Privacy Policy
Effective September 8, 2026 · Last updated October 1, 2026
This Privacy Policy explains how Roostmate, Co. ("Roost," "we," "us," or "our") collects, uses, discloses, retains, and deletes personal information when you use the Roost website and mobile application. Roost is currently offered only in the United States and only to people age 18 or older.
Information we collect
Account and verification information
- Verified phone number, date of birth, account creation date, and acceptance of our Terms and this Policy.
- Optional email address and a one-way password hash for accounts that set a password. We never store a plain-text password.
- Phone or email verification status, hashed local verification codes, provider verification references, and signed session identifiers.
- An optional, separately controlled consent record if you choose to receive marketing text messages.
Profile and housing information
- Name, age, gender, optional pronouns, occupation, employer, school, biography, photos, photo captions, and profile-prompt answers.
- The city and neighborhoods where you want to live, housing budget, move-in timing, separate lease and property selections, desired household size, private discovery filters, and a selected map center and radius (coordinates rounded to three decimal places). If you already have a place, we collect neighborhood, bedrooms, current roommates, and open spots—without requesting your exact residential address or device GPS location.
- Lifestyle and living-compatibility answers, including schedule, cleanliness, guests, pets, smoking, drinking, hobbies, and an optional roommate-contract answer.
Activity, communications, and safety
- Profiles you pass, handshakes and notes you send, matches, compatibility results, and the algorithm version used.
- Shared-household membership, secure invitations, shortlist choices, and member votes.
- Private messages you exchange with matches.
- Blocks, reports, report reasons and details, and actions taken in response to a report. When you report a conversation, the latest 50 messages are included for safety review and retained with the report even if you subsequently block or unmatch.
- Information you submit through a waitlist or contact form, such as your name, email, city, phone or email, housing situation, referral source, and message.
Technical and usage information
- IP address and temporary rate-limit records used to prevent abuse, protect accounts, and keep the service available.
- Product-interaction data such as page views and onboarding milestones, an internal or app/browser analytics identifier, and basic device, browser, and operating-system information. You can turn product analytics off in Settings.
- If you allow notifications in the iOS app, a push token for that device, the app version, and when it was registered, linked to your signed-in session. We also keep a short record of which kind of notification was sent to you and when—never its text—so we don't repeat ourselves.
- Crash and error diagnostics. We configure error monitoring to remove account identity, cookies, authorization headers, request bodies, message content, email addresses, and member photo URLs before an error event is sent.
Information we do not collect
Roost does not request payment-card or bank-account information, device contacts, precise GPS location, exact residential addresses, government IDs, biometric identifiers, or identity selfies. Information you voluntarily put in photos, messages or free text can nevertheless reveal sensitive facts or an address; avoid sharing these. We do not ask for race, ethnicity, religion, health, disability, or sexual orientation for matching. A "verified" badge means only that the member confirmed access to a phone number or legacy email address; it is not government-ID verification, a background check, or a guarantee of a member's identity, statements, or conduct.
How we use information
- To create and secure accounts, confirm age eligibility, and deliver verification texts or legacy emails.
- To create profiles, calculate compatibility, progressively refine sample previews, and show potential roommates.
- To deliver handshakes and messages and operate matching and blocking features.
- To send the push notifications you allow: new messages (with the sender's first name and a preview of the message), new matches, likes, household updates, and at most one reminder a day. You can turn each kind off in Settings, or all of them in your device settings. We do not use notifications for advertising.
- To screen member-written names, profile text, household names, handshake notes, and messages using our own rules-based safeguards for slurs and hateful language, threats, harassment, sexual content, profanity in public profile text, and common payment scams before that text is posted. Text the screen refuses is kept with your account for up to 90 days so people can review repeated attempts, and is deleted with your account.
- To review reports, enforce our rules, prevent fraud and abuse, and respond to support requests.
- To maintain, debug, measure, and improve Roost and comply with legal obligations.
Compatibility algorithm and AI
Roost's compatibility score comes from our own deterministic, versioned scoring system—not a generative-AI model. It compares known practical information such as budget, desired neighborhoods, move-in timing, property and lease plans, confirmed lifestyle answers, and the roommate questionnaire. Missing dimensions are excluded and the remaining weights are normalized. The score does not analyze photos or messages and never uses a protected trait. Compatibility results rank potential roommates; they do not make decisions about housing eligibility, credit, employment, insurance, or access to a lease.
The short match note on a profile (“You and [name]”) is written by a generative-AI model (OpenAI). To write it, we send the structured answers already shown on that member's profile (roommate type, life stage, desired neighborhoods, budget range, move-in month, housing and lease plans, lifestyle answers, and hobbies), the compatibility notes for the pairing, and a match verdict taken from Roost's score. We do not send names, ages, gender, pronouns, jobs, employers, schools, bios, prompt answers, photos, messages, contact details, account identifiers, or protected traits; the member's first name is added by Roost after the note is written. The note does not change the score or ranking. We keep the note so it is not rewritten on every view, and delete it when either account is deleted.
Who processes information for us
We use service providers only to operate and protect Roost. They process information for the purposes described below and are required to protect it consistently with applicable law and their agreements with us.
- Vercel hosts the app and stores uploaded photos through Vercel Blob.
- Neon hosts Roost's application database.
- Resend delivers verification and operational email. It receives the recipient email address and email contents; safety-alert emails can include report details.
- Telnyx Verify delivers and checks one-time phone verification codes and receives the destination phone number. Twilio Verify may be used as an alternative provider when configured.
- Google Maps displays the optional interactive search-area map and receives the map area and interactions, IP address, and browser/device information when its script loads. We do not request device GPS. Google processes that data under its Privacy Policy.
- OpenAI writes the profile compatibility note described above. It receives the structured profile answers, compatibility notes, and verdict listed above, with no names, contact details, account identifiers, photos, or messages. We ask OpenAI not to store responses; under its API terms it does not train on API data by default and may keep requests for a limited period for abuse monitoring.
- Apple Push Notification service delivers notifications to your iPhone when you allow them. It receives your device's push token and the notification itself, which can include a member's first name and a preview of a message.
- Upstash provides rate limiting and may temporarily process rate-limit keys based on IP addresses or internal user identifiers.
- Sentry processes scrubbed crash and error diagnostics so we can detect and fix technical problems.
- PostHog processes page views and product-funnel events using an internal or app/browser analytics identifier. We do not send message contents or photos to PostHog, and members can opt out in Settings.
- Have I Been Pwned may check whether a new password appears in known breaches. When enabled, Roost sends only the first five characters of a one-way password hash; it never sends the password or complete hash.
When information is disclosed
- Other members can see the profile information you choose to publish. Matches can see the messages you send them. Block and report actions are not shown to the reported member.
- Authorized Roost personnel can review reports and related account information for safety and support.
- We may disclose information if reasonably necessary to comply with law, protect a person from harm, investigate fraud or abuse, or protect Roost's rights and service.
- If Roost is involved in a merger, financing, acquisition, reorganization, or sale of assets, information may be transferred as part of that transaction, subject to this Policy.
We do not sell your personal information. We do not share personal information for cross-context behavioral advertising, show third-party ads, or use member data to track people across other companies' apps or websites.
Retention and deletion
- Account, profile, onboarding, household, photo, message, match, and interaction data is generally kept while your account is active. Session authority expires after 30 days unless renewed. Verification codes become unusable after 10 minutes; a successfully used phone challenge is deleted immediately, and expired abandoned challenges are pruned automatically.
- Temporary rate-limit counters expire within 24 hours.
- A device's push token is deleted when you log out on that device. Records of which notifications were sent are deleted after 30 days.
- When you delete your account in Settings, Roost hard-deletes the account, profile, uploaded photo objects, claimed onboarding state, household membership and votes, verification challenges, prompts, handshakes, matches, messages, sessions, notification settings and push tokens, blocks, and passes. Deletion cannot be undone.
- Reports may be retained after account deletion with account links removed so Roost can detect patterns of abuse, document safety actions, resolve disputes, and comply with law. Report details may still identify people; removal of account links does not anonymize free text.
- Waitlist and contact-form submissions are separate from an account and are kept only as long as reasonably needed for the request, outreach, safety, or legal purposes. Contact us to request their deletion.
- Service providers may retain limited backup, security, or legal records for their configured retention periods. De-identified or aggregated statistics that no longer identify you may be retained longer.
Your choices and rights
From Settings, you can edit your profile, choose which notifications you get, turn product analytics off, view instructions for requesting a copy of your account data, and permanently delete your account without emailing us. To request a data copy, email info@roostmate.app with your full name and the phone number linked to your Roost account. You can also ask to access, correct, or delete personal information, or appeal our response, by contacting us. Depending on where you live, state law may provide additional privacy rights. We will not discriminate against you for exercising a privacy right, and we may need to verify your request before completing it.
Mobile information and SMS consent
We do not sell, rent or disclose mobile numbers or SMS opt-in records to third parties or affiliates for their own promotional campaigns. Messaging vendors and carriers may process this information to deliver and protect the messaging service, and legally required disclosures may occur. Providing a number for verification does not enroll you in marketing. Optional marketing consent can be withdrawn by replying STOP to a marketing text or contacting info@roostmate.app. See Text messaging terms.
Storage, sources and privacy requests
Information comes from you, your device, other members interacting with or reporting you, and providers returning verification or diagnostic results. We also derive compatibility results from your answers. We use essential cookies and optional analytics local storage; see Cookies and analytics. We do not currently change analytics behavior for the legacy Do Not Track signal. Our service providers may process data in the United States and other countries where they operate. We do not offer Roost outside the United States.
Applicable state laws may provide rights to know, access, correct, delete or obtain a portable copy, and to opt out of sale, targeted advertising or certain consequential profiling. We do not sell information, share it for cross-context advertising or make housing-eligibility decisions. For verified requests, authorized agents, appeals, separate waitlist/contact records and retention exceptions, see Account deletion and privacy requests. Provider backup and log periods depend on configuration; we do not promise immediate deletion of every external copy.
Security
We use encrypted network connections, password hashing, access controls, authenticated photo delivery, and limited administrative access to protect personal information. No internet service can guarantee absolute security, so contact us immediately if you suspect account misuse.
Children
Roost is not for anyone under 18, and we do not knowingly collect personal information from children. Contact us if you believe a person under 18 has created an account.
Changes to this Policy
We may update this Policy as Roost changes. We will post the revised Policy here, update the date above, and provide additional notice before a material change takes effect when required.
Contact
Contact Roostmate, Co. with privacy questions or requests at info@roostmate.app. For safety concerns about another member, use the in-app report tool or see our Safety Guide.
Business mailing address: Roostmate, Co., 9009 Golf Road, Apt 9GG, Des Plaines, IL 60016, United States.