CodingPepper

Privacy Policy

RootCausa Symptoms Tracker · Last updated: 1 August 2026

Applies to: the RootCausa Symptoms Tracker mobile application (Android package com.rootcausa.rootcausa_symptoms, and the equivalent iOS application if released).

Provider / data controller: Rafael Traista, Romania
Contact: traista.rafael@yahoo.com

Summary — we collect nothing

RootCausa Symptoms Tracker collects no personal data whatsoever. It is an offline app: everything you record stays in storage on your own device, under your own control.

  • We collect no data. None. Not your entries, not usage statistics, not device identifiers, not crash reports, not an email address, not an advertising ID.
  • Your entries never leave your device. The app does not upload, sync, transmit, or send your information anywhere — not to us, and not to anyone else.
  • We do not operate a server. The app has no user accounts, no login, and no backend of any kind. There is nowhere for your data to be sent to us, because there is no “us” on the network.
  • No analytics, no advertising, no tracking, no crash reporting, and no third-party SDK that collects information about you.
  • We do not sell, rent, or share your data — we could not, because we do not have it.

Because we hold no copy of your information, there is nothing for us to disclose, sell, leak, lose, or hand over to anyone, including under legal compulsion.

What this means for GDPR

The GDPR governs the processing of personal data by a controller. We process none. Your health entries are created by you, stored by you on your own device, and never transmitted to us — so with respect to that data we are not a data controller and there is no processing for you to consent to, object to, or ask us to stop.

The practical consequence: the rights the GDPR gives you (access, portability, erasure, and the rest) are not requests you need to send anyone — they are already in your hands, immediately and completely. See section 6.

1. What information the app handles

1.1 Health and wellbeing entries you create

The purpose of the app is to let you record daily entries, which may include:

  • food and drink items,
  • physical activity and sleep,
  • supplements and medication,
  • symptom ratings on a numeric scale,
  • free-text sticky notes,
  • the dates and times attached to all of the above.

Some of this is health-related information. Under the EU General Data Protection Regulation (GDPR) it may qualify as a special category of personal data (Article 9). We treat it accordingly: it is stored only where you put it, and we never receive it.

1.2 Where it is stored

All entries are written to a single file in the app's private storage area on your device (rootcausa_data.json). On both Android and iOS this directory is sandboxed — other apps cannot read it.

Two small preference files are stored the same way: your view settings (rootcausa_view.json) and your subscription status cache (rootcausa_pro.json).

1.3 What we collect

Nothing. The developer receives no data from the app — not your entries, not usage statistics, not device identifiers, not crash reports, not an email address.

2. The only ways data leaves your device — all of them started by you

The app never moves your data on its own. The only way anything leaves your device is if you deliberately export or share it, as described below.

2.1 Cloud backup is not enabled

This version of the app has no cloud backup and no sync. Google Drive backup is not available and cannot be turned on. Nothing is uploaded anywhere, automatically or otherwise.

If a future version enables it, it will be strictly opt-in, the backup will go to your own Google Drive account (never to us, and using a permission scope limited to the single file the app creates), and this policy will be updated before that version ships.

2.2 Export and sharing (manual, one action at a time)

Settings → Export / Import lets you produce a JSON backup, a plain-text summary, an HTML report, or a PDF report. For each, you choose either:

  • Save as file — written to your device's Downloads folder, or
  • Share — handed to your operating system's share sheet.

When you choose Share, you pick the destination app (email, messaging, cloud drive, notes, an AI assistant, and so on). Once your data reaches that destination it is governed by that service's privacy policy, not this one. We have no visibility into, and no control over, where you send it.

Please note: the “Text for AI” export is designed to be pasted into a chat or AI assistant. If you do that, you are sending health information to a third party. Consider that service's data practices — some retain submitted text or use it for model training. This is your decision to make, and we mention it so you can make it knowingly.

2.3 Import

Importing reads a file you select and merges it into your local data. The file never leaves your device.

3. Subscription and payments

RootCausa Pro is an auto-renewing monthly subscription. It unlocks features that are themselves entirely offline (additional tracking rows and the local export formats) — subscribing does not move your data anywhere, and does not enable any cloud storage, sync, or account.

  • Purchases are processed entirely by Google Play or the Apple App Store. When you tap Subscribe, the app hands off to your store, which manages the whole transaction. The app never sees, receives, or stores your name, card number, billing address, or any other payment detail — and it sends the store nothing about you or your entries.
  • We operate no subscription server. Your entitlement is a small expiry date cached locally on your device.
  • Google and Apple provide us only with aggregate, anonymous sales reporting. We cannot identify individual purchasers from it.

Billing is governed by your store account terms: Google Play Terms / Apple Media Services Terms.

4. Permissions the app requests

  • Internet access — used only so your app store can process a subscription purchase, and so the Terms and Privacy links can open in your browser. The app sends none of your data over it.
  • Storage (Android 9 and older only) — only to write a file to your Downloads folder when you tap “Save as file”. Android 10+ needs no such permission.

The app requests no access to your location, contacts, camera, microphone, photos, calendar, health platform (Apple Health / Google Fit), or advertising identifier.

5. Data retention and deletion

Because your data lives on your device, you control its lifetime completely:

  • Delete individual entries — from any view in the app.
  • Delete everything — uninstall the app, or clear its data in your device settings. This permanently removes the local file.
  • Delete exported copies — remove any files you saved or shared yourself.

We retain nothing, so there is no deletion request to send us and no retention period on our side. Note that uninstalling removes only the app's own data — any file you exported or shared earlier stays wherever you put it, and is yours to remove.

6. Your rights

If you are in the European Economic Area or the United Kingdom, the GDPR gives you rights of access, rectification, erasure, restriction, portability, and objection regarding personal data a controller holds about you.

In practice these are already fully self-service in this app, because we hold no copy: your data is on your device, you can read and edit every entry, the JSON export is a portability export in a documented machine-readable format, and deletion is immediate and under your control.

If you believe we hold information about you, or you have any privacy question, contact traista.rafael@yahoo.com. You also have the right to lodge a complaint with your national data protection authority (in Romania, the ANSPDCP).

7. Children

RootCausa Symptoms Tracker is not directed at children and we do not knowingly collect information from anyone. The app is intended for users aged 13 and over, or the minimum age required in your country, whichever is higher.

8. Security

Your data is stored in the app's sandboxed private directory, which the operating system protects from other applications. Because nothing is transmitted, there is no data in transit to intercept.

Two honest limitations you should be aware of:

  • The local data file is not separately encrypted by the app. It is protected by your device's own security — your screen lock and, on most modern phones, full-disk encryption. Someone with unlocked physical access to your device, or root/jailbreak access, could read it. Use a device passcode.
  • A file you export or share leaves our protection entirely. It carries no encryption and no access control of its own.

No method of storage or transmission is perfectly secure.

9. International transfers

There are no international transfers of your data, because there are no transfers of your data at all. Your entries stay on your device, in your country, wherever you happen to be.

10. Changes to this policy

We may update this policy — for example if a future version of the app adds a feature that handles data differently. Material changes will be reflected by a new “Last updated” date, and where the change is significant we will note it in the app or its store listing. Continuing to use the app after an update means you accept the revised policy.

11. Contact

Questions, concerns, or requests:
Rafael Traista
Email: traista.rafael@yahoo.com

← Back to RootCausa

RootCausa Terms of Use Contact
© 2026 CodingPepper. All rights reserved.