We don't collect names, passwords, or advertising identifiers, and we set no analytics cookies. Our analytics do keep a random identifier in your browser so we can tell a repeat visit from a new one; it isn't linked to your name or email, and it is never shared with another site. Route queries and AI chat messages are processed and then discarded. The only things we keep are what you deliberately send us: a waitlist or developer-API email, a bug report, or route feedback. If you join the waitlist or sign up for an API key, our provider Clerk may set its own cookies.
One thing to know while we're in beta: we record anonymous session replays of how the app is used, so we can find and fix the rough edges. That means on-screen activity, clicks, mouse movement and typing, kept for 30 days. Addresses you type are masked out before the recording leaves your browser. Replays run on desktop only; we do not record sessions on phones or other touch devices. See “Third-party services” below for the detail.
No ad tracking
No accounts
Queries discarded after use
Kept data stored in Canada
Reroute is in active beta. This policy reflects our current practice, but because the app is still being iterated on, we may update this page. Material changes will be surfaced on the app itself.
What we collect
Route queries
The origin and destination coordinates you enter, plus any filters (mode, agency, departure time). These are processed by our backend to generate route options and are not retained after the response is returned.
Location
If you allow it, your device location is used once as a starting point or for proximity. During live turn-by-turn navigation only, your GPS position is streamed to our server so we can guide you; it is held in memory for that session and discarded when the session ends (within about 10 minutes). We do not store your location history.
AI chat
Your message, recent chat history, and an optional context block (your current route, rough location, and preferences) are sent to Google Gemini to generate a reply. They are not stored on our servers.
Browser-local state
Preferences, recent search places (with coordinates and labels), saved places, saved trips, map layer settings, and dismissal flags are stored in your browser's localStorage. They never leave your device.
Waitlist email
If you join the waitlist, your email address is collected via Clerk and stored for early-access notification only. It is not used for marketing or shared with third parties.
Developer API email
If you create an API key, we store your email address, a one-way SHA-256 hash of the key (never the key itself), your plan, and a creation timestamp, so we can issue and manage the key and meter usage. Usage metering is a daily request count per key; it does not record your IP address, your requests, or their contents.
Bug reports
If you submit one, the text you write is stored so we can act on it, and it may be filed as a GitHub issue for triage. Please don't include sensitive personal information.
Route feedback
If you rate a route, your rating, any note you add, and a snapshot of that route are stored to help us improve our estimates.
Analytics identifier
A random identifier generated in your browser and kept in its localStorage, so that repeat visits can be counted as one person rather than as several strangers. It is not a cookie, it is not derived from anything about you or your device, it is never shared with another site, and clearing your browser's site data for Reroute erases it and starts a new one. We use it to answer questions like whether people who find a guide page come back, not to build a profile.
Session replays (beta)
While Reroute is in beta, we record anonymous replays of how the app is used: what was on screen, clicks, mouse movement, scrolling and typing activity. Addresses you type into the origin, destination and search fields are masked in your browser before the recording is sent, and console output is not captured. Replays carry a session identifier that lasts only for that browsing session and are deleted after 30 days. We record on desktop only, not on phones or other touch devices. See PostHog under “Third-party services”.
Server access logs
Standard request metadata (including IP address) is processed in memory for abuse prevention and rate-limiting. It is not linked to any identity, not retained long-term, and not shared with third parties.
What we don't collect
No email required to use routing (the waitlist and API sign-up collect one; see above).
No passwords or user accounts.
No advertising identifiers or cross-site tracking.
No analytics cookies, and no identifier that follows you off this site. Our analytics identifier is stored in your browser, is specific to Reroute, and is erased when you clear site data; see “Analytics identifier” above. Session replay uses a separate identifier that lasts only as long as that browsing session; see “Third-party services” below.
No trip history tied to you on our servers. Saved trips and recent places live only in your browser.
No payment or card information. We have no payment processor; see billing in our Terms.
Data retention
Discarded immediately
Route queries, AI chat messages, and live-navigation location are used to answer your request and then dropped.
Kept until you ask
Waitlist and developer-API emails, bug reports, and route feedback. We currently keep these until you request their removal.
Deleted after 30 days
Beta session replays. They expire on their own; you can also email us to have them removed sooner.
Stays in your browser
Preferences and saved or recent places stay until you clear your site data.
To delete a developer key, or any bug report or feedback you sent us, email privacy@rerouteapp.ca.
Third-party services
To compute routes, render maps, power AI chat, and keep the app healthy, Reroute relies on the services below. We disclose them so you can review their policies directly:
Mapbox
Map tiles, geocoding, and driving/walking directions. Geocoding and tiles load in your browser, so Mapbox receives your IP address and the coordinates you look up directly; Mapbox may also collect its own usage telemetry. Mapbox Privacy Policy
Google Gemini
Powers the AI chat assistant. Your messages and optional context are sent to Google's Gemini API and are not stored on our servers. Google Privacy Policy
Clerk
Handles waitlist sign-up and developer early-access. If you use these, your email is processed by Clerk, which may set its own cookies in your browser. Clerk Privacy Policy
MOTIS
Open-source transit routing engine that we self-host. Your origin and destination are sent to our routing server to plan transit itineraries. motis-project.de
PostHog (analytics)
Product analytics, with no cookies. A random identifier is kept in your browser's localStorage so repeat visits count as one person; see “Analytics identifier” above. We count page visits and a small set of anonymous product events (for example, that a route search happened, that a navigation session started, diagnostic signals such as a navigation session reloading mid-trip on a device, or that a bug report was submitted and how it was triaged). URLs are stripped of query parameters and events never include locations, addresses, or your message or bug-report content, so your coordinates never reach it, and IP-based location lookup is disabled. Events are processed in PostHog's US region. PostHog Privacy Policy
PostHog (session replay)
While Reroute is in beta, the same provider records anonymous replays of app sessions so we can see where the app is confusing or broken. A replay captures what was on screen, clicks, mouse movement, scrolling and typing activity, plus a session identifier that lasts only for that browsing session. It is not linked to your name or email, because we don't have them. What we exclude: the text you type into the origin, destination and search fields is masked in your browser before anything is sent, so addresses are never in a recording, and browser console output is not captured. Replays run on desktop only and are not recorded on phones or other touch devices. Replays are processed in PostHog's US region and deleted after 30 days. We also collect page-performance measurements and aggregate heatmaps of where people click. If you'd rather not be recorded, a tracker blocker or your browser's “do not track” blocking list will stop it, and you can email us to have your recordings deleted.
Sentry
Error and performance monitoring for the web app and backend. Personal data is turned off, and coordinates and access tokens are scrubbed before any error is sent. Sentry Privacy Policy
Open-Meteo
Weather data powering both our delay model and the live weather widget.
Environment Canada
Weather alerts near your route (weather.gc.ca). It receives a coarse (~15 km) bounding box around your location, not your exact position.
Amazon Web Services
Stores developer API keys, bug reports, and usage counters in DynamoDB in the Canada Central (ca-central-1) region, and hosts the site via S3 and CloudFront. AWS Privacy Notice
GitHub
When bug triage is enabled, a bug report you submit may be filed as a GitHub issue so we can track it. GitHub Privacy Statement
Transit & civic data feeds
Public feeds from TTC, GO Transit / Metrolinx, YRT, MiWay, Toronto Open Data, and other GTA sources are fetched server-side to build routes and alerts. No user data is sent to them.
International data transfer
Some of these providers are based in the United States. Mapbox, Google, Clerk, Sentry, and PostHog process your request data in the US under their own privacy policies. Data we store ourselves (developer keys, bug reports, and feedback) is held in AWS's Canada Central region. By using Reroute, you understand that your request data may be processed outside Canada.
Non-affiliation
Reroute is operated by Reroute Technologies Inc, an independent company, and is not affiliated with, endorsed by, or sponsored by TTC, GO Transit / Metrolinx, YRT, MiWay, Brampton Transit, Durham Region Transit, UP Express, the City of Toronto, or any other transit agency. Agency names and logos are used descriptively for service identification only.
Your choices & rights
Clear your browser's site data for Reroute at any time to wipe all local state.
Skip granting geolocation permission if you'd rather type your origin manually.
Opt out of beta session replay with any tracker blocker, or email privacy@rerouteapp.ca to have your recordings deleted before they expire.
Revoke or delete a developer API key, or ask us to delete a bug report or feedback you submitted, by emailing privacy@rerouteapp.ca.
Stop using the app. There's no account to delete.
Contact
Questions about this policy, or a data request? Email privacy@rerouteapp.ca. For anything else, reach us through the social links in the site footer.