Privacy policy
Last updated · August 15, 2026
Roger is a neutral go-between for asks between people. You ask someone for
something, and Roger delivers the ask, collects the answer, does the
reminding, and keeps the shared record. Roger is operated by
ViaRoger, LLC, which is responsible for the data described here. In this
policy, "Roger" means the service at viaroger.com and ViaRoger, LLC.
This page says what Roger collects, why, who sees it, and how to get it
changed or deleted. It is written to be read. If anything here is unclear,
email support and a human will answer.
1. What Roger collects
Roger collects what the service needs to work, plus the technical data that running any web service produces:
- Your email address. It is your identity on Roger. There are no usernames.
- Your display name. You type it yourself. Nobody else can set it for you.
- Your timezone. Your browser reports it the first time you use Roger while signed in, without asking you, and Roger stores it so reminders arrive in your morning rather than your midnight. You can change it in Settings.
- Contacts you add. When you ask someone for something, you give Roger that person's name and email address.
- The asks themselves. Title, description, due date, and any files either party attaches.
- The shared timeline. Comments, date proposals, files, status changes, and a record of every reminder Roger sends.
- Task page visits. When either party opens a task page, Roger records the first and the most recent visit, and shows them to the sender until the ask is declined.
- Deliverability facts. Roger's email provider tells Roger whether each email was accepted, bounced, or reported as spam. When email to an address bounces hard or is reported as spam, Roger records that so it stops sending there.
- Your notification preferences. Mutes, pauses, and unsubscribes are stored so they can be honored.
- Technical data. Server logs and error reports include your IP address, browser type, and timestamps. Section 8 says how long they are kept.
- Support email. What you send to support is kept so Roger can answer you and keep a record of the request.
- A session cookie. See the cookies section below.
2. What Roger never collects
- No open tracking. Roger's emails contain no tracking pixels, and Roger never knows whether you opened one. What happens in your inbox stays in your inbox. Roger does record when a task page is opened, and shows that to the sender until the ask is declined; Section 4 has the details.
- No advertising and no ad trackers, on the site or in the app.
- No third party analytics services. Do Not Track and Global Privacy Control signals are honored for everyone by default, because there is no tracking, selling, or sharing to opt out of.
- No passwords. Sign-in works through a link sent to your email, so there is no password to store, forget, or leak.
Roger does not sell, rent, or trade your data. Not to advertisers, not to
data brokers, not to anyone. Roger does not sell or share personal
information as US state privacy laws define those terms, and does not use
it for targeted advertising or profiling.
3. If Roger emailed you and you never signed up
Roger sends email to people who have not signed up, because that is the
product: someone you know asked you for something and used Roger to
deliver it and do the reminding, so they would not have to nag you
themselves. The email names that person, and
replying goes straight to them.
- You do not need to sign up, and you never need a password. The buttons in the email open the task page directly.
- Until you engage, Roger holds your email address, the name the sender typed for you, the content of the ask they wrote to you, and delivery facts about the email sent to you.
- Opening the task page starts a signed-in session for your address on that browser and records the visit; the sender can see when you first and most recently opened it, and stops being able to once you decline. Every Roger email links to this policy.
- Every reminder carries a one-tap mute link. You can silence reminders for one ask, for one sender, or for all of Roger's reminders.
- The one-click unsubscribe in mail apps such as Gmail is honored, and it mutes all Roger reminders.
- If you report a Roger email as spam, Roger's email provider tells Roger, and Roger stops sending ask email to your address.
- Declining an ask is one tap and guilt-free by design.
- You can have everything Roger holds about you deleted by emailing support from the address the ask went to.
The sender and Roger have a legitimate interest in delivering a message
you were asked to receive, and that is the basis on which Roger handles
this data. You can object at any time by muting, and Roger will stop.
Roger never asks for a password or for payment in an email.
4. Who sees what
- An ask has exactly two parties: the person asking and the person asked. Both see the identical timeline: the ask, the comments, the files, the date proposals, and every reminder Roger sent. On a declined ask both of them see the ask, its files, and the decline, and Roger stops there.
- Task page visits are recorded for both parties. The view metadata, first viewed and last seen, is shown to the sender only, and once an ask is declined it is shown to nobody: it exists to tell a sender whether an ask is being avoided or simply not arriving, and after a no there is nothing left to work out.
- When you send an ask, the recipient sees your name and your email address, and
replies go straight to you.
Your name on outgoing email comes from your verified account and cannot be set per ask.
- If you mute reminders on an open ask, the other party is told that reminders are off, because it changes what happens next for them. Why someone cannot be reached is never disclosed: a sender is told only that a person has switched Roger emails off, never which control they used.
- Roger's operator can look at asks, files, and account data when needed for support, abuse review, or fixing bugs, and does not otherwise read them. The operator also receives automated operational reports: a notice when an account is created, and a daily summary of activity that carries counts and account email addresses. These reports never carry the content of an ask.
- Roger may disclose data when the law, a subpoena, or a court order requires it, or when needed to protect Roger, its users, or others from harm or abuse. Where lawful and practical, Roger tells the affected person first.
- If Roger is acquired, or the service changes hands, your data goes with it under this policy, and account holders are told by email.
- Nothing on Roger is public. There are no profiles, no feeds, and no directories.
5. Services Roger relies on
Roger runs on a small set of providers that process data on Roger's
behalf, under agreements that limit them to that:
- Postmark sends Roger's email and reports bounces and spam complaints back to Roger.
- Laravel Cloud, a managed hosting provider, runs the application and its database.
- Files you attach are stored in S3-compatible object storage managed by Laravel Cloud, and are served through short-lived signed links, never public ones.
- Sentry receives error reports when something in the app breaks. A report can include technical details of the failed request, and it is used to fix the bug and for nothing else.
- Migadu hosts the support mailbox.
Each of these processes data to run Roger, and for nothing else. Roger's
data is stored in the United States. Where a provider is outside your country,
transfers rely on that provider's certification under the Data Privacy
Framework or on standard contractual clauses in Roger's agreement with
them.
6. Cookies and sessions
- Roger sets two first-party cookies: a session cookie so you stay signed in, and a security token cookie that protects forms against forgery. Sessions are stored in Roger's own database and last roughly 30 days.
- Tapping a link in a task email signs you in on that browser. On a shared machine, sign out from Settings.
- There are no advertising cookies and no cross-site cookies. Both cookies are strictly necessary, which is why Roger shows no cookie banner.
7. Security
- Data is encrypted in transit, and encrypted at rest by Roger's providers. Files are served only through short-lived signed links.
- Task links are sign-in credentials. Treat them like passwords, and do not forward task emails. Links expire after 60 days, and you can sign out from Settings.
- If Roger learns of a breach affecting your data, Roger will tell you, and where the law requires it the relevant regulator, without undue delay.
8. How long Roger keeps things
- The timeline is append-only by design. Receipts are the product, so the record of an ask is kept for as long as either party's account exists. Nothing on a timeline is edited or deleted after the fact, apart from removals under the terms of service and the deletions described below; change is recorded as new events.
- An ask that never gets an answer is not quietly erased: it stops being chased, and it stays on the sender's record like any other ask. If its recipient never engaged with Roger in any other way and wants their details gone, one email to support deletes them.
- Server logs and database backups are kept by Roger's hosting provider only as long as operating the service needs them, and rotate automatically. Postmark keeps the content of sent email for 45 days and Sentry keeps error reports for 90 days.
- To delete your account and its data, email support from your account address. Roger may ask you to confirm through a link sent to that address. A human handles it, and Roger completes the deletion within 30 days and confirms by email.
- When your account is deleted, the other party to each of your asks keeps their record, with your name and email replaced by a placeholder. Your comments and files stay on their record, because the history of a shared ask is their history too. Your own copy is gone.
- After a deletion, Roger keeps the minimum needed to keep its promises: an address on the do-not-email list stays there, so a deletion never causes Roger to start emailing someone again, and records Roger must keep to meet a legal obligation are kept for as long as that obligation lasts.
9. Your rights
- See it: both parties can read the record of an ask on its task page at any time. A declined ask settles: its page keeps the ask, its files, and the decline itself, and the rest of its record stays on file rather than on screen. Email support for a copy of it.
- Fix it: your display name is editable in Settings. For anything else, email support.
- Take it: email support for a copy of your data, and it arrives within 30 days.
- Delete it: email support to delete your account.
- If you are in the EU or the UK, you also have the right to restrict or object to processing, to portability of your data, and to complain to your data protection authority. If the law where you live gives you further rights over your data, email support to exercise them and Roger will honor them.
- Roger will not treat you differently for exercising any of these rights.
10. Children
Roger is not directed at children under 16, and Roger does not knowingly
collect their data. Senders may not add contacts they know to be under
16. If you believe a child under 16 has data on Roger, email support and
it will be deleted.
11. Changes to this policy
When this policy changes, the date at the top changes with it, and prior
versions are available from support on request. If a change is material, meaning it
changes what Roger collects or who can see it, account holders get an
email before it takes effect, and every Roger email sent afterward links
to the new version.
12. Contact
Roger is run by ViaRoger, LLC. Questions, corrections, deletions: email
[email protected].
Postal mail reaches Roger at 2093 Philadelphia Pike, Claymont, DE 19703.