budgr

Rooted Privacy Policy

Effective Date: June 9, 2026 Last Updated: August 28, 2026 App Name: Rooted: Budget & Money Coach Developer: Juan David Larraondo Contact: rooted@larraondolabs.com


Overview

Rooted is designed from the ground up to protect your privacy. We built this app for teens and young adults, and we take that responsibility seriously. The short version: we do not collect, store, or sell your personal information. Your financial data stays on your device.


1. Information We Do NOT Collect

Rooted does not collect, transmit, or store any of the following:

Rooted does not require you to create an account. No login. No sign-up. Nothing.


2. How the AI Features Work

Rooted includes optional AI-powered features: personalized advice based on your budget, and Ask Rooted, a chat where you can ask money questions. When you use these features, the relevant information is sent to the Anthropic API to generate a response.

What is sent: For advice, an anonymized budget summary (income range, expense categories, and budget status, no personal identifiers), such as “Monthly income: $1,200. Expenses: $950. Status: healthy budget. Credit card debt: none.” For Ask Rooted, only the question you type. In both cases: no names, no account numbers, and no device identifiers.

What Anthropic does with it: Per Anthropic’s API usage policy, data submitted via the API is not used to train their models and is subject to their data retention policies. You can review Anthropic’s privacy practices at anthropic.com/privacy.

If you prefer not to use these features: The app’s core budgeting tools work fully without the AI advice or chat. Simply close or ignore those cards.


3. Data Storage

The data you enter, income figures, expense amounts, and goal targets, is saved locally on your own device, using your device’s local storage. This lets your budget carry over between sessions so you can pick up where you left off. The app also keeps a small amount of progress data on your device, your weekly check-in streak, earned badges, completed lessons, which sections of the cryptocurrency learning module you have read, savings-challenge progress, and a monthly summary of income, expenses, and money kept, so you can see your progress over time. It also remembers simple app preferences on your device, such as whether you prefer dark mode, your chosen currency, and whether you have already seen the introductory “show me around” guide, so the app looks and behaves the way you left it.

The app also remembers whether you turned on optional crash reporting (see below). It is off unless you switch it on.

None of this information ever leaves your device. It is not transmitted to us or to any server, it is not stored in any cloud, and it is not shared with anyone. You stay in full control: tapping “Start over” (or “Start fresh” on the welcome-back banner) permanently clears your saved budget from your device at any time. Progress data (streaks, badges, lessons, cryptocurrency-module reading progress, challenges, and monthly summaries) and your app preferences (such as dark mode) are kept so your progress and settings are not lost when you rebuild a budget; deleting the app removes all of it permanently. If you use “Share my progress”, the image is generated on your device and is only shared if and where you choose. The app does not use cookies or behavioral tracking technologies.


3b. Optional Crash Reporting (off by default)

Rooted includes an optional setting called “Help improve Rooted.” It is switched off unless you turn it on, and the app behaves identically either way.

If you turn it on, then when the app hits an unexpected error it sends us a short technical report containing only: the error message, the name of the source file and line number where it happened, the app version, and whether you are on iOS, Android, or the web.

What it never contains: your income, expenses, budget figures, savings goals, or any other number you entered; anything you typed, including questions to Ask Rooted or feedback text; your name, email, or any identifier; your location, ZIP code, or city; and any device or advertising ID. Web addresses are reduced to a bare filename before sending, so nothing else can travel with them.

Reports are capped and de-duplicated so a repeating error cannot flood anything, are stored privately on Cloudflare, and are automatically deleted after 30 days. You can switch this off at any time and nothing further is sent.

4. Third-Party Services

Rooted uses the following third-party services:

Service Purpose Data Shared Privacy Policy
Anthropic API Generate AI advice and answer your questions Anonymized budget summary and the questions you type anthropic.com/privacy
FDIC BankFind (official U.S. government directory) The optional “Find a home for your money” tool, which lists banks near you in the U.S. Only the ZIP code you type into the finder, sent directly from your device to the FDIC’s public directory. It is never sent to us and never stored fdic.gov/privacy
Open-Meteo geocoder and OpenStreetMap (Overpass) The same finder outside the U.S., which lists banks near a city Only the city name you type, sent directly from your device to these public directories. It is never sent to us and never stored open-meteo.com · osmfoundation.org
Our feedback service (hosted on Cloudflare) The optional “Share feedback” form inside the app Only if you choose to send feedback: your star rating, the category you pick, the comment you type, the app version, and the platform (iOS/Android). No budget data, no name, no email address, and no identifiers are included. It is stored privately and used only to improve the app cloudflare.com/privacypolicy

For credit unions, the ZIP code you type passes through our locator service (hosted on Cloudflare) to the NCUA’s public directory, and the results come straight back to you. It is never stored or logged, and nothing else is sent with it.

We do not use advertising networks, analytics platforms (Google Analytics, Firebase, etc.), or social media tracking pixels.


5. Children’s Privacy (Users Under 13)

Rooted does not knowingly collect any personal information from children under the age of 13. The app is designed for users ages 13 and older. Because we collect no personal information from any user, we believe the app is compliant with the Children’s Online Privacy Protection Act (COPPA). If you are a parent and have concerns, please contact us at rooted@larraondolabs.com.


6. Users in California (CCPA)

Under the California Consumer Privacy Act (CCPA), California residents have the right to know what personal information is collected about them. Rooted collects no personal information. There is nothing to request, delete, or opt out of. If you have questions, contact us at rooted@larraondolabs.com.


7. Users in the European Union (GDPR)

Rooted does not collect personal data as defined under the General Data Protection Regulation (GDPR). The anonymized budget summary and questions sent to the Anthropic API do not constitute personal data under GDPR as they contain no identifiers. If you have questions or concerns, contact us at rooted@larraondolabs.com.


8. Security

Because Rooted does not store your financial data on our servers, or any servers, there is no database to breach. The only data transmission is the anonymized budget summary and the questions you choose to ask, sent to the Anthropic API over an encrypted HTTPS connection.


9. Changes to This Policy

If we update this privacy policy, we will update the “Last Updated” date at the top of this document and post the new version to https://juandavidlarraondo.github.io/budgr/privacy. Continued use of the app after changes constitutes acceptance of the updated policy.


10. Contact Us

If you have questions about this privacy policy or how Rooted handles data, please contact:

Juan David Larraondo Email: rooted@larraondolabs.com Website: juandavidlarraondo.github.io/budgr


Rooted is committed to financial empowerment through education, not data collection.