roost

Service providers and external services

Last updated October 2, 2026

Scope

This directory describes integrations present in Roost. Whether an optional provider runs depends on deployment configuration. A software package in the source code is not, by itself, a recipient of member data. Providers may operate subprocessors and have their own retention and legal duties. Contact info@roostmate.app for questions.

Hosting, database and photos

Vercel hosts web requests and receives network metadata; Vercel Blob stores uploaded photo variants. Neon hosts the application Postgres database, including account, profile, messages, household, consent and safety records. Photos are delivered through authenticated routes. Local development can use a local database and filesystem instead.

Phone and email

Telnyx Verify or the configured alternative Twilio Verify receives phone numbers and verification transactions. Carriers and delivery vendors also process SMS traffic. Resend delivers email with recipient addresses and message contents; safety-alert messages may include report details. These are operational recipients, not recipients for their own marketing.

Abuse prevention and diagnostics

Upstash Redis, when selected, stores temporary rate-limit keys derived from identifiers. Postgres can provide rate limits instead. Sentry receives filtered error diagnostics and device/runtime information. PostHog, when enabled, processes product events with internal or browser identifiers. Have I Been Pwned, when enabled, receives a five-character password-hash prefix for breached-password screening, not the password or complete hash.

Maps and platform services

Google Maps, when enabled, receives browser/network information and the selected search-area map coordinates and interactions. No device GPS permission is requested. Google processes data under https://policies.google.com/privacy and map use is subject to https://maps.google.com/help/terms_maps/. Apple distributes the iOS app and handles its own platform services; Roost does not receive your Apple account password. When you allow notifications, Apple Push Notification service receives your device's push token and each notification, which can include a member's first name and a message preview. User-initiated native sharing passes the content you choose to your selected app.

Matching and AI

The compatibility score, ranking and basic text moderation run as Roost code. When configured, OpenAI writes the short match note on a profile. It receives that member's structured profile answers (roommate type, life stage, desired neighborhoods, budget range, move-in month, housing and lease plans, lifestyle answers and hobbies), the compatibility notes for the pairing and a verdict taken from the score. It does not receive names, ages, gender, pronouns, jobs, schools, bios, prompt answers, photos, messages, contact details or account identifiers. Requests ask OpenAI not to store responses. Images supplied by members can reveal personal information, even though Roost does not perform identity or biometric verification.