Introduction
Taproot Library is a service operated by Acatium, Inc. (“Acatium,” “Taproot Library,” “we,” “us,” or “our”), a New York corporation, with a mailing address at P.O. Box 94, Purchase, NY 10577.
Taproot Library is an online service and mobile application for storing, organizing, reading, transcribing, searching, and connecting personal and family collections, including photos, videos, audio recordings, scanned documents, letters, and related materials (your “Content”). This Privacy Policy explains what information we collect, how we use it, when and with whom we share it, how long we keep it, the choices you have, and the rights you may exercise under privacy laws.
This Policy applies to the Taproot Library website at www.taprootlibrary.com, our iOS and Android applications, any upload or desktop helper tools we provide, and related services (together, the “Service”). It does not apply to third-party services that you connect to or that link to our Service, which have their own privacy practices.
Because a family archive necessarily contains information about people other than the account holder, please read Section 12 (Content About Other People) and our separate Biometric Data Policy carefully.
A Note on Our Privacy-Protective Design
We have built Taproot Library around a set of commitments that shape everything in this Policy:
We do not train AI models on your Content. We use hosted third-party AI services and fixed open-source models to provide features to you. We do not operate a training pipeline on user Content, and we do not sell, license, or share your Content (or derived data such as embeddings) with third parties for their AI training.
We do not sell or “share” your personal information as those terms are defined under California and other state privacy laws.
We do not use third-party advertising, analytics, or tracking SDKs, and we do not engage in cross-context behavioral advertising.
Facial recognition is strictly opt-in, on a per-Library basis, and is governed by our Biometric Data Policy.
You can export your Content at any time (“no lock-in” is a product commitment).
Information We Collect
3.1 Information you provide to create and manage an account
When you register, we collect your email address, password, phone number, full name, date of birth or age, mailing address, username or display name, and, if you choose to add one, a profile photo or avatar. If you purchase a subscription, our payment processor collects your payment information (see Section 3.5).
We do not currently offer third-party or social logins (for example, Sign in with Apple, Google, or Facebook).
3.2 Content you upload
The core of the Service is the Content you choose to upload. This includes still photos, videos, audio recordings and voice memos, scanned documents (which may include birth certificates, letters, and similar records), live or motion photos, screenshots, GIFs, and any captions, titles, descriptions, tags, comments, or stories you attach. We do not currently restrict file types.
Your Content is personal information about you and frequently personal information about other identifiable people who appear in it.
3.3 Metadata associated with your Content
When you upload Content, we collect and store associated metadata, which may include EXIF data (such as camera, lens, and exposure settings), the date and time the Content was captured, precise GPS geolocation embedded in the file, the device model used to capture it, the original file name and format, and the identity of the uploader. We also generate metadata about your Content using automated tools, including identifying faces and text regions and producing AI-generated tags for faces, places, and objects (see Section 4).
3.4 Content you import from other services
If you choose to import Content from a file-storage service you use (for example, a cloud drive), we pull the available data associated with the items you import so that we can store and organize them for you. We act on your instruction when importing, and we only import what you direct.
3.5 Payment information
We use Stripe to process payments and manage subscriptions on the web. Stripe collects and processes your payment card or account details directly; we receive limited information such as your subscription and payment status, not your full card number. For in-app purchases on iOS or Android, Apple and Google process the payment under their own rules and policies.
3.6 Information we collect automatically
When you use the Service, we automatically collect your IP address; device type, operating system, browser, and version; application or web version and language; crash logs and diagnostic data; usage data (features used, time spent, content viewed); storage volume and bandwidth usage; information from first-party cookies and similar technologies (see Part VI); and inferences we draw from your usage to operate and improve the Service. We do not use device advertising identifiers (such as IDFA or AAID), and we do not use third-party analytics or attribution SDKs.
3.7 Information from third parties
We receive limited information from our payment processor (Stripe) about your payment and subscription status. We do not receive personal information about you from identity providers, marketing partners, or data brokers.
AI and Machine Learning Features
The Service uses artificial intelligence and machine learning to help you read, transcribe, search, organize, and enrich your Content. These features operate on your Content to provide the Service to you.
4.1 What our AI features do
Content understanding and organization: object and scene recognition (for example, “beach” or “birthday cake”), automatic album generation by event, date, or location, optical character recognition (OCR) and text extraction from images and scanned documents, duplicate and near-duplicate detection, quality scoring or “best shot” selection, and sentiment or emotion detection.
Audio and video: voice-to-text transcription and speaker identification.
Generative enhancement: photo enhancement, upscaling, denoising, restoration of old or damaged photos, colorization of black-and-white content, style transfer or filters, AI-generated highlight reels or slideshows, and AI-generated captions or stories. Generative outputs are saved into your archive. We do not offer features that generate new depictions of a person from scratch (for example, avatar creation, face generation, or voice cloning).
Facial recognition and people-tagging: governed by our separate Biometric Data Policy (Part III). This feature is opt-in on a per-Library basis. We do not create face templates, faceprints, or other biometric identifiers from your Content unless you have opted in.
4.2 Where AI processing happens, and our AI providers
AI and generative processing is performed on our servers and through our cloud providers, not on your device. We use:
Anthropic (Claude models, direct API): large-language-model reasoning and user-initiated deep-read and vision extraction.
Amazon Web Services (AWS) Bedrock: transcription (Mistral Voxtral; Amazon Nova) and large-language-model fallback (including Anthropic models via Bedrock).
In-house open-source models (for example, CLIP, Tesseract, and face and speaker models), run inside Taproot Library’s own infrastructure.
Each provider processes your Content only to perform the requested function on your behalf. No provider retains rights to use, retain beyond the processing window, or train on your Content. We do not operate a training pipeline.
4.3 No training on your Content
We do not train, fine-tune, or improve our own AI or machine-learning models using your Content, metadata, captions, faces, or voices. We do not sell, license, or share your Content or derivatives such as embeddings with third parties for AI training.
4.4 AI accuracy
AI features can make mistakes. Recognition, transcription, tagging, and generative outputs may be inaccurate or incomplete, and you should not rely on them as a definitive record. See the AI disclaimer in the Terms of Use.
How We Use Your Information
We use personal information and Content to: provide the storage, archive, and sharing Service; apply the AI features described above; create and authenticate accounts and manage Library membership; process payments, refunds, and subscriptions; provide customer service and support; personalize the Service (for example, smart albums and memories); send transactional notifications (such as upload-complete and sharing alerts); send marketing communications where you have not opted out and where permitted by law; perform analytics and improve the Service; conduct research and product development; prevent fraud, abuse, and security incidents (including malware and CSAM scanning, described in Section 7); and comply with legal obligations.
We do not use your Content to train or improve AI models.
Automated Processing and Content Safety Gates
We do not make automated decisions that produce legal or similarly significant effects on you, and we do not automatically suspend accounts by algorithm. Our safety systems act on uploaded files, not on user status: every upload is scanned for malware and for child sexual abuse material (CSAM) before storage, and content that fails or cannot clear a scan may be quarantined pending human investigation (see Section 7 and Part II, Section 5). Any account suspension or termination follows the process in the Terms of Use.
Content Safety, Malware, and CSAM Scanning
To keep the Service safe and to meet legal obligations, we scan every upload synchronously before it is stored. Scanning is “fail-closed,” meaning that if a scan is inconclusive, the file is treated as unsafe and moved to quarantine rather than stored normally.
Malware scanning protects the Service and other users.
CSAM detection uses perceptual-hash matching (PhotoDNA). When a match is identified, the content is placed under an evidence hold and we file a report with the National Center for Missing and Exploited Children (NCMEC) as required by federal law, 18 U.S.C. § 2258A. Under that statute, as amended by the REPORT Act of 2024, we preserve the relevant report contents for one year. We may be legally prohibited from notifying you of a CSAM report.
The Service is not end-to-end encrypted, and we are able to access Content to perform these scans and to provide the Service. See Section 8.
Storage, Hosting, Security, and Encryption
Your Content is stored on Amazon Web Services in the United States (primary region us-east-1; backups in us-west-2). We do not store user Content outside the United States.
Encryption at rest: AES-256-GCM envelope encryption, using a multi-region AWS Key Management Service customer master key per environment, with per-Library tenant isolation enforced cryptographically through encryption-context binding.
Encryption in transit: TLS 1.2 or higher.
Tenant isolation: row-level security plus cryptographic isolation per Library.
Access controls: least-privilege identity and access management; secrets held in AWS Secrets Manager with declared rotation.
Authentication: time-based one-time-password multi-factor authentication with single-use recovery codes.
Monitoring and governance: structured audit logging, automated dependency and vulnerability scanning, and a mandatory data-classification registry covering every database column.
Backups: encrypted automated database backups with a 7-day retention window, copied to a second U.S. region, with deletion protection and object versioning enabled.
We do not offer end-to-end encryption (encryption that would prevent us from accessing Content) for any feature or tier, because we must scan uploads for malware and CSAM.
No system is perfectly secure, and we cannot guarantee absolute security.
Your Choices and Privacy Rights
9.1 Choices available to everyone
Access and curate: you can browse, organize, and curate your own Content in the Service.
Export: you can download and export your Content.
Delete: you can delete individual files or close your account (see Section 11).
Facial recognition: you can opt in or withdraw consent on a per-Library basis (see Part III).
Marketing communications: you can opt out of marketing email and push notifications at any time, including through the unsubscribe link in emails or your notification settings. Transactional messages are not optional while you maintain an account.
9.2 State privacy rights (United States)
Depending on your state of residence, you may have some or all of the following rights: to know or access the personal information we hold about you; to correct inaccurate personal information; to delete personal information; to obtain a portable copy; to opt out of the sale or sharing of personal information and of targeted or cross-context behavioral advertising; and to limit the use of sensitive personal information. We do not sell or share personal information, we do not engage in targeted or cross-context behavioral advertising, and we do not use sensitive personal information beyond what is necessary to provide the Service, so several of these opt-outs do not apply to our practices. You also have the right not to be discriminated against for exercising your rights.
9.3 California residents (CCPA/CPRA)
This section supplements the above for California residents under the California Consumer Privacy Act, as amended by the California Privacy Rights Act (Cal. Civ. Code § 1798.100 et seq.).
Categories of personal information we collect map to the categories in Section 3, and include identifiers, customer records, commercial information, internet/network activity, geolocation, audio/visual information, and sensitive personal information.
Sensitive personal information. Because of the nature of a family archive, the Content you upload may contain sensitive personal information, including government identifiers from scanned documents (such as Social Security, driver’s license, state ID, or passport numbers), account log-in credentials, precise geolocation, racial or ethnic origin, religious or philosophical beliefs, the contents of personal correspondence, biometric information used for identification (only if you opt in to facial recognition), health information, information about a known minor, sex life or sexual orientation, and citizenship or immigration status. We use sensitive personal information only to provide the Service you request and for the limited purposes permitted under Cal. Civ. Code § 1798.121, and not to infer characteristics about you. Because of that limited use, you are not required to direct us to “limit the use” of your sensitive personal information, although you may contact us with any request.
Sale/Share. We do not sell or share personal information and have not done so in the preceding twelve months. We do not knowingly sell or share the personal information of consumers under 16.
“Do Not Sell or Share” and “Limit the Use of My Sensitive Personal Information” links. Because we neither sell nor share personal information, nor use sensitive personal information beyond the purposes permitted by statute, we are not required to post these links.
Financial incentive (free tier).
How to exercise rights and our verification process are described in Section 10.
9.4 Right to appeal
If we decline a privacy request, residents of states that provide an appeal right (for example, Virginia, Colorado, and Connecticut) may appeal by replying to our decision or contacting us at the address in Section 15. We will respond within the period required by your state’s law.
How to Exercise Your Rights
To make a privacy request (access, correction, portability, or deletion), email support@taprootlibrary.com. You may also delete Content and close your account using in-app controls.
We will take reasonable steps to verify your identity before fulfilling a request, which may include confirming control of your account email or other information we already hold. We will not use information you provide for verification for any other purpose. An authorized agent may submit a request on your behalf with proof of authorization. We respond within the timeframes required by applicable law (generally 45 days, with one permitted extension).
Data Retention and Deletion
Individual files you delete: soft-deleted with an approximately 30-day recovery window, then permanently purged along with all associated AI derivatives.
Closing your account: when you close your account, we run a right-to-be-forgotten cascade: your user record email and password are nulled, sessions are deleted, and each Library you own is either transferred to an administrator you designate or deleted. A 30-day grace window applies before a Library is purged, and we target completion well within the 30-day regulatory ceiling.
AI derivatives: embeddings, tags, transcripts, and faceprints are deleted together with the underlying asset or Library. Faceprints are additionally destroyed upon withdrawal of facial-recognition consent.
Shared Content: members access Content within a shared Library rather than holding separate copies, so removing Content from a Library removes shared access for all members.
Lapsed subscriptions: We will not automatically delete Content based on a lapsed subscription alone.
What we retain after deletion: we retain audit and financial records for approximately seven years in PII-redacted form, under legal-basis and recordkeeping exemptions; our metering ledger is anonymized; and backups roll off according to their retention windows (see Section 8). We may also retain information as needed to comply with legal obligations, resolve disputes, and enforce our agreements, or under a legal hold.
Content About Other People (Non-Users)
A family archive will contain images, voices, and information about people who are not Taproot Library users, including relatives, friends, bystanders, and deceased family members. We rely on the uploading user’s representation that they have the right to upload Content depicting others (see Part II, Section 8). For biometric processing, we apply a per-person consent or attestation and withdrawal framework described in our Biometric Data Policy (Part III).
If you are not a user and you wish to have your image, biometric identifier, or other personal information addressed, contact us at support@taprootlibrary.com.
Children’s Privacy
The Service is not directed to children under 13, we do not knowingly allow anyone under 13 to create an account, and we do not offer child sub-profiles. A family archive will nonetheless contain photos and videos of children uploaded by adults. Our handling of children’s information and our COPPA position are described in the Children’s Privacy Notice (Part IV). If you believe a child under 13 has created an account or that we have collected a child’s personal information as a user without verifiable parental consent, contact us at support@taprootlibrary.com and we will delete it.
International Users and Data Location
The Service is offered to users in the United States and is hosted in the United States. We do not transfer or store user Content outside the United States.
Changes to This Policy; Contact
We may update this Policy from time to time. We will post the updated Policy with a new “Last Updated” date and, for material changes, provide additional notice as required by law. For changes that require consent (for example, a new use of biometric data or any future training on Content), we will obtain consent before the change takes effect.
Privacy contact: support@taprootlibrary.com
Mailing address for privacy notices: Acatium, Inc., P.O. Box 94, Purchase, NY 10577
Privacy Officer: Attn: CTO