TL;DR
A privacy-first transit tool.
We don't collect names, passwords, or advertising identifiers, and we set no analytics cookies. Our analytics do keep a random identifier in your browser so we can tell a repeat visit from a new one; it isn't linked to your name or email, and it is never shared with another site. Route queries and AI chat messages are processed and then discarded. The only things we keep are what you deliberately send us: a waitlist or developer-API email, a bug report, or route feedback. If you join the waitlist or sign up for an API key, our provider Clerk may set its own cookies. Anything you post to our public feedback board is kept by UserJot, who runs it, and is visible to other riders. See “UserJot” below.
The main thing to know while we're in beta: we record session replays of how the app is used, so we can find and fix the rough edges. A replay is an unmasked recording of your screen, kept for 30 days. It shows on-screen activity, taps, clicks, mouse movement and what you type, including the addresses you enter and the place names we show back to you. It shows the map as drawn, including your live position while navigating. Replays are not labelled with your name unless you are signed in, but they are not anonymous in any strong sense: someone watching one can see where you were going. Only password fields and the trip suggestion card are hidden. If you would rather not be recorded, a tracker blocker will stop it, and you can email us to have your recordings deleted. See “Third-party services” below for the detail.
- No ad tracking
- No accounts
- Queries discarded after use
- Kept data stored in Canada
Reroute is in active beta. This policy reflects our current practice, but because the app is still being iterated on, we may update this page. Material changes will be surfaced on the app itself.
What we collect
localStorage and never leave your device. Your conversation with Miles is kept there too — your questions, its answers, the result cards it showed and the routes it drew — for up to 24 hours or your last 12 exchanges, so the thread is still there if you come back to the tab; “Clear conversation” erases it immediately. Saved places and saved trips are also browser-local while you are signed out; signing in syncs them to your account (see “Account” below). If you are signed in, whole Miles chats (not just the one open in your browser) are also saved to your account — up to your last 30 — so you can reopen an earlier conversation from the history icon and pick up where you left off, on any device. You can delete any saved chat from that same history list.localStorage, so that repeat visits can be counted as one person rather than as several strangers. It is not a cookie, it is not derived from anything about you or your device, it is never shared with another site, and clearing your browser's site data for Reroute erases it and starts a new one. We use it to answer questions like whether people who find a guide page come back, not to build a profile. If you sign in, the identifier is linked to your account id so we can count you as one person across devices. The link carries the account id only, never your email or name, and signing out stops linking further events.What we don't collect
- No email required to use routing (the waitlist and API sign-up collect one; see above).
- No passwords, ever. An account is optional, and signing in uses email verification codes via Clerk.
- No advertising identifiers or cross-site tracking.
- No analytics cookies, and no identifier that follows you off this site. Our analytics identifier is stored in your browser, is specific to Reroute, and is erased when you clear site data; see “Analytics identifier” above. Session replay uses a separate identifier that lasts only as long as that browsing session; see “Third-party services” below.
- No coordinates, street addresses, or search text in your trip stats: only place labels, transit lines and station IDs, and route metrics. See “Trip stats (for your Wrapped)” above, which replaces our earlier “no trip history” claim now that Wrapped collection is live; it's on by default with a Settings toggle and delete-all.
- No payment or card information. We have no payment processor; see billing in our Terms.
Data retention
Route queries and AI chat messages are used to answer your request and then dropped. Live-navigation location is held in memory only and cleared within about fifteen minutes of your trip ending or your device disconnecting (six hours at the outside).
Waitlist and developer-API emails, route feedback, your account's saved places and trips, and your signed-in trip stats. We keep these until you remove them, delete your history in Settings, or request their removal. Bug reports are also kept this way but expire on their own after about 180 days.
Beta session replays. They expire on their own; you can also email us to have them removed sooner.
Preferences and recent places stay until you clear your site data. Saved places and trips stay browser-local too unless you sign in and sync them.
To delete a developer key, or any bug report or feedback you sent us, email privacy@rerouteapp.ca. A bug report is kept until you ask us to delete it or for about 180 days, whichever is sooner; for up to a further 35 days after that, a copy can still exist in an encrypted backup before it is purged too. Trip stats recorded while you're signed out are keyed to a random device identifier and automatically expire after about 16 months; deleting them sooner is one tap in Settings → Trip history, for either an anonymous device or a signed-in account.
Third-party services
To compute routes, render maps, power AI chat, and keep the app healthy, Reroute relies on the services below. We disclose them so you can review their policies directly:
localStorage so repeat visits count as one person; see “Analytics identifier” above. We count page visits and a small set of anonymous product events (for example, that a route search happened, that a navigation session started, diagnostic signals such as a navigation session reloading mid-trip on a device, or that a bug report was submitted and how it was triaged). These named events never include locations, addresses, or your message or bug-report content. Until September 2026 we also stripped the query parameters off every URL we sent; we no longer do, so a page address that carries a shared trip in its link reaches PostHog whole. IP-based location lookup stays disabled. If you sign in, events are additionally linked to your account id (never your email or name) so usage can be counted per person across devices. Since August 2026 that event set also includes the onboarding funnel (started, each step completed by name, finished, or skipped), a mark for each one-time live-map coach mark shown, the guided tour (started, finished, or skipped along with which step number you were on when you skipped), and the Trip History toggle and delete actions. None of these carry any trip content. Since September 2026 it also records the moment you press a sign-in button, with two coarse labels and nothing else: which provider you chose (Apple, Google, or “modal” when the choice happens inside the sign-in window) and where you pressed it (during onboarding, from the account button, from the one-time reminder that offers to sync a trip or place you just saved, or from the rider report sheet at the moment you send a report, a surface that is not visible to riders yet; see “Rider reports” above). Never your email or your name, and never the category you were reporting, and never which trip or place prompted the reminder. When Miles carries out something you asked for (showing a route, opening a screen, saving a place), we record which kind of action it was and whether you had to confirm it, never the words you used or the place, note or bug description behind it. When you ask Miles something out loud we record that one spoken question happened: how you started it (the microphone button, the “Hey Miles” phrase if you have turned that on, or a shortcut that opened Reroute with your question already in the link), whether your phone answered it by itself from your trip's own progress or the assistant answered it, which of a short list of trip questions it was (time left, arrival time, next step, or stopping navigation) when your phone answered it, and whether the answer arrived within ten seconds. Never what you said, and never the answer. If you turn on “Listen for Hey Miles” and Reroute hears the phrase but you then say nothing, we record that one such moment happened and which of two things it was: the microphone opened and closed with nothing said, or the question had nowhere to go. Never any audio, never any words, and never anything about what you were doing at the time. In the Reroute phone app the phrase is listened for and recognised on your phone itself, and no audio leaves your phone while it listens; what you say to Miles after the phrase is processed by your phone's own speech service, as anything you say into its microphone button is. In a web browser your speech is processed by your browser's own speech service. When Miles asks you a question back, the app may open the microphone by itself for about six seconds so you can answer without reaching for it, and your answer goes to the same speech service; the only thing we record about that is whether it was answered. Never what you said, never what Miles asked, and never how long you took. A link that carries a question for Miles in its address, which is how those phone shortcuts hand one over, counts as a question you asked out loud and is recorded the same way. When you pick a search suggestion we record which kind of row it was (a station, a landmark, an address, a transit line, a recent place), its position in the list, how many characters you had typed and whether you were online; when a search comes back empty we record how many characters you had typed and how many of our sources failed. Never the text you typed and never the name of the place. When you open a station, stop or place card, we record a “place card opened” event with only three things: which kind of card it was, where you opened it from (the map, search, the Nearby list, or another card's “Getting there” list) and, for a place, whether we found its details. Never the name of the station or place, and never where it is. Six categorical onboarding answers (age range, whether you have a car, how often you drive, the modes you use, why you use Reroute, and how you found us) plus which days you commute are attached to your analytics identifier as person properties, never your name, and never Home/Work; see “Onboarding profile” above. Events are processed in PostHog's US region. PostHog Privacy PolicylocalStorage: which product update you last read, and the id of our board. Neither is a visitor identifier and neither follows you to another site. If you post a request, a comment or a vote, what you write (along with any screenshot you choose to attach, and the name or email you give UserJot) is stored by UserJot, and posts on the board are public to other riders by design. We never pass it your Reroute account, name or email: the widget is anonymous to it unless you sign in to UserJot yourself. Submissions are processed in the United States. To remove something you posted, contact UserJot or email us and we will take it down. UserJot Privacy PolicyInternational data transfer
Some of these providers are based in the United States. Mapbox, Google, Clerk, Sentry, PostHog, and UserJot process your request data in the US under their own privacy policies. Data we store ourselves (developer keys, bug reports, and feedback) is held in AWS's Canada Central region. By using Reroute, you understand that your request data may be processed outside Canada.
Non-affiliation
Reroute is operated by Reroute Technologies Inc, an independent company, and is not affiliated with, endorsed by, or sponsored by TTC, GO Transit / Metrolinx, YRT, MiWay, Brampton Transit, Durham Region Transit, UP Express, the City of Toronto, or any other transit agency. Agency names and logos are used descriptively for service identification only.
Your choices & rights
- Clear your browser's site data for Reroute at any time to wipe all local state.
- Skip granting geolocation permission if you'd rather type your origin manually.
- Opt out of beta session replay with any tracker blocker, or email privacy@rerouteapp.ca to have your recordings deleted before they expire.
- Revoke or delete a developer API key, or ask us to delete a bug report or feedback you submitted, by emailing privacy@rerouteapp.ca.
- Stop using the app. There's no account to delete.
Contact
Questions about this policy, or a data request? Email privacy@rerouteapp.ca. For anything else, reach us through the social links in the site footer.