Legal
Privacy Policy
This policy explains what data Rootmap processes, why, who we share it with, how long we keep it, and what you can require of us about it.
Last updated:
1.The short version
We do not sell your data. We do not use your study content to train AI models, ours or anyone else's. We show no advertising and share nothing with ad networks.
- From Google we receive only your name and email — we never create or store a password.
- We keep what you write in the product and the material the AI generates for you, because that is what the product is: study material that persists.
- To generate that material, parts of your content are sent to AI providers under terms that forbid using it for training.
- You can ask for access, correction, portability or deletion of your data at any time, by email.
2.Who processes your data
The data controller is Rootmap, responsible for the service at rootmap.ai. For anything to do with privacy — including reaching whoever acts as data protection officer — write to contato@rootmap.ai.
This policy covers the website, the web application and any communication we send you. Rootmap is operated from Brazil and processing is governed by the Brazilian General Data Protection Law (LGPD, Law 13.709/2018); where the GDPR or another data protection law applies to you, the equivalent rights are honoured through the same channel.
3.Data we process
- Account data
- Your name and email address, received from Google when you sign in. Also an internal identifier, your plan, the interface language and content language you choose, and when the account was created.
- Study content
- The subject and context you provide, your maps, topics, content blocks, chat messages, notes and highlights, quizzes, flashcards and generated audio episodes. This includes the material the AI produces for you and the record of corrections and regenerations.
- Progress and learning preferences
- Your mastery level per topic and interaction signals (what you opened, went deeper on, answered correctly, or asked to be rephrased) used to calibrate the depth and style of explanations. The section on personalisation describes this in detail.
- Usage and technical data
- Access records — IP address, date and time, browser type and pages visited — plus error and service logs. When something breaks, an error report goes to Sentry (see the sharing section) carrying the technical failure, the page it happened on and, if you are signed in, your identifier and email — so we can tell who was affected. That report does not include your study content: the text you write and the terms you search for are stripped before it is sent. Application access records are also kept because Brazilian law requires it (Marco Civil da Internet, Law 12.965/2014, art. 15).
- Product usage events
- Which screens you open and in what order, and the milestones of your journey — arrived, created an account, started a subscription, subscribed — along with your plan, your interface language and where your first visit came from (the campaign or site that brought you). They are tied to your account's internal identifier, never to your name or email, and contain nothing from your study content.
- Consumption metering
- The number of tokens and AI operations attributed to your account, and their cost. This is what lets us enforce plan limits and contain abuse.
- Payment data
- If you subscribe to a paid plan, payment is processed by Stripe. We never receive or store card numbers. We keep only your Stripe customer and subscription identifiers, the plan, its status and the cycle dates.
We do not ask for and do not want sensitive personal data (health, biometrics, religious belief, political opinion, sexual orientation, among others). Please avoid putting it into what you write to Rootmap — if you do, it is handled as part of your study content and sent to the AI providers like any other text.
4.What we use it for, and on what legal basis
- Running the service
- Creating and maintaining your account, generating and storing your study material, keeping your sessions, syncing your progress. Legal basis: performance of the contract.
- Billing and subscriptions
- Processing payments, tracking plan and cycle, issuing tax documents. Legal basis: performance of the contract and compliance with a legal obligation.
- Personalising explanations
- Adapting the depth and style of content to your history. Legal basis: performance of the contract — it is the core function of the product.
- Enforcing limits, preventing fraud and abuse
- Metering consumption, detecting multiple accounts, automation and anomalous use, protecting the infrastructure. Legal basis: legitimate interest — without it the free plan is not viable.
- Monitoring failures and keeping the service up
- Detecting, diagnosing and fixing errors in the site and the API, and identifying who was affected so we can tell them or put it right. Legal basis: legitimate interest — a product that holds your study material has to know when it breaks, which is why the report carries who you are but not what you wrote.
- Improving the product
- Understanding in aggregate what works — how many maps get created, where people stop, which features get used, how many visitors go on to create an account and subscribe. We use a product analytics tool (Mixpanel) for this; it receives usage events identified only by your account's internal identifier — never your name, email or content. We read the results in aggregate. Legal basis: legitimate interest, on the assessment that measuring our own usage funnel is the minimum needed to improve the product and does not change what you get from it.
- Communicating with you
- Operational and security notices, changes to these documents, replies to your messages. Legal basis: performance of the contract and legal obligation. Marketing messages, if any, only with your consent and with one-click unsubscribe.
- Complying with the law and defending rights
- Responding to valid requests from authorities, keeping access records for the statutory period, exercising rights in legal proceedings. Legal basis: legal obligation and the regular exercise of rights.
5.Personalisation and your learning profile
Rootmap infers from your interaction — never from a questionnaire — the level of difficulty that suits you and the explanation style you prefer, and keeps two profiles: one global and one per map. This decides how content is written, not who you are.
- That profile is not shared, sold or used for advertising.
- It produces no decisions with legal or similarly significant effects on you — it does not set your price, grant or deny credit, or rate you to anyone else.
- You can ask what criteria are used and request human review of it, by email.
6.AI providers and model training
Rootmap has no models of its own. To generate content, answer in chat, find references, compute similarity between topics and synthesise audio, we send AI providers the text needed for that operation: what you wrote, the context of the topics involved, and the system instructions.
- We do not use your content to train models, ours or anyone else's.
- We use these providers through their commercial APIs, whose terms prohibit using submitted content for training and limit retention to short periods for safety and abuse prevention.
- We do not send your name, email or payment data along with the content.
- If we change providers, this list is updated, and a contractual no-training commitment remains a condition of using any of them.
7.Who we share it with
We share data only with the processors the service needs to work, and only the minimum each purpose requires. All of them are bound by contract and by confidentiality and security obligations.
- Authentication (sign in with Google) and, through the Gemini API, speech synthesis for audio episodes. Receives your name and email at sign-in; receives the episode script at synthesis time.
- Supabase
- Database, authentication and file storage. This is where your content is kept.
- Railway
- Hosting for the website and the API. It handles traffic and keeps access logs.
- Anthropic
- The language models that generate study content and answer in chat.
- OpenAI
- Embeddings — the numeric representation of passages that makes meaning-based search inside your maps possible.
- Tavily and Wikimedia (Wikipedia)
- Looking up external sources to reference the content. They receive a search term derived from the topic, not your content and not your identity.
- Stripe
- Payment processing and subscription management. It handles your payment details directly, under its own privacy policy.
- Mixpanel
- Product usage analytics. It receives the events described under “Product usage events”, tied to your account's internal identifier — it does not receive your name, your email or any part of your study content.
- Sentry
- Error monitoring. It receives the technical report for each failure of the site or the API and, if you are signed in, your identifier and email, so we can tell whoever was affected. It does not receive your study content or the terms you search for. Unlike the usage analytics, Sentry only records failures — it does not follow your browsing.
Beyond that, we may share data with authorities on a valid legal request, and with an acquirer in a merger, acquisition or corporate reorganisation — in which case you will be told, and this policy keeps applying until another replaces it, with advance notice.
8.International transfers
The providers above operate mainly in the United States, so your data is transferred outside Brazil. We make those transfers on the grounds allowed by LGPD art. 33 — chiefly necessity for performance of the contract — and under data protection clauses agreed with each processor.
9.How long we keep it
- Study content
- For as long as your account exists. The product is built on material that persists: nothing is deleted for inactivity without notice.
- Content you delete
- Items removed inside the product are marked deleted and disappear immediately; permanent removal from our databases happens within 30 days. A few records stay linked for referential integrity where they were reported or corrected.
- Closed accounts
- When you close your account, account data and content are deleted within 30 days, except what the law requires us to keep.
- Access records
- Kept for 6 months, as required by article 15 of the Marco Civil da Internet.
- Error reports
- Retained by Sentry for up to 90 days and discarded automatically after that. We do not copy them anywhere else.
- Tax and billing records
- Kept for the period tax law requires, as a rule 5 years.
- Product usage events
- Kept in the analytics tool for the retention period of the plan we hold with it. When you close your account we ask for the corresponding profile to be deleted.
- Backups
- Backup copies may hold already-deleted data for up to 30 further days, until the rotation cycle expires.
10.Security
- All database access is isolated per user in the data layer itself: every row carries its owner and is filtered by it, so a query cannot reach another account's content.
- Data travels encrypted (TLS) and is encrypted at rest on our providers' infrastructure.
- Administrative access is restricted, individually attributed, and used only to operate and debug the service.
- We store no passwords: authentication is delegated to Google.
No system is immune to incidents. If a security incident poses a material risk to your rights, we will notify you and the Brazilian data protection authority (ANPD) within the deadlines the law sets.
11.Your rights
At any time and free of charge, you have the right to obtain:
- confirmation that we process your data, and access to it;
- correction of incomplete, inaccurate or out-of-date data;
- anonymisation, blocking or deletion of data that is unnecessary, excessive or processed unlawfully;
- portability of your data to another provider;
- deletion of data processed on the basis of your consent;
- information about who we share your data with;
- information about your option not to consent and what follows from that;
- withdrawal of consent, where processing relies on it;
- objection to processing based on legitimate interest, and review of automated decisions.
To exercise any of these, write to contato@rootmap.ai from your account email. We answer within 15 days. We may ask you to confirm your identity before acting on access or deletion requests — that is a protection against someone impersonating you.
The in-product export and delete tools are still being built; until they ship, email is the way, and requests are honoured just the same. If you are in the European Union or the United Kingdom, the equivalent GDPR rights apply and are handled through the same channel.
13.Children and teenagers
Rootmap is intended for people aged 18 and over. We do not knowingly collect data from children or teenagers. If you are a parent or guardian and believe a minor created an account, write to us — we will close it and delete the data.
14.Changes to this policy
We may update this policy as the product evolves. The date of the last update is at the top of the page. Material changes — new purposes, new processors with access to your content, changed retention periods — will be announced by email or in the product at least 30 days in advance.
15.Contact
Questions, requests and complaints about privacy: contato@rootmap.ai. You may also complain to the Brazilian data protection authority (ANPD), or to your local supervisory authority. For the service in general, see the Terms of Use.