Privacy Policy

Effective date: August 5, 2026 · Applies to the RORY iOS app and rorypoints.com

The short version:

Your points live on your phone. Not on our servers. Rory doesn't ask for your bank logins, doesn't sync your accounts, and doesn't sell your data. What you enter stays on your device. When you talk to Rory, what's needed to answer is sent, answered, and not kept. That's the whole arrangement.

Who we are

RORY is published by Rory, LLC, a Georgia limited liability company ("we," "us"). RORY helps you track loyalty points balances you enter yourself and tells you about opportunities to use them well. Contact us any time at support@rorypoints.com.

What RORY does not collect

This list is the heart of our design, so it goes first. RORY does not:

Information you enter, and where it lives

You may enter into RORY: the credit cards you hold (chosen from a list), points and miles balances, loyalty programs you belong to, offers you choose to track, and redemption goals. This information is stored locally on your device. It is not uploaded to, or stored on, our servers. If you delete the app, it is gone (see "Deleting your data" below).

The opportunities feed (transfer bonuses, elevated redemptions, and similar) is public information that the app downloads from our content server. Serving that feed does not require sending us your wallet: matching opportunities to your cards happens on your device.

Rory (AI conversations)

When you talk to Rory, the app sends your message — together with the context needed to answer it, which may include the cards, balances, goals, and tracked offers you've entered — to our server, which processes it with our AI provider, Anthropic, to generate a response. This is transient, per-question processing: our server is stateless and does not store your conversations, wallet, or goals; conversation history you see in the app lives on your device and is re-sent with each question. We do not use your conversations for advertising, and under our API terms Anthropic does not use them to train its models. Rory's responses are suggestions about loyalty programs — not financial, legal, or investment advice.

Notifications

RORY's alerts (expiring offers, activation deadlines, and similar) are currently scheduled locally on your device — the app sets the reminder and iOS delivers it, without a notification identifier being sent to our servers. If a future version adds remote push notifications, delivery will involve a device push token (an identifier that lets a notification reach your device — it does not identify you personally), and we will update this policy first. You can turn notifications off at any time in iOS Settings, and per-alert-type toggles are available in the app.

Information collected automatically

Like most apps, our servers and service providers may log basic technical data when the app fetches content or asks Rory a question — such as IP address, device type, app version, timestamps, and request status — used for security, rate-limiting, debugging, and keeping the service running. We use this data in aggregate; we do not build advertising profiles from it.

Affiliate links

Some content in the app or on our website may include affiliate links — if you tap through and, for example, apply for a card, we may earn a commission from the issuer's affiliate program. Two commitments: affiliate relationships never determine what opportunities RORY shows you or what Rory recommends, and tapping an affiliate link shares no information from your RORY wallet with anyone. What happens on the destination site is governed by that site's privacy policy.

Service providers

We use a small number of service providers to run RORY, each receiving only what's needed for its job:

Deleting your data

Because your data lives on your device, you are in control of deleting it: use the reset option in the app's settings, or simply delete the app. Because RORY does not maintain user accounts, there is no server-side account to delete. If you have contacted support, you may ask us to delete that correspondence at support@rorypoints.com.

Security

Data you enter is protected by your device's own security (passcode, Face ID, and iOS encryption). Content served to the app and conversations with Rory travel over encrypted connections (HTTPS). No system is perfectly secure, but our best protection is structural: the most sensitive data simply never leaves your phone, and what does leave is processed and released rather than stored.

Children

RORY is not directed to children under 13, and we do not knowingly collect personal information from children. Credit card rewards are grown-up business.

Your privacy rights

Depending on where you live, you may have legal rights regarding personal information — such as the right to know what is collected, to request deletion, or to opt out of sale or sharing (we do not sell or share personal information as those terms are defined in US state privacy laws). Because RORY stores your data on your device rather than on our servers, most of these rights are already in your hands — but you can always contact us at support@rorypoints.com and we will help.

Changes to this policy

If we change how RORY handles data — for example, if a future version adds optional account sync or remote push notifications — we will update this policy, change the effective date above, and for material changes, tell you in the app before they apply to you.