Privacy Policy

Last updated: December 9, 2025

Rally Us is operated by mad concepts llc ("we," "our," or "us"). We operate the rally-us.com website and related services (collectively, the "Service"). This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our Service.

1. Information We Collect

Information You Provide

  • Account Information: Email address, name, profile photo, bio, and location when you create an account.
  • Phone Number: If you opt-in to SMS notifications, we collect your phone number.
  • User Content: Photos, videos, text submissions, and other content you upload during challenges.
  • Group & Challenge Data: Group names, lore entries, challenge configurations, and participation data.
  • Communications: Messages you send us for support or feedback.

Information Collected Automatically

  • Device Information: Browser type, operating system, device identifiers.
  • Usage Data: Pages visited, features used, time spent on the Service.
  • Log Data: IP address, access times, referring URLs.
  • Cookies: We use essential cookies for authentication and preferences. See our Cookie section below.

Information from Third Parties

  • Social Login: If you sign in via Google, we receive your email, name, and profile picture from Google.
  • Magic Links: We use Supabase for passwordless authentication via email magic links.

2. How We Use Your Information

We use your information to:

  • Provide, maintain, and improve the Service
  • Create and manage your account
  • Process challenge submissions and calculate leaderboards
  • Send notifications (email and SMS if opted-in) about challenges, reminders, and updates
  • Generate AI-powered content (roast prompts, challenge suggestions) using your group's lore
  • Respond to your inquiries and provide customer support
  • Monitor and analyze usage patterns to improve user experience
  • Detect, prevent, and address technical issues and security threats

3. AI and Automated Processing

Rally uses artificial intelligence (AI) to enhance the challenge experience. This includes:

  • Prompt Generation: AI generates personalized prompts using your group's lore (inside jokes, people, places).
  • Image Generation: For certain challenge types, AI may generate themed images.
  • Content Moderation: AI may be used to detect inappropriate content.

AI-generated content is based on information you voluntarily provide. You can control what lore is shared with your group through your group settings.

4. How We Share Your Information

We may share your information with:

Other Users

Your profile, submissions, and scores are visible to other members of your groups and challenges.

Service Providers

We use trusted third parties for:

Authentication (Supabase)
Database hosting (Supabase/PostgreSQL)
File storage (Supabase Storage)
AI services (Google Gemini, OpenAI)
Email delivery (Resend)
SMS delivery (Twilio)
Hosting (Vercel)

Legal Requirements

We may disclose information if required by law or to protect rights, safety, or property.

Business Transfers

In connection with a merger, acquisition, or sale of assets.

We do not sell your personal information to third parties.

5. Data Retention

We retain your personal information for as long as your account is active or as needed to provide the Service. You can request deletion of your account and associated data at any time by contacting us at privacy@rally-us.com.

Challenge submissions and group lore may be retained in anonymized form for improving our AI models, unless you request deletion.

6. Data Security

We implement appropriate technical and organizational measures to protect your personal information, including:

  • Encryption in transit (HTTPS/TLS)
  • Encryption at rest for sensitive data
  • Secure authentication with magic links and OAuth
  • Regular security reviews and updates
  • Access controls limiting employee access to personal data

No method of transmission over the Internet is 100% secure. While we strive to protect your information, we cannot guarantee absolute security.

7. Cookies and Tracking

We use the following types of cookies:

  • Essential Cookies: Required for authentication and core functionality.
  • Preference Cookies: Remember your settings like theme preferences.

We do not use advertising or tracking cookies. We do not participate in cross-site tracking or sell data to advertisers.

8. Your Rights

Depending on your location, you may have the following rights:

Access

Request a copy of your personal data.

Correction

Request correction of inaccurate data.

Deletion

Request deletion of your personal data.

Portability

Request your data in a portable format.

Objection

Object to certain processing of your data.

Withdraw Consent

Withdraw consent for optional processing.

To exercise these rights, contact us at privacy@rally-us.com.

9. California Privacy Rights (CCPA/CPRA)

If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA):

  • Right to Know: You can request information about what personal data we collect, use, disclose, and sell.
  • Right to Delete: You can request deletion of your personal information, subject to certain exceptions.
  • Right to Opt-Out of Sale: We do not sell personal information. If this changes, we will provide an opt-out mechanism.
  • Right to Non-Discrimination: We will not discriminate against you for exercising your privacy rights.
  • Right to Correct: You can request correction of inaccurate personal information.
  • Right to Limit Use of Sensitive Information: You can limit how we use sensitive personal information.

Categories of Personal Information We Collect

CategoryExamplesCollected
IdentifiersName, email, phone number, IP addressYes
Personal InformationName, phone number (CA Civil Code 1798.80)Yes
Internet ActivityBrowsing history, interactions with ServiceYes
Geolocation DataGeneral location from IP addressYes
Audio, Visual, ElectronicPhotos and videos you uploadYes
InferencesPreferences derived from usage patternsYes

To submit a CCPA request, email privacy@rally-us.com with "CCPA Request" in the subject line. We will verify your identity before processing requests.

10. European Privacy Rights (GDPR)

If you are located in the European Economic Area (EEA), United Kingdom, or Switzerland, you have rights under the General Data Protection Regulation (GDPR):

Legal Basis for Processing

  • Contract: Processing necessary to provide the Service you requested.
  • Consent: Processing based on your explicit consent (e.g., SMS opt-in, lore sharing).
  • Legitimate Interests: Processing for our legitimate business interests, balanced against your rights.
  • Legal Obligation: Processing required to comply with applicable laws.

Your GDPR Rights

  • Right of Access: Obtain confirmation of processing and access to your data.
  • Right to Rectification: Correct inaccurate or incomplete data.
  • Right to Erasure: Request deletion ("right to be forgotten").
  • Right to Restrict Processing: Limit how we process your data.
  • Right to Data Portability: Receive your data in a structured, machine-readable format.
  • Right to Object: Object to processing based on legitimate interests.
  • Rights Related to Automated Decision-Making: Not be subject to decisions based solely on automated processing.

International Data Transfers

Rally is based in the United States. If you access the Service from outside the US, your data may be transferred to and processed in the US. We use appropriate safeguards for international transfers, including Standard Contractual Clauses where applicable.

Data Protection Officer

For GDPR-related inquiries, contact us at privacy@rally-us.com. You also have the right to lodge a complaint with your local data protection authority.

11. Children's Privacy

The Service is not intended for children under 13 years of age. We do not knowingly collect personal information from children under 13. If you believe we have collected information from a child under 13, please contact us immediately at privacy@rally-us.com.

12. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by posting the new policy on this page and updating the "Last updated" date. For significant changes, we may also send you an email notification.

13. Contact Us

If you have questions or concerns about this Privacy Policy or our data practices, please contact us at:

mad concepts llc
Email: privacy@rally-us.com
Website: https://rally-us.com