Privacy Policy
Last updated: January 2026
1. What this policy covers
This policy explains how Roottine collects, uses, and protects information — both for practice owners and team members who use the Roottine dashboard, and for patients who interact with a practice's rewards program (spin-to-win, points, referrals, newsletters, and the AI assistant).
2. Information we collect
From practice accounts: name, email, phone, practice details, and billing information. From patients: name, email, phone, date of birth, visit history, and points/rewards activity, submitted either by the practice or directly by the patient through the rewards program. We also collect standard usage data (device, browser, pages visited) to keep the Service reliable and secure. We do not collect diagnoses, treatment notes, clinical images, or procedure codes — see our Security page for what patient data is deliberately excluded.
3. How we use information
We use this information to operate the Service: running the points and rewards program, sending recall/nurture/milestone/newsletter messages on a practice's behalf, powering the AI practice assistant from documents a practice uploads, generating analytics for the practice, providing customer support, and processing subscription payments. We don't sell patient or practice data to third parties, and we don't use patient data to train AI models beyond what's needed to answer that specific practice's patients.
4. Cookies and similar technologies
We use essential cookies to keep you signed in and remember your session — these are required for the Service to function and can't be turned off. We don't currently use third-party advertising or analytics cookies. See our Cookie Policy for the full breakdown.
5. Sharing
We share data with service providers who help us run Roottine — for example, our database host, email delivery provider, AI model providers, and payment processor — under agreements that limit their use of the data to providing that service. Patient data collected for a specific practice is only visible to that practice, not to other practices on the platform. We may disclose information if required by law, subpoena, or to protect the rights, safety, or property of Roottine, our users, or others.
6. HIPAA and protected health information
For practices that use Roottine to process protected health information subject to HIPAA, we act as a business associate and offer a signed Business Associate Agreement on request. Where a BAA is in place, its terms govern the handling of that protected health information and control in the event of a conflict with this policy. Practices remain the covered entity responsible for determining what data is appropriate to store in the Service and for obtaining patient authorization where required.
7. Data retention
We retain practice and patient data for as long as the practice account is active, plus a reasonable period afterward to comply with legal, tax, and support obligations. A practice can request deletion of their data through Help & support; we'll complete deletion requests within a reasonable timeframe, subject to any legal retention requirements.
8. Patient choice
Patients can opt out of email or SMS communications at any time using the unsubscribe link included in every message, or by updating notification preferences in the patient app, or by asking their practice to update their preferences on their behalf.
9. Security
We use industry-standard safeguards — encrypted connections, encryption at rest, access controls, and row-level data isolation between practices — to protect data stored in Roottine. No system is perfectly secure, and we encourage practices to use strong, unique passwords and enable available account protections. See our Security page for the complete breakdown.
10. Your rights
Depending on where you're located, you may have rights to access, correct, delete, or export your personal information. Practice owners can reach us through Help & support; patients should contact their practice directly, since the practice controls its own patient records and is the appropriate party to fulfill most patient-data requests.
11. Children's privacy
Roottine's patient rewards program is intended for use by or on behalf of patients of the practice, not for independent use by children. We don't knowingly collect information directly from children under 13 outside of what a practice enters on a patient's behalf as part of normal patient record-keeping.
12. International users
Roottine is operated from and primarily serves practices and patients in the United States. If you access the Service from outside the United States, your information will be transferred to and processed in the United States, which may have different data protection laws than your jurisdiction.
13. Changes to this policy
If we make material changes to this policy, we'll notify practice owners by email or through the dashboard before the changes take effect.
14. Contact
Questions about this policy can be sent to support@roottine.app or through the Help & support page in your dashboard.
Also see Terms of Service, Cookie Policy, Security & Compliance.