1. Introduction
RootPit ("we," "us," or "our") operates the Root community directory at rootpit.com (the "Platform"). This Privacy Policy explains what information we collect, how we use it, who we share it with, and the choices you have.
Read it together with our Terms of Service and Community Guidelines. If you don't agree with this policy, please don't use the Platform.
RootPit is not affiliated with, endorsed by, or officially connected to Root, Rootapp, Inc., or their affiliates. We are an independent third-party platform.
2. Information We Collect
2.1 Information you give us
Account
- Username and email address (your email is never shown publicly)
- Password, stored only as a salted scrypt hash, never in plaintext
- Whether you want listing emails
- Optional profile details: display name, avatar, bio, website
- The date and version of the Terms you accepted
Listings you submit
- Community or bot name, tagline, description, invite link, tags, icon, banner, and age-restriction flag
- For bots: developer name, commands, requested permissions, and support, privacy, and website links
Activity
- Votes, reviews, replies, "helpful" marks, saved listings, reports you file, and ownership claims
- Messages you send through the contact form (name, email, topic, message)
2.2 Information from Root
We load each community's public Root invite page when it's submitted and about once a day after that, to confirm the invite still works and to read the community name and member count Root shows there. If an owner connects an optional Root Bridge, Root also sends us the community's ID, name, icon, and member count.
Listings added by the RootPit team are imported only with the community's permission, and the permission basis is recorded.
2.3 Information collected automatically
- Session records: when you sign in we store a session with its creation and expiry time and your browser's user agent, so you can stay signed in and review where you're signed in.
- Rate-limit counters: to stop spam and brute-force attempts we count requests per account or per network address. Network addresses are stored only as one-way hashes, and counters expire within 24 hours.
- Listing analytics: we count how often each listing is shown in lists, viewed, and clicked through to Root, and which websites referred visitors (host names only, like
google.com). These counts are aggregated per listing per day, are not linked to your account, and don't use cookies. - Webhook logs: deliveries from optional Root Bridges are logged (time, status, which fields changed) for 30 days so owners can troubleshoot.
- Server logs: our hosting provider keeps standard request logs (IP address, URL, time, status) for operating and securing the service.
2.4 Cookies
We use one kind of cookie: strictly necessary session cookies that keep you signed in and protect sign-in flows. We don't use analytics, advertising, or tracking cookies, so there's nothing to opt out of. If you uncheck "Keep me signed in", your session cookie is deleted when you close the browser.
3. How We Use Information
- Run the Platform: create your account, show listings, count votes, publish reviews, send notifications you ask for, and let owners manage listings.
- Verify and moderate: confirm owners control the communities they list, check invite links, review listings and reports, enforce the guidelines, and keep an audit log of moderation actions.
- Communicate: send account emails (welcome, password reset, security notices) and listing emails if you leave them on, and reply to support messages.
- Protect the Platform: detect vote manipulation, spam, and account abuse; rate-limit requests; investigate reports.
- Help owners: show listing owners aggregate, anonymous analytics about their own listings.
- Comply with law: respond to valid legal requests and defend legal claims.
We don't sell your personal information, share it for cross-context behavioral advertising, or use it for third-party ads.
4. What's Public
- Your username, display name, avatar, bio, website, join date, and live listings (your public profile)
- Reviews and replies you post, with your username
- Listing details you submit, including the listing owner's public profile
Individual votes, saved listings, reports, and your email address are not public. Vote counts are shown only as totals.
5. Who We Share Information With
We share information only with service providers that run the Platform for us, under contracts that limit their use of it:
| Provider | Purpose | Data involved |
|---|---|---|
| MongoDB Atlas (MongoDB, Inc.) | Database and file storage | All data described above |
| Our hosting provider | Serving the website and API | Request and log data |
| Resend | Sending account, listing, and support emails | Email address, message content |
We may also disclose information when required by law, to protect the rights and safety of users or the public, or as part of a merger or acquisition (with notice before a materially different policy applies).
6. How Long We Keep It
| Data | Retention |
|---|---|
| Account, profile, listings, reviews | Until you delete them or your account |
| Sessions | Until they expire (up to 30 days) or you sign out |
| Notifications | 180 days |
| Webhook delivery logs | 30 days |
| Rate-limit counters | Up to 24 hours |
| Aggregate listing analytics | While the listing exists |
| Support messages | As long as needed to resolve the request, then up to 2 years |
| Moderation audit log | Up to 3 years (actor IDs are pseudonymous) |
| Database backups | Rolling backups kept by our database provider expire within 30 days |
When you delete your account we immediately delete your profile, listings, reviews, replies, saved listings, notifications, uploaded images, and vote records. Vote totals you contributed stay on listings but are no longer linked to you, and reports you filed are kept without your identity so moderation history stays intact.
7. Your Rights and Choices
You can do these yourself in Account settings:
- Access and portability: download a JSON copy of your data.
- Correction: edit your profile, username, and listings.
- Deletion: delete your account and associated data.
- Email: change your email address or turn listing emails off. Security emails (password resets, email changes) always send.
For anything else (objecting to processing, restricting it, or a question about your data), contact us or email support@rootpit.com. We respond within 30 days. Depending on where you live (for example the EEA, UK, or California), you may have additional rights, including the right to complain to your data protection authority.
Legal bases (EEA/UK): we process data to provide the service you signed up for (contract), to keep the Platform safe and improve it (legitimate interests), to meet legal obligations, and, for optional notification emails, based on your choices.
8. Children
The Platform isn't for children under 13, and we don't knowingly collect their information. If you believe a child under 13 has an account, contact us and we'll delete it.
9. Security
We use TLS for all traffic, hash passwords with scrypt, store only hashes of webhook and claim tokens, restrict moderation tools to authorized staff, and log moderation actions. Our database provider encrypts data at rest. No system is perfectly secure; if a breach affects you, we'll notify you as the law requires.
10. International Transfers
Our providers may process data in the United States and other countries. Where required, we rely on appropriate safeguards such as standard contractual clauses.
11. Third-Party Links
Listings link to Root and other sites. Their privacy practices are their own; review their policies before sharing information with them.
12. Changes
If we make material changes, we'll update the date above and tell you on the Platform or by email before they take effect.
13. Contact
Questions or requests: contact form or support@rootpit.com.
RootPit is an independent platform. "Root" and the Root logo are trademarks of their respective owners. RootPit is not affiliated with, endorsed by, or in any way officially connected with Root or Rootapp, Inc.