Hangouter privacy policy

Privacy, in plain English

Last updated

This policy covers the Hangouter website, iPhone app, and Messages extension during the beta. “We” means the team operating Hangouter.

The beta does not require an email address or password to schedule a hangout. Your display name and responses are still personal data, even though your account has an anonymous ID.

  • Your name and availability help your group find a time.
  • Invite links can be forwarded. Share them with people you trust.
  • Push notifications are optional. We do not sell your personal data or use it for targeted advertising.

1. What we collect

  • Information you provide: your display name; event titles, emoji, dates, time windows, duration, timezone, expected group size, and selected time; and the half-hour availability slots you submit. You can use a nickname.
  • Account and event records: an automatically assigned user ID, event membership and role, response timestamps, and notification preferences. The ID links your activity within Hangouter; “anonymous” does not mean the records cannot be connected to you.
  • Activity and technical information: invite previews, joins, submissions, edits, and event changes, including timestamps and whether you used web, iOS, or Messages. Our services may process IP addresses, browser/device information, request URLs, and error and delivery logs to operate and troubleshoot the beta.
  • Notifications and support: notification service identifiers and device/session information described below, plus any contact details and content you choose to send in feedback or a support request.

We do not ask for your contacts, calendar, precise location, or advertising identifier. We do not read your full iMessage conversation. The Messages extension uses the conversation’s participant count to suggest a group size and handles Hangouter cards and links.

2. How we use it

We use this information to maintain your guest session, show shared schedules, rank matching time windows, save responses, refresh events, and deliver requested reminders and event updates. It also helps us provide support, prevent abuse, investigate failures, and measure beta outcomes such as response rates and time to submit.

Beta reports summarize activity, but the underlying activity records can be linked to an event and user ID. We do not sell personal data, run targeted advertising, or use your availability for advertising profiles.

3. Who can see your hangout

An invite link grants access. Anyone who has it can preview event details and response counts and, while joining is open, become a member. Private invite previews may also show the display names of people who have responded. Joined members, including the organizer, can see the named availability grid and results.

Access is not restricted to the original Messages conversation. A forwarded link can let someone else join. Public link-preview metadata does not include member names or availability, but people can copy, forward, or screenshot cards and event information. Deleting an event cannot remove copies already shared in Messages or saved by someone else.

4. Our service providers

These services process information to provide their part of Hangouter:

  • Supabase provides guest authentication, the event database, and realtime updates. Supabase privacy policy.
  • Vercel hosts the website and processes web requests and operational logs. Vercel privacy notice.
  • OneSignal manages push subscriptions, notification delivery, and related device/session data. OneSignal privacy policy.
  • Apple provides TestFlight/app distribution, Messages, and Apple push delivery. TestFlight may share beta usage, crash diagnostics, feedback, and, depending on how you join or send feedback, your name/email with us. Other devices use their platform’s push service. See the Apple privacy policy and TestFlight privacy details.

The Hangouter team may access records when necessary for operation, support, security, or a data request. We may disclose information when legally required or necessary to address abuse or protect people’s safety. Third-party services also have their own privacy terms, linked above.

5. Cookies and device storage

The website uses session cookies to recognize your guest account and protect member-only pages. It saves unfinished availability in your browser’s local storage so you can return after navigation or a failed request. A draft is removed after a successful submission; unfinished drafts do not have a timed expiry.

On iOS, the app and Messages extension share session credentials through Keychain and keep drafts, cached event information, your display name, and invite links in shared device storage. OneSignal also uses browser/device storage for subscription, permission, and session state.

Clearing browser data can remove your guest session and drafts, but it does not delete server records. Without a recoverable sign-in, losing the session or switching devices may mean you cannot access the same response again. Removing the app is not a server-side deletion request either.

6. Optional notifications

Responding never requires push permission. You can decline it, mute an event, or disable notifications in your browser or device settings. iPhone and iPad web push requires adding the site to the Home Screen.

Push permission and SDK data collection are different. When enabled in a Hangouter build, OneSignal initializes on website/app load, before you choose push permission. It may process IP-derived country, device/browser and OS details, language, timezone, session activity, and notification permission state. Registering for push adds a push token or subscription identifier; we link subscriptions to your Hangouter user ID. Declining or muting push does not itself delete OneSignal records or prevent all SDK processing. See OneSignal’s SDK data details.

Notification text may include an event title, a responder’s display name, and response progress or event status. That text can appear on a lock screen. The notification service receives delivery identifiers, message content, and an event ID/action; we do not send it the full availability grid.

7. Retention and deletion

Events do not automatically expire during the beta. Event details, responses, activity, and related notification records remain until an organizer or beta operator deletes them. Finalizing or cancelling an event freezes responses; it does not erase the event or its history.

Organizers can delete an event. This removes its active database records, including membership, windows, availability, event notification preferences, activity, and queued/delivery records, and invalidates the invite. Members cannot use that control to delete the whole event.

Event deletion does not automatically remove your guest authentication account, other events, provider subscription records, device copies, or messages already delivered. Service logs and backups can remain under provider retention processes. We have not set a single fixed retention period for all of these records; retention depends on their operational, security, support, and legal purpose. Contact us to request a broader review and deletion of your information.

8. Your choices and rights

Use a nickname, share only the availability you want your group to see, edit your response while the event is open, and choose whether to enable push. Organizers can delete events using the event controls. There is not yet a self-service guest-account deletion control.

You can request access to, correction of, or deletion of your information through the contact options below. Depending on applicable law, you may also have rights to a portable copy, to object to or restrict processing, to withdraw consent where processing relies on it, or to complain to a privacy regulator. These rights and any exceptions depend on your location and the request.

We may need to verify which guest records belong to you before acting. Include an event ID and your display name if available. Do not send session tokens, passwords, or other people’s private availability. A lost guest session can make verification harder.

9. Security and international processing

Hangouter uses HTTPS, membership-based access controls, and hashed invite tokens in the event database. No service can promise absolute security. Treat invite links as private access keys and use caution on shared devices.

Our providers may process information in the United States and other countries, which may have different privacy laws from where you live. Their policies describe their processing locations and transfer practices.

10. Children’s privacy

The beta is not directed to children under 13. We do not knowingly collect personal information from children under 13. If you believe a child has provided personal information, use the contact options below so we can investigate and arrange removal. The beta does not currently verify age.

11. Changes and contact

We may update this policy as the beta changes. The date at the top shows the latest revision; material changes will be highlighted on this page and, where required, communicated separately.

Direct privacy contact pending

A monitored privacy email for web-only participants has not yet been confirmed. TestFlight testers can contact the Hangouter team using “Send Beta Feedback” in TestFlight; Apple also receives that feedback. A direct contact address must be added here before this policy is published for the public beta.

Back to top ↑