Legal

Privacy Policy

Last updated 23 August 2026

Rootlume is made by Vorby Studios. This page says what the app and the website collect, why, who else can see it, and how to get rid of it. It is written to be read rather than to be survived.

The short version: Rootlume stores the account you create, the people you are connected to, and the messages you send. There are no analytics, no advertising, no trackers and no third-party scripts on this site beyond a web-font request. Nothing here is sold.

What Rootlume stores

Your account

  • Email address, and a password hash if you signed up with a password. Rootlume never stores the password itself — that is handled by Supabase Auth, which stores a hash.
  • If you signed in with Google: the email address, name and profile picture Google returns. Rootlume asks Google for nothing else.
  • A display name, username and avatar image, if you set them.
  • Your language and time zone, so dates and copy come out right.
  • When your account was created, and when you were last seen — the last one is what makes a node glow green for the people connected to you.

Your network

  • Seed codes you create, and which account redeemed each one.
  • Connections between you and other people, when each was made, how many messages have passed along it and when the last one was — that count is what thickens the branch.
  • Pulses: a short record that a message was sent or someone joined, so the animation can play for people watching. A pulse records who and when, never what.

Your messages

Messages are stored as ordinary text and are not end-to-end encrypted. They are encrypted in transit and at rest by the database host, but Vorby Studios can technically read them, and would have to hand them over under a valid legal order. If that is not acceptable for something you were about to write, use something else for that message. Rootlume is a visualization of a friendship graph first; it is not a secure messenger and does not claim to be.

Feedback you send

The feedback form stores what you wrote, the kind of feedback it was, your account ID if you were signed in, and an email address if you chose to give one. It is stored in Rootlume's own database and read by Vorby Studios; it is not sent anywhere else.

What is not collected

  • No analytics and no tracking pixels. There is no Google Analytics, no Meta pixel, no Segment, no session recording. This page and every other page on rootlume.com load no third-party JavaScript at all.
  • No advertising identifiers, and no advertising.
  • No contact-list upload. Rootlume grows only by seed codes, which is why there is no "find your friends" step anywhere.
  • No location beyond the time zone your browser reports.

Cookies

Rootlume sets five cookies. None of them are for advertising or analytics, which is why there is no consent banner to click through:

  • access_token and refresh_token keep you signed in. Both are httpOnly and Secure, so page scripts cannot read them. They last seven days.
  • session holds your language preference across requests.
  • user_language remembers the language you picked.
  • user_timezone is set by your browser so timestamps render in your local time.

Who else can see your data

Rootlume runs on other companies' infrastructure. These are the only ones that touch your data, and each is used for one job:

  • Supabase — the database and the authentication system. Your account, network and messages live here, in a region in the United States (AWS us-west-2).
  • Google Cloud Run — runs the Rootlume server itself, in us-west1. It processes requests; it does not keep your data.
  • Google Sign-In — only if you choose it. Google will know you signed in to Rootlume.
  • Cloudflare — DNS for rootlume.com.
  • No email provider. Rootlume currently sends no email at all — not to you, and not about you. That is also why there is no password reset and no address verification yet. If that changes, this list changes with it.
  • Google Fonts — this website loads its typefaces from fonts.googleapis.com, which means Google sees the IP address of anyone loading a page. Nothing else on the site is third-party. We would rather serve the fonts ourselves and intend to.

Your data is not sold, rented, or shared with anyone else, and it is not used to train any model.

What other people on Rootlume can see

This matters more day to day than the paragraph above:

  • People directly connected to you see your name, avatar, whether you are online, how strong your bond with them is, and the messages you have exchanged with them.
  • People one step further out — the friends of your friends — can see that you exist as a node in their extended generation, with your name and avatar. They cannot see your messages or your email address.
  • Nobody on Rootlume is shown your email address.
  • Redeeming somebody's seed code tells them you redeemed it. That is the entire point of a seed.

How long it is kept

Your account and its data are kept until you delete the account. Deleting your account removes your user record, and the database removes with it your connections, your seed codes, your pulses and the messages you sent. Feedback you submitted is kept but detached from your account.

A message you sent to someone else is stored once, so deleting your account removes it from their conversation too.

Deleting your account

There is not yet a delete button in the app or on the website. Until there is, email support@vorby.com from the address on the account and it will be deleted, along with its data. Saying so plainly is better than implying a button that does not exist.

Your rights

Depending on where you live — in particular in the UK, the EU/EEA and California — you have the right to ask for a copy of your data, to correct it, to have it deleted, and to object to how it is handled. Rootlume honours these requests regardless of where you live. Write to support@vorby.com and expect an answer within 30 days.

Where the law requires a legal basis: Rootlume processes your data to perform the contract you entered into by making an account, and on the basis of legitimate interest in keeping the service working and secure. There is no processing for advertising, so there is nothing here to opt out of.

Children

Rootlume is not intended for anyone under 13, and accounts are not knowingly created for them. If you believe a child has an account, tell us and it will be removed.

Security, honestly

Traffic uses HTTPS. Session cookies are httpOnly and Secure. Passwords are hashed by Supabase Auth and never seen by Rootlume's own code. Two things worth stating plainly rather than burying:

  • Messages are not end-to-end encrypted, as above.
  • There is no email verification and no password reset yet, because no outbound mail sender is configured for user email. That means an address on an account has not been proven to belong to the person holding it.

Changes

If this policy changes in a way that affects what is collected or who sees it, the date at the top changes and the change is described here. Rootlume is small and new; this page is expected to grow more specific, not more vague.

Contact

Vorby Studios — support@vorby.com. Data requests, deletion requests and questions about this page all go there. There is also a feedback form on the sign-in page that needs no account.

Questions about this page, or a request about your own data? support@vorby.com. There is also a feedback form on the sign-in page that needs no account.