YOUR INFORMATION, EXPLAINED
Privacy & retention
JAWNA helps people find friends through shared hobbies and activities. This page explains the information used by the app and the choices available to you.
Updated 1 October 2026 · اقرأ بالعربية
What you share with members
Standalone checklists are private to their owner and people who explicitly join. A direct friend invitation remains pending until accepted and its membership ends when that owner–friend connection ends. Owners can optionally enable a revocable sign-in-and-join link; joining through that link does not require or create a friendship. Joined members can see the list, item authors and volunteers. Resetting or disabling a link prevents new joins; removing a member also disables the current link. Leaving or removal deletes your authored items and releases your claims, with nothing restored on rejoining. Closed standalone lists are read-only for 30 days and then unavailable. Activity checklists belong only to the host and currently accepted participants and become unavailable at the activity’s end; they cannot bypass host approval or capacity. Quantities refer to one volunteer taking the whole item. Optional due dates use their saved time zone and do not send reminders or extend access. Private exports include your authorized authored items and volunteering, without another person’s completion details or invitation tokens. Pending saves remain in this tab’s memory; bounded retry fingerprints contain no item text and expire after the following UTC day. Existing backup retention applies.
Important dates are private until you choose which accepted friends may see them. Birthdays store a month and day, without a birth year or age. Other dates can happen once or each year. Sharing is limited to the specific friendships you selected; new friends receive nothing automatically. Unsharing, blocking, losing that friendship, suspension or account deletion removes the affected sharing and reminder settings. Reconnecting does not restore them. Friends can privately choose an early reminder, using their saved time zone, and mark an occurrence Done. The date owner cannot see those choices. Reminders appear only inside this tool; no email, push notification or message is sent, and missed reminder windows do not create a delivery backlog. Editing the date updates what its selected friends see. Your dates remain until you delete them; past one-time dates remain in My dates. Your export includes your own dates and sharing choices, and your own authorized reminder settings, without copying a friend’s date text or exposing other recipients. Account deletion removes your dates, sharing, reminders and retry records. Retry records contain opaque identifiers, request fingerprints and times; they expire after the following UTC day and are removed in bounded cleanup. Nonrefundable daily usage counters survive account deletion until cleanup after that expiry. Drafts and uncertain retries stay in this tab’s memory and clear when your account or session changes. Existing private-backup retention applies; removing access cannot recall a copy someone already saw.
Your personal schedule starts private. Each dated Free, Busy or Open to plans block stores its optional label, start time, time zone and duration. You can share an individual block with selected accepted friends. Sharing does not expose the rest of your schedule. Common time compares your free blocks with the blocks one friend has explicitly shared with you; missing time does not indicate availability. Unsharing, blocking, ending a connection, suspension or account deletion removes the affected access. Reconnecting does not restore it. Turning a slot into an invitation creates a separate plan only after you review and save it; later schedule changes do not change an existing invitation. No device calendar is uploaded and no message or reminder is sent automatically. Blocks expire 30 days after their end and are removed in bounded cleanup. Your export contains only your own retained blocks and sharing choices. Account deletion removes your blocks, grants and retry records. Nonrefundable daily usage counts remain until cleanup after the following UTC day. Retry fingerprints expire after the following UTC day; drafts and uncertain retries stay in this tab and clear when your session changes. Existing private-backup retention applies, and removing access cannot recall copies already seen.
Social profile links are optional. They appear wherever your profile is already visible, including an eligible public member page. These are links you enter, not verified identities or sign-in connections. Opening one takes the visitor to that platform, which may receive their network and account information under its own privacy policy. We store the links with your profile, include them in your export and remove them when your account is deleted. Removing a link stops future display here but cannot recall copies.
Signed-in members can see your display name, bio, hobbies, languages, group preferences, organization or community, posts and photos. Your residence country and approximate city appear in profiles and location searches only if you enable sharing. Birthplace is separate, optional and appears only when both people consent and share the same country. It never affects match ranking.
Country and city suggestions are searched on this server using a local copy of GeoNames data, licensed under CC BY 4.0. The data has been filtered and compacted and may be incomplete. You can enter a city yourself. The picker does not request your device location or send your search to a geocoding provider.
In Discover → Experiences, Use my location requests your browser's permission only when tapped. Coordinates are rounded to three decimal places before being sent to this server to sort venues by approximate straight-line distance. They are not saved to your profile or database. Choose a country or city to browse without device location. Opening Map loads visible map tiles from OpenStreetMap, which receives your IP address, this site's origin and the map area requested. Only locations explicitly set for published businesses become venue pins; city centers are approximate reference points.
Activity titles, hobbies, dates, UAE times and approximate areas are visible to eligible signed-in members. Exact meeting notes are sent only to the organizer and accepted members. Blocking, account suspension and content moderation can further restrict visibility.
Quick questions for friends
Quick offers are visible only to the sender and the accepted friends they choose. The sender sees names and replies; recipients see only their own reply. Replies close after 30 minutes, 1 hour or 3 hours. Ending an offer closes new and changed replies. Authorized history remains for seven days after the original deadline, and you can clear your answer during that time. Blocking, disconnecting or suspension ends affected access and clears replies permanently; reconnecting does not restore them. Account deletion removes your offers and anonymizes your recipient entries. After seven days, history is hidden and removed during bounded cleanup. Private backups follow the retention rules below.
Separate Quick room
The Quick room at /quick is separate from your JAWNA account. It stores your chosen name, three hobbies and any contact details you choose to add. People who join the room and share a hobby can see your name, the hobbies you share, and optional contact details; anyone with the link may join. A separate browser cookie identifies your room profile. Leave deletes your live Quick profile. Your profile stops appearing 24 hours after your last save. Signing out of or deleting your main JAWNA account does not perform Quick's Leave action. Private backups follow the backup limits below.
Activity invitation links
Anyone holding an activity invitation link can see its organiser's display name and public plan details. Guest names are unverified, and only the organiser sees names and replies. Private meeting details require the organiser's approval and are shown only to that approved guest. A group-sourced invitation does not reveal the private group's members, conversations or calendar. Do not put a home address in the public place field.
Your browser stores a random guest key for this invitation in the current session so you can change or clear your answer. Clearing erases your name and choice; an anonymous version record remains until the plan is removed. Closing the session or using another device can lose access to your answer. Replacing or revoking the invitation link ends access through the old link, but cannot recall details already seen. No guest contact information, account or download is required.
Dated links close at the end of the chosen UAE day; undated links close after 30 days. Plans and replies are removed within 30 days after closure by scheduled cleanup, which may be delayed while this PC is off. Deleting the organiser's account removes their invitations and replies. Account exports omit other guests' names and all invitation secrets. Private backups follow the retention described below. There are no email or push reminders; keep the link to check changes.
Private scoreboard
When enabled, Scoreboard saves the game title, player or team names you enter, and scores privately in your account until you delete the game or account. Finished games remain in your history. Your data export includes retained games. Deletion clears live names and scores; a minimal retry record prevents deleted games from reappearing. Existing private backup retention applies. Guest games stay in this browser, can be seen by anyone using its guest mode, and do not automatically transfer to an account.
Experience wishlist
Your experience wishlist is private until you make it Public. Anyone can then see your display name, username and saved published experiences through its link or your eligible member page, including when signed out. Hidden or deleted experiences are excluded. Making the list private or replacing its link ends access through the old link, but cannot recall saved copies. Account deletion removes your wishlist. Your account export includes saved items without public-link tokens.
Public posts: your choice
New posts are visible to everyone by default, including visitors without an account. You can optionally limit who sees a post by selected interests, gender or nationality, or a combination. If interests are selected, a signed-in viewer must have at least one of them in their current profile. The viewer must also match any gender or nationality restriction. Interests, gender and nationality are self-declared, not verified. If you provide a nationality, it determines eligibility for nationality-limited posts even when you choose not to display it on your profile; it is not inferred from your location. Guests cannot satisfy these limits. Authors are not excluded by their own audience filters. The same limits apply to photos, videos and their URLs, comments and access to an attached activity. Only posts without interest, gender or nationality limits can enable guest access to the author's profile picture. Older Members-only posts keep that restriction until their owner explicitly removes it; ordinary editing does not publish them. Unrestricted public posts show your display name, caption, hobby, photo and like count without revealing your email or private profile details. Signed-out visitors can include someone you blocked. Changing the audience ends further access for people who no longer qualify, but cannot recall copies already saved or shared.
What stays private
Gender is optional and self-declared, not verified. If you provide it, signed-in members can see it and use it in people/post-author searches. Every post starts with Everyone as its gender audience. Women-only or men-only posts require a signed-in viewer with the matching profile selection; the author can always see their own post. These restrictions cover the post and photo, including shared photo URLs. Guests cannot see restricted posts. Audience controls cannot recall copies someone already saved.
Place-group chat is visible to eligible members who join, including people who join later. Leaving ends your group access but does not delete earlier messages. You can delete your own messages. Blocking and moderation restrict what each member can see.
Appearing in a place’s people list is optional and starts off for existing memberships and every new join or rejoin. If you opt in, eligible current and later group members can see your name and hobbies there and open the parts of your member profile they are already allowed to view. Hiding, leaving, account deletion, suspension or group archiving removes you from subsequent directory results. Blocks hide the two accounts from each other. Hiding or leaving does not erase earlier chat or its authorship; account deletion follows the rules below. Previously viewed or saved copies cannot be recalled.
Group counts describe membership, not people physically at the venue. These place groups do not request GPS, track presence or calculate nearby distances. Opening a venue’s Maps link sends Google Maps a search using public venue details, without private profile information or meeting notes.
Feedback, bug reports, suggestions and the operator's replies are visible only to the author and the operator. The form sends the text and category you choose, not automatic screenshots or copies of your private conversations. Place suggestions are reviewed by the operator; approved place information becomes visible to signed-in members.
Your email, account export, password credentials, sessions and recovery codes are not part of another member's public profile. Reports and contact requests go to the community operator, not to other members. A report against you is not included in your account export.
Age and nationality are optional, self-declared profile details. Each stays private unless you choose to share it with signed-in members. Shared values appear on your member profile and can be used in People search; shared nationality can also filter activity hosts. Guests cannot see or search these fields. Turning sharing off removes them from subsequent discovery results. No date of birth is collected for age search, and neither field is inferred from residence or birthplace.
The sharing choice controls nationality's display and discovery. Your declared nationality can still determine access to nationality-limited posts when sharing is off.
Matching uses profile interests, shared approximate area, organization, languages and group preferences. It does not use birthplace, nationality, religion, private messages or moderation records. A score is an explanation of shared fields, not a compatibility probability or identity check.
Direct messages
Signed-in members can send private text and one optional photo, video, voice note or GIF to a chosen member without becoming connections. These conversations are stored on the operator’s PC and are not end-to-end encrypted. Blocking or suspension prevents future private access; removing a connection alone does not hide the conversation. Reporting a selected received message, including after a block, copies only that message, its attachment if present, and your report details into the operator’s inbox. Deleting your own message or operator removal clears its live text and attachment, but a selected report copy may remain. Deleting either participant’s account removes the pair’s conversation, attachments and selected report evidence from the live database. Your export includes only your own retained sent messages and attachments, never received media or report copies. Access changes cannot recall copies already saved by recipients, and the private backup policy below still applies.
You can delete your own message text; the conversation retains a “Message deleted” marker and identifiers to prevent a retry from restoring it. A previously submitted report may retain its selected-message evidence. Deleting either participant’s account removes their shared live conversation and its message reports. Your account export includes your own sent messages, not copies of the other person’s messages. Backups follow the retention rules below.
Where information is stored
When enabled, Message the creator lets visitors chat privately with the selected creator account without registering. A separate private browser cookie provides access for up to 30 days from creation; clearing it removes access to that chat. Messages expire after 30 days. Delete this chat removes its live messages; anti-spam records with hashed network/browser identifiers and delivery IDs remain for up to 24 hours. This chat is stored on the operator's PC, is not end-to-end encrypted, and follows the backup policy below. A guest chat is tied to this browser rather than a member account.
The community operator stores application data and private backups on their PC. The operator can access data to run and moderate the community. Meeting notes are protected by access controls; they are not encrypted from the operator. Use the public HTTPS address when it is available to protect information in transit.
The app does not require a paid matching or photo-processing service. Public HTTPS may pass through the configured tunnel provider. When configured, Google, Discord or GitHub can appear as optional sign-in choices. If you choose one, that provider handles authentication. The app uses your provider account identifier, verified email and a suggested display name to create or link your account. Your account email and linked sign-in details stay private. Provider access and refresh tokens are not saved in the community database or sent to your browser. These sign-in methods do not verify your age or real-world identity.
When configured, Facebook is another optional sign-in choice. We use your app-scoped Facebook account identifier and suggested display name. Facebook may suggest an email, which you can change during signup and which this app does not treat as verified. Matching email addresses never automatically link accounts. The current Settings and Profile screens do not offer manual provider linking. Your account email and linked sign-in details stay private. Facebook access tokens and the app secret are not saved in the community database or sent to your browser. Facebook sign-in does not verify your age or real-world identity.
When configured, Continue with TikTok uses your app-scoped TikTok account identifier and display name. TikTok does not supply an email address. You enter a private contact email during signup; it is not proof of email ownership and never automatically links an existing account. We request only basic profile access, not videos, posts, contacts or followers. Provider access and refresh tokens are discarded after sign-in and are not stored in the community database or sent to the app. The current Settings and Profile screens do not offer manual TikTok linking.
When available, private voice and video calls share your microphone and, for video, your camera only after you choose to call or answer and allow access. Both people must keep JAWNA open. JAWNA does not record these calls or save their live media in its database. Temporary call identifiers, participants and connection signals are held in server memory for the call. The configured Cloudflare TURN service relays encrypted media and receives connection information such as IP addresses and traffic volume. The other participant can see or hear the media you share and may record it independently. Mute, camera-off and end-call controls let you stop sharing; leaving the foreground also ends the call.
When configured, Sign in with Apple identifies you by your Apple account identifier. Email may be missing or use Apple's private relay; you can enter a contact email during signup, and matching emails never automatically link accounts. We encrypt Apple refresh tokens on this server so we can revoke them when you delete your account. Tokens, encryption keys and signing keys are excluded from account exports and browser responses. Deleting your JAWNA account queues Apple disconnection without waiting for Apple: encrypted revocation material is kept and retried until Apple confirms it. Temporary provider or configuration failures can delay disconnection. Existing private backups may retain encrypted tokens. Short-lived keyed digests prevent an older sign-in from recreating a deleted account.
For experience catalog searches, JAWNA may send your selected destination, search text and filters to Viator through its server to obtain results. Some results come from temporary catalog caches; searching the destination list does not itself send your search text to Viator. Provider images load from Tripadvisor-related image services, which receive the image request and network information such as your IP address. On the website, choosing Check availability opens the provider's booking site. Planning an experience in JAWNA does not make a booking; the provider's own notice applies when you use its site.
Photos and browser storage
Your optional profile gallery contains up to six ordered photos and videos, including at most one video. It appears in People for eligible viewers. Guests can view it while you have an eligible public post; blocks, bans, suspension and removal of public eligibility restrict later access. Gallery photos share the app’s photo storage allowance, and gallery video shares the post-video allowance; new items also count toward the shared rolling upload limit. Reordering or deleting items does not restore a recent upload allowance. Removing a gallery item ends subsequent access to its old link, but cannot recall copies already saved. Your account export contains your own gallery, and account deletion removes its live files. Existing private backup retention applies.
Post media and direct-message and group-message attachments share an allowance of 20 uploads in a rolling 24 hours. Post and chat photos share a limit of 20 live photos or 5 MiB per sender. Chat videos, voice notes and GIFs share a separate limit of 30 live files or 50 MiB per sender across direct and group messages; post videos retain their separate 200 MiB allowance. All live media and selected report copies count against the server’s shared storage budget. Deleting media frees live storage but does not refund a recent upload. Photos are limited to 256 KiB and 1,200 pixels per side and have image metadata removed. A chat video must be MP4 with H.264 video and optional AAC audio, up to 60 seconds, 16 MiB and 3,840 pixels per side. A voice note must be WebM Opus or MP4 AAC, up to 120 seconds and 8 MiB. GIFs are limited to 5 MiB, 1,600 pixels per side, 200 frames, 60 seconds and 67,108,864 decoded pixels. Video, audio and GIF files retain their uploaded bytes and may retain embedded metadata; format checks do not review their meaning. Posts retain their existing limit of 10 ordered photos or videos totalling 60 MiB; each post video can be up to 20 MiB. Each message contains at most one attachment. Group attachments follow the message’s 30-day expiry, membership access, removal and selected-report retention. Own exports contain only currently authorized authored media. Existing private backup retention applies.
The supplied browser uploader compresses photos and removes original image metadata before sending them. Direct post-photo API uploads are checked for format and size but may retain metadata. Avoid posting private information, including precise home locations, documents or someone else's contact details.
A private session cookie keeps you signed in. When browser storage is available, local storage saves your language and Experiences display-currency preferences. For a signed-in account, it also saves People search filters—interests and matching mode, country or city, gender, age range, nationality and spoken languages—and the chat-background choice, including an optional locally processed background photo, in this browser. It also saves the last Tools tab separately for each account or guest, plus local Four Card Thief and Tonj game progress. Guest Decision Wheel libraries use IndexedDB in this browser for up to 20 saved wheel names, choices, emoji and optional locally stored photos; anyone using this browser's guest mode can see them. GEIE222 study progress stores the selected chapter, tab, question type, review choice and current item, plus each question's answer, checked state and revealed state, in local storage. These browser-only preferences, libraries, game states and study progress do not sync to another browser or device and disappear when that browser storage is cleared. The main JAWNA app uses dark appearance only. Jawna Quick keeps its separate local colour-theme preference. Form drafts remain in the current page until discarded, closed or replaced; they are not saved as an offline account copy. No private content is stored in an offline service worker cache.
To reopen an activity, group, plan or poll, or preview an invitation after provider sign-in, this tab may temporarily store its identifiers, target view or invitation code, the provider and a 15-minute expiry. No messages, plan text, poll questions, ledger, answers or account details are stored. The app clears this when you return or cancel. Joining, attendance and voting still require separate choices.
Team picker keeps the names you enter or select and its results in this tab's memory. Selecting friends or a group loads names you already have permission to see; adding them to the picker does not invite or notify them. It does not upload them or save them across a reload. Copy results only when you want to keep or share them. Adding a joined activity to your calendar creates a file containing its activity name, public meeting location and schedule; it does not read your calendar. A downloaded copy does not update automatically, and deleting or changing the activity cannot remove copies you kept elsewhere.
Access, export and deletion
If you start account-deletion review and choose provider sign-in on the website, this tab may temporarily remember that review request, the provider and a 15-minute expiry. It saves no account details, password or deletion approval. Returning only reopens account review; deletion still requires your confirmation. Expired requests are not resumed. Leaving the deletion flow cancels the request.
Use Profile to edit your information and sharing choices. While signed in to an active account, choose Delete account in Settings to review and delete your live account data after confirming authentication. The retention exceptions below still apply.
Your sign-in email, password credentials, sessions and recovery codes remain private. The current Settings and Profile screens do not offer data download, new recovery-code generation, password changes or provider linking.
JAWNA does not send email-verification or password-reset messages. Where an email-and-password sign-in screen is available, including in supported native builds, a previously saved recovery code can be used there to reset your password. On the social-only website, open Settings, then Help & feedback. Under Contact support, choose Use a recovery code. Each code works once. An already-linked sign-in provider can provide another way into your account when available. Matching email addresses do not by themselves merge accounts. An authoritative verified provider email may link automatically only when this account already has verified history for that exact email; otherwise the proof-gated sign-in flow requires confirmation of the existing account. Without a saved code or usable linked sign-in, there is no email reset fallback.
Deletion removes your live profile, sign-in identities, sessions, recovery codes, posts, photos, owned activities, relationships, requests and blocks. Reports involving your account, related moderation records and your messages to the operator are also removed from the live database. Other members' unrelated records remain.
Optional activity details on a post—including the venue or area, time, duration, group size, confirmed signup count and cost—follow that post's audience. Use a public meeting place rather than a private home address. Joining requires an account. Only the host sees the participant list and requests; other readers see counts, not names. A signup is not a location check-in. Deleting the post removes its activity and signup records.
Post comments and replies
Comments follow the post's current audience. Anyone can read comments on a visible Public post shared with Everyone; writing requires an account. Your display name and eligible profile picture appear with your comment. Changing the post audience changes who can read its comments. Blocking and moderation also affect access. Avoid including private contact details in public comments.
Deleting a comment removes its text, but an anonymous top-level marker may remain to keep other people's replies together. Identifiers, retry records and timestamps can remain to prevent duplicate writes and enforce limits. Account deletion removes your comment text and identity; anonymous markers may remain for other people's replies. Deleting the post removes its comments and replies.
A report shares the selected comment text and report details with the operator. That selected evidence may remain after the comment is edited or deleted, but related account or post deletion removes it. Your account export includes your own comment records, not other people's replies or private parent content. Comment drafts and pending retries stay only in the current tab's memory. The private backup policy below applies to comments too.
Shared cost groups
A cost-group owner can select accepted friends to invite inside the app. Before joining, an invited friend sees only the group name, currency, owner and member count. Pending friends cannot be assigned expenses. The recipient chooses Join or Decline; no code or external message is needed. Invitations expire after seven days. A response marker used for safe retries remains until seven days after expiry, then bounded cleanup removes it. Blocking, suspension, account deletion or owner transfer invalidates affected invitations.
Share lets a cost-group or friend-group owner reopen the current invitation link, copy it or display a QR generated on this device. The server keeps a private key in its database and backups so it can recover new links for the authorized owner. Account exports exclude the key and invitation codes. Existing links stay valid until replaced or invalidated by group access changes. A private group-plan or group-poll link grants no access: recipients must already belong to that group.
Tools includes private cost groups. Joining from an invitation link shares your display name and the group's expense, split and recorded repayment history with its members, including people who join later. Share links only with people you trust. Group records do not include your sign-in email. The app calculates balances; it does not collect, send or verify payments.
Members can correct entries they recorded. Leaving requires your recorded balance to be zero and ends group access, but preserves shared calculations. Account deletion is always available: it removes your account link and displayed identity from cost records while keeping numerical shares and recorded repayments so other members' balances do not change. Deleting an account does not settle a balance. Your account export includes the cost records made available under your current access.
Group members can see recent expense changes and deleted expenses, including their saved titles and notes. An eligible author can restore a deleted expense after reviewing its balance effects. Change history starts when this feature is installed and keeps up to 50 recent changes per group, subject to the server's 50,000-change limit; older changes may be removed. Account deletion clears your authored titles and notes from both expenses and retained change history. Shared numerical records remain.
A friend-group owner who also owns a cost group can connect them. Eligible current and later friends can preview the cost group’s name, currency and member count, then choose to join and see its existing shared history and member names, including people outside the friend group. Joining is never automatic. Leaving or deleting a friend group, or disconnecting its costs, does not remove cost membership, erase expenses or settle balances. Replacing the cost invitation or transferring cost ownership stops new joins through the old connection; current cost members keep their ordinary authorized access.
Previous date polls
The earlier date-poll tool remains under Previous date polls. These polls are private to people who explicitly join by invitation. Members, including people who join later, can see your display name and the times you select. A preview reveals only the organizer name, title, time zone, voting deadline and current member count; it does not reveal proposed times or answers. Poll membership is separate from cost groups and activities. The organizer chooses a time; your answer is not an attendance booking.
You can clear your answers or leave. Removing a member deletes their membership and answers. Blocking ends one person's participation in shared polls: if the organizer is involved, the other person is removed; otherwise the person making the block leaves. Unblocking does not restore membership or answers. Account deletion removes polls you organize entirely and removes your membership, answers and retry records elsewhere. Your account export contains your own answers and authorized poll context, not other members' answers.
Voting and joining close at the displayed deadline. Selecting a time freezes answers and closes invitations. Cancellation removes answers immediately. After the chosen time ends, or the latest option ends if no time was chosen, answers become unavailable immediately and are removed during bounded cleanup. Cancelled and expired summaries remain for up to seven days after cancellation or the effective event end; after that they are unavailable and all poll records are purged during cleanup. The app does not import or read private calendars. Poll drafts stay in the current tab's memory and clear when your session changes. The private backup policy below also applies to polls.
Friend groups and weekly availability
Groups are private to people who explicitly join. An owner can invite accepted friends or share an invitation link; receiving an invitation does not add you automatically. Your name and any weekly Free or Busy times you choose are visible to eligible group members, including people who join later. Unanswered times mean Not shared. Common time compares the saved calendars and shows windows when every current member has explicitly marked Free. Busy and unshared times prevent a confirmed overlap. All times use UAE time. This does not read your calendar, reveal your location or indicate live presence.
You can clear your availability or leave. Removal deletes your group availability. Removing a member also invalidates existing invitation links. Blocking removes the non-owner when an owner is involved; otherwise the person making the block leaves their shared groups. Unblocking restores nothing. Suspending or deleting an owner deletes their groups; other members' suspension or deletion removes their membership and availability. Your export includes your own availability, not other members' answers. Group invitations can use the same 15-minute sign-in continuation described above.
Conversations in friend groups
Only eligible, joined members can open a friend-group chat. Current members, including people who join later, can see the retained messages and their authors’ current names and usernames. Text messages expire 30 days after first sending; editing does not extend that deadline. Expired messages become unavailable immediately and are removed during bounded cleanup, which can be delayed while the PC is off. These conversations are stored on this PC and are not end-to-end encrypted.
You can edit or delete your own messages. The group owner can remove a message but cannot rewrite it. Deletion clears the text and leaves an empty marker until expiry. A report shares only the selected message version, your reason and your added details with operators. An operator can remove that reported message without opening the conversation. The selected reported copy can survive an edit or manual deletion until the source message expires or is removed by membership, group or account cleanup.
Leaving or removal deletes your messages and the chat reports you submitted. This also applies to membership ended by blocking, suspension or account deletion; rejoining restores nothing. Deleting or suspending the owner removes the group and its conversation. Your account export includes your own retained messages and submitted report details, not other members’ messages. Retry fingerprints contain no message text and expire at the end of the UTC day after their request day, giving 24–48 hours for safe retries. Drafts and pending requests stay only in this tab’s memory and clear on account or session changes. The private backup policy below applies.
Activity proposals in friend groups
Any current member can propose an activity. Current members, including people who join later, can see the proposal and each respondent's current name, username and choice: joining, interested, interested but busy, or not interested. These answers are not anonymous. You can change or clear your own answer. The author can edit a proposal; a real change clears all answers so everyone can choose again. The author or group owner can delete it.
Bucket list items are saved text without ongoing replies. Any current member can add one. Only an idea's author can choose Keep; this clears previous answers. Saved text has no automatic expiry and stays visible to current and later members until deleted or the author's membership ends. Only the author can edit it; the author or group owner can delete it. Exports include only saved items you authored. Poll and invitation drafts copy only the title; nothing is published or sent automatically.
Ordinary proposals and their answers expire 30 days after creation; edits do not extend this. Expired content becomes unavailable immediately and is removed during bounded cleanup, which may be delayed while the PC is off. Leaving, removal, blocking or suspension that ends your membership deletes your authored proposals and your answers elsewhere. Account deletion does the same; deleting or suspending the owner deletes the group and its proposals. Rejoining restores nothing.
Your export includes only retained, currently authorized proposals you authored or answered, with your own current answer and no other members' answers. Retry fingerprints contain no proposal text or cached responses and remain until the group or actor account is deleted. Drafts and pending retries stay only in this tab's memory and clear on account or session changes. Responding does not join a dated plan, change shared availability, cast a poll vote or affect costs. The private backup policy below applies.
Dated plans in friend groups
The group owner can arrange dated outings. Current members, including people who join later, can see retained plan details and current named Going or Not going answers. Weekly availability and poll votes never count as attendance. A real change to the plan details clears previous answers so everyone can confirm again. A cost note is descriptive; publishing, answering or cancelling a plan never changes cost-group membership, expenses or balances.
Leaving or removal deletes your answers; rejoining restores none. The same applies when blocking, suspension or account deletion removes your membership. Suspending or deleting the owner deletes the group and all its plans. At the end of an outing or on cancellation, all answers become unavailable immediately. Cancellation deletes answers immediately; bounded cleanup removes ended answers. Plan text remains for 30 days after the end or cancellation unless the owner deletes it sooner. After that deadline it is unavailable, and bounded cleanup removes it from the live database. Cleanup can be delayed while the host computer is off.
Your export includes only currently authorized plans you own or have explicitly answered, and only your own current answer. Past and cancelled exports include only plans you own, without attendance answers or counts. Retry fingerprints contain no plan text. New requests expire at the end of the following UTC day; older unversioned fingerprints remain until the friend group or your account is deleted. Rolling usage counters contain group identifiers and counts, survive group or account deletion and expire with their request period. Drafts and pending retries stay in this tab’s memory and clear on account or session changes. A calendar download includes the plan title, public venue and time, without reading your calendar. It is a snapshot that does not update automatically; later changes or deletion cannot recall copies you keep elsewhere. The private backup policy below also applies.
For weekly or monthly hangouts, we store the organiser’s schedule, time zone, optional last date and plan details. The server prepares upcoming dates while the series is active and the organiser still has access. Each date has separate responses and starts without attendance answers or preparation items. Skipping a date does not stop later dates; stopping the series cancels future dates and keeps outings already in progress or past outings under the retention above. After a series becomes inactive, its rule is removed once its dates have been removed and at least 30 days have passed. The organiser’s export includes their currently authorized series. Repeating a plan does not send messages or notifications or share anyone’s calendar.
Keep in touch reminders are private to the account that creates them. We store the chosen friend, date and time zone until you dismiss the reminder or the recorded friendship ends. Blocking, suspension or deletion of either account also removes it; reconnecting does not restore it. Your export includes only your own currently authorized reminders. The due count appears inside the app; this feature sends no email, push notification or message. Opening a chat does not dismiss a reminder. Retry records contain identifiers and fingerprints, without message text; they expire at the end of the UTC day after the original request date and are removed in bounded cleanup, which may be delayed while the PC is off. Account deletion removes your retry records. Daily usage counters contain an account identifier and count, survive account deletion, and stop counting at the end of their UTC day; they are removed after the following UTC day by bounded cleanup. Drafts and pending retries stay in this tab’s memory and clear when the account or session changes. The private backup policy below applies.
Preparation lists in a plan
Current group members, including people who join later, can see the plan’s Bring / do list, its authors and volunteers. Members volunteer only for themselves; volunteering or marking an item done never changes attendance, calendars or costs. The author may edit an unclaimed or self-claimed item. The group owner may release a volunteer or remove an item, but cannot assign work to someone else or mark their task done. Real edits to the plan details keep the item text and clear volunteers and completion so members can choose again.
At the plan’s end or cancellation, all checklist text and volunteer information become unavailable immediately. Cancellation or plan deletion removes the list; bounded cleanup removes ended lists and can be delayed while the host is off. Leaving or removal deletes your authored items and releases your volunteered tasks. The same cleanup applies when blocking, suspension or account deletion removes membership; rejoining restores nothing. Deleting the group deletes its lists.
Your export includes only currently authorized item text you authored and items you volunteered for, with only your own completion state. It does not include another person’s volunteer identity or completion. Retry fingerprints contain no item text and expire at the end of the following UTC day; rolling counters remain until their epoch expires. Drafts and pending requests stay in this tab’s memory and clear on account or session changes. Existing private backups follow the policy below.
Polls in friend groups
Group polls use your existing friend-group membership. Current members, including people who join later, can see questions, choices and results. Anonymous polls show vote totals and your own choice without other voters' names. Named polls show each voter's current display name and username beside their choice. The host database links votes to accounts; anonymous results are not secrecy from the host, and small-group totals can sometimes reveal a choice by inference.
You can change or remove your vote while voting is open, and remove it after voting closes. The question, choices and voting mode stay fixed after publication. The creator or group owner can close or delete a poll. Deleting a poll removes it and all its responses.
Leaving or being removed from a friend group deletes your votes and every poll you created there, including its responses. The same cleanup applies to membership removed by blocking, suspension or account deletion. Deleting a friend group deletes all its polls. Your export includes your own vote and currently authorized question/choice context, without other members' votes. Request fingerprints used to prevent duplicate actions remain until the friend group or account is deleted; they contain no question or choice text. Drafts and pending retries stay in the current tab's memory and clear on account or session changes. The private backup policy below also applies.
Profile pictures
A profile picture is optional. Eligible signed-in members can see it. Visitors can also see it while you have at least one visible Public post with Everyone selected. Changing every such post's audience, deleting those posts, or removing your photo ends new public access; saved copies cannot be recalled. Signing out may allow someone to see content available to all visitors.
The browser compresses profile pictures to at most 512 pixels per side and 128 KiB. The server strips metadata and accepts only supported still JPEG, PNG or WebP pictures. You can replace or remove your picture; five successful uploads are allowed per rolling 24 hours, and removal does not reset that allowance. Profile, post and business photos share the PC's image storage budget. Export includes your current picture and retained upload records. Deleting your account removes them.
Business listings
Published business listings, prices, public venue details and gallery photos are visible without an account. Only current operators can create or manage them; drafts and hidden entries are restricted to operators. Each listing can have up to four supported still JPEG, PNG or WebP photos, each at most 256 KiB and 1,200 pixels per side. The server removes image metadata. Hiding or deleting an entry ends new public access to its photos; previously saved copies cannot be recalled.
Map and YouTube or Vimeo links open an external site only when you choose them. No external map, video player or thumbnail loads automatically. Those sites receive your browser request and apply their own privacy policies.
Operator actions have private attribution, retry records and moderation audit records. Deleting an operator account removes its creator/editor attribution and request records; shared listings and their photos remain. Your export contains your attributed listing identifiers, timestamps and retained request metadata, not catalog photos, draft contents or other operators' information. An operator can separately hide or delete a listing.
Retention and backups
A photo-upload allowance record stores your account ID, upload ID, time and byte size without copying the photo. Deleting a photo does not reset the 24-hour allowance. Expired allowance records are removed during a later successful photo upload; account deletion removes your records. Your account export includes your retained upload records.
Deleting a chat message removes its text. Its identifiers, authorship and time remain to prevent a retried send from restoring it; account deletion removes those records. Group drafts are kept only in the current tab and cleared when the session changes.
Account deletion also removes your place memberships, chat messages, chat reports and private product feedback. Approved shared-place entries may remain with their creator attribution removed. Deleting a feedback submission removes its text and reply; a record containing your account ID, submission ID and time may remain to enforce the daily submission limit. Expired limit records are cleaned on a later successful submission, and account deletion removes them. Moderator audit records do not retain earlier copies of feedback reply text.
Unless a shorter retention period is described above, content remains in the live community until it is deleted by its owner, removed through moderation or cleaned up with account deletion. Ordinary sign-out ends that session; it does not delete your account.
Private backup snapshots can contain earlier records. Scheduled backups expire after 14 days during successful supervisor backup cycles; manually retained copies may last longer. Account deletion does not rewrite old backups, and restoring an older backup can restore deleted records. Deletion is not a promise of forensic erasure from disks or database journal files.
Questions and privacy requests
Anyone can use Contact me to reach the creator by email or WhatsApp without an account. Private creator chat appears there when enabled; signed-in members can also submit an account request. Replies are not guaranteed immediately. This is not an emergency service.