hangpostSupport

Privacy Policy

Last updated: August 2026

Entity: Hangpost, Inc., a Delaware corporation · privacy@hangpost.app

The short version (not a substitute for the full policy)

  • You set one home point and a radius; we use it to show you nearby people and posts. We do not track your live GPS location, and we limit how often your home base can move.
  • We never sell your personal data, and we never sell or share location data for advertising. Period.
  • Recommendations are computed from the structured profile fields you provide, and we show you the reasons for every recommendation.
  • You can delete your account in-app, and request a copy of your data by email; deletion is real and propagates to our processors.
  • 18+ only. US only.

1. What we collect

CategoryWhatSource
AccountName, phone number (verified via a one-time code), email, date of birth (to enforce 18+), and authentication identifiersYou; our auth provider (Clerk)
Waitlist (website)If you join the waitlist at hangpost.app: your name, email, an optional phone number, the city you are waiting for, and referral details (a code you can share, and who referred you). We email you a confirmation link; your spot counts once you click it. If you never confirm, the signup is deleted after 30 days. Once confirmed, we remove your name, email, and phone from the record 30 days after you create a Hangpost account, or after 12 months if you never do, keeping only an anonymous placeholder so the public queue count stays honest. Email privacy@hangpost.app to be removed sooner or entirelyYou
ProfileStructured fields you fill in: interests, hobbies, hometown, college, major, job ("Role at Employer"), age, and a profile photo. Uploaded photos are screened automatically for explicit content before they appear (see "Safety and integrity" below)You
Instagram handle (optional)If you choose to add it, an Instagram username shown as plain text on your profile. It is visible to anyone nearby who can open your profile, not just your connections (the same wording you see when you type it in), so add it only if you want it visible. It is never a clickable link, never used by our matching system, and we never connect to Instagram. Remove it any time in profile editYou
Photo verification (optional)If you choose to verify your profile photo, a one-time selfie taken in the app. It goes to a private storage location, our processor (Amazon Rekognition) compares its facial geometry against your profile photo, and the selfie is deleted immediately after the comparison, pass or fail. We keep only the fact and time of verification, never the selfie and never a face template, and we never run face recognition against other users, other photos, or any external database. Changing your photo clears the badge. One narrow exception: if an image is flagged as apparent child sexual abuse material, US law requires us to preserve it rather than delete it. See "Safety and integrity" belowYou, only when you start verification
Guest RSVPs (legacy; collected before July 8, 2026)Before July 8, 2026, people could RSVP to a shared hangout link without an account using a name and US phone number. That option is retired: RSVPing now requires a Hangpost account. Legacy guest records are kept only so the host can run attendance, are deleted automatically 30 days after the hangout, and are never used for marketing or any outreach. Only the host sees the name; the phone number is never shown to anyone. Email privacy@hangpost.app to have a legacy guest RSVP removed soonerYou
Derived profileA synthesized text description generated deterministically from your structured fields (you do not write a free-text bio) and a numeric embedding of it, used for rankingGenerated by us
LocationHome base: one point plus a radius that you set, optionally via a one-time GPS tap. We store it at reduced precision (snapped to roughly a 100-meter grid). You can move your home base at most twice in any 30 days. Setting it for the first time does not count, and changing only your radius does not count. We cap it because a home base is meant to be the place you actually live rather than a setting you flip, and keeping it steady is part of how we keep your location a small, low-profile part of the product. To enforce the cap we record when your last two moves happened, as times only. We never keep a list of the places you have been. Hangout locations: a venue or point you attach to a post. We do not collect continuous or background locationYou
Social graphFriend connections made in-app; if you choose to import contacts, the imported identifiers as hashes, with a recorded consent receipt (consent_hash) proving you authorized the importYou, with explicit consent per import
ActivityPosts, hangouts, RSVPs, reports, and blocks; recommendation impressions (what we showed you, with an internal score and the reason breakdown) and outcomes (viewed, opened, friend request, RSVP, block)Your use of the Service
Device and logsIP address, device and OS identifiers, and crash and performance logsAutomatic
Payments (if and when offered)Handled by our payment processor; we receive transaction records, never full card numbersProcessor (Stripe)

2. How we use it

  • Run the product: show the nearby feed, rank recommended connections (with visible reasons), run hangouts and RSVPs, and send notifications you control.
  • Run the waitlist: hold your place in line, tell you when Hangpost opens in your city, and credit referrals. We do not sell this data or use it for advertising. To correct or delete your waitlist record, even if you never create an account, email privacy@hangpost.app.
  • Improve matching: train ranking models on whether the recommendations we showed led to real connections (our impression and outcome records). Our north-star metric is repeat in-person meetings, not screen time.
  • Safety and integrity: verification, automated content review of uploaded images for explicit material, checking uploaded images against databases of known child sexual abuse material through Project Arachnid Shield (a service of the Canadian Centre for Child Protection, which receives the image bytes for the check and is listed in our Subprocessor Register), human review of reports, moderation, enforcing blocks and bans, and meeting our legal duties, including reporting apparent child sexual abuse material to NCMEC as required under 18 U.S.C. § 2258A. When an image is flagged that way, the law requires us to preserve it rather than delete it, and to keep enough information to file a report: the image itself in a locked location no one can serve or delete, its digital fingerprint, and the uploading account's identifiers together with the IP address and device information of the upload. We hold that material for the period the law requires, disclose it only to NCMEC and law enforcement, and it survives account deletion because the law does not let us destroy it. This is the only circumstance in which we keep an image you asked us to delete. If we permanently ban an account for a serious violation, we keep a one-way hash (never the raw number) of its phone and email and use it to refuse a new signup with the same phone or email, so a banned person cannot simply make another account. This is the one use of your phone number beyond verification; it is a safety use, never advertising, and we do not use face recognition for it.
  • Support and communications: respond to you, send service messages, and send optional product emails you can opt out of.
  • Legal: comply with law, enforce the Terms, and establish or defend claims.

We do not use the content of your private messages for advertising or for training models unrelated to safety.

One messaging behavior worth knowing: direct messages open only after you both accept a connection. If you later remove that connection, the conversation is not deleted. It moves to a quiet Requests area, new messages from that person stop notifying you, and reconnecting brings the thread back. Blocking someone stops their messages entirely.

3. What we never do

  1. Sell personal data, as "sell" and "share" are defined in the CCPA/CPRA and similar state laws. No exceptions.
  2. Sell, license, or disclose location data to data brokers or advertisers. Internally, your approximate location is used only as an in-or-out radius filter when we retrieve candidates; it is never a ranking input and never leaves that layer.
  3. Run third-party advertising, ad-targeting, or cross-app tracking SDKs in the app. We do not currently run any third-party product-analytics SDK either. If we add first-party, privacy-respecting product analytics, we will name the vendor in our Subprocessor Register and update this policy before it goes live, and only if it can run without cross-app tracking.
  4. Track your location in the background.

Sponsored content on Hangpost, when present, is labeled, is targeted only by the same city and zone scoping as everything else, and pays for verified attendance, not for your attention or your data.

4. Who we share it with

  • Service providers (subprocessors) under contracts that limit their use of data to providing their service to us: hosting, database, authentication, object storage, and error monitoring, plus a large-language-model provider used only in an offline pipeline to generate match-quality training labels (never from your messages). The live list, with the data categories each vendor touches, is the Subprocessor Register; the in-force version is published at hangpost.app/subprocessors.
  • Other users, per your visibility settings: your profile to in-radius users, your posts to the audience you pick, and your RSVP to the hangout's attendees.
  • Legal and safety: law enforcement and others where required by law, or where necessary to address fraud, security, or threats to any person, under our Law-Enforcement Guidelines, which require legal process appropriate to the data sought and a warrant for location data.
  • Corporate transactions: a merger or acquisition successor, bound by this policy, with notice to you.

5. Retention and deletion

  • Account data is kept while your account is active.
  • Account deletion is available in-app and by emailing privacy@hangpost.app. On deletion we delete or de-identify your personal data within 30 days, with backups rotating out within 90 days, except that we retain moderation, safety, and legal-compliance records for up to 2 years (longer where the law requires) to protect other users, and transaction records for the period tax law requires.
  • Impression and outcome logs used for model training are de-identified on account deletion.
  • Imported contact data is deleted on request, on deletion of the import, or on account deletion.

6. Your rights and choices

We honor these for all users, regardless of which state you are in:

  • Access and export: get a copy of your data by emailing privacy@hangpost.app.
  • Correction: edit your profile at any time.
  • Deletion: in-app, as above.
  • Opt-outs: notifications (in-app settings) and product emails (unsubscribe link).

State-law mechanics (CCPA/CPRA, Virginia CDPA, Colorado CPA, and the other state privacy acts): we do not sell or share personal data, so there is nothing to opt out of under those provisions; we treat the limited sensitive categories we handle, such as the approximate location you set, with the heightened care those laws require; we will not discriminate against you for exercising your rights; and you may use an authorized agent. If we deny a request you may appeal by replying to our decision, and we will respond within the statutory window (generally 45 days, extendable where the law allows); if it remains unresolved you may contact your state Attorney General.

We verify requests against your authenticated account or your verified phone or email.

7. Security

We use encryption in transit and at rest, least-privilege access, secrets held in managed stores, and an incident-response plan. No system is perfectly secure; we will notify you and regulators of breaches as required by law.

8. Children

The Service is for adults 18+. We use a neutral age gate at signup and delete the account and data of anyone we learn is under 18. We do not knowingly collect data from children under 13 (COPPA).

9. Where data lives

We operate in the United States, and the Service is offered only to US users. Our subprocessors store data in the United States, with one exception: images you upload are checked against databases of known child sexual abuse material by the Canadian Centre for Child Protection, in Canada, as described in section

  1. That check is the only routine transfer of your data outside the United

States. Every provider we use, and the region it operates in, is listed on our Subprocessors page.

10. Changes

Material changes get 30 days' in-app or email notice. The change history of this policy is public.

11. Contact

Hangpost, Inc., a Delaware corporation · privacy@hangpost.app

HomeSupportPrivacyTermsGuidelinesHostingSubprocessorsCookiesDMCAReport intimate imagesLaw enforcementContact

© 2026 Hangpost, Inc. · Made in DC, one neighborhood at a time.