Identifiers
Username, email, password, and phone number.
The February rewrite dropped the phone number from the identifiers list. The August text had it.
root@exposed / privacy
The placeholder file
In February 2026, Discord refugees opened Root’s privacy policy and found a sentence about voice, video, and screenshare. Root went into damage control. Four months later the founder called the whole thing a rumor about a placeholder. The Wayback Machine is not a rumor.
Timeline
The August text
Captured by the Wayback Machine on 8 February 2026 and again on 18 February, still carrying the 7 August 2025 effective date. Emphasis ours.
We collect the personal information and content of communications that you disclose through the Service. This may include messages, pictures and files shared between users and within communities. We may also collect voice, video or screensharing “calls” between users and within communities. Root Privacy Policy, effective 7 August 2025, archived 8 February 2026
Identifiers
The February rewrite dropped the phone number from the identifiers list. The August text had it.
Device
Current policy still takes device type, identifiers, IP, and “approximate location.” The old one said geolocation, full stop.
Analytics
Google Analytics named. Current policy keeps GA on the marketing site and in-app feature metrics, and says those metrics are not PII.
Cookies
August text, targeting cookies: “used to display ads on other websites based on your visits to our Site and other online activity.” Current text: targeting cookies only on rootapp.com after a consent banner. Do Not Track: still ignored, both versions.
The alibi
Jesse, on camera and in the blog, folded the backlash into a single move: people on Twitter and YouTube misread “older privacy policies that we were using as placeholders because we weren’t officially in open beta yet.” Then: “all you need to know is that we never did that, and we never will.”
Open beta is the load-bearing word. Root’s own Guilded post, 18 December 2025: “Starting today, Root will be open to everyone, no invite or access code needed.” The closed-beta announcement is 27 August 2025. The policy people quoted is dated 7 August 2025. That document governed the closed beta, the public opening, and the February 2026 influx of Discord refugees. A placeholder is the Webflow footer they still have not deleted. A privacy policy with an effective date is a contract.
PiunikaWeb, 18 February: Root framed the issue as communication. “The legal text apparently does not reflect how the platform actually handles user data.” That is an admission that the legal text said something else. It is also a request that you trust a blog post over the PDF. Closed source, TLS-only, US servers, no export. Trust is the entire product.
What still sits in the current file
| Clause | Now | Stamp |
|---|---|---|
| Sell data / train AI | Bold denial at the top of the 19 Feb policy. | true, as text |
| Store messages | Yes, for delivery and history. No E2EE. | plaintext at rest, on their disk |
| Record calls | Now: real-time only, “does not record or store.” August: “may also collect.” | take the new sentence on faith |
| Do Not Track | “At this time, we do not recognize automated do-not-track browser signals.” | still ignored |
| Where the data lives | United States. You “agree and consent.” EEA protections “may not” apply. | US company, US servers |
| M&A / bankruptcy | Personal information may transfer with the company. “Not as a standalone commercial product.” | the Guilded clause |
| Export | Terms: no export tools. No guarantee content survives deletion or account close. | you do not own the exit |
| Arbitration | JAMS, individual only, class waiver, one-year limit, $100 cap, California law. | standard VC chat ToS |
| Idea submissions | Unsolicited ideas are non-confidential. They can use them forever, worldwide, unpaid. | do not email them a feature |
| CSAM scanning | Current policy: scan uploaded media for CSAM, cooperate with law enforcement. | ordinary, and they should |
TLS in transit is table stakes. End-to-end encryption is the thing Discord alternatives keep promising and Root does not claim. Credit them for not pretending. Do not confuse “we use TLS” with “nobody at the company can read #general.”