Privacy Policy
Last updated: September 2026
Entity: Hangpost, Inc., a Delaware corporation 路 privacy@hangpost.app
The short version (not a substitute for the full policy)
- You set one home point and a radius; we use it to show you nearby people and posts. We do not track your live GPS location, and we limit how often your home base can move.
- We never sell your personal data, and we never sell or share location data for advertising. Period.
- Recommendations are computed from the profile fields you provide, the connections you have in common, and, where contacts were imported, whether one of you has the other saved or you both have the same person saved; we show you the reasons for every recommendation.
- You can delete your account in-app, and request a copy of your data by email; deletion is real and propagates to our processors.
- 18+ only. US only.
1. What we collect
| Category | What | Source |
|---|---|---|
| Account | Name, phone number (verified via a one-time code), email, date of birth (to enforce 18+), and authentication identifiers | You; our auth provider (Clerk) |
| Waitlist (website) | If you join the waitlist at hangpost.app: your name, email, an optional phone number, the city you are waiting for, and referral details (a code you can share, and who referred you). We email you a confirmation link; your spot counts once you click it. If you never confirm, the signup is deleted 30 days after your last confirmation link was issued. A new link is issued only when an expired link is renewed, but submitting the form again queues another email either way, and if you are already confirmed that email tells you so. While an email waits in the queue it holds your name, your email address and the message itself, including the link. We erase that the moment the email is sent, is canceled, or finally fails, and anything still waiting after 7 days is canceled rather than sent. The queue's own record of the attempt, which holds no contact details, is deleted after 30 days. Once confirmed, we remove your name, email, and phone from the record 30 days after you create a Hangpost account, or after 12 months if you never do, keeping only an anonymous placeholder so the public queue count stays honest. Email privacy@hangpost.app to be removed sooner or entirely | You |
| Profile | Structured fields you fill in: interests, hobbies, hometown, college, major, job ("Role at Employer"), age, a profile photo, and, if you pick one, the accent color shown with your name and profile (a display preference only, never used by our matching system). Uploaded photos are screened automatically for explicit content before they appear (see "Safety and integrity" below) | You |
| Instagram handle (optional) | If you choose to add it, an Instagram username shown as plain text on your profile. It is visible to anyone nearby who can open your profile, not just your connections (the same wording you see when you type it in), so add it only if you want it visible. It is never a clickable link, never used by our matching system, and we never connect to Instagram. Remove it any time in profile edit | You |
| Photo verification (optional) | If you choose to verify your profile photo, a one-time selfie taken in the app. It goes to a private storage location, our processor (Amazon Rekognition) compares its facial geometry against your profile photo, and the selfie is deleted immediately after the comparison, pass or fail. We keep only the fact and time of verification, never the selfie and never a face template, and we never run face recognition against other users, other photos, or any external database. Changing your photo clears the badge. One narrow exception: if an image is flagged as apparent child sexual abuse material, US law requires us to preserve it rather than delete it. See "Safety and integrity" below | You, only when you start verification |
| Government-ID verification (optional) | If you choose to verify your identity, you are handed to our identity-verification provider (Persona) inside the app. Persona checks that a government-issued ID is valid and matches a selfie you take; that comparison happens on Persona's systems, not ours. We never receive or store your ID image, your ID number, the fields Persona reads from the document, or that selfie. We keep only the yes-or-no result, the time you were verified, and an opaque reference to Persona's own record. Persona retains the ID and selfie on its side, under our contract with it and its own retention schedule. The check runs only when you start it, and never against any external database. The result appears only as a badge on your profile: it is never fed to our matching system, never used to rank you, and never shared or sold. Verifying your identity is optional, and you never need it to use Hangpost | You, only when you start verification |
| Guest RSVPs (legacy; collected before July 8, 2026) | Before July 8, 2026, people could RSVP to a shared hangout link without an account using a name and US phone number. That option is retired: RSVPing now requires a Hangpost account. Legacy guest records are kept only so the host can run attendance, are deleted automatically 30 days after the hangout, and are never used for marketing or any outreach. Only the host sees the name; the phone number is never shown to anyone. Email privacy@hangpost.app to have a legacy guest RSVP removed sooner | You |
| Derived profile | A synthesized text description generated deterministically from your structured fields (you do not write a free-text bio) and a numeric embedding of it, used for ranking | Generated by us |
| Location | Home base: one point plus a radius that you set by choosing a neighborhood. The app does not read your device location to do it. We store it at reduced precision (snapped to roughly a 100-meter grid). You can move your home base at most twice in any 30 days. Setting it for the first time does not count, and changing only your radius does not count. We cap it because a home base is meant to be the place you actually live rather than a setting you flip, and keeping it steady is part of how we keep your location a small, low-profile part of the product. To enforce the cap we record when your last two moves happened, as times only. We never keep a list of the places you have been. Hangout locations: a venue or point you attach to a post. We do not collect continuous or background location | You |
| Attendance and profile activity | Check-ins ("I'm here"). If you tap to say you have arrived at a hangout, we record the time on your RSVP, or on the hangout itself if you are the host. It is a tap, never a location reading: the app does not read your device's location to confirm it, and the server accepts it only during that hangout's own short window, from an hour before the start to a few hours after. While the window is open, the people who joined the same hangout can see who has said they are there. Regulars, thanks, and "Up to lately." Your profile also shows the number of people who have RSVP'd "going" to two or more of your finished hangouts, the number of 馃憤 reactions your posts have received, and a short list of your last few finished hangouts that were open to everyone nearby. Those three are shown only to you and your accepted connections, never to a stranger who opens your profile. The list never includes an invite-only or connections-only plan, and it never shows whether a hangout repeats, so it cannot be read as a prediction of where you will be in future. All of it is worked out when the page is loaded rather than stored as its own field, and none of it is ever shown as a score or a ranking | Your use of the Service |
| Saved interest groups ("Circles") | A named, reusable list of your own accepted connections who are into one thing (for example, "Pickleball"), so that when you post about doing that thing the same group sees it. A Circle is a filter over people you are already connected to, never a way to reach your contact list. It is private to you: the people on it are never told they are on it, and nobody else can see it or its name. Delete it any time | You |
| Per-post "hide from" list | When you post, you can hide that post from specific people who would otherwise see it. The choice is saved with that one post only, is never reusable, never becomes a block, and the hidden-from person is never told. Only you can see it | You |
| City Expert status | Whether your local tips have been marked helpful by enough other people nearby to earn the City Expert star, or whether we granted it. The star is shown to anyone who can see your profile or a tip you posted, including people who are not your connections. It is a credential, not a score, and cannot be bought | Earned from others' reactions, or granted by us |
| Social graph | Friend connections made in-app; if you choose to import contacts, the imported identifiers as hashes, with a recorded consent receipt (consent_hash) proving you authorized the import | You, with explicit consent per import |
| Being found by people who know you | When you sign in, we store a one-way, keyed hash of your verified phone number and of your email. When another member chooses to import their phone contacts, we compare the hashes of their contacts with yours. If your number or email is in their contacts and Let contacts find me is on (it is on unless you turn it off): they may get a one-time notification that you joined, showing your display name, if they imported their contacts before you joined; you appear in their list of contacts who are on Hangpost; you can be shown near the top of their suggested connections; and your posts can be shown higher in their feed and included in its "My people" view. If you have both imported contacts, both have Let contacts find me on, and both have the same person saved in your phones, that shared contact counts as someone you both know in each of your suggestions, and each of you sees that person's name only as it is saved in your own phone. We never tell you who has your number or email saved. Turn it off any time in the app's Settings, under Contacts, Let contacts find me: from that moment nothing about you reaches them through their contacts (not their list, their suggestions, their feed ranking or their "My people" view), and the join notification disappears from their Alerts (a notification already delivered to their phone's lock screen can't be recalled). Each imported contact hash is deleted 180 days after the last contact sync that included it, when the member removes their imported contacts, or when they delete their account. When you delete your account, your stored hashes and every match to you are deleted | Your sign-in details; other members' contact imports, made with their consent |
| Activity | Posts, hangouts, RSVPs, reports, and blocks; recommendation impressions (what we showed you, with an internal score and the reason breakdown) and outcomes (viewed, opened, friend request, RSVP, block) | Your use of the Service |
| Device and logs | IP address, device and OS identifiers, and crash and performance logs | Automatic |
| Payments (if and when offered) | Handled by our payment processor; we receive transaction records, never full card numbers | Processor (Stripe) |
2. How we use it
- Run the product: show the nearby feed, rank recommended connections (with visible reasons), run hangouts and RSVPs, and send notifications you control.
- Run the waitlist: hold your place in line, tell you when Hangpost opens in your city, and credit referrals. We do not sell this data or use it for advertising. To correct or delete your waitlist record, even if you never create an account, email privacy@hangpost.app.
- Improve matching: train ranking models on whether the recommendations we showed led to real connections (our impression and outcome records). Our north-star metric is repeat in-person meetings, not screen time.
- Safety and integrity: verification, automated content review of uploaded images for explicit material, checking uploaded images against databases of known child sexual abuse material through Project Arachnid Shield (a service of the Canadian Centre for Child Protection, which receives the image bytes for the check and is described on our Service providers page), human review of reports, moderation, enforcing blocks and bans, and meeting our legal duties, including reporting apparent child sexual abuse material to NCMEC as required under 18 U.S.C. 搂 2258A. When an image is flagged that way, the law requires us to preserve it rather than delete it, and to keep enough information to file a report: the image itself in a locked location no one can serve or delete, its digital fingerprint, and the uploading account's identifiers together with the IP address and device information of the upload. We hold that material for the period the law requires, disclose it only to NCMEC and law enforcement, and it survives account deletion because the law does not let us destroy it. This is the only circumstance in which we keep an image you asked us to delete. If we permanently ban an account for a serious violation, we keep a one-way hash (never the raw number) of its phone and email and use it to refuse a new signup with the same phone or email, so a banned person cannot simply make another account. That ban check is a safety use, never advertising, and we do not use face recognition for it. Your phone number and email also let people who already have them saved find you on Hangpost, as described under "Being found by people who know you" in section 1. We never use either for advertising.
- Support and communications: respond to you, send service messages, and send optional product emails you can opt out of.
- Legal: comply with law, enforce the Terms, and establish or defend claims.
We do not use the content of your private messages for advertising or for training models unrelated to safety.
One messaging behavior worth knowing: direct messages open only after you both accept a connection. If you later remove that connection, the conversation is not deleted. It moves to a quiet Requests area, new messages from that person stop notifying you, and reconnecting brings the thread back. Blocking someone stops their messages entirely.
3. What we never do
- Sell personal data, as "sell" and "share" are defined in the CCPA/CPRA and similar state laws. No exceptions.
- Sell, license, or disclose location data to data brokers or advertisers. Internally, your approximate location is used only as an in-or-out radius filter when we retrieve candidates; it is never a ranking input and never leaves that layer.
- Run third-party advertising, ad-targeting, or cross-app tracking SDKs in the app. We do not currently run any third-party product-analytics SDK either. If we add first-party, privacy-respecting product analytics, we will name it on our Service providers page and update this policy before it goes live, and only if it can run without cross-app tracking.
- Track your location in the background.
- Confirm a check-in with your device's location, or record where you physically were. Saying "I'm here" is a tap you choose to make, and the only thing it records is the time you made it.
Sponsored content on Hangpost, when present, is labeled, is targeted only by the same city and zone scoping as everything else, and pays for verified attendance, not for your attention or your data.
4. Who we share it with
- Service providers that only handle the data they need to run their part of Hangpost, never for their own advertising: hosting, database, sign-in, photo storage, identity verification, email, error monitoring, and ad measurement (a Google Ads conversion tag and a Meta Pixel on our public website pages that count whether an ad we bought led to a waitlist signup -- Google's personalization signals off, Meta's Limited Data Use on with no advanced matching, and neither ever receives your name, email, or phone), plus a large-language-model provider used only in an offline pipeline to generate match-quality training labels (never from your messages). We summarize these by category on our Service providers page, and we'll name the specific companies on request at privacy@hangpost.app.
- Other users, per your visibility settings: your profile to in-radius users, your posts to the audience you pick, your RSVP to the hangout's attendees, and, while Let contacts find me is on, the fact that you are on Hangpost to members who have your number or email saved.
- Legal and safety: law enforcement and others where required by law, or where necessary to address fraud, security, or threats to any person, under our Law-Enforcement Guidelines, which require legal process appropriate to the data sought and a warrant for location data.
- Corporate transactions: a merger or acquisition successor, bound by this policy, with notice to you.
5. Retention and deletion
- Account data is kept while your account is active.
- Account deletion is available in-app and by emailing privacy@hangpost.app. On deletion we delete or de-identify your personal data within 30 days, with backups rotating out within 90 days, except that we retain moderation, safety, and legal-compliance records for up to 2 years (longer where the law requires) to protect other users, and transaction records for the period tax law requires.
- Impression and outcome logs used for model training are de-identified on account deletion.
- Imported contact data is deleted on request, when you remove your imported contacts, or on account deletion, and each imported contact hash is deleted in any case 180 days after the last contact sync that included it.
- If you start signing up but never finish creating your profile, we delete the account and its data 30 days after you started.
6. Your rights and choices
We honor these for all users, regardless of which state you are in:
- Access and export: get a copy of your data by emailing privacy@hangpost.app.
- Correction: edit your profile at any time.
- Deletion: in-app, as above.
- Opt-outs: notifications (in-app settings) and product emails (unsubscribe link).
State-law mechanics (CCPA/CPRA, Virginia CDPA, Colorado CPA, and the other state privacy acts): we do not sell or share personal data, so there is nothing to opt out of under those provisions; we treat the limited sensitive categories we handle, such as the approximate location you set, with the heightened care those laws require; we will not discriminate against you for exercising your rights; and you may use an authorized agent. If we deny a request you may appeal by replying to our decision, and we will respond within the statutory window (generally 45 days, extendable where the law allows); if it remains unresolved you may contact your state Attorney General.
We verify requests against your authenticated account or your verified phone or email.
7. Security
We use encryption in transit and at rest, least-privilege access, secrets held in managed stores, and an incident-response plan. No system is perfectly secure; we will notify you and regulators of breaches as required by law.
8. Children
Hangpost is for adults 18 and older. We ask for your date of birth when you sign up and don't let anyone under 18 create a profile. If we learn a member is under 18, we delete their account and data. We do not knowingly collect data from children under 13 (COPPA).
9. Where data lives
We operate in the United States, and the Service is offered only to US users. Our service providers store data in the United States, with one exception: images you upload are checked against databases of known child sexual abuse material by the Canadian Centre for Child Protection, in Canada, as described in section
- That check is the only routine transfer of your data outside the United
States. The kinds of providers we rely on are summarized on our Service providers page.
10. Changes
Material changes get 30 days' in-app or email notice. The change history of this policy is public.
11. Contact
Hangpost, Inc., a Delaware corporation 路 privacy@hangpost.app