Privacy
What stays local, and what does not
This page covers the Root website, the Chrome extension, the iPhone and Android apps, Root Connect, and Root for Codex. Private by default means Root does not host your workspace or automatically send your notes to a Root server. You choose when to connect an outside service or move information out of your local workspace.
Where Root stores your workspace
In Chrome, Root stores workspace content locally in the browser. That includes items, tags, snippets, pinned state, and local version history.
On iPhone, Root keeps its library in the app's local storage unless you choose a Root folder in Files, iCloud Drive, or another file provider. Files stored through a provider are also handled under that provider's terms and privacy practices.
On Android, Root keeps its library in the app's local storage. Android system Auto Backup is disabled for the current app. Import and export happen only when you choose a folder through Android's system file picker.
Clearing browser data, deleting a Chrome profile, deleting a mobile app or its data, or removing a selected Files folder can delete local Root content. Keep a separate copy of anything you cannot afford to lose.
Chrome backup and portability
In Chrome, use Last backup in the top bar, then choose Export library to save a full copy outside the browser. A good low-friction habit is to export once a week, after important work, and before a browser cleanup, profile change, or big reorganization.
If you are restoring a full exported Root library, keep rootpad.json with the exported note files. The note files hold the content, and rootpad.json helps Root recognize the full export cleanly.
In Chrome, Delete moves items into Trash first. Trashed items can be restored or deleted forever, and the current public Chrome package keeps them for 30 days before cleanup.
Page and selection capture
Choosing Attach page lets Root read the active page title and URL locally. Using Root's right-click research action also lets it receive the text you selected with that page source. Root adds this information to Research Draft only after the corresponding action and does not send it to a Root server.
If Root Connect is enabled, a title or URL that you save into the workspace can later sync through your Google Drive with the rest of that saved content.
If you want the exact permission-level explanation, read Security & Permissions.
Photo Text
On iPhone, Photo Text uses Apple's on-device Vision framework to extract editable text from a selected or captured image. Root saves the recognized text, not the source image.
On Android, Photo Text uses bundled text recognition to extract editable text from an image you choose through Android's system picker or capture through the system camera app. Recognition runs on the device. Root saves the recognized text, not the source image, removes its temporary camera file after review, and does not request broad access to your photo library or direct camera permission.
Android Photo Text includes Google's ML Kit text-recognition SDK. When this component is used, Google may collect device and app information, a per-install identifier, performance metrics, and API-utilization metrics for diagnostics and analytics. Google states that this operational data is encrypted in transit. The selected image, recognized text, and resulting note are not sent to Google by ML Kit. See Google's ML Kit data-disclosure guide.
Voice Note and Meeting Transcripts
On iPhone, Voice Note and Meeting Transcripts use Apple's Speech framework. Root does not promise that every speech-recognition step is fully offline. Processing can vary by device, language, and system conditions, and speech data may be processed by Apple under Apple's privacy practices.
On Android, Root asks for microphone permission when you start Voice Note or Meeting. During an active capture, Root records microphone audio and passes it only to Android's on-device speech-recognition service. If Android has no on-device recognizer or offline language available, Root shows that the feature is unavailable rather than falling back to a network speech provider.
Meeting uses Android's microphone foreground-service mechanism so a user-started capture can continue while Root is hidden. On supported Android versions, Root also asks for notification permission so it can show the ongoing Meeting recording state.
Root saves the resulting text in your workspace. It does not keep a lasting audio recording or send the recording to a Root server.
Root for Android
The current Android test build does not require a Root account, include ads, operate first-party product analytics, expose Root Connect, or connect to Google Drive. The limited ML Kit operational metrics described above are third-party SDK diagnostics and analytics. Notes and workspace data stay in the app's local storage unless you deliberately move text or files out.
You can send selected text into Root through Android's share and process-text actions. You can copy or share a Context Handoff packet, and you can import or export a portable Root library through Android's system file picker. These transfers happen only after you choose the corresponding Android action.
Fresh workspace, item deletion, Android's clear-storage control, and uninstalling the app provide local deletion paths. Root for Android does not create an online account, so there is no remote Root account or server-side workspace to delete.
Root Connect and Google Drive
Root Connect is optional. When you connect it, the Root installations you authorize read and write Root workspace files in your Google Drive so you can sync devices with your Google Drive.
Root requests Google's limited drive.file permission. This allows Root to work with files it creates or that you open for Root, rather than giving Root general access to every file in your Google Drive.
Root does not copy that workspace into a Root-hosted account or note server. Google processes and stores the connected files under your Google account and its terms. Root Connect is for workspace continuity, not a complete backup or Google account recovery system.
Disconnecting Root Connect stops that installation from syncing, but it does not delete Root files already stored in Google Drive. To protect against accidental data loss, permanently deleting a note in Root can leave an ignored file in Drive that is no longer part of the active workspace. If you also want those stored copies removed, delete them from Google Drive.
Google Sign-In is used only when you choose Root Connect. Its embedded iOS privacy manifest declares Name, Email Address, Phone Number, Coarse Location, User ID, Device ID, Other Usage Data, and Other Data Types for app functionality and SDK analytics, with tracking set to false. Root's App Store privacy disclosure includes those third-party declarations and User Content stored through Root Connect even though Root does not operate its own product-analytics service.
Root Connect purchases
Apple processes Root Connect purchases and payment information through the App Store. Root checks verified transaction and entitlement information so it can unlock or restore Root Connect. Root does not receive your payment-card details.
Local Root Connect diagnostics
Root Connect keeps a rolling seven-day diagnostic log on the device to help explain sync problems. It can include timestamps, status and error information, counts, and limited identifiers, but it is designed not to include note bodies, Google access tokens, email addresses, or device names.
The diagnostic log leaves the device only if you choose to copy it and share it, for example in a support message.
Root for Codex
Root for Codex works with local Markdown called Codex Drafts outside your live Root Workspace. It does not require Root Connect, Google Drive, a Root account, or a Root-hosted server. Root Chrome imports files only after you choose the local folder and select Import Codex Drafts; it does not watch the folder in the background. Existing folders named Codex notes remain supported.
When you ask Codex to read, write, summarize, or otherwise use a local note, the content included in that Codex request may be processed by Codex and OpenAI under the account, workspace, and privacy settings you use there. That processing is initiated through Codex, not by a background transfer from Root.
Browser tools and extensions
Other browser tools and extensions are separate from Root. Depending on their permissions and the browser settings you turn on, they may be able to read tab titles, URLs, or the content of the current Root page.
If a Root tab is visible and you give another extension, browser assistant, or shared-tab feature access to that page, that tool may be able to use the notes shown there. That is browser behavior, not a background transfer initiated by Root.
Workspace size
Root works best as an active work surface, not a giant permanent archive. Very large libraries, lots of long notes, or mass text storage can make the browser do more work than Root is meant to carry. If something no longer feels active, export it or move it out.
Context Handoff and export
Context Handoff, export, and import are user-triggered. Root prepares a preview or file set, and you decide what to copy, paste, export, or import. Root does not automatically send a Context Handoff packet to an assistant or model.
If you enable Root Connect, saved workspace content can sync through Google Drive as described above. If you ask Root for Codex to work with local files, the content included in that request can be processed by Codex and OpenAI.
The Root website and support
The Root website does not currently use first-party product analytics, advertising trackers, or tracking cookies. Cloudflare hosts and protects the site and may process ordinary request and security information, such as your IP address, browser or device information, the page requested, and security signals, under Cloudflare's privacy policy.
If you email Root, Root receives the email address, message, and any attachments or diagnostic information you choose to include. That information is used to respond, troubleshoot, and keep the necessary support record. Do not send passwords, recovery codes, payment-card details, or Google access tokens.
Accounts, analytics, and remote storage
Root Workspace does not require a Root account to use the local workspace, does not operate a first-party product-analytics service, and does not store workspace content on a Root server.
Root Connect uses Google Drive only after you grant access. Root for Codex uses local files only after you ask Codex to work with them. Apple handles App Store purchases and may process speech recognition as described above. If you save an export to another cloud folder, that is a storage or backup choice you made outside Root.
Third-party services can still process the limited data described above when you deliberately use them. If Root adds its own analytics, Root accounts, or Root-hosted storage later, this page will be updated before those features launch so it explains what changes, what data moves, and what remains local.
Privacy questions
For privacy questions, contact support@rootworkspace.com.