Privacy
Last updated: 2026-08-03
GetRallied is built by a small team and we keep things simple. Here's what we collect, why, and what we do with it.
What we collect
- Account info: the email address and name you provide when you sign up, plus an optional profile photo.
- Event content: anything you create — event titles, vision statements, tasks, locations, banners, organizer name and email.
- Claim info: when you claim a task, we store your name, email, and any optional phone or note you provide so the organizer can coordinate.
- Authentication state: a signed cookie for web sessions, or an opaque bearer token for the mobile app. Tokens are hashed (SHA-256) before storage.
- Mobile device data: an optional device label and Expo push token so we can deliver claim decisions, event updates, and reminders.
- Location: if you choose “Near me” in the mobile app, your current coordinates are sent to GetRallied to return nearby public events. We do not store those coordinates in your account or location history.
- Operational logs: request IPs and basic security events (failed logins, password resets) for rate limiting and abuse prevention. Server errors are forwarded to Sentry.
- Safety reports and blocks: if you report an event, we store the reason, optional details, your account ID, and our review decision. If you block an organizer, we store that preference so their events stay hidden from you.
How we use it
- To operate the service (show you the events you organize, the tasks you've claimed, send confirmation emails).
- To send transactional emails (sign-in links, claim confirmations, organizer notifications) via Postmark.
- For AI task breakdown, your event vision text is sent to OpenAI's API. OpenAI does not use API data for model training.
- To geocode event locations via OpenStreetMap Nominatim.
- To deliver mobile notifications through Expo and Apple Push Notification service.
- For nearby-event discovery, current coordinates are used only to answer that request; we don't retain a location history or infer location from your IP address.
- To screen public content, investigate reports, enforce our Terms, and protect people from abusive or illegal material.
What we don't do
- We don't sell your data.
- We don't run third-party advertising or behavioral tracking.
- We don't share your info with anyone except the strictly transactional services listed above.
Storage
Data is stored in Neon (Postgres) hosted in AWS US-West. Uploaded images live in Cloudflare R2. The application runs on Railway.
Deletion
You can delete your account at any time from your account page or the Account tab in the mobile app. This removes your account record, authentication and push tokens, your claim history, and all events you've created (including their tasks, claims, and updates).
Children
GetRallied is not directed at children under 13 and we don't knowingly collect data from them. If you believe a child has signed up, email [email protected].
Changes
If we materially change this page, we'll update the date at the top. Substantial changes affecting your data will be communicated by email to active organizers.
Contact
Questions or requests: [email protected].
← Back to home