Rally
How it works The app Platforms FAQ Support
Contact Open the app
Privacy

Privacy Policy

Rally is a coordination app. An admin invites people to a team, posts a link with an action attached, and the members who were targeted get a push notification. This page describes exactly what the app stores while doing that, who can see it, and how to get it deleted.

Last updated: 20 September 2026

Who runs Rally

Rally is built and operated by the Rally team at Codersera. For anything on this page, including data access and deletion requests, write to shubh@codersera.com.

Accounts are invite-only

There is no public sign-up. An admin adds your email address to a team first; only then can you sign in, using Google Sign-In with that same address. If your email is not already on a team, sign-in is refused and no account is created. You can ask an admin, or us, to remove you at any time.

What Rally collects

This is the complete list of what the app stores about a person:

  • Google account details. When you sign in with Google, Rally receives and stores your email address, your display name, and Google's subject identifier for your account (an opaque id Google uses to recognise you on the next sign-in). Rally does not store your Google password, and does not read your Gmail, Drive, contacts or calendar.
  • Team and tag membership. Which teams and tags you belong to, who invited you, whether you are an admin or a member, and the date you were added.
  • Task assignments and activity. Which tasks were assigned to you, when you were notified, when you claimed a task, and when you marked it complete.
  • Proof screenshots (optional). If an admin marks a task as requiring proof, the image you attach when marking it done is stored. Only you choose what to upload.
  • Push notification tokens. The Expo push token issued by your device, so a notification can reach that device. Removing the app or signing out of it ends its usefulness; ask us and we will clear it.
  • Notification preferences. Quiet hours and any action types you have muted.
  • Admin audit log. A record of administrative actions taken in the app — who created, edited or closed a task, and when — so a team can see what its admins did.

Rally does not collect your location, your contacts, your photo library, your device identifiers for advertising, or your browsing activity.

Rally has no access to your social accounts

This is the part people ask about most, so it is stated plainly. Rally requests no access whatsoever to Reddit, YouTube, X / Twitter, Instagram, LinkedIn, Product Hunt or any other platform. It never asks for those usernames or passwords, never receives an access token for them, and has no connection to them of any kind.

Rally sends a notification and opens a link. Everything after that happens in the real platform's own app, under your own account, done by you. Rally never posts, votes, comments, watches, shares or follows on anyone's behalf, and it is not technically able to.

Who can see what

  • Your name and email are visible to the admins of the teams you belong to, and your name appears to other members of those teams alongside tasks.
  • Your completion record — which tasks you finished and when — is visible to the admins of your team, and appears in their dashboard and CSV export.
  • Proof screenshots are visible only to admins of that team. They are stored in a private bucket with no public URL, no shareable link and no CDN address. The app holds only an internal key, and the image can be fetched only through an authenticated admin-only route that streams it through the server. They are never public, never posted anywhere, and never shown to other members.
  • Nothing in Rally is public. There are no public profiles and no public pages containing member data.

Third parties Rally actually uses

These are all of them. Each one receives only what is listed here.

ServicePurposeWhat it receives
Google Sign-in Your sign-in request. Google returns your verified email, display name and account id to Rally.
Backblaze B2 Storage for proof screenshots The screenshot image itself, in a private bucket. No public access is configured.
Expo Push notification delivery Your device's push token and the text of the notification (the task title and a short line about the action).
Resend Sending the invite email Your email address and the invite message.
Anthropic Optional — drafting suggested comments, only if the team has this enabled The task's title, its link and the admin's instruction text. No personal data: no names, emails or member records are sent.

If AI comment drafting is not enabled, Rally uses fixed local templates and nothing is sent to Anthropic. Drafts are always suggestions — an admin reviews them, a member edits and posts them personally, and Rally never posts anything itself.

When an admin pastes a link, Rally fetches that public page to read its title and thumbnail image. That request goes to the linked site, not to a data broker, and carries no information about you.

No advertising, no analytics, no tracking

Rally contains no advertising, no advertising SDKs, and no analytics or tracking software. It does not build profiles, does not track you across apps or websites, and does not use your data to target ads. Rally does not sell your personal data and does not share it with anyone beyond the service providers listed above, who process it only to do the job named in the table.

How long data is kept, and how to delete it

Your account record and your task history are kept for as long as you are a member of a team, because that is what the app is for. Tasks expire on their own once their deadline passes; the record of who completed them stays with the team's history until deleted.

To have your account and your data deleted, email shubh@codersera.com from the address you use to sign in, or ask an admin of your team to remove you. On a deletion request we remove your member record, your assignments and completion history, any proof screenshots you uploaded, and your push tokens. We will confirm by email when it is done. You can also ask us for a copy of what is stored about you, or for a correction, at the same address.

Deleting your Rally account has no effect on your Reddit, YouTube, X, Instagram or LinkedIn accounts, because Rally was never connected to them.

Security

Traffic to Rally is served over HTTPS. Sign-in produces a session token that expires, and every request for member data or a proof screenshot is checked against that session and the requester's role. Proof screenshots are stored in a private bucket that is not reachable without server credentials.

Children

Rally is a workplace and team coordination tool and is not directed at children. Accounts are created by an admin for adults on their team.

Changes to this policy

If this policy changes, the date at the top of this page changes with it. Material changes will also be sent to admins by email.

Contact

Questions, data requests or complaints: shubh@codersera.com.

Rally

The coordination layer for organic growth. Real people, real accounts, on time.

Product

How it works The app Platforms FAQ

Legal

Privacy policy Terms of service Support

Contact

shubh@codersera.com Codersera
© 2026 Rally. Rally informs and drafts. People act.