Last updated and effective: September 28, 2026
Rootle is a calorie and nutrition tracking app made by The Burrow Co ("we", "us"). This page explains what data the app collects, why, who else touches it, and how to get it back or delete it.
This policy is written under California law. It is our notice at collection and privacy policy under the California Consumer Privacy Act, as amended by the California Privacy Rights Act (together, the "CCPA"), and it also covers the California Online Privacy Protection Act ("CalOPPA") and California's "Shine the Light" law. The California-specific details are in Your California privacy rights below.
| Data | Why |
|---|---|
| Email address, and your name if your sign-in provider supplies it | Account sign-in — email/password, Google Sign-In, or Sign in with Apple. If you use Apple's "Hide My Email", we only ever see the relay address. |
| Food entries you log (description, calories, macros, meal type, timestamp) | Core app functionality — your food diary |
| Weight and body measurement entries | Progress tracking; optionally synced with Apple Health / Health Connect if you enable it |
| Profile details you enter (age or birthday, height, sex, activity level, goal) | Calculating your calorie and macro targets |
| Food photos you submit for AI estimation | Sent to our server, which calls Google's Gemini model on Vertex AI to estimate nutrition. Photos are used only for that single estimate and are not stored — not by us, and not in your entry. They are discarded as soon as the response returns. |
| Food descriptions you type or dictate | Same estimation path as photos. Short, generic descriptions may also be cached — see How AI estimation works. |
| Barcodes you scan | The barcode number is looked up against open food databases (Open Food Facts, USDA FoodData Central) to fill in nutrition info. The lookup carries the barcode only — never your identity. |
| A digest of your recent food log, if you open Insights | Your last three weeks of entries are summarised on our server and sent to Gemini to generate eating-pattern observations. See Insights. |
| Daily AI usage counters | Enforcing the daily AI allowances server-side |
| Monthly AI usage and subscription payment totals (number of AI requests, their estimated cost to us, and what your subscription paid after store fees and tax) | Enforcing the monthly AI allowance, and checking that the service covers its costs. Kept with your account and deleted with it. |
| Subscription status, store, and product ID | Managed by RevenueCat on our behalf if you purchase Rootle Premium through the App Store or Play Store, and mirrored into your profile so the app knows what you're entitled to |
| App usage events (onboarding completed, an entry logged, the paywall shown, a subscription started or restored), a device identifier, and an approximate location | Firebase Analytics, so we can see where people get stuck. We log which flow produced an event, never what you logged — no food names, descriptions, or photos. The approximate location, at about city level, is worked out by Google Analytics from your IP address; Rootle never asks for your device's location. |
| Crash reports (stack trace, device model, OS version) | Firebase Crashlytics, to diagnose crashes |
| A device attestation token | Firebase App Check, to stop people calling our AI endpoints from outside a genuine build of the app |
We do not sell or share your personal information as the CCPA defines "sell" and "share", and we have not done so in the past 12 months. We do not use it for advertising, and we do not track you across other companies' apps or websites.
The app never talks to an AI model directly. Photos and descriptions go to a Cloud Function we control, which calls Google's Gemini model through Vertex AI on our Google Cloud project. Under Google Cloud's terms, Vertex AI does not use the content we send it to train Google's models, and Google does not receive your account identity — only the food photo or text.
Photos are not stored anywhere. They are held in memory for the length of the request and discarded. Rootle has no photo storage, and your entries keep no image.
Short, generic text descriptions may be cached. If you type something like "two scrambled eggs", we may save that phrase and its nutrition result in a shared lookup cache so the next person asking the same thing gets an instant answer without another AI call. The cache stores the phrase and the result only — it is not linked to your account or to any identifier. We skip the cache entirely for anything longer than 60 characters or containing personal or relative wording ("my usual", "mum's", "leftover", "homemade", and similar), so personal phrasing never lands in it.
If you open the Insights feature, our server reads your own recent entries (up to the last 21 days), builds a compact text digest of them alongside your calorie and macro goals, and sends that digest to Gemini to produce two or three observations about your eating patterns. The result is cached in your account for the rest of your local day, so this happens at most once per day. The digest contains food descriptions, calories, meal types, and times — it does not contain your email, name, or user ID. If you don't open Insights, nothing is sent.
If you turn on Health sync in Settings, Rootle reads from and writes to Apple Health or Health Connect. Depending on what you grant, that covers weight, waist circumference, body fat percentage, active energy burned, steps, and nutrition (the calories and macros you log, written back out). Health sync is off by default, runs only while the toggle is on, and you can revoke the permission at any time in iOS Settings or Health Connect.
Health data stays between your device, your Rootle account, and the platform health store. It is never sent to our AI estimation service, never used for analytics, and never shared for advertising — which is also a condition of Apple's and Google's health platforms.
You can dictate a food description instead of typing it. When you do, the microphone is active only while you hold the dictation session open, and the audio is handled by your device's own speech recogniser — Apple's on iOS, Google's on Android — under that platform's privacy policy. Rootle receives only the transcribed text, and we never record, upload, or store audio. If you never use dictation, the microphone is never opened.
The camera is used to photograph food and to scan barcodes; the photo library is used only when you pick an existing picture. Both are opened only when you ask for them, and what comes back follows the rules above — a food photo is estimated and discarded, a barcode becomes a database lookup.
If you enable the weekly review, Rootle schedules that notification locally on your device. It is generated on the device from your own data — no notification content is sent through our servers or any third party.
App data is stored in Google Firebase (Firestore and Firebase Auth) under our project, and AI requests are processed by our Cloud Functions — all hosted in the United States. If you use Rootle from outside the US, your data is transferred to and processed in the US.
Your entries, weights, and profile are kept for as long as your account exists, because they are the app — your history is the point. Daily usage counters are short-lived. Analytics and crash data are retained on Firebase's own schedule (currently up to 14 months for analytics events and 90 days for crash reports). Delete your account and the account data goes immediately, as below. The retention period for each CCPA category is listed under Your California privacy rights.
What account deletion does not cover. Deleting your account does not cancel an active App Store or Play Store subscription — cancel that separately in your device's subscription settings. It also does not retroactively erase aggregate analytics and crash records, which are not tied to your identity once your account is gone, or the anonymous shared food cache described above, which contains no personal data. RevenueCat keeps its own billing record of the purchase, as payment processors are generally required to.
This section gives California residents the disclosures the CCPA requires. It covers the 12 months before the date above, and it describes what we will keep doing going forward.
Using the categories defined in Cal. Civ. Code § 1798.140, here is what Rootle collects, where it comes from, why, who receives it, and how long we keep it. Everyone listed as a recipient is a service provider or contractor acting on our behalf under a contract that bars them from using the data for their own purposes. None of it is sold or shared.
We do not collect precise geolocation, biometric information, professional or employment information, or education information.
Sensitive personal information. We use and disclose sensitive personal information only to provide the service you asked for, keep it secure, and for the other purposes permitted by Cal. Code Regs. tit. 11, § 7027(m). We do not use it to infer characteristics about you. Because of that, the CCPA's right to limit the use of sensitive personal information does not apply, and we don't offer a "Limit the Use of My Sensitive Personal Information" link.
No sale or sharing. We do not sell or share personal information, including that of consumers under 16, so there is nothing to opt out of and no "Do Not Sell or Share" link is needed. We still treat a Global Privacy Control signal as a valid opt-out request.
The fastest route is in the app: Settings → Export my data answers a request to know, Settings → Account → Delete account answers a request to delete, and any entry or profile field can be edited to correct it. You can also email support@theburrow.co. Rootle is operated only online and we deal with you directly, so email is our designated method for requests.
We will confirm receipt within 10 business days and respond within 45 calendar days. If we need longer, we will tell you why, and we can extend by up to 45 more days. Requests are free. We verify requests by matching them to the email address on the account, and may ask you to confirm from that address; we won't ask for more than we need. You can use an authorized agent: we will ask for your signed permission and may ask you to verify your identity with us directly. You may make a request to know up to twice in any 12-month period.
We don't offer financial incentives or price differences in exchange for personal information. Every subscriber gets the same features for the same price.
Under Cal. Civ. Code § 1798.83, California residents can ask whether we disclosed personal information to third parties for their own direct marketing in the previous calendar year. We don't do that. You can still ask us to confirm by emailing the address below.
As CalOPPA requires us to say: Rootle doesn't track you across other companies' apps or websites, so there is no cross-site tracking for a Do Not Track signal to switch off, and we don't change our behavior in response to one. We don't allow third parties to collect personally identifiable information about your activity across other apps or websites through Rootle. Firebase Analytics measures use of Rootle itself and is not linked to advertising.
Traffic is encrypted in transit. Your account data is protected by Firestore security rules that scope every document to your own user ID, so one account cannot read another's. Our AI endpoints require both a signed-in account and a valid App Check attestation. No system is perfect, but we keep the surface small — notably by not storing photos at all.
Rootle is for adults. It is not directed at anyone under 18, and we do not knowingly collect data from anyone under 18: sign-up turns away anyone whose birthday shows they are under 18, and deletes the sign-in they just created. If you believe someone under 18 has an account, email us and we will delete it. See also the age requirement in our Terms of Use.
We review this policy at least once every 12 months, as the CCPA requires. If it changes materially, we'll update the date above and notify you in the app before the change takes effect.
Questions or data requests: support@theburrow.co