Who we are
Rootlynq is a connectivity diagnostics product. The operating legal entity and data controller is Hexorium Inc, 1610 Avion St, Big Spring, Texas 79702. Brand roles (Rootlynq, Helios, Hexium, Hexorium) do not by themselves identify the contracting entity.
The short version
No account is required.
There are no advertising trackers and no behavioral analytics.
Rootlynq has no cloud report database; saved reports stay in your browser.
Opening Test requests the Cloudflare measurement node location; speed measurements wait until you press Start.
Resolve can be used before any test. Helios receives only the technician message you choose to send and recent conversation context; those statements are user-reported context, not measurements.
If a Rootlynq Test or optional Diagnose evidence exists, Resolve can attach that sanitized evidence to the Helios conversation automatically so Helios can use what is already known and recommend another measurement only when it would materially help.
When you open a page
Lovable hosts the application and processes ordinary request metadata such as your IP address, browser user agent, the page requested and timestamps to serve the site. When you open Test, your browser makes a small request to Cloudflare Speed Test to identify the measurement node before you press Start. Cloudflare receives your connecting IP address and ordinary request metadata. This request may also return the provider, ASN and approximate IP-derived location of the path Cloudflare sees. If that endpoint does not return a node code, Rootlynq requests Cloudflare's edge trace and reads its node code without using its IP field. No download, upload or latency speed test runs until you press Start.
When you start the connection test
Your browser sends bounded measurement traffic — with a configured request budget capped at about 250 MB — through Cloudflare's measurement transport at speed.cloudflare.com. Rootlynq's own clean-room browser engine controls the 8-second response, download and upload windows, adaptive parallel transfers, latency/jitter sampling, loaded-latency sampling and final throughput calculation. Standard mode can scale to multiple concurrent transfers; Single mode keeps one worker for comparison. The primary engine does not call Cloudflare's measurement-result or final AIM logging APIs.
Rootlynq refreshes the Cloudflare measurement-path metadata when the test starts. It can return the Internet-facing ASN, provider organization, measurement node and an approximate city/region/country for the path Cloudflare sees. Separately, after Start, a same-origin Rootlynq endpoint can display the public IP visible to rootlynq.com and use that address in a server-to-server standards-based RDAP query to obtain the registered network organization/name. When Safari Private Relay, WARP, a VPN/proxy, carrier gateway or another intermediary is in use, either path can describe an egress network rather than the subscriber network. Rootlynq labels detected Cloudflare privacy/WARP paths accordingly and never presents a relay exit city as your device location. When you press Start, Rootlynq can first offer an optional device-location step. Your browser's location permission prompt appears only if you choose Use location. Precise device coordinates stay in page memory only and are not saved in reports, exported, or sent to Helios. To show a human-readable city/state label, Rootlynq rounds latitude/longitude to two decimal places in the browser before any network request is created, then sends only that rounded city-scale point through Rootlynq's server to OpenStreetMap Foundation Nominatim. The precise coordinates never leave the page. If you skip or deny location, the connection test continues normally.
The Test card may show the full public IP that Rootlynq actually observes so you can verify the path, but the value stays in page memory and is excluded from saved/exported reports, copied support text, shared summaries and Helios evidence. If Safari Private Relay hides the direct provider, Rootlynq may explain Safari's per-site Show IP Address control; Rootlynq does not use WebRTC, WebTransport or another bypass to defeat Private Relay.
Optional Deep Diagnosis
Deep Diagnosis is a separate user-triggered step after a Standard adaptive test. It can add up to about 30 MB of Cloudflare measurement traffic to compare one real HTTP transfer with the multiple-connection result.
It also measures first-party web responsiveness against Rootlynq itself. The optional first-party probe.rootlynq.com alias is used to create a separate origin for DNS, TCP and TLS setup timing. If that alias is unavailable, or the browser does not expose a fresh setup, those values stay unknown instead of being displayed as 0 ms.
When configured, v4.rootlynq.com and v6.rootlynq.com are first-party A-only and AAAA-only probe aliases used only to compare IPv4/IPv6 HTTPS reachability and elapsed request time. They do not provide ICMP ping or traceroute.
Deep Diagnosis does not add a new third-party measurement provider.
Optional real-time quality test
The Real-time quality test uses Cloudflare Speedtest's TURN-based UDP round-trip probe for packet loss and a separate silent synthetic WebRTC audio path for jitter and RTC round-trip time. It does not request microphone or camera permission and does not send your voice, video or device media.
Rootlynq obtains short-lived TURN credentials through its server and Hexium; the long-lived Cloudflare TURN key is never sent to your browser. The synthetic WebRTC leg forces relay transport so its jitter and RTT describe the relayed real-time path rather than a local browser-to-browser shortcut.
Cloudflare's TURN service necessarily sees the network address used to create the relay. Rootlynq keeps the resulting quality metrics in page memory and includes only the sanitized metrics — not TURN credentials or raw ICE candidates — in the optional Helios evidence bundle.
What stays on your device
Saved reports: at most 20, each deleted automatically after 30 days, stored in your browser's local storage.
Active troubleshooting case: the current report, optional user-reported symptom/context, recent Helios conversation turns, and bounded test history are kept in session storage so Test, Diagnose and Resolve can work as one case. Closing the browser session can clear this active-case state depending on browser behavior.
Preferences: speed unit, motion, connection mode and whether to show approximate location.
You control copy, export (JSON), import (up to 256 KB) and deletion from Results, Reports and Settings.
An offline application-shell cache may be used by the browser when the installable app is enabled.
Fields intentionally excluded from reports
Full or partial IP address, device-location coordinates, SSID, BSSID, local IP addresses, MAC addresses, device identifiers, city and ASN are never written into saved or exported reports.
Browser measurement limits
A browser cannot read Wi-Fi signal, router state, the operating system's DNS resolver state, or other devices on your network. The standard browser speed test also does not provide true packet-loss telemetry. Rootlynq can optionally measure packet loss, jitter and RTT on a synthetic WebRTC/TURN path; those values describe that RTC path only and do not identify where loss occurred.
Helios
Resolve is a conversation with Helios and does not require a completed Test. A server-side Rootlynq proxy sends the message you choose to submit plus a bounded recent technician transcript to the governed Helios runtime.
When a live Rootlynq case exists, the same request can also carry the strict sanitized evidence bundle: network metrics, the deterministic diagnosis, layer assessments, unknown-field names, and any guided-comparison, Deep Diagnosis, real-time quality, or verification summary. Conversation text remains user-reported context rather than measured telemetry. The interface asks you not to enter passwords, account numbers or precise addresses.
If you run Deep Diagnosis, the sanitized bundle may also include the Deep Diagnosis metrics shown on screen: first-party web response timing, single-transfer versus aggregate ratios, loaded-latency deltas, and IPv4/IPv6 family-path timing/status when available. If you run the optional real-time quality test, Helios may also receive its packet-loss percentage, jitter, RTC round-trip time and relay-status result.
The Helios evidence schema excludes full public IP, SSID, BSSID, MAC or local IP, precise coordinates, report IDs, TURN credentials, raw ICE candidates and raw device identifiers. Helios may explain evidence, ask a bounded follow-up question, rank competing supported hypotheses, choose the next discriminating test and identify when the case is ready for escalation, but it cannot convert an unavailable measurement into a fact or replace Rootlynq's deterministic evidence boundary.
Your rights
See Privacy Rights for how to request access, correction or deletion, and how appeals work. Because reports are stored only in your browser, you can delete them yourself at any time in Settings.
Contact and changes
Privacy questions: support@rootlynq.com. Effective September 27, 2026; last updated September 28, 2026. We will update this notice before adding accounts, cloud report storage, analytics or any new data recipient beyond the disclosed measurement and Helios reasoning services.
Rootlynq