Regroot est. 2026

Regroot Privacy Policy

Effective date: September 6th 2026

Last updated: September 6th 2026

This Privacy Policy explains what information Regroot (“the Service”) collects, how we use it, who can see it, and what choices you have. Regroot is operated by Ingenthron Engineering, LLC, a Florida limited liability company located at 5312 Barcelona Street, Orlando, Florida 32807 (“we,” “us,” or “Ingenthron Engineering”).

Terms defined in our Terms of Use — Organization, Organization Space, Administrator, Member, Attendee, Service Order — have the same meaning here.


1. The short version

  • We collect the minimum we need to run the Service. A username and email address are required; everything else is optional.
  • We never sell your information, share it with advertisers, or use it to train machine learning models.
  • Your real name, email address, and phone number are stored encrypted, with a separate encryption key for each user.
  • Organizations cannot browse or export member contact information. It is visible only to Administrators and to the organizers of events you have signed up for.
  • We send you notifications only if you have explicitly asked for them, and you can change your preferences at any time.
  • We have no third-party analytics, no advertising trackers, and no error-reporting services.

The rest of this policy is the detail behind those statements.


2. Our role and the Organization’s role

Regroot is software that Organizations use to manage their own members, volunteers, and events. Each Organization decides what information it collects in its Organization Space, who may access it, and how it is used. We host and process that information on the Organization’s behalf.

This means two parties handle your information, with different responsibilities:

  • The Organization decides why your information is collected and what it is used for. If you have questions about why an Organization asked for something, or you want it changed or removed, start with that Organization’s Administrator.
  • We provide and secure the infrastructure. We use your information only to operate the Service, as described in this policy.

If you cannot reach an Organization, or the Organization does not act, you can contact us directly at hello@ingenthron.us and we will help.


3. Information we collect

Information you provide

Required when you register: - Username - Email address

Optional: - Real name - Pronouns - Phone number

We encourage you to use an email address set up specifically for your Organization activity if you prefer to keep it separate from your personal or work email.

Other information you or your Organization enter: - Event sign-ups, attendance, and volunteer shift assignments - Your role and membership within an Organization Space - Notes, descriptions, and other content entered by you or by Organization staff - Your notification preferences and the consents you have given

Information about additional guests

An Attendee may register additional guests for an event. We collect only the number of guests. We do not collect names, ages, or contact information for them.

Information generated by the Service

Activity records. The Service records changes to data — what was changed, by whom, and when — and displays that history on the record that was changed. This helps Organizations understand who made a change and provides accountability for actions taken within a space.

Notification records. We keep records of notifications sent, including whether delivery succeeded, so that we can troubleshoot problems and calculate an Organization’s usage.

Server logs. Our web server keeps standard technical logs, which typically include IP addresses, timestamps, requested pages, and browser user-agent strings. We use these only to operate and secure the Service, diagnose faults, and investigate abuse.

Cookies. We use a cookie to keep you signed in, to save your preferences, and to protect against cross-site request forgery. We do not use advertising cookies, tracking pixels, or third-party analytics of any kind.

Information we do not collect

We do not collect payment card or bank information — Regroot does not process payments. We do not collect precise location data, health information, background check results, government identifiers, photographs, or biometric data. We do not buy information about you from data brokers or other outside sources.


4. How your information is protected and who can see it

What is encrypted

Information How it is stored
Real name Encrypted, with a separate key for each user
Email address Encrypted, with a separate key for each user
Phone number Encrypted, with a separate key for each user
Username Stored as ordinary text
Pronouns Stored as ordinary text

Your username and pronouns are readable within your Organization Space. Treat your username as public within your Organization, and choose one accordingly.

Who can see your contact information

  • You can always see and edit your own profile.
  • Administrators of an Organization you belong to can see your profile, including your real name and contact details, and can manage or delete your record.
  • Event organizers can see the profile information, including contact details, of Members and Attendees who have signed up for their events. If you sign up for an event, expect the organizer of that event to see your contact details.
  • Other Members cannot see your contact information.

There is no feature that lets an Organization browse, search, or download a list of member contact details in bulk. An Organization can send messages to its members through the Service without being shown their email addresses or phone numbers.

What we can see

We hold the means to decrypt your contact information. The Service must decrypt your email address or phone number in order to deliver a notification you have asked for. We want to be straightforward about this rather than imply the information is inaccessible to us.

We access decrypted information only to operate the Service, to troubleshoot a problem, to respond to a support request, or where the law requires it. Access is limited to personnel who need it for those purposes.


5. How we use your information

We use your information to:

  • Create and maintain your account, and authenticate you when you sign in
  • Operate the features of the Service — events, sign-ups, rosters, and scheduling
  • Send you notifications you have consented to receive
  • Send you essential account and security messages, such as password resets and notices about changes to the Service or these policies
  • Provide support when you ask for it
  • Keep the Service secure, investigate abuse, and enforce our Terms of Use
  • Calculate an Organization’s notification usage for billing
  • Comply with legal obligations

We do not use your information for advertising, sell or rent it, share it with data brokers, use it to train machine learning or AI models, or build profiles about you for any purpose outside the Service.


7. When we share information

We do not sell your information. We share it only in these situations:

Our hosting provider. The Service runs on infrastructure operated by a cloud hosting provider located in the United States. They store the encrypted data that makes up the Service but do not access it, and have no role in how it is used.

Our notification providers. To deliver messages, we transmit the message content and the recipient’s email address or phone number to our notification providers — currently SendGrid for email, and Twilio for text messages when that feature launches. They need the address to route the message. They act on our instructions and are not permitted to use that information for their own purposes.

Within your Organization. As described in Section 4.

Legal requirements. We may disclose information if we are required to by law, subpoena, court order, or other valid legal process, or where we believe in good faith that disclosure is necessary to protect someone’s safety, investigate fraud, or protect our legal rights. Where we are permitted to notify you first, we will.

Business transfer. If Ingenthron Engineering is acquired or its assets are sold, information may transfer as part of that transaction. We will notify Organizations and Members before information becomes subject to a different privacy policy, and you will have the opportunity to delete your account first.


8. How long we keep information

Your account. We keep your profile while your account is active. If you delete your account, your profile and contact information are removed from the Organization Spaces you belong to.

Records deleted by an Organization. When an Administrator deletes a record, it is removed from the live database.

When an Organization’s subscription ends:

  1. The Organization Space becomes inaccessible immediately.
  2. The live database is retained for up to 30 days, so the Organization can resume service.
  3. After 30 days, the live database is deleted. An encrypted archive is exported and stored offline for up to 12 months, so the Organization can resume service later.
  4. After 12 months, the archive is destroyed.

Backups. Backups are retained for a maximum of 30 days, then overwritten or deleted. Information you delete may persist in a backup or an offline archive until that copy expires on the schedule above. We do not restore individual records from backups on request.

Records we keep longer. We retain billing records and records needed to comply with legal obligations, resolve disputes, or enforce our agreements for as long as necessary for those purposes.


9. Your choices and rights

Whatever state you live in, you can:

  • See and correct your profile information at any time in your account settings.
  • Delete your account, which removes your profile and contact information from the Organization Spaces you belong to.
  • Change your notification preferences, or withdraw consent for any category of notification, at any time.
  • Ask us questions about how your information is handled, by writing to hello@ingenthron.us.

To exercise a right, start with your account settings. If what you need is not available there, or you cannot reach your Organization’s Administrator, email us at hello@ingenthron.us. We will respond within 45 days. We may need to verify your identity, which we will normally do by sending a confirmation to the email address on your account.

We will not deny you service, charge you a different price, or provide you a lower quality of service because you exercised a privacy right.

If you live in California

California residents have the right to know what personal information we collect and how we use it, to request access to it, to request correction or deletion of it, and to be free from discrimination for exercising these rights.

We do not sell personal information, and we do not share personal information for cross-context behavioral advertising. We have not done so in the preceding twelve months.

You may designate an authorized agent to make a request on your behalf; we will ask for proof of that authorization.

If you live in another state with a privacy law

Several states — including Colorado, Connecticut, Virginia, Texas, Oregon, and others — give residents similar rights of access, correction, deletion, and portability, and a right to appeal a decision we make about a request. We extend the rights described in this section to all our users regardless of state. If you are unhappy with how we handled your request, you may appeal by replying to our response, and we will review it and respond within 45 days.


10. Security

We take the following measures:

  • All traffic is encrypted in transit using HTTPS/TLS.
  • Real names, email addresses, and phone numbers are encrypted at rest, with a separate encryption key for each user.
  • Each Organization has its own separate database, so one Organization’s information is not commingled with another’s.
  • Role-based access control limits what each Member can see and do within an Organization Space.
  • Activity records capture changes to data and display them on the affected record.
  • We perform security hardening and testing on our servers.
  • We use no third-party analytics or error-reporting services, so your information is not sent to outside parties for those purposes.

Multi-factor authentication is not yet available. We plan to offer it. Until then, use a strong, unique password for your Regroot account — a password manager is the easiest way to do this.

No system is perfectly secure. We cannot guarantee that unauthorized access will never occur. If we become aware of a breach affecting your personal information, we will notify you and any affected Organization without undue delay, and as required by applicable law.


11. Children

Regroot is not intended for anyone under 18, and you must be 18 or older to create an account. We do not knowingly collect personal information from anyone under 18.

An adult Attendee may register additional guests for an event, including minors, but the Service records only the number of guests — no names, ages, or contact information.

If you believe someone under 18 has created an account, or that identifying information about a minor has been entered into the Service, contact us at hello@ingenthron.us and we will delete it.


12. Where your information is held

Regroot is offered only in the United States, and all information is stored on servers in the United States. The Service is not designed for use outside the United States and does not comply with the data protection laws of other countries. Do not use the Service from outside the United States.


13. Changes to this policy

We may update this Privacy Policy. When we do, we will change the “Last updated” date at the top.

If a change materially affects how we handle your personal information, we will notify you by email or through the Service at least 30 days before it takes effect, so you can review it and close your account if you disagree.


14. Contact us

Questions, concerns, or requests about your information:

Ingenthron Engineering, LLC 5312 Barcelona Street Orlando, Florida 32807 hello@ingenthron.us

If your question is about information an Organization has collected about you, contacting that Organization’s Administrator will usually get you an answer faster. If that does not work, write to us.