Rally ("we", "us", or "our") provides a group scheduling service that helps you find times that work for everyone in your circle. This Privacy Policy explains what information we collect, how we use it, and what choices you have.
By using Rally, you agree to the practices described in this policy.
We do not use your information for advertising. We do not sell your data.
We share the minimum data necessary with the following service providers. Each named provider publishes its own privacy policy.
| Service | Purpose | Data shared |
|---|---|---|
| Clerk | Authentication (sign-in, sign-up, account management) | Email, name, authentication tokens |
| Hosting provider (self-managed servers) | API runtime and database storage | All API traffic (request/response payloads), and all user content (circles, events, responses, optional coarse ETA, optional recap participation) |
| Resend | Transactional email (event invites, RSVP reminders, account deletion/restoration warnings) | Recipient email and the minimum content for that message; account lifecycle warnings contain only the deadline/state and no circle or event content |
| Apple / Google device location services | User-initiated foreground positioning and on-device geocoding | Current device location and organizer-entered place query, only after Share rough ETA is chosen |
| Apple MapKit / Google Maps SDK (in-app map) | Renders the map used to pick an event place while creating an event | Map view coordinates requested for display, and the chosen place coordinates. No background or continuous location. |
| Expo | Opt-in push notification delivery | Expo push token and privacy-minimized notification content |
| PostHog | Product analytics and API error monitoring | Anonymous product events with a random analytics identifier; no Rally account ID or profile fields; API error diagnostics |
| Sentry | API and mobile error monitoring, plus mobile performance monitoring | API and mobile exception messages and stack traces, app/device version, fixed or templated route/navigation context, status, and random request IDs. Rally does not attach account or profile fields; dependency exception text may contain unexpected values. |
Rally's hosting infrastructure processes API traffic, including ordinary connection metadata, at the infrastructure boundary; the application-level limits above do not claim that hosting infrastructure receives no network metadata.
The following table summarizes the data we collect. This is the same information you'll see in the Google Play "Data Safety" section.
| Data type | Collected | Shared | Optional | User can delete? |
|---|---|---|---|---|
| Email address | Yes | Yes | No | Yes |
| Circle invitation recipient email | Yes | Yes | Yes | Yes |
| Display name | Yes | Yes | No | Yes |
| Circle names and colors | Yes | Yes | No | Yes |
| Circle membership | Yes | Yes | Yes | Yes |
| Event titles, descriptions, locations, time slots | Yes | Yes | No | Yes |
| Availability responses (name, optional email/note, authenticated organizer response) | Yes | Yes | No | Yes |
| Optional on-my-way status | Yes | Yes | Yes | Yes |
| One-time approximate ETA location | Yes | Yes | Yes | Yes |
| Event place coordinates chosen by the organizer | Yes | Yes | Yes | Yes |
| Optional self-confirmed recap attendance | Yes | Yes | Yes | Yes |
| Push notification preferences | Yes | No | Yes | Yes |
| Expo push token | Yes | Yes | Yes | Yes |
| Anonymous pages viewed and buttons tapped, not linked to your Rally account | Yes | No | No | No |
| Exception messages and stack traces; app/device version; fixed or templated operation/route labels; status and request IDs | Yes | No | No | No |
| Transient apparent network address | Yes | Yes | No | No |
| Device model, OS version, app version | Yes | No | Yes | No |
We keep active-account data for as long as the account is active. A deletion request has one stored deadline exactly 30 days later. The recovery deadline does not move if the scheduler runs late: restoration is refused at or after that exact time, and the bounded scheduler retries physical purge until both the Clerk identity and Rally account are gone. Anonymized analytics may be retained longer in aggregate form.
Pending circle invitations are removed when accepted, declined, cancelled, expired after 30 days, or immediately when the matching account requests deletion. A non-owner membership, authenticated response, and self-confirmed recap participation move out of live product views during the recovery window; surviving related circles/events restore those durable rows if the account is restored. On-my-way status and shared coarse ETA, push tokens/preferences, notification jobs/history, and invitations are removed immediately and never restored. Outside deletion requests, push tokens are removed when the current device is removed, on successful sign-out, when Expo reports the device unregistered, or when account-wide push is disabled. A sole-member circle is hidden from public links during recovery; a circle transferred to another member stays with its new owner even if the account returns. Anonymous rate-limit state exists only in API process memory for the active window (at most one hour); a deployment restart can remove it earlier.
We take reasonable measures to protect your data:
No system is perfectly secure. If you discover a security issue, please email support@kazman.uk.
Rally is intended for adults aged 18 and over. Because Rally can share a live location and ETA with a meetup's members, we set the minimum age at 18 as the lowest legal surface for location sharing. We do not knowingly collect data from anyone under 18. If you believe someone under 18 has provided us data, contact us at support@kazman.uk and we will delete it.
We may update this policy from time to time. We will post the updated policy here and update the "Last updated" date. Material changes will be communicated through the app.
If you have any questions about this policy, contact us at support@kazman.uk.