The short version
- → We only collect what we need to run the app.
- → Your plan details are only visible to invited friends.
- → Location is only collected while you actively share your ETA — never in the background otherwise.
- → We never sell your data.
- → Your phone number is verified via SMS for friend discovery — you can remove it any time.
- → Contact info from your phone is hashed — we never store raw numbers from your address book.
- → You can delete your account (and all your data) at any time from Settings.
1. Who We Are
Cliqit (“we,” “us,” “our”) operates the Cliqit mobile application (iOS and Android) and the website at cliqit.app. This Privacy Policy explains how we collect, use, disclose, and safeguard your personal information when you use our Service.
If you have questions, contact us at cliqit-support@googlegroups.com.
2. Information We Collect
2.1 Information You Provide Directly
| Username | A 3–20 character handle you choose during onboarding. Visible to other authenticated users. |
| Display name | An optional friendly name shown on your profile. Visible to other authenticated users. |
| Avatar photo | An optional profile picture you upload. Visible to other authenticated users. |
| Plan content | Names, descriptions, dates, times, and locations for plans you create. |
| RSVP responses | Your going/maybe/can't-go responses to plan invitations. |
| Poll votes | Your votes on polls within plans (e.g., choosing a time or place). |
| Report content | Reason and optional notes submitted with a content report. Visible only to our moderation team. |
2.2 Information from Authentication Providers
When you sign in with Apple or Google, they pass us a unique user ID, your email address, and optionally your full name (if it’s your first sign-in). We use this to create and identify your account. We do not receive your Apple/Google password.
2.3 Information We Collect Automatically
| Location data | GPS coordinates collected only while you actively share your live ETA for a plan. Used to calculate route and arrival time. Not used for advertising or analytics. See Section 2.6 below for details. |
| Device tokens | An Expo push token, generated if you enable push notifications, used only to deliver plan reminders and updates to your device. |
| Timezone | Your device timezone, used to display plan times correctly in your local time. |
| Crash & error reports | Anonymized stack traces and error metadata collected via Sentry to help us fix bugs. No User Content is included in error reports. |
| App update metadata | When you receive over-the-air (OTA) JavaScript updates via Expo EAS, your device may transmit its runtime version and platform to the update server. |
| IP address and headers | Standard HTTP metadata passed to our infrastructure for security and fraud prevention. |
2.4 Your Phone Number
During onboarding, we ask you to verify your phone number via a one-time SMS code. Once verified, your number is stored in E.164 format on your profile. This allows other users who have your number in their contacts to discover you on Cliqit. You may remove your phone number from your profile at any time in Settings, though doing so will make you undiscoverable via contact matching.
2.5 Contact Information (Optional)
If you grant contact access, your device’s contact phone numbers are hashed (SHA-256) on-device before being sent to our servers. We compare these client-provided hashes against server-side hashes of existing Cliqit users’ stored phone numbers to show you mutual connections. We never receive or store raw phone numbers from your address book, and the client-sent hash set is not persisted after the lookup completes. You may deny contact access at any time without losing any app functionality.
2.6 Location Data
When you choose to share your live ETA for a plan, Cliqit collects your GPS coordinates to calculate your route and estimated arrival time. Location is shared only with other attendees of that specific plan.
- When collected: Only while you have actively opted in to share your ETA for a specific plan. You must explicitly start sharing each time.
- Auto-stop: Location tracking stops automatically when you arrive at the destination, when the plan ends, or after a maximum of 30 minutes — whichever comes first.
- Retention: Location coordinates are ephemeral and are not stored after the sharing session ends. Only the final “arrived” timestamp is retained.
- Not used for: Advertising, analytics, profiling, or any purpose other than real-time ETA sharing with plan attendees.
- Background access: If you grant background location permission, your ETA remains accurate even when the app is not on screen. You can revoke this at any time in your device settings.
3. How We Use Your Information
| Provide the Service | To operate plans, process RSVPs, manage friendships and groups, share live ETA, and display your profile. |
| Authentication | To verify your identity at sign-in and across sessions. |
| Push notifications | To send you plan reminders, invite alerts, RSVP updates, and ETA notifications (only if you opt in). |
| Friend discovery | To match hashed contact numbers against existing users so you can find friends. |
| Moderation | To investigate content reports, enforce our Terms of Service, and apply automated content filters (e.g., profanity screening on usernames and plan names). |
| Analytics & improvement | To understand how features are used (in aggregate, non-identifiable form) so we can improve the product. |
| Security | To detect, prevent, and respond to fraud, abuse, and security threats. |
| Legal compliance | To comply with applicable laws, regulations, or legal proceedings. |
4. How We Share Your Information
We do not sell your personal information. We share it only in these limited circumstances:
4.1 With Other Users
Your username, display name, and avatar are visible to all authenticated Cliqit users so friends can find and add you. Plan details and RSVP status are visible only to invited friends in each plan. Your live ETA is visible only to friends in the specific plan you are sharing it for.
4.2 With Service Providers
| Supabase | Database, authentication, and file storage. Processes your data on our behalf under GDPR data processing agreements. Hosted in the US. |
| Expo / EAS | App build, delivery, and over-the-air update infrastructure. Receives your Expo push token for notification routing and runtime version for OTA updates. |
| Sentry | Error monitoring. Receives anonymized crash reports. No User Content is transmitted. |
| Apple / Google | Authentication providers. Their privacy policies govern data they collect during sign-in. |
All service providers are contractually obligated to use your data only to provide services to us and to protect it.
4.3 For Legal Reasons
We may disclose information if required to do so by law or in good faith that such action is necessary to comply with a legal obligation, protect the rights or safety of Cliqit or others, or investigate fraud or abuse.
4.4 Business Transfers
If Cliqit is acquired by or merged with another company, your information may be transferred as part of that transaction. We will notify you before your information becomes subject to a different privacy policy.
5. Data Retention
We retain your personal information for as long as your account is active or as needed to provide the Service. Specifically:
- Account data (profile, username, avatar) — retained until you delete your account.
- Plan data (names, dates, locations, invitees, RSVPs, polls) — retained until the plan creator or your account is deleted.
- Content reports — retained for up to 2 years for moderation integrity, even after account deletion, but stripped of any identifiable references if the reporter’s account is deleted.
- Crash logs (Sentry) — retained per Sentry’s standard retention policy (90 days by default).
- Location data — ephemeral; GPS coordinates are not stored after each ETA sharing session ends. Only the “arrived” timestamp is retained.
- Push tokens — deleted immediately when you disable notifications or delete your account.
- Phone number — retained on your profile until you remove it or delete your account.
- Contact hashes — not persisted; used only for the duration of the lookup request.
6. Your Rights and Choices
6.1 Access and Correction
You can view and update your profile information (username, display name, avatar, timezone) at any time from the app’s Profile screen.
6.2 Account Deletion
You can permanently delete your account from Settings → Delete account in the app. Deletion removes your profile, all plans you created, your RSVPs, poll votes, and your friendships. This action is irreversible.
6.3 Push Notifications
You can enable or disable push notifications at any time from Settings → Push notifications in the app, or via your device’s system settings.
6.4 Contact Access
You can revoke contact access at any time via your device’s system settings. This only affects friend discovery — it does not impact any other feature.
6.5 Location
You can stop sharing your location at any time by tapping “Stop Sharing” in the app. You can also revoke location permissions entirely via your device’s system settings. Sharing automatically stops when you arrive or after 30 minutes.
6.6 Data Requests
To request a copy of your data or to raise a data-related concern, email us at cliqit-support@googlegroups.com. We will respond within 30 days.
6.7 California Residents (CCPA)
If you are a California resident, you have the right to know what personal information we collect, to request deletion, to opt out of sale (we do not sell your data), and to non-discrimination for exercising these rights. Submit requests to cliqit-support@googlegroups.com.
6.8 EEA / UK Residents (GDPR)
If you are in the European Economic Area or United Kingdom, you have rights including access, rectification, erasure, restriction, portability, and objection. Our legal basis for processing is primarily contractual necessity (to provide the Service) and legitimate interests (security, fraud prevention). Contact us at cliqit-support@googlegroups.com to exercise your rights or to lodge a complaint with your local supervisory authority.
7. Data Security
We take reasonable technical and organizational measures to protect your information:
- All data in transit is encrypted using TLS/HTTPS.
- Database access is governed by row-level security (RLS) policies that enforce per-user visibility at the query layer.
- Authentication uses industry-standard OAuth 2.0 flows via Apple and Google; we never store passwords.
- Rate limiting is applied to sensitive endpoints to prevent brute-force and abuse.
- Plan data is only accessible to invited friends via database-level access controls.
No method of transmission over the internet is 100% secure. We cannot guarantee absolute security, and you use the Service at your own risk.
8. Children's Privacy
Cliqit is not directed at children under the age of 13. We do not knowingly collect personal information from children under 13. If you believe we have inadvertently collected such information, please contact us immediately at cliqit-support@googlegroups.com and we will delete it promptly.
9. Third-Party Links and Services
The Service may contain links to third-party websites or services. This Privacy Policy does not apply to those third parties, and we are not responsible for their privacy practices. We encourage you to review the privacy policies of any third-party services you access.
10. International Data Transfers
Our infrastructure is currently hosted primarily in the United States. If you access the Service from outside the US, your information will be transferred to and processed in the US. By using the Service, you consent to this transfer. Where required, we rely on standard contractual clauses or other approved mechanisms to facilitate international transfers.
11. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. When we do, we will update the effective date at the top of this page. For material changes, we will notify you in-app or by email. Your continued use of the Service after the update constitutes acceptance of the revised policy.
12. Contact Us
For any privacy questions, requests, or complaints:
Cliqit — Privacy TeamEmail: cliqit-support@googlegroups.com