bemyroomie

privacy policy

effective 19 may 2026

bemyroomie ("we", "us") is a discovery platform for verified university students looking for roommates and sublets. this policy explains what personal data we collect, how we use it, and the rights you have over it.

if you have questions, email privacy@bemyroomie.app.

what we collect

  • account info: first and last name, email, phone number, hashed password (for email/password signup) or the Google subject id (for Google sign-in).
  • listing content: apartment address, coordinates, rent, bedroom/bathroom counts, photos, videos, descriptions, and dates that you choose to post.
  • session data: a signed authentication cookie (JWT) that keeps you logged in, and basic request metadata (IP address) used for rate limiting and abuse prevention.
  • communications: emails you send to our support address.

how we use it

  • verify your email address (via a confirmation link).
  • display listings you post on the map and listings pages so other verified users can find them.
  • reveal email or phone to verified seekers when you have opted to share those fields on your listing.
  • send transactional emails (verification, account).
  • investigate abuse and enforce our terms.

we do not sell your personal data. we do not run advertising on the platform.

sub-processors

to operate the service we share the minimum necessary data with the following processors:

  • Neon — hosts our application database (US region).
  • Mailgun — sends transactional emails.
  • Cloudflare R2 — stores listing photos and videos.
  • Vercel — hosts and serves the application.
  • Mapbox — renders the map and resolves address autocompletion.
  • Upstash — rate-limit counters (request IP or user id only, no payload).

cookies

we set one cookie: session, an httpOnly, secure, sameSite=lax JWT used to keep you logged in. it expires 24 hours after issue. we do not use analytics or tracking cookies.

retention

  • account data persists until you delete your account.
  • listings persist until you delete them; deleted listings are removed within 30 days.
  • rate-limit counters expire automatically within the relevant window (minutes).

your rights

you can request a copy of your data, request correction or deletion, or close your account at any time by emailing privacy@bemyroomie.app. we will respond within 30 days.

if you are located in the EEA, UK, or California, you have additional rights under GDPR / CCPA. the contact above is the path to exercise them.

changes to this policy

if we materially change how we handle your data we will email verified users and update the effective date above before the change takes effect.