Name Roots GmbH ("we", "our", "us") is committed to protecting your privacy and ensuring full transparency about how we collect, use, store, and protect your personal information. This Privacy Policy applies to all users worldwide and is designed to comply with the Swiss Federal Act on Data Protection (revFADP), the EU General Data Protection Regulation (GDPR), the UK GDPR, the California Consumer Privacy Act (CCPA) / California Privacy Rights Act (CPRA), and other applicable data protection laws globally.
We never sell, rent, trade, or share your personal data with third parties for their marketing purposes. Period.
01Data Controller & Contact Information
Name Roots GmbH operates as the data controller responsible for processing your personal data. For the purposes of the revFADP, the GDPR and the UK GDPR, the data controller is:
Name Roots GmbH
Luzernerstrasse 4, 6010 Kriens, Switzerland
Email: hello@nameroots.app
Phone / WhatsApp: +41 76 411 7975
Because Name Roots GmbH is established in Switzerland (outside the EU/EEA and the UK) but offers its Service to individuals in those territories, we have appointed representatives as required by Article 27 GDPR and Article 27 UK GDPR:
- EU Representative (Art. 27 GDPR): [Name & EU address — to be appointed / confirmed with counsel]
- UK Representative (Art. 27 UK GDPR): [Name & UK address — to be appointed / confirmed with counsel]
For data protection enquiries, you may contact us at any time using the details above. We aim to respond to all data protection requests within 30 days (or 45 days for complex requests under CCPA/CPRA, with notice).
02Definitions
- "Personal Data" means any information relating to an identified or identifiable natural person, including but not limited to names, email addresses, journal entries, and usage data.
- "Processing" means any operation performed on personal data, including collection, recording, storage, alteration, retrieval, use, disclosure, or deletion.
- "Data Subject" means you — the individual whose personal data is being processed.
- "Sub-processor" means a third-party service provider that processes personal data on our behalf.
- "Service" means the Name Roots web and mobile application, including all features such as name readings, journal tools, workbook exercises, and ancestral explorations.
- "Sensitive Data" in the context of our Service refers to ancestral and family information, journal entries, and personal reflections you choose to share.
- "Consumer" (for US state privacy laws) means a natural person who is a resident of the applicable state, acting in an individual or household context.
03Categories of Personal Data We Collect
a) Account Information
Email address, encrypted password (or OAuth tokens if using Google/Apple sign-in), display name, and profile avatar. Collected when you create an account.
b) Name & Ancestral Data
First names, surnames, family member names, relationship types, birth years, birth regions, migration indicators, and lineage-side designations you voluntarily provide. This data is treated as sensitive personal data and is used exclusively to generate personalised name readings and lineage explorations.
c) Journal & Workbook Entries
Gratitude journal entries, workbook reflections, exercise responses, Vedic journal entries, and personal notes. These are encrypted at rest and accessible only by you.
d) Personality & Assessment Data
Responses to personality assessments (e.g., Vedic archetype test), resulting scores, and archetype classifications.
e) Usage & Interaction Data
Feature usage events (e.g., "opened journal", "generated reading"), session frequency, and language preference. This data is anonymised and does not contain personally identifiable information. Collected to improve app experience.
f) Technical & Device Data
Browser type, operating system, screen resolution, timezone, and IP address (processed but not stored). No device fingerprinting is performed.
g) Payment Data
We do not collect, store, or process your credit card number, CVV, or bank details. All payment processing is handled by Stripe, Inc., a PCI-DSS Level 1 certified payment processor. We receive only a transaction confirmation, subscription status, and Stripe customer identifier.
h) Communication Preferences
Push notification subscription tokens, email reminder settings, preferred reminder times, and opted-in communication channels.
04Legal Basis for Processing (GDPR Art. 6)
We process your personal data under the following legal bases as defined by GDPR Article 6(1) (and the corresponding provisions of the revFADP and UK GDPR):
| Purpose | Legal Basis |
|---|---|
| Account creation & management | Contractual necessity (Art. 6(1)(b)) |
| Generating name readings & AI content | Contractual necessity (Art. 6(1)(b)) |
| Storing journal & workbook entries | Contractual necessity (Art. 6(1)(b)) |
| Processing payments via Stripe | Contractual necessity (Art. 6(1)(b)) |
| Sending email/push reminders | Consent (Art. 6(1)(a)) |
| Anonymised usage analytics | Legitimate interest (Art. 6(1)(f)) |
| Security & fraud prevention | Legitimate interest (Art. 6(1)(f)) |
| Legal compliance & responding to lawful requests | Legal obligation (Art. 6(1)(c)) |
Where we process the special categories of data described above (ancestral and family information), we rely on your explicit consent (Art. 9(2)(a) GDPR), which you may withdraw at any time. Where we rely on consent, you may withdraw your consent at any time without affecting the lawfulness of processing prior to withdrawal. Where we rely on legitimate interest, we have conducted a balancing test to ensure your rights and freedoms are not overridden.
05How We Use Your Information
We use your personal data strictly for the following purposes:
- To create and manage your user account and authenticate your identity
- To generate personalised name readings, ancestral insights, and AI-powered reflections
- To store and retrieve your journal entries, workbook progress, exercises, and personality assessments
- To process payments and manage subscriptions through Stripe
- To send email reminders and push notifications you have explicitly opted into
- To provide customer support and respond to your enquiries
- To detect, prevent, and address security issues, fraud, or technical problems
- To improve our services through aggregated, anonymised usage patterns (no personal data is included)
- To comply with legal obligations, enforce our terms, and protect our rights
We do not use your personal data for advertising, profiling for marketing, or any purpose not listed above.
06AI-Generated Content & Data Processing
Name Roots uses artificial intelligence (AI) models to generate name interpretations, reflections, conversational responses, and personalised insights. We want you to understand exactly how your data interacts with AI systems:
- What data is sent to AI providers: When you request a name reading or engage in a conversation, your input data (names, questions, and relevant context) is transmitted to our AI service providers for processing.
- No training on your data: Your personal data is never used to train, fine-tune, or improve AI models. We have contractual agreements with all AI providers prohibiting the use of user data for model training.
- No data retention by AI providers: Our AI service providers process your data in real-time and do not retain your personal data after generating a response, in accordance with their data processing agreements.
- AI content is probabilistic: All AI-generated content is probabilistic and interpretive in nature. It should be treated as reflective prompts for personal exploration, not as factual statements, medical advice, psychological diagnosis, or therapeutic guidance.
- No automated legal decisions: AI-generated content does not produce legal effects or similarly significant effects on you as defined under GDPR Article 22.
07Data Sharing & Third-Party Processors
We do not sell, rent, trade, or otherwise disclose your personal data to third parties for their own purposes.
We share data only with the following categories of service providers ("sub-processors") who process data on our behalf under strict data processing agreements:
| Provider | Purpose | Data Shared |
|---|---|---|
| Stripe, Inc. | Payment processing | Email address, subscription plan (credit card data goes directly to Stripe, never to us) |
| AI Service Providers | Generating name readings & chat responses | Names, user questions, conversation context (not retained by providers) |
| Email Delivery Services | Sending opted-in email reminders | Email address, reminder content |
| Cloud Infrastructure | Database hosting & edge functions | All user data (encrypted at rest and in transit) |
We may also disclose your data if required by law, regulation, legal process, or governmental request, or to protect our rights, privacy, safety, or property.
08International Data Transfers
Your personal data may be transferred to and processed in countries outside your country of residence, including Switzerland, the European Union, and the United States, where some of our service providers operate.
For transfers from the EU/EEA/UK to third countries, we rely on the following safeguards as required by GDPR Chapter V:
- Switzerland adequacy: The European Commission and the UK recognise Switzerland as providing an adequate level of data protection, so transfers from the EU/EEA and UK to Name Roots GmbH in Switzerland do not require additional safeguards.
- EU–US Data Privacy Framework: Where applicable, we work with providers certified under the EU–US Data Privacy Framework (and its UK and Swiss extensions).
- Standard Contractual Clauses (SCCs): We have executed the European Commission's Standard Contractual Clauses with all sub-processors that process EU/EEA personal data in third countries.
- UK International Data Transfer Agreement (IDTA): For UK transfers, we use the UK Addendum to the EU SCCs or the IDTA as appropriate.
- Supplementary measures: We implement technical and organisational measures including encryption, pseudonymisation, and access controls to supplement transfer safeguards.
You may request a copy of the relevant transfer safeguards by contacting us at hello@nameroots.app.
09Data Retention & Deletion
We retain your personal data only for as long as necessary to fulfil the purposes for which it was collected, or as required by law:
- Account data: Retained for the lifetime of your account. Deleted within 30 days of account deletion.
- Name readings & chat history: Retained for the lifetime of your account. Permanently deleted upon account deletion.
- Journal & workbook entries: Retained for the lifetime of your account. Permanently deleted upon account deletion.
- Payment records: Retained for 10 years after the transaction as required by Swiss and applicable tax and accounting regulations.
- Anonymised usage analytics: Retained indefinitely as they contain no personal data.
- Support tickets: Retained for 2 years after resolution, then permanently deleted.
- Email/push notification preferences: Deleted immediately upon account deletion or when you unsubscribe.
When you delete your account, we initiate a permanent deletion process. All your personal data, journal entries, readings, connected names, workbook progress, and preferences are permanently erased from our systems. This action is irreversible.
- Inside the app: Account → Edit profile → Danger zone → Delete my account.
- If you cannot sign in: use the public form at nameroots.app/delete-account.
- By email: contact hello@nameroots.app from your account email.
Deletion is immediate and irreversible. Stripe payment records are retained to comply with tax law (without app data).
10Data Security Measures
We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, alteration, disclosure, or destruction, in accordance with GDPR Article 32 and the revFADP:
- Encryption in transit: All data transmitted between your browser and our servers is encrypted using TLS 1.2 or higher.
- Encryption at rest: All personal data stored in our database is encrypted at rest using AES-256 encryption.
- Row-Level Security (RLS): Database-level security policies ensure that each user can only access their own data. No user can view, modify, or delete another user's records.
- Authentication security: Passwords are hashed using bcrypt. We support multi-factor authentication.
- Access controls: Internal access to user data is restricted on a need-to-know basis using role-based access controls.
- No credit card storage: We never receive, process, or store credit card numbers. All payment data is handled by Stripe (PCI-DSS Level 1).
- Regular security assessments: We conduct regular security reviews and vulnerability assessments of our systems.
- Secure development practices: Our codebase follows security best practices including input sanitisation, parameterised queries, and Content Security Policy headers.
11Your Rights Under GDPR (EU/EEA)
If you are located in the European Union or European Economic Area, you have the following rights under the General Data Protection Regulation (EU) 2016/679:
- Right of Access (Art. 15): obtain confirmation as to whether personal data concerning you is being processed, and access that data along with information about how it is used.
- Right to Rectification (Art. 16): have inaccurate personal data corrected and incomplete data completed.
- Right to Erasure / "Right to be Forgotten" (Art. 17): request deletion of your personal data when it is no longer necessary, when you withdraw consent, or when you object to processing.
- Right to Restriction of Processing (Art. 18): request that we restrict processing in certain circumstances.
- Right to Data Portability (Art. 20): receive your personal data in a structured, commonly used, machine-readable format, and transmit it to another controller.
- Right to Object (Art. 21): object to processing based on legitimate interests, including profiling. We will cease processing unless we demonstrate compelling legitimate grounds.
- Rights Related to Automated Decision-Making (Art. 22): not be subject to decisions based solely on automated processing that produce legal or similarly significant effects. Name Roots does not make such decisions.
- Right to Withdraw Consent (Art. 7(3)): where processing is based on consent, withdraw it at any time without affecting the lawfulness of prior processing.
- Right to Lodge a Complaint: lodge a complaint with a supervisory authority in the EU Member State of your habitual residence, place of work, or place of the alleged infringement.
To exercise any of these rights, contact us at hello@nameroots.app. We will respond within 30 days. We may ask you to verify your identity before processing your request.
12Your Rights Under Swiss Law (revFADP)
If you are located in Switzerland, your data is protected under the revised Federal Act on Data Protection (revFADP, in force since 1 September 2023) and the Data Protection Ordinance. You have rights equivalent to those described in Section 11, including the right to information, access, rectification, erasure, and to object to processing.
- You may lodge a complaint with the Federal Data Protection and Information Commissioner (FDPIC) at edoeb.admin.ch.
- As the data controller is established in Switzerland, Swiss law applies as the primary data protection framework alongside the GDPR where the Service is offered to EU/EEA residents.
13Your Rights Under UK GDPR
If you are located in the United Kingdom, your data is protected under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. You have all the same rights as described in Section 11 above.
In addition:
- You may lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk.
- International data transfers from the UK are governed by the UK International Data Transfer Agreement (IDTA) or UK Addendum to the EU SCCs.
14Your Rights Under US State Privacy Laws
California (CCPA / CPRA)
If you are a California resident, you have the following rights under the California Consumer Privacy Act (Cal. Civ. Code §§ 1798.100–1798.199.100) as amended by the California Privacy Rights Act:
- Right to Know: request details about the categories and specific pieces of personal information we have collected, the sources, the purposes, and the third parties with whom we share it.
- Right to Delete: request deletion of your personal information, subject to certain exceptions.
- Right to Correct: request correction of inaccurate personal information.
- Right to Opt-Out of Sale/Sharing: We do not sell or share your personal information as defined by the CCPA/CPRA. There is no need to opt out because we never engage in these practices.
- Right to Limit Use of Sensitive Personal Information: limit the use of sensitive personal information to purposes necessary for performing the Service.
- Right to Non-Discrimination: we will not discriminate against you for exercising any of these rights.
To submit a request, email hello@nameroots.app. We will respond within 45 days.
Virginia (VCDPA)
Virginia residents have rights to access, correct, delete, and port their personal data, and to opt out of targeted advertising, sale, and profiling. We do not engage in any of these practices.
Colorado (CPA)
Colorado residents have the right to access, correct, delete, and port personal data, and to opt out of targeted advertising and sale. An appeal process is available if your request is denied.
Connecticut (CTDPA)
Connecticut residents have similar rights to access, correct, delete, and port personal data. We do not sell personal data or use it for targeted advertising.
Other US States
We comply with all applicable US state privacy laws, including but not limited to those in Utah (UCPA), Iowa (ICDPA), Indiana (INCDPA), Tennessee (TIPA), Montana (MCDPA), Oregon (OCPA), Texas (TDPSA), and Delaware (DPDPA). If you are a resident of any state with a consumer privacy law, you may contact us to exercise your applicable rights.
15Your Rights Under Other Jurisdictions
Brazil (LGPD — Lei Geral de Proteção de Dados)
Brazilian residents have rights to confirmation of processing, access, correction, anonymisation, portability, deletion, information about shared data, and revocation of consent under Law No. 13.709/2018. You may contact us or the ANPD (Autoridade Nacional de Proteção de Dados) to exercise your rights.
Canada (PIPEDA)
Canadian residents have rights to access, correct, and challenge compliance under the Personal Information Protection and Electronic Documents Act. You may contact the Office of the Privacy Commissioner of Canada with complaints.
Australia (Privacy Act 1988)
Australian residents have rights to access and correct personal information under the Australian Privacy Principles (APPs). You may complain to the Office of the Australian Information Commissioner (OAIC) if unsatisfied.
Japan (APPI)
Japanese residents have rights to request disclosure, correction, and cessation of use of personal information under the Act on the Protection of Personal Information.
South Korea (PIPA)
Korean residents have rights to access, correct, suspend processing, and delete personal information under the Personal Information Protection Act.
Israel (Privacy Protection Law 5741-1981)
Israeli residents have rights to access, correct, and delete personal data. You may contact the Privacy Protection Authority with complaints.
16Cookies, Local Storage & Tracking Technologies
Name Roots takes a privacy-first approach to browser storage:
- No third-party cookies: We do not use any third-party cookies, tracking pixels, or advertising beacons.
- No cross-site tracking: We do not track your browsing activity across other websites.
- No analytics cookies: We do not use Google Analytics, Facebook Pixel, or any similar tracking services.
- Browser local storage: We use browser local storage (not cookies) solely to maintain your authentication session, language preferences, app settings, and cached UI state. This data never leaves your device.
- Session tokens: Authentication session tokens are stored in local storage and transmitted via secure HTTPS headers. They are automatically invalidated when you sign out.
Because we do not use cookies for tracking or advertising, a cookie consent banner is not required under ePrivacy Directive rules. However, we disclose our use of local storage here for full transparency.
17Children's Privacy
Name Roots is not intended for or directed at children. The Service is available only to users who are at least 16 years old, applied consistently across all jurisdictions worldwide. Where local law sets a higher minimum age, that higher age applies.
We do not knowingly collect personal information from anyone under 16. If we become aware that we have collected personal data from a child without verified parental consent, we will take steps to delete that information as quickly as possible. If you believe a child has provided us with personal data, please contact us at hello@nameroots.app.
18Data Breach Notification
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will:
- Notify the relevant supervisory authority within 72 hours of becoming aware of the breach, as required by GDPR Article 33, and notify the Swiss FDPIC as soon as possible as required by the revFADP.
- Notify affected individuals without undue delay when the breach is likely to result in a high risk to rights and freedoms, as required by GDPR Article 34.
- Notify California residents in compliance with Cal. Civ. Code § 1798.82 if their unencrypted personal information is reasonably believed to have been acquired by an unauthorised person.
- Document all breaches including facts, effects, and remedial actions taken, regardless of whether notification thresholds are met.
Notifications will be sent via email to the address associated with your account and/or via in-app notification.
19Automated Decision-Making & Profiling
Name Roots uses AI to generate personalised name readings, archetype assessments, and reflective content. We want to be transparent about the nature of this processing:
- No decisions with legal effects: Our AI-generated content does not produce any legal effects or similarly significant effects on you. It is provided solely for personal reflection and self-exploration.
- No profiling for marketing: We do not profile you for advertising, credit scoring, insurance, employment, or any other purpose beyond the Service itself.
- Human oversight: Our AI systems are regularly reviewed by our team. You may request human review of any AI-generated content by contacting us.
- Opt-out: You may choose not to use AI features and still benefit from manual journaling and workbook exercises.
20Push Notifications & Communications
We respect your communication preferences:
- Push notifications: Sent only if you have explicitly granted permission through your browser and enabled them in app settings. You can disable them at any time through your browser settings or within the app.
- Email reminders: Sent only if you have explicitly opted in. You can unsubscribe at any time through the app settings or by clicking the unsubscribe link in any email.
- Transactional emails: We may send essential transactional emails (e.g., password reset, subscription confirmation, data breach notification) without separate opt-in, as these are necessary for the performance of the Service.
- No marketing emails: We do not send promotional marketing emails or share your email address with marketers.
21Do Not Sell or Share My Personal Information
In compliance with the CCPA/CPRA and other applicable laws, we affirm:
We do not sell your personal information.
We do not share your personal information for cross-context behavioural advertising.
We have not sold or shared personal information in the preceding 12 months.
We do not have actual knowledge that we sell or share personal information of consumers under 16 years of age.
Because we do not engage in "sales" or "sharing" as defined by the CCPA/CPRA, there is no need to submit a "Do Not Sell" request. However, if you have any concerns, you may contact us at any time.
22Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technologies, legal requirements, or for other operational reasons.
- Material changes: For significant changes that affect your rights or how we process your data, we will notify you via email and/or a prominent in-app notification at least 30 days before the changes take effect.
- Minor changes: For non-material updates (e.g., formatting, clarifications), we will update the "Last updated" date at the top of this page.
- Continued use: Your continued use of the Service after the effective date of any updated Privacy Policy constitutes your acceptance of the changes.
- Previous versions: You may request previous versions of this Privacy Policy by contacting us.
23Contact Us & Data Protection Enquiries
If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:
Name Roots GmbH
Luzernerstrasse 4, 6010 Kriens, Switzerland
Email: hello@nameroots.app
WhatsApp: +41 76 411 7975
Instagram: @nameroots.app
We aim to respond to all privacy-related enquiries within:
- GDPR / revFADP requests: 30 days (extendable by 60 days for complex requests, with notification)
- CCPA/CPRA requests: 45 days (extendable by 45 days, with notification)
- General enquiries: 5 business days
This Privacy Policy is provided in English. In the event of any conflict between a translated version and the English version, the English version shall prevail.