Privacy Policy

Last updated: 23 August 2026

RoutineRoot ("we", "us", "our") is committed to protecting the privacy of you and your family. This Privacy Policy explains how we collect, use, store, and protect your personal data when you use our app and services. We comply with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

1. Who We Are

RoutineRoot is a family routine management app operated from the United Kingdom. We are the data controller for the personal information you provide to us through the app.

2. Data We Collect

2.1 Account Data

  • Name, email address, and password (encrypted)
  • Family name and parenting preferences
  • Subscription and billing information (processed via Stripe)
  • Preferred display language, as selected in Settings or on the language page
  • Device mode preference (shared or separate) and your parent push notification setting

2.2 Family & Child Data

  • Child profile information including name, age, and motivation mode
  • Routine and task data created within the app
  • Task completion records, including optional photo evidence
  • Points balances, streaks, and reward redemption history
  • Child profile customisation choices (avatar emoji and wallpaper selection)
  • Custom reward requests submitted by a child for parent approval

2.3 Usage Data

  • Device type, app interactions, and feature usage patterns
  • Crash reports and diagnostic data for improving the service

3. How We Use Your Data

  • To provide and maintain the RoutineRoot service
  • To create and manage child profiles, routines, and reward systems
  • To process subscription payments and manage your account
  • To send important account notifications and service updates
  • To improve our features and develop new functionality
  • To detect, prevent, and address technical issues or abuse

4. Legal Basis for Processing

We process your personal data under the following lawful bases:

  • Contract: To deliver the service you signed up for
  • Consent: For optional features like photo evidence and marketing communications
  • Legal obligation: To comply with UK law and tax requirements
  • Legitimate interests: To improve our service and ensure security

5. Data Sharing

We do not sell your personal data. We share data only with trusted third-party processors who help us operate the service:

  • Stripe โ€” payment processing (card details never touch our servers)
  • Cloud hosting providers โ€” secure data storage and infrastructure
  • Analytics providers โ€” aggregated, anonymised usage data only

We may disclose data if required by law or to protect our rights, property, or safety.

6. Children's Data โ€” Special Protections

RoutineRoot is designed for families, and children's data receives enhanced protection:

  • Children do not create their own accounts โ€” parents set up and manage child profiles
  • Parent PIN protection restricts access to sensitive controls
  • Photo evidence is automatically deleted after 30 days
  • Children cannot communicate with anyone outside their family through the app
  • No advertising is shown to children
  • Native push notifications are off by default, so alert banners do not appear over a child's screen on a shared device; parents can enable push on their own separate device from Settings

7. Data Retention

We retain your data for as long as your account is active. Task completion photo evidence is automatically deleted after 30 days. You may request data export or account deletion at any time from the Settings page, and we will process your request within 30 days.

8. Your Rights Under UK GDPR

  • Access: Request a copy of your personal data
  • Rectification: Correct inaccurate or incomplete data
  • Erasure: Request deletion of your data
  • Restriction: Limit how we process your data
  • Data portability: Receive your data in a machine-readable format
  • Objection: Object to certain types of processing
  • Withdraw consent: At any time, without affecting prior processing

To exercise these rights, use the in-app data export and deletion tools, or contact us through the Help Centre. You also have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk.

9. Data Security

We use industry-standard security measures including encryption, secure authentication, role-based access controls, and regular security reviews. Despite these measures, no system can be guaranteed 100% secure. We will notify you of any data breach affecting your rights within 72 hours, as required by law.

9.1 Encryption & Data Security (App Encryption Documentation)

Protecting your family's data is central to RoutineRoot. The following describes the encryption and security controls we apply across the app, in transit, and at rest.

  • Encryption in transit (TLS 1.2+): All data sent between the RoutineRoot app and our servers is encrypted using industry-standard Transport Layer Security (TLS 1.2 or higher). This includes logins, routine and task data, photo evidence, and payment requests.
  • Encryption at rest: Your data is stored on cloud infrastructure that encrypts stored databases and backups at rest using strong, industry-standard ciphers (such as AES-256). File-based data (e.g. photo evidence) is stored in encrypted object storage.
  • Authentication & passwords: Passwords are never stored in plain text. They are hashed using strong, salted one-way hashing algorithms before storage, and authentication tokens are signed and short-lived. Session tokens are transmitted only over encrypted connections.
  • Role-based access control (RBAC): Access to data is governed by strict role-based permissions. Parents, co-parents, children, and admins each have scoped access, enforced both in the app and at the database level via row-level security. A child can only access their own profile and data; parents can only access their own family's data.
  • Parent PIN protection: Sensitive parent controls are protected by a separately-hashed PIN with lock-out after repeated failed attempts, so a child using a shared device cannot reach billing or account settings.
  • Payment data: We never receive or store your full card details. All card information is handled directly by Stripe, our PCI-DSS-compliant payment processor, within its own secure environment. We only retain tokenised references and non-sensitive billing summaries.
  • Photo evidence: Optional task completion photos are uploaded over an encrypted connection, stored in encrypted object storage, accessible only to the child's own family, and automatically deleted after 30 days.
  • Secrets management: API keys, signing secrets, and other sensitive credentials are stored in a secure secrets vault and are never exposed to the app's front-end or included in client bundles.
  • Least-privilege backend access: Administrative and automated actions run through a limited service role, and sensitive operations (such as role changes, PIN resets, and subscription updates) are restricted to authorised server-side functions.
  • Monitoring & breach response: We monitor for security events and, in the unlikely event of a data breach affecting your rights, will notify you without undue delay and in any case within 72 hours, as required by UK GDPR.

No system can ever be guaranteed 100% secure, but we apply these layered controls to keep your family's data confidential, intact, and available only to those who should see it. If you have a specific security question, contact us through our Contact Us page.

10. International Data Transfers

Your data is primarily stored within the UK and EU. Where any data is processed outside these regions, we ensure appropriate safeguards such as Standard Contractual Clauses are in place.

11. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of significant changes via email or in-app notification. Continued use of the service after changes constitutes acceptance of the updated policy.

12. Contact Us

If you have any questions about this Privacy Policy or your data, please contact us through our Contact Us page or Help Centre.