RootlynqTrust & Legal
Providers
Every external service Rootlynq contacts, when, and what it can see. Generated from the audited data-flow inventory.
Lovable (application hosting)
- Hostname
- rootlynq.com (Lovable-hosted site)
- Service
- Application hosting and content delivery
- Purpose
- Serve the Rootlynq application
- Trigger
- Opening any page
- Data involved
- Ordinary request metadata: IP address, user agent, requested URL, timestamps
- Destination
- Lovable hosting infrastructure
- Retention
- Lovable privacy policy and workspace settings
- Privacy policy
- https://lovable.dev/privacy
Browser / device Location Services
- Hostname
- Browser API (no Rootlynq network destination)
- Service
- Optional browser geolocation requested only after an explicit Rootlynq pre-permission choice and the browser's own permission prompt.
- Purpose
- Provide the browser's device position for the active page so Rootlynq can distinguish physical test location from an IP relay, VPN, carrier gateway, or ISP egress location.
- Trigger
- Only after the user presses Start and then chooses Use location.
- Data involved
- Precise latitude, longitude and browser-reported accuracy stay only in page memory. Before any city-label network request is created, the browser rounds latitude/longitude to two decimal places (roughly city scale). Precise coordinates are never written to reports, local/session storage, exports, Cloudflare metadata requests, OpenStreetMap requests, or Helios evidence.
- Destination
- Precise coordinates: page memory only. A separately derived two-decimal rounded point may be sent to Rootlynq's same-origin city-label endpoint after Use location.
- Retention
- Precise coordinates: Rootlynq page memory only
- Privacy policy
- /privacy
OpenStreetMap Foundation Nominatim
- Hostname
- nominatim.openstreetmap.org (server-to-server from Rootlynq)
- Service
- Optional reverse geocoding of a browser-rounded two-decimal point into a human-readable city/region label.
- Purpose
- Display a city/state or equivalent locality label without exposing the browser's precise device coordinates to the geocoder.
- Trigger
- Only after the user presses Start, chooses Use location, grants browser location permission, and Rootlynq has rounded the coordinates in the browser.
- Data involved
- Only latitude/longitude rounded to two decimal places (roughly city scale) is forwarded server-to-server. The precise browser coordinates never leave the page. OpenStreetMap sees Rootlynq's server request rather than the browser's direct geolocation request. Rootlynq returns only the human-readable locality label to the page and does not save it in reports or send it to Helios.
- Destination
- OpenStreetMap Foundation Nominatim via Rootlynq server
- Retention
- OpenStreetMap Foundation privacy policy; Rootlynq keeps only an in-memory short-lived cache of the returned locality label by rounded cell.
- Privacy policy
- https://osmfoundation.org/wiki/Privacy_Policy
Rootlynq hosting edge + IANA/RIR RDAP + RDAP.org fallback
- Hostname
- rootlynq.com; data.iana.org; authoritative Regional Internet Registry RDAP endpoint; rdap.org (fallback bootstrap only)
- Service
- Same-origin endpoint reads the hosting edge's trusted client-IP header after Start. For a non-relay address, the server uses the IANA RDAP bootstrap file to select the authoritative Regional Internet Registry and retrieves the registered network organization/name. If that standards path is temporarily unavailable, Rootlynq may use RDAP.org only as a bootstrap fallback; RDAP.org redirects the query to the authoritative registry.
- Purpose
- Show the public IP and registered network/provider visible to Rootlynq independently from the Cloudflare speed-test path. Known Cloudflare Private Relay addresses are labeled locally; Rootlynq offers Safari's supported per-site Show IP Address workflow instead of bypassing privacy protections.
- Trigger
- Only after the user starts a Test or explicitly refreshes the network identity card.
- Data involved
- The public IP already present in the HTTPS request is returned to the active page for display. For non-relay addresses, that IP is used in a server-to-server RDAP lookup via the IANA-selected authoritative RIR; if that path is unavailable, the same IP may be sent to RDAP.org as a bootstrap fallback and then redirected to the authoritative registry. Rootlynq does not write the full IP, network identity or device-location label into saved/exported reports or Helios evidence.
- Destination
- Rootlynq application server; IANA RDAP bootstrap; authoritative Regional Internet Registry; RDAP.org only as fallback bootstrap
- Retention
- Rootlynq keeps the identity in page memory and may keep short-lived in-memory caches of bootstrap/RDAP organization results. RDAP.org states that individual queries are not logged, while Cloudflare may aggregate source IP data for rate limiting; registry operators apply their own policies.
- Privacy policy
- https://about.rdap.org/
Cloudflare Speed Test
- Hostname
- speed.cloudflare.com
- Service
- Cloudflare Speed Test metadata endpoint (/meta) plus same-host trace metadata, returning the Internet-facing client IP, ASN/provider organization, edge colo, approximate IP-derived city/region/country, and WARP state when exposed by trace.
- Purpose
- Describe the address/path visible to the Cloudflare measurement service, including relay/proxy state and the selected Cloudflare test location. This remains separate from Rootlynq's same-origin direct-network identity.
- Trigger
- When the Test page opens, to show the measurement node before Start, and again when the user starts a connection test, Retest, Verify fix, or an explicit diagnostic comparison.
- Data involved
- Connecting address and ordinary request metadata. Cloudflare can return provider/ASN and approximate IP-derived location for the path it sees; with Safari Private Relay this can be a relay egress rather than the subscriber network. The full value stays page-memory-only and is excluded from reports and Helios evidence.
- Destination
- Cloudflare
- Retention
- Cloudflare privacy policy
- Privacy policy
- https://www.cloudflare.com/privacypolicy/
Cloudflare measurement transport
- Hostname
- speed.cloudflare.com
- Service
- Rootlynq clean-room browser capacity engine using bounded adaptive concurrent transfers against Cloudflare's documented /__down and /__up measurement transport, plus Rootlynq-owned latency, jitter and loaded-latency sampling. Cloudflare's JavaScript speed-test SDK is not used for the primary capacity result.
- Purpose
- Measure idle response/jitter, aggregate download/upload capacity and response while busy. Standard mode scales from a warm-up estimate to as many as eight concurrent workers; Single mode keeps one worker. Response, download and upload each retain a fixed 8-second visible window.
- Trigger
- Only after the user starts the connection test, Retest, Verify fix, or an explicit diagnostic comparison.
- Data involved
- Connecting network address, request metadata and bounded measurement traffic (standard Test configured request budget capped at about 250 MB; optional Deep Diagnosis may add up to about 30 MB). Rootlynq does not post the primary measurement result to Cloudflare measurement-result or AIM logging APIs.
- Destination
- Cloudflare
- Retention
- Cloudflare privacy policy
- Privacy policy
- https://www.cloudflare.com/privacypolicy/
Hexium Helios
- Hostname
- hexium-ai-production.austin-d-gomez-mil.workers.dev (server-to-server from Rootlynq)
- Service
- Governed Rootlynq technician conversation and diagnostic reasoning
- Purpose
- Let customers talk to Helios before or after testing, use any attached Rootlynq evidence, recommend Test or optional Diagnose measurements only when useful, guide safe troubleshooting, and prepare support-ready escalation.
- Trigger
- Only when the user explicitly interacts with Helios in Resolve, or when an existing governed diagnostic reasoning flow is invoked after measurement. A Rootlynq Test is not required before conversation starts.
- Data involved
- The user's bounded Resolve message and recent Rootlynq technician conversation context. If a Test/Diagnose case exists, the request can also include the sanitized diagnostic evidence already attached to that case. User-reported text is not measured telemetry. Full public IP, SSID, BSSID, MAC or local IP, precise location, report ID, TURN credentials, raw ICE candidates, passwords, account numbers, and raw device identifiers are excluded by schema or explicitly discouraged in the interface.
- Destination
- Canonical Hexium Helios production Worker
- Retention
- Rootlynq keeps the active technician transcript in browser session storage rather than a Rootlynq cloud report database. Server-to-server Helios/provider processing follows the Hexium AI runtime policy.
- Privacy policy
- https://hexorium.io/privacy
Rootlynq first-party probe aliases
- Hostname
- probe.rootlynq.com, v4.rootlynq.com and v6.rootlynq.com
- Service
- First-party HTTPS timing aliases: a fresh-origin setup probe plus A-only and AAAA-only family reachability probes
- Purpose
- Measure Rootlynq web response behavior, expose DNS/TCP/TLS setup only when a fresh first-party connection is observable, and compare IPv4/IPv6 HTTPS reachability when family-specific aliases are configured
- Trigger
- Only when the user explicitly runs Deep Diagnosis after a standard diagnosis
- Data involved
- Ordinary HTTPS request metadata to Rootlynq hosting. The client retains only request timing/status evidence; probe hostnames and raw timing samples are excluded from the Helios evidence bundle.
- Destination
- Rootlynq/Lovable hosting through first-party family-specific aliases
- Retention
- Same hosting policy as rootlynq.com
- Privacy policy
- https://rootlynq.com/privacy
Cloudflare Calls TURN via Hexium credential broker
- Hostname
- turn.cloudflare.com / stun.cloudflare.com (short-lived ICE session)
- Service
- Optional TURN-based UDP packet-loss measurement plus relayed synthetic WebRTC quality measurement
- Purpose
- Measure TURN round-trip UDP packet loss and, separately, jitter and WebRTC round-trip time on a silent synthetic audio path without microphone or camera access
- Trigger
- Only when the user explicitly runs the Real-time quality test, or accepts Helios' rtc_probe next-test action
- Data involved
- TURN connection metadata, purpose-built UDP probe traffic, and synthetic RTP traffic. Rootlynq sends no microphone, camera, SSID/BSSID, precise location, report ID, TURN credential, or raw ICE candidate inside the Helios evidence payload. The TURN provider necessarily observes the network address used to establish the relay.
- Destination
- Cloudflare Calls TURN; short-lived ICE credentials are generated server-side by the Hexium production Worker
- Retention
- Cloudflare Calls and Hexium operational policies apply; Rootlynq does not persist TURN credentials or raw WebRTC stats beyond the active page session
- Privacy policy
- https://www.cloudflare.com/privacypolicy/
Not contacted
- ipwho.is and commercial IP-geolocation/ISP lookup services (not used)
- fonts.googleapis.com / fonts.gstatic.com (removed; system fonts only)
- Advertising or analytics services (none)
- Any device-location request before the user explicitly chooses Use location (never)