Privacy Policy

Root & Seal (dba CultureFit Health Engine™) — rootandfork.app

Last updated: July 31, 2026

This Privacy Policy explains how Root & Seal ("we," "us," or "our") collects, uses, shares, and protects information when you use the CultureFit Health Engine™ website and services (the "Service"). By using the Service, you agree to this Policy.

1. Information We Collect

Account information. Name, email, password (stored hashed), and authentication identifiers when you sign up or log in.

Profile and preferences. Cultural cuisine selection, dietary preferences, allergies and restrictions, household/family settings, and goals you choose to share.

Generated content. The meal plans, recipes, and substitutions returned to you, plus the inputs that produced them.

Usage and device data. Log data, IP address, browser type, device identifiers, and basic analytics about how you use the Service.

Payment data. Processed by our payment provider; we do not store full card numbers on our servers.

2. Consumer Health Data

This section describes how we handle consumer health data — information that relates to your physical or mental health that you choose to share with the Service. We treat this category of information with heightened care.

What we may collect. Only what you choose to enter: food allergies and intolerances, ingredient dislikes, general nutrition and weight goals, body weight and activity level, self-selected condition filters (for example type 2 diabetes, hypertension, PCOS, cardiovascular risk, or chronic kidney disease), hydration and movement entries, medication names and refill timing if you use the refill reminder, and any readings you or a connected device record. You are never required to enter a clinical diagnosis to use the Service.

Why we collect it. Solely to generate and adjust your meal recommendations, apply safety guardrails (such as allergen exclusion and the renal safety layer), deliver reminders you have asked for, and support features you have turned on. We do not use consumer health data for advertising, and we do not sell it.

How it is stored. Consumer health data is stored in our managed database in the United States, encrypted at rest, and transmitted over encrypted connections (TLS).

How it is protected. Access is restricted by row-level security policies so your records are readable only by your authenticated account and by the limited administrative processes required to operate the Service. Personnel access is role-based and logged.

Who it is shared with. We share consumer health data only with the service providers required to run the Service (hosting, database, authentication, and the AI inference gateway that generates recommendations), each under confidentiality obligations, and only to the extent needed to perform that function. If you use Root & Fork through a clinician, employer, health plan, or health system, we share only what that arrangement authorizes and what you consent to — employers and plan sponsors receive aggregate, de-identified reporting, not your individual health entries. We do not sell consumer health data and we do not share it for cross-context behavioral advertising.

How to request deletion. You may withdraw consent and request deletion of your consumer health data at any time by contacting us or by deleting your account from Settings. We will delete or de-identify the data, and direct our processors to do the same, within the period required by applicable law, retaining only what we must keep for legal, tax, or fraud-prevention purposes.

Applicable U.S. consumer health privacy laws. Where they apply to us, we honor consumer health data rights under state consumer health privacy laws — including the Washington My Health My Data Act, the Nevada consumer health data law (SB 370), and the health-data provisions of comprehensive state privacy laws such as the California Consumer Privacy Act — covering the rights to know, access, delete, and withdraw consent, and the requirement to obtain your consent before collecting or sharing consumer health data.

HIPAA status. When you use CultureFit Health Engine directly as a consumer, we are not acting as a HIPAA covered entity or business associate, and the Service should not be used to store or transmit Protected Health Information such as clinical records or lab reports. Where CultureFit Health Engine is deployed by a covered entity under a written business associate agreement, the terms of that agreement govern the protected health information processed under it.

Not medical advice. Recommendations produced by the Service are informational nutrition education and do not replace advice, diagnosis, or treatment from your healthcare provider.

3. How We Use Information

We use information to: (a) operate, personalize, and improve the Service; (b) generate and deliver meal recommendations; (c) maintain security and prevent abuse; (d) communicate with you about your account, updates, and support; (e) comply with legal obligations; and (f) develop aggregated, de-identified analytics that do not identify you.

4. AI and Recommendation Processing

To generate meal plans, your inputs (cuisine, preferences, restrictions) are sent to our server, which uses our proprietary scoring and substitution logic together with a third-party large-language-model gateway. We do not sell your inputs, and we instruct providers not to use your inputs to train their general-purpose models where that option is available.

5. Sharing

We share information only with: (a) service providers who help us operate the Service (hosting, database, authentication, analytics, AI inference) under confidentiality obligations; (b) our Merchant of Record, Paddle.com, which processes all payments, subscription management, tax compliance, and invoicing on our behalf and acts as an independent data controller for that purpose (see Paddle's Privacy Notice); (c) professional advisers (legal, accounting); (d) authorities when required by law or to protect rights and safety; and (e) successors in a merger, acquisition, or asset sale (with notice where required). We do not sell your personal information.

6. Cookies and Analytics

We use cookies and similar technologies for authentication, preferences, and basic analytics. You can control cookies through your browser settings; disabling them may break parts of the Service.

7. Data Retention

We retain account and profile data while your account is active and for a reasonable period afterward to comply with legal obligations, resolve disputes, and enforce our agreements. You can request deletion at any time (see "Your Rights").

8. Security

We use industry-standard administrative, technical, and physical safeguards including encryption in transit (TLS), encryption at rest for our managed database, row-level security, and access controls. No system is perfectly secure; we cannot guarantee absolute security.

9. Your Rights

Depending on your jurisdiction (including California/CCPA and EU/UK GDPR), you may have the right to access, correct, delete, port, or restrict processing of your personal information, and to withdraw consent. To exercise these rights, contact us. We will respond within the timeframe required by applicable law.

10. Children's Privacy

The Service is not directed to children under 13 (or under 16 in the EEA/UK). We do not knowingly collect personal information from children. If you believe a child has provided us information, contact us and we will delete it.

11. International Transfers

We are based in the United States and may process information in the U.S. and other countries that may have different data-protection laws than your country. Where required, we use appropriate safeguards for cross-border transfers.

12. Changes to This Policy

We may update this Policy from time to time. Material changes will be posted on this page with an updated "Last updated" date.

13. Contact

Questions about this Policy or your data? Contact us.