Privacy Policy

Last updated August 13, 2026

This policy explains what information CharmRoot collects, why we collect it, and the choices you and your organization have. CharmRoot acts as a processor for the records your organization stores, and as a controller for the account and usage data we need to run the service.

Information we collect

  • Account information — name, email address, phone number, organization membership and role.
  • Customer Data — records your organization enters: members, prospective and former members, program participants and their guardians, events and attendance, partners and giving, dues, documents and custom fields you define.
  • Operational data — audit entries recording who created, changed or deleted a record and when, plus technical logs needed for security and troubleshooting.

How we use information

  • To provide the workspace, authenticate you and enforce role-based permissions.
  • To keep an audit trail of changes for your organization's accountability and ours.
  • To send transactional email such as invitations, verification, password resets and approval decisions.
  • To secure the platform, investigate abuse, and meet legal obligations.

We do not sell personal information, and we do not use Customer Data to train AI models.

Tenant isolation

Every record carries the identifier of the organization that owns it, and database-level row security policies prevent any account from reading or writing data outside the organizations it belongs to. Platform administrators can see organization-level metadata and the audit log; day-to-day operational records remain scoped to your organization.

Children's and participant data

Mentoring programs often involve minors. Your organization decides what participant information to store and is responsible for collecting guardian consent. We recommend recording only what your program genuinely needs, and using the document vault's category controls for anything sensitive.

Service providers

We rely on a small set of vendors to host the database and application, deliver email, and provide optional AI and integration features. These providers process data on our instructions and under confidentiality obligations.

Retention

Customer Data is kept while your organization's workspace is active. Audit entries are retained for a rolling period to support security investigations. When an organization leaves the platform, its data is deleted or anonymized after the export window described in the Terms of Service.

Your rights

Depending on where you live, you may have the right to access, correct, export or delete personal data about you. For records held inside an organization's workspace, contact that organization's administrator first; they control the data. For account-level requests, contact us and we will respond within the period required by applicable law.

Security

Access is protected by authenticated sessions, row-level database policies, per-module role permissions and audit logging. Documents are stored in private buckets and served through short-lived signed links. No system is perfectly secure, so please report any suspected vulnerability to security@charmroot.com.

Contact

Privacy questions can be sent to privacy@charmroot.com.