Privacy Policy
Last updated September 16, 2026
Who runs this
Rant to Me is operated by Korey Davis, based in Ontario, Canada. Korey Davisis the person accountable for how your information is handled under Canada’s Personal Information Protection and Electronic Documents Act (PIPEDA). For any privacy question or request, write to koreyydaviss@gmail.com.
Who this is for
Rant to Me is for people 18 and older. You confirm this when you sign up. We do not knowingly keep an account for anyone under 18. If you believe a minor has an account, email koreyydaviss@gmail.com and we will remove it.
What we collect, and why
| Data | What it is | Why we have it |
|---|---|---|
| Account | Email address, password (hashed by our auth provider), the display name you choose, the time you confirmed you are 18 or older, and the time you accepted the Terms. | So you can log in and so a listener has a first name to use. The display name does not have to be your real name. |
| Calls | Room name, whether it was audio or video, who the listener was, the display name you used, the mood chip you picked, start and end time. Calls are not recorded, transcribed, or stored. Audio and video go directly between you and the listener through Daily.co. | To connect the call, to count a listener’s volunteer hours, and to act on a report. |
| Listener application | Name, email, school or program, availability, why you want to listen, and the time you accepted the Terms and listener conduct rules. If you tick the optional box, the time you agreed to hear about listener news. | To review applications and onboard listeners. |
| Reports | The reason you picked, an optional note, which call or post it concerns, who reported and who was reported. | To review the report, and to make sure two people who reported each other are never matched again. Only Korey Davis can open the full report. An alert goes to a private Slack channel with the reason and the time only. No names, notes, or IDs leave the database. |
| Usage events | Event type (session started, call requested, call connected, call failed, call abandoned, AI chat started, tip line shown, clicked, or dismissed), your account ID, the time, and for calls a request ID, whether it was during live hours, and how long matching took. | To know whether the service works. Stored only in our own database. No third-party analytics. |
| AI companion | The text of your current chat with the AI. Each message you send, together with the earlier messages in that chat, is sent to Google’s Gemini service to produce a reply. Your account ID, email, and display name are not sent. We do not store companion chats. They exist only in your browser until you leave the page. | To generate the reply. |
| Shared space posts | Your post, the mood you tagged, your display name, your account ID, the time, and any replies or supports. | To show the post to other members and let you delete it. |
| Thank-yous and feelings | When you thank a listener or pick how you felt after a call: the listener, your display name, the feeling, the time. | To show listeners how calls landed. |
| Waitlist | Email address, the time you joined, and where on the site you joined from. | To email you once when priority matching opens. Nothing else is sent to this list. |
| Daily mood check-in | The mood you tapped and your account ID. | To colour the home page for everyone. |
| Push notifications | If you are a listener and allow notifications, the browser subscription needed to send them. | To tell listeners when a caller is waiting and nobody is on. |
Posts show your display name
Posts and replies in the shared space are shown with the display name you chose at signup and are linked to your account in our database. Other members see the display name, never your email. You can delete your own posts and replies at any time. If you report a post, we keep a record of the report to act on it.
Cookies
We set no cookies. The site keeps four small values in your browser’s local storage instead. They never leave your device and none of them is used to track you across other sites.
- The Supabase session token: your login session, so you stay signed in. Kept until you sign out.
- rtm_theme: light or dark mode. Kept until you change it.
- rant_onboarded: that you have seen the three welcome screens. Kept until you clear your browser data.
- rtm_checkin: the date of your last mood check-in, so we ask once a day. Kept until you clear your browser data.
Because there are no cookies and no third-party trackers, there is no cookie banner. Clearing your browser’s site data for ranttome.ca removes all four values.
Where your data lives
Every provider we use is in the United States, so your information leaves Canada and is subject to US law while it is there.
- Supabase (database and login), AWS region us-east-2, Ohio. Holds everything in the table above except companion chats.
- Vercel (hosting), region iad1, Virginia. Runs the website and API. Does not store your data beyond request logs, which Vercel keeps briefly.
- Daily.co (voice and video). Carries the live call between you and the listener. We do not turn on recording or transcription. Daily.co keeps its own connection logs under its privacy policy.
- Google (Gemini). Receives the text of AI companion chats to generate replies, under Google’s API terms.
We do not sell your data, share it with advertisers, or use third-party analytics, pixels, or ad networks.
How long we keep it
- Call records: the display name and mood chip on a call are erased 7 days after the call by a scheduled job. Listeners see only the last 7 days of their calls. The remaining fields (times, mode, listener) are kept for up to 12 months to count verified volunteer hours, then deleted.
- Companion chats: never stored.
- Account, posts, thank-yous, mood check-ins, usage events: kept while your account exists, then deleted with it.
- Reports: kept while either account involved exists, so that people who reported each other are not matched again.
- Listener applications: kept for 12 months after the decision, then deleted.
- Waitlist: deleted when priority matching opens and the one email has been sent, or on request.
- Push subscriptions: deleted when you turn notifications off or your account is deleted.
Your rights
You can ask to see the information we hold about you, correct it, withdraw consent, or delete your account and everything tied to it. Email koreyydaviss@gmail.com from the address on your account. Step-by-step deletion instructions are at ranttome.ca/delete-account. We reply within 30 days, and account deletion is completed within 30 days of the request. Withdrawing consent for the waitlist or listener news takes effect right away. If you are not satisfied with our answer, you can complain to the Office of the Privacy Commissioner of Canada.
Changes
If this policy changes in a way that matters, we will say so in the app before the change takes effect. The date at the top always shows the current version.
Contact
Korey Davis, Ontario, Canada. koreyydaviss@gmail.com