# Privacy Policy

[Read this page on Reroute](https://rerouteapp.ca/privacy)

Legal

Last updated: September 27, 2026

TL;DR

## A privacy-first transit tool.

We don't collect names, passwords, or advertising identifiers, and we set no analytics cookies. Our analytics do keep a random identifier in your browser so we can tell a repeat visit from a new one; it isn't linked to your name or email, and it is never shared with another site. Route queries and AI chat messages are processed and then discarded. The only things we keep are what you deliberately send us: a waitlist or developer-API email, a bug report, or route feedback. If you join the waitlist or sign up for an API key, our provider Clerk may set its own cookies. Anything you post to our public feedback board is kept by UserJot, who runs it, and is visible to other riders. See “UserJot” below.

The main thing to know while we're in beta: we record session replays of how the app is used, so we can find and fix the rough edges. A replay is an unmasked recording of your screen, kept for 30 days. It shows on-screen activity, taps, clicks, mouse movement and what you type, including the addresses you enter and the place names we show back to you. It shows the map as drawn, including your live position while navigating. Replays are not labelled with your name unless you are signed in, but they are not anonymous in any strong sense: someone watching one can see where you were going. Only password fields and the trip suggestion card are hidden. If you would rather not be recorded, a tracker blocker will stop it, and you can email us to have your recordings deleted. See “Third-party services” below for the detail.

-   No ad tracking
-   No accounts
-   Queries discarded after use
-   Kept data stored in Canada

Reroute is in active beta. This policy reflects our current practice, but because the app is still being iterated on, we may update this page. Material changes will be surfaced on the app itself.

## What we collect

**Route queries**

The origin and destination coordinates you enter, plus any filters (mode, agency, departure time). These are processed by our backend to generate route options and are not retained after the response is returned.

**Location**

If you allow it, your device location is used once as a starting point or for proximity. During live turn-by-turn navigation only, your GPS position is streamed to our server so we can guide you. It is held in memory and never written to disk: it is discarded within about fifteen minutes of your device disconnecting; if a trip is still active but your device has stopped sending updates it may persist up to about an hour, and in every case it is dropped within six hours. We do not store your location history.

**AI chat**

Your message, recent chat history, and an optional context block are sent to Google Gemini to generate a reply. That block describes what is on your screen: an approximate location rounded to about 100 metres; your saved home and work places, sent as the words “Home” and “Work” plus a location rounded the same way, never the address you saved, and only if you've set them; the start and end of the trip you have planned, with the labels you picked them as, locations rounded the same way, and the departure or arrival time you chose; a summary of the route you have selected on screen (its name, how long it takes, when it arrives, and how many transfers); which subway lines and GO corridors are not running normally; which screen you have open, where the map is pointed (rounded the same way) and which map layers you have switched on; your routing preferences (modes, bus agencies, sort order, fare type, payment method, whether you avoid highways or tolls, and your walking, transfer and drive-radius limits); whether you are signed in, and nothing else about your account (never your name, email, or account ID); and, while a turn-by-turn trip is running, that trip's next instruction and estimated arrival time. Separately from that block, and only when your question actually needs it, Miles looks things up while it answers: places near you, near your trip's start or end, or near a place you name (that search runs through Mapbox, which sees the coordinates it searches around); your saved places and trips, if you are signed in, by the names you gave them and with any street number dropped; how many trips you have taken, counted against your account when you are signed in and against this device otherwise; rider reports near those same points; service alerts, schedules and departures for the transit you asked about; and the weather. What it finds goes back to Google Gemini the same way the block does, with every location rounded to about 100 metres first. We do not keep what it looked up. The thread itself is kept on your device (see “Browser-local state” below) unless you are signed in, in which case your chats are also stored against your account, along with a record of what Miles did on each turn; see “Account” below for exactly what that holds.

**Browser-local state**

Preferences, recent search places (with coordinates and labels), map layer settings, and dismissal flags are stored in your browser's `localStorage` and never leave your device. Your conversation with Miles is kept there too — your questions, its answers, the result cards it showed and the routes it drew — for up to 24 hours or your last 12 exchanges, so the thread is still there if you come back to the tab; “Clear conversation” erases it immediately. Saved places and saved trips are also browser-local while you are signed out; signing in syncs them to your account (see “Account” below). If you are signed in, whole Miles chats (not just the one open in your browser) are also saved to your account — up to your last 30 — so you can reopen an earlier conversation from the history icon and pick up where you left off, on any device. You can delete any saved chat from that same history list.

**Trip suggestions**

Miles can suggest the trip you are probably about to take, like work on a weekday morning. It learns this on your device only, from trips you start: where each one went (to about 10 metres, with its name), the day and time you left, and the subway or GO lines you rode, never where you started or the route itself. None of it is ever sent to Reroute or saved to your account. Turning off Trip suggestions in Settings clears everything it learned, and so does deleting your trip history.

**Onboarding profile (optional)**

The first time you open the map, a short welcome flow asks a few questions to help us tailor the app: your first name (used only to greet you, never sent to our analytics provider), the modes you use, whether you have a car and how often you drive, which days you commute, your age range, why you're mostly using Reroute, and how you found us. Every question is optional and skippable. Home and Work, if you add them here, are saved the same way as Home/Work shortcuts (see “Account” below), as a label and coordinates, not free text. Your answers are stored against your device or account so we can apply them; six of them (age range, car access, drive frequency, the modes you use, your trip purpose, and how you found us) plus which days you commute are also attached to your analytics identifier as categorical properties. Never your name, and never Home/Work. See “PostHog (analytics)” below.

**Trip stats (for your Wrapped)**

To build your December Transit Wrapped, we keep a record of each trip you plan or take: when it happened, the mode, the origin and destination labels you searched for (not coordinates), the transit lines and station IDs involved, how long and far it was, its estimated cost and predicted delay, and a coarse weather tag (like “snow” or “clear”) stamped by our server from data we already have. We never store the coordinates you searched, the street addresses behind them, or any search text. This is on by default (it's what makes a Wrapped possible for everyone, not just signed-in users), and you can turn it off or delete everything we've recorded anytime from Settings → Trip history. If you're signed out, these records are keyed to a random device identifier and automatically expire after about 16 months; signing in merges your device's history into your account. We also keep a running count of how many messages you've sent Miles (for a “you asked Miles N questions” stat), the count only, never what you asked.

**Rider reports (in build)**

We are building a way for signed-in riders to report what they're seeing on the platform or on board, like a delay, a fare inspection, or a car worth avoiding, so other riders see it before we do. It is not visible to riders yet. Once it is, a report stores the category you pick, the station or line it happened on, and when it happened; there is nowhere to type free text. A report is tied to your account for 30 days, in case it needs a correction or a takedown, and after that we replace your account id with a one-way hash so the report can no longer be traced back to you. We keep reports, identified or not, to look for patterns over time, like where fare inspections tend to happen, not to build a profile of any one rider. Reports never train our delay predictions or change which route we show you. Deleting your account removes every report still tied to it; you can also ask us to take one down within that first 30 days by emailing [privacy@rerouteapp.ca](mailto:privacy@rerouteapp.ca); a report already past 30 days has already been anonymized and can't be traced back to delete individually.

**Account (optional)**

Routing needs no sign-in. If you create an account, sign-in is handled by Clerk (email verification codes, and we never see or store a password). The things you explicitly save, your Home and Work shortcuts, saved places, and saved trips (names, labels, and coordinates), are stored against your account id in our database in Canada (AWS ca-central-1) so they follow you across devices. The same is true of your Miles chats once you are signed in — each one's title and its full back-and-forth with the assistant, up to your last 30 chats. Stored alongside those chats is a record of what Miles did for you on each turn: the kind of each action it took, the one line you were shown describing it (which can name a place or a trip you asked about), and whether you undid it. On your first sign-in on a device, the saved trips already in that browser are uploaded to your account once. Automatic history (recent searches) is never uploaded and stays on the device. You can remove any saved item in the app at any time; to delete your account and its data, email [privacy@rerouteapp.ca](mailto:privacy@rerouteapp.ca).

**Waitlist email**

If you join the waitlist, your email address is collected via Clerk and stored for early-access notification only. It is not used for marketing or shared with third parties.

**Developer API email**

If you create an API key, we store your email address, a one-way SHA-256 hash of the key (never the key itself), your plan, and a creation timestamp, so we can issue and manage the key and meter usage. Usage metering is a daily request count per key; it does not record your IP address, your requests, or their contents.

**Bug reports**

If you submit one, the text you write, plus an optional email address if you gave one, is stored so we can act on it and follow up, and the report text may be filed as a GitHub issue for triage (your email is never included in that issue). We use it only to reach you about that report.

**Route feedback**

If you rate a route, your rating, any note you add, and a snapshot of that route are stored to help us improve our estimates.

**Delay-model training data**

We archive the same live transit signals your route results are built from (service alerts, vehicle positions, estimated arrival times, slow-zone reports, subway arrivals and trip updates) to train and evaluate our delay predictions. These are operational transit-system signals, not tied to your account or device. If you tell us you caught a different train than the one we predicted, or use live turn-by-turn navigation, that correction or GPS-quality sample is stored the same way, for the same purpose. Everything in this row is encrypted at rest and kept for up to 730 days.

**Analytics identifier**

A random identifier generated in your browser and kept in its `localStorage`, so that repeat visits can be counted as one person rather than as several strangers. It is not a cookie, it is not derived from anything about you or your device, it is never shared with another site, and clearing your browser's site data for Reroute erases it and starts a new one. We use it to answer questions like whether people who find a guide page come back, not to build a profile. If you sign in, the identifier is linked to your account id so we can count you as one person across devices. The link carries the account id only, never your email or name, and signing out stops linking further events.

**Session replays (beta)**

While Reroute is in beta, we record replays of how the app is used: what was on screen, taps and clicks, mouse movement, scrolling and what you type. Until September 2026 large parts of this were masked out in your browser. They no longer are, because a masked recording showed grey blocks where the app's own text should be and could not tell us what had gone wrong. So a replay now includes: the addresses you type into the origin, destination and search fields; the place names shown back to you on the trip card, the place card, search suggestions, recents and saved trips; your messages to the assistant and its replies; bug report and feedback text; your account name and email if you are signed in; the browser console; and the full web address of each page, including anything after the “?”. Two things are still hidden: password fields, and the trip suggestion card, because what it shows was learned on your device and stays there. Replays carry a session identifier that lasts only for that browsing session and are deleted after 30 days. We record on phones and desktop alike. See PostHog under “Third-party services”.

**The map, in replays**

A replay includes the map exactly as it was drawn on your screen. We do this because the map is where most problems show up, and a recording without it cannot tell us whether the app failed to draw your route. Nothing on it is painted over. That means the basemap, the route line, the origin, destination and place pins, and, while you are navigating, the moving dot showing where you actually are. Until September 2026 that dot was blacked out; it is not any more. Said plainly: a replay of a navigating session shows your route and your position along it. Replays expire after 30 days and are not labelled with your name unless you are signed in, but neither of those makes the trip in them unidentifiable.

**Taps and clicks**

We record that an element was tapped or clicked, where it sits in the page, and the text and attributes on it, so we can find controls that people press repeatedly with nothing happening. Until September 2026 we left the text out. We now keep it, because without it every one of these records read as an anonymous box and told us nothing. On this app that text is often a place name or a destination, so these records contain them. Taps on the trip suggestion card are the exception: we do not record them.

**Server access logs**

Standard request metadata (including IP address) is processed in memory for abuse prevention and rate-limiting. It is not linked to any identity, not retained long-term, and not shared with third parties.

## What we don't collect

-   No email required to use routing (the waitlist and API sign-up collect one; see above).
-   No passwords, ever. An account is optional, and signing in uses email verification codes via Clerk.
-   No advertising identifiers or cross-site tracking.
-   No analytics cookies, and no identifier that follows you off this site. Our analytics identifier is stored in your browser, is specific to Reroute, and is erased when you clear site data; see “Analytics identifier” above. Session replay uses a separate identifier that lasts only as long as that browsing session; see “Third-party services” below.
-   No coordinates, street addresses, or search text in your trip stats: only place labels, transit lines and station IDs, and route metrics. See “Trip stats (for your Wrapped)” above, which replaces our earlier “no trip history” claim now that Wrapped collection is live; it's on by default with a Settings toggle and delete-all.
-   No payment or card information. We have no payment processor; see billing in our [Terms](https://rerouteapp.ca/terms).

## Data retention

**Discarded immediately**

Route queries and AI chat messages are used to answer your request and then dropped. Live-navigation location is held in memory only and cleared within about fifteen minutes of your trip ending or your device disconnecting (six hours at the outside).

**Kept until you ask**

Waitlist and developer-API emails, route feedback, your account's saved places and trips, and your signed-in trip stats. We keep these until you remove them, delete your history in Settings, or request their removal. Bug reports are also kept this way but expire on their own after about 180 days.

**Deleted after 30 days**

Beta session replays. They expire on their own; you can also email us to have them removed sooner.

**Stays in your browser**

Preferences and recent places stay until you clear your site data. Saved places and trips stay browser-local too unless you sign in and sync them.

To delete a developer key, or any bug report or feedback you sent us, email [privacy@rerouteapp.ca](mailto:privacy@rerouteapp.ca). A bug report is kept until you ask us to delete it or for about 180 days, whichever is sooner; for up to a further 35 days after that, a copy can still exist in an encrypted backup before it is purged too. Trip stats recorded while you're signed out are keyed to a random device identifier and automatically expire after about 16 months; deleting them sooner is one tap in Settings → Trip history, for either an anonymous device or a signed-in account.

## Third-party services

To compute routes, render maps, power AI chat, and keep the app healthy, Reroute relies on the services below. We disclose them so you can review their policies directly:

**Mapbox**

Map tiles, geocoding, and driving/walking directions. Geocoding and tiles load in your browser, so Mapbox receives your IP address and the coordinates you look up directly; Mapbox may also collect its own usage telemetry. Place details work differently: when you open the card for a place on the map or in search (a feature we are still rolling out, so you may not see it yet), our server looks up its opening hours, phone number and website from Mapbox. It sends the name and map position of the place you tapped, or, for a place you picked from search, Mapbox's own id for that place, so Mapbox sees the request come from our server, not from you. We hold what comes back in memory for up to five minutes, so opening the same card again does not ask twice, and we never store it. [Mapbox Privacy Policy](https://www.mapbox.com/legal/privacy)

**Google Gemini**

Powers the AI chat assistant. Your messages and optional context are sent to Google's Gemini API and are not stored on our servers. Any location in that context is rounded to roughly a city block (about 100 metres) before it is sent. [Google Privacy Policy](https://policies.google.com/privacy)

**Clerk**

Handles account sign-in (email verification codes), the waitlist, and developer early-access. If you use these, your email (and for accounts, your name if you provide one) is processed and stored by Clerk, which may set its own cookies in your browser. We never see or store passwords; our servers verify your session using Clerk's public keys. [Clerk Privacy Policy](https://clerk.com/privacy)

**MOTIS**

Open-source transit routing engine that we self-host. Your origin and destination are sent to our routing server to plan transit itineraries. [motis-project.de](https://motis-project.de/)

**PostHog (analytics)**

Product analytics, with no cookies. A random identifier is kept in your browser's `localStorage` so repeat visits count as one person; see “Analytics identifier” above. We count page visits and a small set of anonymous product events (for example, that a route search happened, that a navigation session started, diagnostic signals such as a navigation session reloading mid-trip on a device, or that a bug report was submitted and how it was triaged). These named events never include locations, addresses, or your message or bug-report content. Until September 2026 we also stripped the query parameters off every URL we sent; we no longer do, so a page address that carries a shared trip in its link reaches PostHog whole. IP-based location lookup stays disabled. If you sign in, events are additionally linked to your account id (never your email or name) so usage can be counted per person across devices. Since August 2026 that event set also includes the onboarding funnel (started, each step completed by name, finished, or skipped), a mark for each one-time live-map coach mark shown, the guided tour (started, finished, or skipped along with which step number you were on when you skipped), and the Trip History toggle and delete actions. None of these carry any trip content. Since September 2026 it also records the moment you press a sign-in button, with two coarse labels and nothing else: which provider you chose (Apple, Google, or “modal” when the choice happens inside the sign-in window) and where you pressed it (during onboarding, from the account button, from the one-time reminder that offers to sync a trip or place you just saved, or from the rider report sheet at the moment you send a report, a surface that is not visible to riders yet; see “Rider reports” above). Never your email or your name, and never the category you were reporting, and never which trip or place prompted the reminder. When Miles carries out something you asked for (showing a route, opening a screen, saving a place), we record which kind of action it was and whether you had to confirm it, never the words you used or the place, note or bug description behind it. When you ask Miles something out loud we record that one spoken question happened: how you started it (the microphone button, the “Hey Miles” phrase if you have turned that on, or a shortcut that opened Reroute with your question already in the link), whether your phone answered it by itself from your trip's own progress or the assistant answered it, which of a short list of trip questions it was (time left, arrival time, next step, or stopping navigation) when your phone answered it, and whether the answer arrived within ten seconds. Never what you said, and never the answer. If you turn on “Listen for Hey Miles” and Reroute hears the phrase but you then say nothing, we record that one such moment happened and which of two things it was: the microphone opened and closed with nothing said, or the question had nowhere to go. Never any audio, never any words, and never anything about what you were doing at the time. In the Reroute phone app the phrase is listened for and recognised on your phone itself, and no audio leaves your phone while it listens; what you say to Miles after the phrase is processed by your phone's own speech service, as anything you say into its microphone button is. In a web browser your speech is processed by your browser's own speech service. When Miles asks you a question back, the app may open the microphone by itself for about six seconds so you can answer without reaching for it, and your answer goes to the same speech service; the only thing we record about that is whether it was answered. Never what you said, never what Miles asked, and never how long you took. A link that carries a question for Miles in its address, which is how those phone shortcuts hand one over, counts as a question you asked out loud and is recorded the same way. When you pick a search suggestion we record which kind of row it was (a station, a landmark, an address, a transit line, a recent place), its position in the list, how many characters you had typed and whether you were online; when a search comes back empty we record how many characters you had typed and how many of our sources failed. Never the text you typed and never the name of the place. When you open a station, stop or place card, we record a “place card opened” event with only three things: which kind of card it was, where you opened it from (the map, search, the Nearby list, or another card's “Getting there” list) and, for a place, whether we found its details. Never the name of the station or place, and never where it is. Six categorical onboarding answers (age range, whether you have a car, how often you drive, the modes you use, why you use Reroute, and how you found us) plus which days you commute are attached to your analytics identifier as person properties, never your name, and never Home/Work; see “Onboarding profile” above. Events are processed in PostHog's US region. [PostHog Privacy Policy](https://posthog.com/privacy)

**PostHog (session replay)**

While Reroute is in beta, the same provider records replays of app sessions so we can see where the app is confusing or broken. A replay captures what was on screen, clicks, mouse movement, scrolling and what you type, plus a session identifier that lasts only for that browsing session. If you are signed in, it can be linked to your account id like any other analytics event. These recordings are not masked. In September 2026 we removed the masking that used to sit between the recorder and your screen, because it left grey blocks where the app's own text should be and we could not tell a broken screen from a working one. So a replay now shows the text you type into the origin, destination and search fields, the place names the app shows back to you, your chat messages with the assistant and its replies, bug report and feedback text, your account name and email if you are signed in, the full web address of each page including its query string, and the browser console. Two things are still hidden: password fields, and the trip suggestion card, whose contents never leave your device. A replay also includes the map as drawn, with nothing painted over: the basemap, the origin, destination and place pins, and your live position while navigating. PostHog replays run on phones as well as desktop, a change we made in September 2026 because most people use Reroute on a phone and we could not see the problems they were reporting. Replays are processed in PostHog's US region and deleted after 30 days. We also record that elements were tapped or clicked, together with the text on them, alongside page-performance measurements and aggregate heatmaps. If you'd rather not be recorded, a tracker blocker or your browser's “do not track” blocking list will stop it, and you can email us to have your recordings deleted.

**Sentry**

Error and performance monitoring for the web app, the mobile app and the backend. Coordinates and access tokens are scrubbed before any error is sent, and we remove your IP address, cookies and the contents of the request from error reports before they leave our server. [Sentry Privacy Policy](https://sentry.io/privacy/)

**Sentry (assistant conversations)**

What you type to Miles, and what Miles replies, is sent to Sentry so we can see where the assistant misunderstands people, picks the wrong route, or fails outright. Please don't tell Miles anything you would not want us to read. Messages are grouped into a conversation, tagged with your account id if you are signed in or an anonymous device id if you are not, and are never tagged with your name or email. They are processed in Sentry's US region. Nothing else you do in the app is recorded this way , so this covers the assistant only.

**Sentry (error replay)**

Separately from the continuous replay above, Sentry records a short replay _only_ when an error occurs. Your device keeps the last few moments in memory and sends them only if something breaks; if your session goes fine, nothing is ever uploaded. All text on screen is masked before recording, including the origin, destination and search fields, and images and video are not captured.

**Open-Meteo**

Weather data powering both our delay model and the live weather widget.

**Environment Canada**

Weather alerts near your route (weather.gc.ca). It receives a coarse (~15 km) bounding box around your location, not your exact position.

**Amazon Web Services**

Stores developer API keys, bug reports, and usage counters in DynamoDB in the Canada Central (ca-central-1) region, and hosts the site via S3 and CloudFront. [AWS Privacy Notice](https://aws.amazon.com/privacy/)

**GitHub**

When bug triage is enabled, a bug report you submit may be filed as a GitHub issue so we can track it. [GitHub Privacy Statement](https://docs.github.com/en/site-policy/privacy-policies/github-general-privacy-statement)

**UserJot (feedback board)**

Runs our public feedback and roadmap board, and the “Give feedback” widget that loads on every page of this site. Because the widget loads on every page, UserJot receives your IP address and which page you were on, the way any embedded script does, but nothing about you is sent until you open it. It sets no cookies here. It keeps two values in your browser's `localStorage`: which product update you last read, and the id of our board. Neither is a visitor identifier and neither follows you to another site. If you post a request, a comment or a vote, what you write (along with any screenshot you choose to attach, and the name or email you give UserJot) is stored by UserJot, and posts on the board are public to other riders by design. We never pass it your Reroute account, name or email: the widget is anonymous to it unless you sign in to UserJot yourself. Submissions are processed in the United States. To remove something you posted, contact UserJot or email us and we will take it down. [UserJot Privacy Policy](https://userjot.com/privacy)

**Wikimedia Commons**

The photographs on station cards come from Wikimedia Commons, each used under the Creative Commons licence or public-domain dedication its photographer chose, and credited on the card beside it. We keep our own copies and serve them from Reroute's own site, so opening a station card sends nothing about you to Wikimedia. [commons.wikimedia.org](https://commons.wikimedia.org/)

**Transit & civic data feeds**

Public feeds from TTC, GO Transit / Metrolinx, YRT, MiWay, Toronto Open Data, and other GTA sources are fetched server-side to build routes and alerts. No user data is sent to them.

## International data transfer

Some of these providers are based in the United States. Mapbox, Google, Clerk, Sentry, PostHog, and UserJot process your request data in the US under their own privacy policies. Data we store ourselves (developer keys, bug reports, and feedback) is held in AWS's Canada Central region. By using Reroute, you understand that your request data may be processed outside Canada.

## Non-affiliation

Reroute is operated by Reroute Technologies Inc, an independent company, and is **not affiliated with, endorsed by, or sponsored by** TTC, GO Transit / Metrolinx, YRT, MiWay, Brampton Transit, Durham Region Transit, UP Express, the City of Toronto, or any other transit agency. Agency names and logos are used descriptively for service identification only.

## Your choices & rights

-   Clear your browser's site data for Reroute at any time to wipe all local state.
-   Skip granting geolocation permission if you'd rather type your origin manually.
-   Opt out of beta session replay with any tracker blocker, or email [privacy@rerouteapp.ca](mailto:privacy@rerouteapp.ca) to have your recordings deleted before they expire.
-   Revoke or delete a developer API key, or ask us to delete a bug report or feedback you submitted, by emailing [privacy@rerouteapp.ca](mailto:privacy@rerouteapp.ca).
-   Stop using the app. There's no account to delete.

## Contact

Questions about this policy, or a data request? Email [privacy@rerouteapp.ca](mailto:privacy@rerouteapp.ca). For anything else, reach us through the social links in the site footer.

## Report a content error

[Give feedback](https://reroute.userjot.com) with this page's URL, the incorrect statement, and supporting evidence.
