FutureRoots

FutureRoots Privacy Policy

Last updated: 2026-08-23 · Effective: 2026-09-06

FutureRoots ("FutureRoots", "we", "us") is a private family platform for preserving memories, sharing wisdom, and building a child's future together. We take the privacy of your family — and especially your children — seriously. This policy explains what we collect, why, how we protect it, and the choices and rights you have.

Operated by FutureRoots Technologies Inc., Winnipeg, Manitoba, Canada. Questions or requests: privacy@futureroots.app.

1. A note about children

FutureRoots is built around children, but children do not have accounts and cannot sign in. A child is a profile created and controlled by an adult family member with parental authority. Children provide us nothing directly; all information about a child is entered by the adults in their family. While a child is a minor, we rely on the recorded consent and authority of the parent or guardian who creates and manages their profile. We do not knowingly allow children to create accounts or contact us directly. This design is intended to align with the United States COPPA, the EU/UK GDPR (including protections for children's data), Canada's PIPEDA, and Quebec's Law 25.

Different laws draw the age line in different places: COPPA at 13, the GDPR somewhere between 13 and 16 depending on the country, and Quebec's Law 25 at 14, where consent for a child under that age must come from the person holding parental authority. Nothing in FutureRoots depends on where that line falls, because no child of any age holds an account or gives us anything directly. Consent always comes from a parent or guardian, and we record it rather than assume it.

If you believe a child's information is in FutureRoots without proper parental authority, contact us at privacy@futureroots.app and we will investigate and, where appropriate, erase it.

When a child in the record becomes an adult.

A child's profile is created and managed by an adult who holds parental authority, and we record that authority when the profile is made. That authority ends when the child reaches the age of majority where they live. In Quebec, a person aged fourteen or over can already make many of these decisions for themselves.

From that day we no longer treat a parent's consent as our reason for keeping the record. We keep it because the people who made it (the family who wrote the messages, took the photographs and built the vault) have a real interest in their own family's record, and because that family maintains the account with us. We weigh that interest against the interests of the person the record is about, we have written down how we weighed it, and you can ask us for that assessment. The person the record is about can object to our keeping it at any time, and we will consider that objection on its own facts.

We usually cannot reach a young adult to tell them any of this. Children never give us an email address, which is the point of the design, so when a child in our records turns eighteen, we hold no way to contact them. Their parent can send them a private link that lets them create their own account, read the whole record and download a copy. Many people will never be sent one. This paragraph is our notice to them, and it is here rather than buried: if you are the subject of a FutureRoots record and you are now an adult, write to privacy@futureroots.app. We will act on your request whether or not anyone has invited you, and we will not ask your parent's permission to do so.

What a grown subject can and cannot do. Once the record is yours you can read all of it, download a copy, and give or withdraw consent for anything that still runs on consent. Your parent can no longer answer those questions for you. You cannot delete the record yourself, because it holds photographs and letters other people in your family made, which are their personal information too. If a parent asks us to delete it, we will tell you first and give you thirty days to download your copy. If you want something removed, write to us and a person will consider it with you within 30 days.

Suggesting people to invite. When you start a new family, we may offer you the people you already share another family with, so you do not have to retype addresses you have already given us. We only ever suggest someone to a person who can already see them, and we show a name and a suggested role — never anything about a family you are not part of. If you would rather not be suggested to anyone, turn it off in Settings and we will stop, everywhere.

2. Information we collect

From adult members (account holders):

  • Name and email address; a securely hashed password (we never store your password in readable form).
  • Your family relationships and role (parent, guardian, grandparent, relative, aunt/uncle/cousin, supporter).
  • Content you create: memories, messages, comments, reactions, milestones, time capsules, legacy items, goals, and predictions.
  • Communication preferences (which notifications you want, by channel), and — if you enable them — web-push subscription endpoints for your device/browser.
  • Payment-related identifiers needed to process transactions (see §5). We do not store your full card number — payments are handled by our processor.

About children (entered by adult family members):

  • First name, birthdate, and profile photo.
  • Memories and media (photos, videos, audio, messages) shared to the child's vault, milestones and achievements, time capsules, and family predictions about the child's future.

Automatically:

  • Basic technical and security data (e.g. session and device information, IP address at the network layer, and logs needed to operate the service and prevent abuse).

We do not collect data through third-party advertising trackers, and we do not run ads.

3. How we use information

  • To provide the service: show your family feed, vaults, funds, capsules, and predictions to the right people, scoped by explicit family relationships.
  • To send the notifications you have chosen (in-app bell, email, and web push), including the optional monthly memory prompt.
  • To process payments and manage Premium memberships and Future Fund contributions (see §5).
  • To keep the platform safe, secure, and working (abuse prevention, debugging, backups).
  • To comply with legal obligations (e.g. retaining financial records).

We do not sell your personal information, and we do not use it for cross-context behavioral advertising.

4. Who can see your information

  • Your family, by relationship. FutureRoots is private by design: there are no public profiles, nothing about your family is searchable or discoverable, and there is no cross-family access. What each member sees is scoped by their role. "Supporter" members have a deliberately narrower view — for example, they never see a child's birthdate or certain dates.
  • Anything a family member deliberately shares outward. The only things that ever leave your family are things someone in it chooses to send out. Today that means a certificate link: a page anyone can open, without signing in, to check that a memory's file has not changed since we recorded it. By default that page shows only dates and a fingerprint. The family member creating it can choose, for each link, to include the memory's title or the image itself, and anyone holding the link can then see whatever was included. Links can be turned off at any time, and deleting the memory deletes its link. See the Terms of Service for how this works.
  • Service providers (processors) who act on our instructions, under contract, only to run the service:
    • Amazon Web Services — hosting, database, and media storage (region US-East-1; see §8 on international transfers).
    • Stripe — payment processing, subscriptions, and Future Fund contributions (Stripe is the custodian of card data; we never receive it).
    • Amazon SES — transactional email delivery.
    • Web-push providers (the push service your browser/OS uses, e.g. Google, Mozilla, Microsoft, Apple) — only to deliver notifications you enabled.
  • Legal and safety disclosures — where required by law, or to protect the rights, safety, and property of families on the platform.

5. Payments, Premium, and the Future Fund

Payments are processed by Stripe. We store only the identifiers needed to operate billing (e.g. a Stripe customer reference, subscription and transaction status, amounts, currency, and timestamps) — never your card number.

How the money moves. When someone gives to a child's Future Fund, their card is charged by FutureRoots Technologies Inc. through our payment processor, Stripe. The payment reaches FutureRoots' Stripe account, and Stripe then transfers it to a Stripe account opened for the child, which is set up and controlled by the child's parent or guardian. FutureRoots does not hold, invest, or control the money in a child's Future Fund account, and cannot spend it. Only the parent or guardian who controls that account can move money out of it.

What we keep. FutureRoots keeps a service fee from each contribution, shown before you pay. It covers the cost of processing the payment and running the service, and everything else is transferred to the child's account.

What FutureRoots is not. FutureRoots is not a bank, a broker, an investment adviser, or a cryptocurrency product. We do not hold deposits, and we do not give investment, tax, or financial advice.

  • FutureRoots Premium is an optional family subscription. Annual plans auto-renew; we send a pre-renewal reminder and honor applicable auto-renewal-notice laws.
  • Future Fund contributions are gifts routed by Stripe to a child's own connected account, which is controlled by the child's parent/guardian. Contributions are gifts, not investments or securities, and FutureRoots does not provide financial advice.

Because these are financial records, we retain them under a legal obligation (§7) even after other data is erased, with the identity link severed where the record no longer needs it.

6. About blockchain / distributed-ledger technology

FutureRoots uses distributed-ledger technology solely as backend infrastructure to help ensure the integrity of certain records. It is invisible to you: there are no wallets, tokens, seed phrases, or cryptocurrency in FutureRoots. No personal information is written to any public ledger. Where an integrity anchor is stored, it is a non-identifying cryptographic proof (a hash), never a name, photo, or other personal data.

7. How long we keep information

  • Most content (memories, capsules, predictions) is kept for as long as the family maintains the profile, or until you ask us to delete it (§9).
  • Family predictions and the sealed "keepsake" image are, by design, preserved until the child's 18th birthday, when they are released to the family. You can ask us to delete them sooner (§9).
  • Financial records are retained to meet tax and accounting obligations for 7 years, after which they are purged. During that period the identity link is severed once the record no longer needs it.
  • Throttle/operational logs (e.g. reminder-sent records) are pruned automatically (typically within 90 days).

8. Where your information is stored

FutureRoots is operated from Canada and hosted on AWS in the United States (US-East-1). If you are in the EU/UK (or elsewhere outside the United States), your information is transferred to and processed in the United States. We rely on appropriate safeguards for such transfers, such as Standard Contractual Clauses, as applicable.

This applies to residents of Quebec as well: your information is stored and processed outside the province. Standard Contractual Clauses are a European instrument, and Quebec law sets its own separate requirements for personal information that leaves the province.

9. Your rights and choices

Depending on where you live, you may have the right to access your information, receive a portable copy of it, correct it, erase it, restrict or object to certain processing, and withdraw consent. While a child is a minor, their parent or guardian exercises these rights on their behalf; in Quebec, a person aged fourteen or over may exercise many of them themselves. Once the child is an adult, they exercise their own rights directly with us, whether or not they hold a FutureRoots account — see section 1.

  • Notification choices: manage email and push toggles anytime in Settings.
  • Download your data / delete your account: you can do both yourself from Settings → "Your data" (deleting your account requires re-entering your password), or contact privacy@futureroots.app for help or for a family- or child-scoped request.
  • What happens on erasure: we erase or export your data across our systems and our processors — including deleting stored media and asking Stripe to delete or anonymize your customer record, subject to Stripe's own legal retention of transaction records.
  • Timing: we respond without undue delay and within the periods required by law (generally within 30 days; we will tell you if we need longer for a complex request).
  • Some data may be retained where we have a legal obligation or need it to establish or defend legal claims (§5, §7); we will explain what and why.

10. Security

We protect your information with encryption in transit and at rest, strict access scoping by family relationship, short-lived credentials for media access, secrets held in a managed secrets store, and least-privilege infrastructure. No system is perfectly secure, but we work to keep your family's space safe.

11. Changes to this policy

We may update this policy. If we make a material change, we will notify account holders (e.g. by email or in-app) before it takes effect. The "Last updated" date above always reflects the current version.

12. Contact us

FutureRoots Technologies Inc.
Privacy: privacy@futureroots.app · General: support@futureroots.app
Winnipeg, Manitoba, Canada

Person in charge of protecting your information. The role responsible for the protection of personal information at FutureRoots is held by the company's Chief Executive Officer. You can reach them at privacy@futureroots.app, or by mail at the address above. If you are not satisfied with how we handle a request, you can complain to the privacy regulator where you live. In Canada that is the Office of the Privacy Commissioner, and in Quebec the Commission d'accès à l'information.