root@exposed:~#

root@exposed / privacy

The placeholder file

They collected the calls, then collected the wording.

In February 2026, Discord refugees opened Root’s privacy policy and found a sentence about voice, video, and screenshare. Root went into damage control. Four months later the founder called the whole thing a rumor about a placeholder. The Wayback Machine is not a rumor.

A printed privacy policy with a highlighted sentence about collecting voice, video, and screensharing calls, a sticky note that says PLACEHOLDER, and a REWRITTEN stamp.
Editorial illustration. The live text, captured 8 February 2026, is linked below.

Timeline

From generator template to call collection to “we never did that.”

  • 2 March 2023. First archived policy is a generic website template: MailChimp, Shine the Light, CCPA financial incentives, contact Jesse at [email protected]. It reads like a Webflow legal pack, because that is what the rest of the site was.
  • 7 August 2025. A new policy takes effect. This is the one people screenshotted.
  • 18 December 2025. Root opens to everyone, no invite code, and posts in r/guilded the week Guilded shuts down.
  • 10-18 February 2026. Reddit and X light up. PiunikaWeb: Root in damage control, two statements, a promise to rewrite for “clarity.” No rollback announced in that coverage.
  • 19 February 2026. Current Terms of Use and Privacy Policy. New headline: no sale of data, no AI training, calls not stored.
  • 5 June 2026. Ask Root. Jesse: never sold data, never will, it was a placeholder from before open beta.

The August text

What the live policy said while people were already in voice.

Captured by the Wayback Machine on 8 February 2026 and again on 18 February, still carrying the 7 August 2025 effective date. Emphasis ours.

We collect the personal information and content of communications that you disclose through the Service. This may include messages, pictures and files shared between users and within communities. We may also collect voice, video or screensharing “calls” between users and within communities. Root Privacy Policy, effective 7 August 2025, archived 8 February 2026

Identifiers

Username, email, password, and phone number.

The February rewrite dropped the phone number from the identifiers list. The August text had it.

Device

IP, unique identifiers, geolocation.

Current policy still takes device type, identifiers, IP, and “approximate location.” The old one said geolocation, full stop.

Analytics

Traffic data “helpful for marketing purposes.”

Google Analytics named. Current policy keeps GA on the marketing site and in-app feature metrics, and says those metrics are not PII.

Cookies

Targeting cookies, other websites, ads.

August text, targeting cookies: “used to display ads on other websites based on your visits to our Site and other online activity.” Current text: targeting cookies only on rootapp.com after a consent banner. Do Not Track: still ignored, both versions.

The alibi

Placeholder is a word you use for lorem ipsum, not for a signed policy.

Jesse, on camera and in the blog, folded the backlash into a single move: people on Twitter and YouTube misread “older privacy policies that we were using as placeholders because we weren’t officially in open beta yet.” Then: “all you need to know is that we never did that, and we never will.”

Open beta is the load-bearing word. Root’s own Guilded post, 18 December 2025: “Starting today, Root will be open to everyone, no invite or access code needed.” The closed-beta announcement is 27 August 2025. The policy people quoted is dated 7 August 2025. That document governed the closed beta, the public opening, and the February 2026 influx of Discord refugees. A placeholder is the Webflow footer they still have not deleted. A privacy policy with an effective date is a contract.

PiunikaWeb, 18 February: Root framed the issue as communication. “The legal text apparently does not reflect how the platform actually handles user data.” That is an admission that the legal text said something else. It is also a request that you trust a blog post over the PDF. Closed source, TLS-only, US servers, no export. Trust is the entire product.

What still sits in the current file

The rewrite is real. So is the rest of the stack.

ClauseNowStamp
Sell data / train AI Bold denial at the top of the 19 Feb policy. true, as text
Store messages Yes, for delivery and history. No E2EE. plaintext at rest, on their disk
Record calls Now: real-time only, “does not record or store.” August: “may also collect.” take the new sentence on faith
Do Not Track “At this time, we do not recognize automated do-not-track browser signals.” still ignored
Where the data lives United States. You “agree and consent.” EEA protections “may not” apply. US company, US servers
M&A / bankruptcy Personal information may transfer with the company. “Not as a standalone commercial product.” the Guilded clause
Export Terms: no export tools. No guarantee content survives deletion or account close. you do not own the exit
Arbitration JAMS, individual only, class waiver, one-year limit, $100 cap, California law. standard VC chat ToS
Idea submissions Unsolicited ideas are non-confidential. They can use them forever, worldwide, unpaid. do not email them a feature
CSAM scanning Current policy: scan uploaded media for CSAM, cooperate with law enforcement. ordinary, and they should

TLS in transit is table stakes. End-to-end encryption is the thing Discord alternatives keep promising and Root does not claim. Credit them for not pretending. Do not confuse “we use TLS” with “nobody at the company can read #general.”