyondBible ("we", "us", "our").

This Privacy Policy explains how we collect, use, store, and share personal information when you use Rooted. If you have questions, contact us at downloadrooted@gmail.com.

2. Age requirement

Rooted is intended for users aged 13 and older. We do not knowingly collect personal information from children under 13. If you believe a child under 13 has created an account, contact us at downloadrooted@gmail.com and we will take steps to delete it.

3. Information we collect

Depending on how you use Rooted, we may collect the following categories of information:

  • Account information: email address, username, display name, and authentication credentials (handled via Firebase Authentication).
  • Optional phone discovery data: if you connect a number, Rooted currently stores a one-way hash, the last four digits, your discoverability choice, and connection time. Rooted does not currently use SMS ownership verification and does not store the full number in your profile.
  • Profile information: profile photo, friend code, Bible version and language preferences, and notification preferences.
  • Usage and habit data: streaks, challenge completion status, daily verse interactions, reflection journal entries, and Memory Garden photos you choose to save.
  • Social and community data: friend connections and requests, nudges, and challenge responses (including photos, text, captions, or voice) that you share with friends.
  • Contact-derived data (optional): if you allow Contacts access, we may process phone numbers from contacts you permit — typically as one-way hashes on device or in transit — to find people already on Rooted. We do not sell your address book or use contacts for advertising.
  • Discoverability preference: whether other Rooted users who have your number in their contacts may find you via contact matching.
  • Pod (group) data: pod membership, settings you control, and content you create inside a pod (such as annotations or messages), visible to other members of that pod.
  • Device and notification data: push notification tokens and locally scheduled notification settings so we can send reminders you enable.
  • Purchase and membership data: whether you have an active Rooted membership or related entitlements. Payment card details are processed by Apple or Google, not stored by us as full card numbers.
  • Sensitive religious information: reflections, prayer requests, scripture activity, pod participation, and other content may reveal your religious beliefs or practices. We process this information only to provide features you choose to use.
  • Safety and moderation data: reports, blocks, automated safety flags, enforcement actions, and related evidence used to protect users and respond to legal claims.
  • Technical data: app version, platform, service logs, errors, security signals, and Firebase App Check tokens where supported.

4. How we use information

We use personal information to:

  • Provide and sync the App across your devices (daily verse, challenges, streaks, reflections, and gardens).
  • Enable friends-only challenge sharing, friend codes, friend requests, nudges, and optional contact-based friend suggestions.
  • Connect a phone-derived hash so you can appear in contact matching when you opt in. Until SMS verification is enabled, this is user-confirmed rather than independently verified.
  • Help you invite people from your contacts who are not yet on Rooted (only when you choose Invite).
  • Operate private Bible Pods for members you join or invite.
  • Send notifications you choose to receive (for example Root Check or streak reminders).
  • Process membership purchases and restore entitlements.
  • Maintain security, prevent abuse, and improve the App.
  • Detect potentially objectionable content, investigate reports, enforce our rules, and maintain records of repeat infringement or serious abuse.
  • Respond to support requests sent to our contact email.

5. What others can see

Rooted is not a public social network. In particular:

  • Challenge feed content is friends-only: your shared responses are visible to your accepted friends, not to the general public.
  • Friends may see limited profile information (such as display name, avatar, and activity status used for features like nudges).
  • Your phone number is not shown publicly. Contact matching uses hashes and only works if you connected a phone and left discoverability on.
  • Other users do not receive your full address book; they only see matches relevant to their own authorized contacts.
  • Pod content is visible to members of that pod.
  • We do not sell your personal information.

6. Third-party services

We use trusted service providers to run Rooted. They process data on our behalf or as independent platforms when you use store features:

  • Google Firebase (authentication, database, file storage; SMS delivery if phone verification is enabled).
  • Expo / notification infrastructure for push delivery where enabled.
  • Apple App Store and Google Play for downloads, subscriptions, and in-app purchases.
  • Your device Contacts frameworks (Apple or Google) when you grant Contacts permission.
  • Theological services hosted through Cloudflare, Biblia, bible-api.com, Prayer Pulse, and similar scripture providers used to retrieve or process Bible passages and study content.
  • Google translation services where you request translated content.
  • AI-assisted services may help retrieve, translate, organise, or draft study content. Do not submit information you do not want processed for that feature.

7. Permissions

Rooted may request device permissions only when needed for a feature you use — for example camera or photo library to attach images, notifications for reminders, and Contacts to suggest friends already on Rooted. Rooted does not currently request SMS access or perform SMS phone verification. You can deny or later revoke permissions in your device settings; some features may then be unavailable.

8. Retention and deletion

We keep account and feature data while your account is active. Reports, transaction records, security logs, and legal records may be retained for as long as reasonably necessary to prevent abuse, meet tax or legal duties, resolve disputes, or establish legal rights.

You may delete your account from within Rooted (Profile → Delete Account) or by emailing downloadrooted@gmail.com. The in-app process removes the authentication account and associated data we control, including private profile data, journals, vault entries, posts, contact hashes, and owned uploads. Backups and limited legal, purchase, fraud-prevention, or moderation records may persist until their normal deletion cycle or for as long as legally required.

9. International processing

We are based in Australia. Infrastructure providers such as Firebase may process data in other countries. By using Rooted, you understand your information may be transferred and stored outside Australia with appropriate safeguards used by those providers.

10. Security

We use reasonable technical and organisational measures to protect personal information, including one-way hashing for contact matching where practical. No method of transmission or storage is completely secure; please use a strong password and protect your devices. Hashing reduces exposure but does not make phone-derived data anonymous, because phone numbers have a limited and guessable range. We therefore restrict hash matching through authenticated server functions.

11. Your choices

You can update profile details and notification preferences in the App, manage friends and pods, connect or disconnect a phone for contact discovery, turn off discoverability, revoke Contacts access in system settings, and request access or correction by contacting us. You can also turn off certain notifications in Profile.

You may also ask about access, correction, deletion, or a moderation decision by emailing downloadrooted@gmail.com.

12. Changes to this policy

We may update this Privacy Policy from time to time. The "Last updated" date at the top will change when we do. Continued use of Rooted after an update means you accept the revised policy, where permitted by law.

13. Contact

BeyondBible

Email: downloadrooted@gmail.com

Governing jurisdiction: Australia

This document is provided for transparency and store compliance. For formal legal advice, consult a qualified professional.