RootLock is a family safety app made by Apexium Marketing LLC. It helps families see where each other are, stay safe on the road, and manage what apps and websites children can use. To do that, RootLock handles some genuinely sensitive information — most importantly, your family's location. This policy explains exactly what we collect, where it lives, who can see it, and how to delete it.
The short version. RootLock collects the data the features need — location, driving activity, and protection settings — and nothing else. Your data is shared only inside your own family, according to roles and sharing settings you control. We show no ads, use no third-party analytics or trackers, and never sell or rent your data to anyone. Removing a family member permanently deletes their history from our servers.
1. Information We Collect
Account information
Sign in with Apple identifier — a stable identifier Apple issues for your account. We never see your Apple ID password. If you choose to share an email address through Sign in with Apple, we receive that address.
Display name — the name you (or a parent, for a child) enter in the app.
Profile photo — optional; stored so your family sees it on the map and in the app.
Family structure — who is in your family, each member's role (parent, co-parent, child), and invite codes while they are active.
Location information
Live location of members who share it, with timestamps, plus device battery level and charging state.
Saved places ("Home", "School", "Work", and custom places), including the addresses you look up to create them, and arrival/departure events at those places.
Check-ins and SOS alerts, including the location they were sent from and any message attached.
Driving information
Trips — route path, start/end times, distance, duration, and top speed.
Safety events — hard braking, rapid acceleration, speeding, and phone use during a drive, with the location where each occurred.
Protection (parental control) information
Restriction settings — which apps, categories, and websites are limited for each child, web filter mode, and blocking schedules. App selections are stored as opaque Apple tokens: our servers cannot read which apps they represent — only the family's own devices can.
Protection alerts — attempts to open something blocked (tamper/bypass attempts), so parents can be notified.
Temporary access grants — when a parent allows a child temporary access, and for how long.
Sign-out PIN — stored only as a salted cryptographic hash. We never store or transmit the PIN itself.
Subscription information
Subscription status for your family (active, trial, expired). All payment is processed by Apple through the App Store — we never see your payment details.
2. What We Do NOT Collect
No contacts, calendars, photos (other than the profile photo you choose to upload), messages, or browsing history.
No health or biometric data.
No payment card or financial details (Apple handles all payment).
No advertising identifiers, and no data from third-party data brokers.
No third-party analytics SDKs or crash-tracking SDKs.
3. No Tracking and No Advertising
RootLock shows no ads and performs no cross-app tracking as defined by Apple's App Tracking Transparency framework. We do not sell, rent, or share your personal information with advertisers, data brokers, or analytics companies — ever. Data is used solely to provide RootLock's features to your family.
4. Where Your Data Is Stored
RootLock's backend — family, location, driving, protection, and subscription-status data is stored by our backend service, which runs on Cloudflare's infrastructure (Cloudflare Workers, D1, and KV) in the United States. Data is encrypted in transit (TLS) and at rest by the platform.
On your devices — restriction configuration is mirrored to each device so protection keeps working offline; some data (like the details of shielded apps) exists only on your family's devices.
Apple services — push notifications are delivered through the Apple Push Notification service; subscriptions are managed by the App Store.
5. Data Sharing — Who Can See What
Data
Who can see it
A member's live location, places, and arrival/departure alerts
The parents/co-parents in that member's family, subject to each adult's own sharing toggles. Children can see only their own location — never a parent's or sibling's.
Driving trips and safety events
The family's parents/co-parents.
Check-ins and SOS alerts
The family's adults (SOS location is controlled by the emergency-group sharing setting).
Protection settings and alerts
The family's parents/co-parents; each child sees only their own protection status.
Nothing is ever visible outside your family. Our service providers are limited to Apple (sign-in, notifications, subscriptions) and Cloudflare (infrastructure hosting for our backend); they process data on our behalf and are not permitted to use it for their own purposes. We may disclose information if required by law, or to protect the safety of a child in an emergency.
6. Push Notifications
RootLock sends notifications for arrivals and departures, check-ins, SOS alerts, protection alerts, and account events, delivered via Apple's push service. Notifications about blocked apps use generic wording (for example, "tried to open a blocked app") — the specific app is only shown inside the app on your own device. You can disable notifications in iOS Settings at any time.
7. Apple's Role in Data Processing
Sign in with Apple authenticates your account; Apple's Family Controls and Screen Time frameworks enforce app and web restrictions on-device; the App Store processes all subscription payments; and the Apple Push Notification service delivers alerts. Apple's handling of that data is described in Apple's own privacy policy.
8. Children's Privacy (COPPA)
RootLock is designed for parents to use with their own children, and we take children's privacy seriously:
A child account can only be created through an invite generated by a parent in that family — children cannot sign up on their own. Creating the invite and setting up the child's device is the parent's verifiable consent to the collection described in this policy.
A child's data (location, activity, protection status) is visible only to the parents and co-parents of their own family.
We collect from children only what the safety features require — never for marketing. RootLock shows no ads to anyone, including children.
A parent can review their child's information in the app at any time, and can permanently delete it by removing the child from the family (or deleting the family). To exercise any COPPA right, parents can also contact us at hello@rootlock.app.
9. User Rights and Data Deletion
Sharing controls — each adult chooses what they share (location, activity, emergency group) with each other adult, in Settings.
Location permission — you can revoke RootLock's location access in iOS Settings at any time; the app will simply stop sharing your location.
Member removal — removing a member permanently deletes their location history, driving records, check-ins, SOS events, protection alerts, and configuration from our servers.
Family deletion — deleting the family deletes all of the above for every member.
Note: deleting the app from a device removes that device's local data, but data already stored on our servers remains until the member or family is removed in the app (or you ask us to delete it).
You can also email hello@rootlock.app to request access to or deletion of your data.
10. International Users & State Privacy Laws
RootLock is operated from the United States and our servers are located there; by using RootLock you understand your information is processed in the U.S. Residents of California and other states with comprehensive privacy laws have rights to access, correct, and delete their personal information — the in-app controls and email address above satisfy those requests. We do not sell or share personal information as those laws define it, and we honor deletion requests regardless of where you live.
11. Data Retention
Account, family, location, driving, and protection data is retained while the member remains part of an active family, so the app's history features work.
Data is deleted from our servers when a member is removed or the family is deleted (see Section 9).
Expired invite codes and ended sessions are purged automatically.
12. Security Measures
All traffic between your devices and our backend uses TLS encryption.
Access to family data requires an authenticated session bound to a family member, and every request is checked against that member's role (for example, a child's device can never read another member's location).
The child sign-out PIN is stored only as a salted hash; app selections are opaque tokens our servers cannot interpret.
Our backend runs on Cloudflare's SOC 2–audited infrastructure with encryption at rest.
13. Changes to This Privacy Policy
If we make material changes — especially any change to what we collect or who can see it — we will update this page, change the date at the top, and notify you in the app before the change takes effect.
14. Contact Information
Email: hello@rootlock.app
Company: Apexium Marketing LLC
Address: 8206 Louisiana Blvd NE, Ste A #7450, Albuquerque, NM 87113, United States