Skip to content
mroot.co
PRIVACY POLICY · VERSION 2026-07-13

Privacy, in plain language.

This policy explains what mroot.co and the Project Advisor collect, why it is processed, and how long it is kept. Forms are for project guidance and contact—not marketing enrollment.

Information the advisor collects

The advisor stores your categorical project answers; sanitized optional project details; name, email, and any optional business, website, or phone information you submit; first-touch attribution; consent acknowledgment; and the resulting assessment. It also stores random session, submission, idempotency, and event identifiers that contain no contact information.

Optional project details are sanitized before storage. Obvious email addresses and phone numbers are redacted, control characters are removed, and the value is limited to 500 characters. The unsanitized version is not stored.

AI processing

Workers AI is disabled in production. Assessments currently use deterministic rules and copy. If AI is re-enabled after a documented consent and redaction review, contact fields will remain excluded and optional free text will remain excluded by default. Any enabled model output must pass schema validation and has a deterministic fallback.

Contact and transactional email

Your contact details are used to respond about the message or assessment you requested. Resend processes the email address and approved message or assessment content to deliver transactional email. General contact-form messages are sent synchronously and are not stored in D1. Advisor submissions are retained as described below. Submission does not subscribe you to a marketing list.

All Contact, Services quote, IDE message, and Emergency Fix forms now use the mroot.co Worker. Formspree is no longer an application processor for new submissions.

Security and operational data

Cloudflare hosts the site and API and Turnstile processes technical request information to help prevent spam. Operational records include non-PII status, latency, model usage, fallback state, notification state, and stable error codes. Prompts, generated prose, contact fields, optional details, and raw IP addresses are not written to application logs.

Analytics

The advisor records bounded, typed events such as opening the flow, viewing a step, selecting an approved option, generating a result, and clicking an approved CTA. Free text and contact information are not analytics fields. Result and booking events are treated as trusted only when they correlate with a completed submission; remaining anonymous funnel telemetry is treated as untrusted. The browser uses session storage and does not create a long-lived cross-session visitor ID.

Third-party resources

  • Google Fonts supplies the site typefaces and may receive normal browser request metadata.
  • GitHub APIs supply public contribution and repository status information.
  • Spotify supplies the embedded music player when a page containing it is opened.
  • Cloudflare provides hosting, API execution, abuse prevention, database, queue, and log infrastructure.
  • Resend delivers form and assessment email.

Retention

  • Incomplete anonymous sessions and related data: 30 days.
  • Analytics events and anonymous visitor records, if used in a future phase: 13 months.
  • Spam leads and associated results: 90 days.
  • Provider-call and notification operational records: 90 days.
  • Completed leads, answers, and generated results: 24 months after last activity.
  • Queue messages: Cloudflare platform retention; D1 remains the operational source of truth.

Choices and deletion requests

You may leave optional fields blank. To request access, correction, or deletion, use the contact page. Associated records will be removed or anonymized unless retention is legally required.

Questions

For privacy questions, contact contact@mroot.co.