Privacy Policy
Last updated July 1, 2026
Friends in Town ("we," "our," "the app") helps people find which of their friends are traveling to or living in cities they're visiting. This policy describes what we collect, what we do with it, and what choices you have.
What we collect
When you create an account we store your email address (for sign-in) and the name you choose to display. Optionally, you can add a phone number, a home city, a profile photo, and a birthday. You can edit or delete any of these at any time.
You can sign in with a magic-link email, a password, or by connecting your Apple or Google account. If you use Apple or Google, we receive the name and email address they share with us — Apple lets you hide your real email behind a private relay address, which works fine here.
When you create a trip we store the destination city, dates, an optional public message ("Want to grab coffee?"), and your private notes. Hangouts you create store a title, location, date/time, and optional notes.
If you turn on calendar sync, the app scans events already on your device to spot upcoming travel (flights, hotels, check-ins) — that scan happens on your device, and only the trip you choose to import (destination city and dates) is saved to your account. The same toggle can also add your trips to your device calendar as events. If you connect TripIt, we store the itinerary feed URL you give us and fetch it periodically to pull in your trips.
If you import contacts to find friends already on the app, your contacts' phone numbers and email addresses are matched against our database in real time and not stored — except for any contact you choose to invite, whose name and the contact info you gave us are saved until they join or you cancel the invite.
We do not collect GPS coordinates. The "use my location" feature in city search asks your device for a coarse fix only to suggest a city name; we never store the lat/lng.
We log basic crash and error metadata (the file/line a JavaScript error happened on, the screen you were viewing) so we can fix bugs. These rows are scoped to your account and viewable only by you and our admins. We also store a device push-notification token so we can deliver the notifications you've opted into, and a record of any account you've blocked or reported.
What we do with it
• Show you which of your friends live in or are visiting cities you care about. This is the entire product.
• Send transactional email — friend invites you initiate, magic-link sign-ins, password resets, hangout invitations. We never send marketing email.
• Push notifications when a friend's trip overlaps with yours, you earn a passport stamp or milestone, someone sends a friend request, or you're invited to a hangout. You can turn each category off in Settings → Notifications.
Who can see what
Your name and home city default to "friends only" — visible only to users you've accepted as a friend. You can change visibility to "public" or "hidden" in Settings → Privacy.
Trips default to "friends only" — friends you've accepted see them on their feed. "Private" means only you see the trip; "public" means anyone with a share link can view it.
Friends always see when a trip of yours overlaps with one of theirs, even if you haven't made your full trip list visible to them — that overlap is the core of the product. Browsing your complete upcoming trip list is separate and off by default; turn it on for friends or the public in Settings → Privacy under travel list visibility. A public profile page is a shareable link anyone can open to see your name, home city, and — only if you've set travel list visibility to public — your upcoming trips.
Phone numbers and email addresses are never shown to other users. Friend matching by phone or email is done server-side (you upload a contact, we tell you whether they're already on Friends in Town without ever revealing their account to you unless they choose to accept your friend request).
Blocking someone hides you from each other completely — no more friend requests, hangout invites, or overlap notices either direction. Reports go only to our admins for review; we never show a report to the person it's about.
Who we share it with
We don't sell your data, share it with advertisers, or use it for marketing. Three infrastructure providers process data on our behalf:
• Supabase hosts our database and storage. Data lives in Supabase's AWS-backed infrastructure in us-west-2.
• Amazon SES sends our transactional email. SES sees the recipient address, subject, and body of email we send.
• Cloudflare serves the web app and runs our bot-protection challenge (Turnstile) on the login form.
• Google Firebase Analytics measures app usage — screens viewed, sign-ins, and actions like sending an invite. It receives a device identifier and approximate (city/region-level, IP-derived) location, never your name, email, or precise location.
• Sentry receives crash reports and error logs so we can fix bugs — stack traces and the screen you were on, with file paths stripped and no personal data attached by default.
We will disclose information when legally compelled (subpoena, court order). We'll notify you of any such disclosure unless we're legally barred from doing so.
Your rights
You can edit or delete every field of your profile from Settings.
You can permanently delete your entire account from Settings → Privacy → Delete My Account. Deletion removes your profile, trips, hangouts, friend connections, RSVPs, contact matches, error logs, bug reports, stamps, milestones, notification preferences, and the list of accounts you've blocked. This is irreversible. Reports other people filed about you are kept for trust-and-safety purposes even after your account is gone, the same way we'd keep them if you were still active.
For a copy of your data, email
[email protected] from your account's address. We'll respond within 30 days.
Children
Friends in Town is not directed at children under 13. We don't knowingly collect data from anyone under 13. If you believe a child has signed up, contact us and we'll delete the account.
Security
Database access is row-level-security restricted: a query for one user's data cannot read another user's rows even if the application layer has a bug. Email addresses, phone numbers, and friend graph data are all protected at the row level.
Passwords are stored hashed via Supabase Auth, never in plaintext.
Changes to this policy
When we change this document, we'll update the "Last updated" date at the top. For material changes (new categories of data we collect, new third parties), we'll notify users in the app before the change takes effect.
Contact