RootsLast updated 2 August 2026
Roots is a CRM for solo real estate agents. Agents store details about the people they work with, so most of the personal information here isn't the agent's own — it belongs to their clients and leads. We treat it as theirs, not ours: we don't sell it, we don't advertise against it, and we don't use it to train AI models.
This policy covers two groups, and the distinction matters:
When a contact replies to a campaign email, or a lead is forwarded to your Roots lead address, that message passes through us. We store the sender's address, the subject line, and a short excerpt of the message (up to 300 characters) — enough to log the reply on the timeline, stop the drip, and show you why it stopped. The message is then forwarded to your own inbox.
Retention: the subject and excerpt are erased after 30 days, and the record is deleted entirely after 90 days. Roots is not an email archive and doesn't try to be one.
Roots only ever sees replies to mail it sent, plus anything you deliberately forward to your lead address. We do not connect to, read, or sync your mailbox.
Connecting Google Calendar or Microsoft 365 is optional and off until you choose it. When you connect, we store the access and refresh tokens that let Roots act on your behalf, the email address of the account that granted access, and the id of the single calendar we create. Those tokens are readable only by our server — never by the browser, and never by another agent.
Roots creates and works inside one calendar of its own, named "Roots". It writes your reminders there and reads back changes you make to those same events. We do not read your other calendars, your existing appointments, your email, or your contacts at either provider.
At Google, that limit is enforced by the permission itself: Roots asks only for access to calendars it creates, so it is technically unable to see the rest of your calendar. At Microsoft, Roots is granted broader calendar access than it uses, so there the limit is one we hold ourselves to rather than one the permission imposes.
Disconnecting from Settings → Integrations deletes the tokens and the sync records we hold. For Google we also revoke the permission at Google in the same step. Microsoft offers no way for us to do that for you, so we tell you where to remove it yourself; the "Roots" calendar and its events stay in your account either way, for you to keep or delete.
Payments are handled by Stripe. We never see or store your card number. We keep your subscription status, plan, billing period, and a card fingerprint Stripe provides — the last of these only to stop the same card claiming repeated free trials.
Standard server logs, and — only if you turn on notifications — a push subscription for each device you enable. Roots does not use advertising or cross-site tracking cookies.
Roots uses Anthropic's Claude API for drafting messages, the weekly coach, database analysis, deal coaching, relationship insights, contact recaps, Ask Roots and the support bot.
Being specific, because this is the part people most want to know: when you ask Roots to draft a message, we send the contact's name, pipeline stage, days since last contact, the context you typed, and — if you have set one — the language you write to that contact in, so the draft and its English translation come back in the right languages. If you then edit that draft, the edited text is sent back the same way so the English translation stays accurate to what you are about to send. When you run a database analysis, we send a batch of contact records — names, emails, phone numbers, stages, sources and notes — for up to 120 contacts at a time. When you open the Activity tab on a contact's profile, we send that one contact's logged history — the notes you wrote and the calls, texts, emails, meetings and stage changes you recorded, up to the 25 most recent — so it can be summarised back to you. When you ask a question in Ask Roots, we send your question along with the labels your database uses — your lead sources, tags, custom field names and saved list names — and then, as the question is answered, the contact records it needed: names, pipeline stage, days since last contact, lead score and deal value. If you ask about one person in particular, that includes their notes and up to their 25 most recent logged entries. Ask Roots can only read; it is never given the ability to send, add, edit or delete anything.
This data is sent so the model can produce your result and return it. Under our agreement with Anthropic, API data is not used to train their models. We don't send contact data to any other AI provider.
If you'd rather no contact data went to an AI provider at all, simply don't use the AI features — the CRM works fully without them.
Roots sends on your behalf, from your name via our sending domain. You are responsible for having a lawful basis to contact those people. Every marketing email carries your business postal address and a one-click unsubscribe link, as anti-spam law requires. When someone unsubscribes we record that suppression and block future campaign mail to that address — including if you later re-import them.
We use a small number of providers. They act on our instructions and don't get rights to use your data for their own purposes.
| Provider | Purpose |
|---|---|
| Supabase | Database, authentication and file storage |
| Vercel | Application hosting |
| Anthropic | AI features (see section 3) |
| Resend | Sending email |
| Cloudflare | DNS and receiving inbound email |
| Stripe | Payments and subscription billing |
| Optional sign-in and optional calendar sync, if you choose them | |
| Microsoft | Optional Microsoft 365 calendar sync, if you choose it |
We do not sell personal information, and we don't share it with anyone else except where the law requires it.
Data is encrypted in transit. Every table is protected by row-level security keyed to your account, so one agent cannot read another's records — enforced by the database itself, not just the app. Secrets and API keys live in managed secret storage, never in our source code. Access to production data is limited to what's needed to operate and support the service.
No system is perfectly secure, and we won't pretend otherwise. If we discover a breach affecting your data, we'll tell you promptly.
Depending on where you live you may have additional rights over your personal data. Write to us and we'll honour them.
Questions, requests, or anything that looks wrong: support@rootsflow.app.
Roots — Stay close. Close more.