Privacy Policy
Your privacy and data protection are fundamental to how we build Anyone. This policy explains how we collect, use, and protect your information.
Privacy Policy (U.S. users)
Effective Date: August 27, 2026
Last Updated: August 27, 2026
1. Who We Are
Anyone, Inc. ("Anyone," "we," "our," or "us") operates the Anyone mobile application and related websites (the "Services"). We are located at 1500 N Grant St, Ste R, Denver, CO 80203 USA.
This Privacy Policy explains how we collect, use, share, and protect your personal information. It describes what we do today. If we begin collecting, using, or sharing information in a way this policy does not cover, we will update this policy before we do so — see Section 14.
2. Scope & Age Requirements
This Privacy Policy applies to users in the United States who are 18 years or older.
Age: We ask for your date of birth when you register and use it to confirm you meet the age requirement.
If you are under 18, you may not use our Services. If we learn that an account belongs to someone under 18, we terminate the account and delete its data. Parents who believe we have collected information from a minor should contact us at privacy@anyone.social.
3. Information We Collect
| Category | Examples | Source | Purpose |
|---|---|---|---|
| Account Data | Name, username, phone number, date of birth, optional contact email, Google login ID if you use it | You provide | Account creation, authentication |
| Profile Content | Profile photo, bio, interests, and optional gender and pronouns | You provide | Profile display |
| Event & Social Data | Events created and joined, RSVPs, venue locations, follows, group memberships | You provide | Event management |
| Communications | Direct messages, group and event chat, photos you share, reports, support requests | You provide | User interaction, safety |
| Usage Data | Screens viewed, features used, session activity | Automatic | Product improvement |
| Device & Log | Device model, OS, app version, language, IP address, crash and error reports | Automatic | Technical support, app stability |
| Location | Approximate device location, only with your permission and only while the app is open | Device | Event discovery and creation |
| Push Token | A device identifier used to deliver notifications you have enabled | Automatic | Notifications |
| Local Storage | Authentication tokens stored on your device | Your device | Keeping you signed in |
About Location Data: We request approximate location, not the most precise fix your device can produce, and we request it only while the app is open in the foreground. The app has no background-location capability and performs no geofencing or continuous tracking. We use it to sort and filter events by distance from you, on the map and during event creation. You can control location permissions in your device settings at any time; if you decline, event discovery still works, without distance sorting.
We do not collect payment information. The Services are currently free, and we have no payment, purchase, or subscription functionality.
4. How We Use Your Information
We use your information to:
- Provide the Services: Create and secure accounts, send one-time passcodes, authenticate sign-ins, display profiles, and run events, groups, and chat
- Recommend Content: Suggest nearby events and people
- Safety & Security: Confirm age, detect abuse, investigate reports, and enforce our policies
- Communications: Send notifications, service updates, safety alerts, and, when you opt in, event reminders and event-related updates from hosts
- Improvements: Analyze usage and diagnose crashes to develop and improve the product
- Legal Compliance: Respond to legal requests, protect rights, and prevent harm
5. Legal Bases for Processing
We process your data based on:
- Contract Performance: To provide the Services you requested
- Legitimate Interests: Safety, security, and platform improvements
- Legal Obligations: Compliance with laws and regulations
- Consent: For optional features such as location, push notifications, and event texts
6. Information Sharing
We share information with the following recipients, and no others:
| Recipient | Data Shared | Purpose |
|---|---|---|
| Other Users | Profile, events, and content you share | Core service functionality |
| Supabase | Account, event, message, and photo data | Database hosting, authentication, storage |
| Twilio | Your phone number | Delivering one-time sign-in codes and, when you opt in, event texts by SMS |
| Resend | Your email address and the contents of transactional emails | Delivering email we send you |
| Expo | Push tokens, app update requests | Push notification delivery, app updates |
| Amplitude | Product usage events, account identifier | Product analytics |
| Sentry | Crash and error reports, device information | App stability and error tracking |
| Google Maps Platform | Venue search text, a one-time device coordinate when you ask the app to detect your location, and venue coordinates in map-image requests | Maps, geocoding, place search |
| Legal Authorities | As required by law | Legal compliance |
| Business Transfers | All data | Mergers, acquisitions |
We DO NOT sell your personal information, and we do not share it for cross-context behavioral advertising.
We do not use advertising or ad-measurement services. There is no advertising in the Services, and we do not share your information with advertising networks, ad-measurement providers, or data brokers.
We do not use your content to train machine-learning or AI models.
Third-Party Privacy Policies: Our service providers have their own privacy policies governing their use of your information:
- Supabase (database, authentication, storage): supabase.com/privacy
- Twilio (SMS sign-in codes and optional event texts): twilio.com/legal/privacy
- Resend (transactional email): resend.com/legal/privacy-policy
- Expo (push notifications, app updates): expo.dev/privacy
- Amplitude (product analytics): amplitude.com/privacy
- Sentry (error tracking): sentry.io/privacy
- Google (Maps, and Google sign-in if you use it): policies.google.com/privacy
7. Your Rights & Choices
You have the right to:
Access & Portability
- Request a copy of your data by emailing privacy@anyone.social
Correction
- Update your profile information at any time in the app
- Contact support for anything you cannot change yourself
Deletion
- Delete your account in Settings → Advanced. This permanently deletes your profile, connections, and personal data
- Messages you have already sent remain visible to the people you sent them to, attributed to "Deleted User" rather than to your name
- Certain records may be retained where required by law or for safety purposes
Notifications
- Control push notifications in Settings → Notifications, and in your device settings
- Unsubscribe from emails using the link in any email we send
- Turn event texts off in Settings → Notifications or reply STOP to any event text; reply HELP for help
Event Texts: If you separately consent, Anyone may use your verified mobile number to send automatic reminders and event-related updates written by hosts for events you join. Message frequency varies with your event participation, and message and data rates may apply. Consent is optional and is not a condition of creating an account, joining an event, purchasing anything, or using the Services. You may withdraw consent in Notification Settings or by replying STOP at any time.
Mobile Information: Mobile information will not be shared with third parties or affiliates for marketing or promotional purposes. We use mobile numbers for authentication and, when a user separately consents, for event texts. No text messaging originator opt-in data or consent will be shared with any third parties, except for vendors and carriers required to deliver SMS messages, or as necessary to comply with law or protect our rights.
Do Not Sell or Share
- We do not sell your personal information and do not share it for cross-context behavioral advertising, so there is nothing to opt out of
Do Not Track
We do not currently respond to browser "Do Not Track" signals, as there is no industry standard for how to handle them. We do not perform cross-site tracking.
8. Data Retention
- Active account data is retained while your account exists.
- When you delete your account, we delete your profile, connections, and personal data. Messages you already sent remain visible to their recipients, attributed to "Deleted User". Residual copies may persist in routine backups for a short period before those backups age out.
- Safety reports and moderation records are retained for as long as needed for safety and legal purposes.
- Crash and analytics data is retained according to our providers' configured retention periods.
- SMS consent and suppression records are retained as needed to document your choice and ensure that an opt-out continues to be honored.
- Records subject to a legal hold or a legal retention obligation are retained for as long as that obligation requires.
9. California Privacy Rights (CCPA/CPRA)
California residents have additional rights under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA):
Categories of Personal Information We Collect
In the past 12 months, we have collected the following categories of personal information:
- Identifiers: Name, username, email, phone number, device identifiers, IP address
- Personal Information: Date of birth, photos, profile content
- Internet Activity: Usage data, interactions, session information
- Geolocation Data: Precise location (with permission) and coarse location
Your California Privacy Rights
- Right to Know: You can request information about the personal information we collect, use, and disclose
- Right to Delete: You can request deletion of your personal information, subject to certain exceptions
- Right to Correct: You can request correction of inaccurate personal information
- Right to Opt-Out: We do not sell personal information, and we do not share it for cross-context behavioral advertising
- Right to Limit Use: You can limit use of sensitive personal information
- Non-Discrimination: We will not discriminate against you for exercising your privacy rights
How to Submit a Request
To exercise your rights, submit a verifiable consumer request by:
- Email: privacy@anyone.social
- Mail: Anyone, Inc., Attn: Privacy Rights, 1500 N Grant St, Ste R, Denver, CO 80203
We will verify your identity before processing your request. You may designate an authorized agent to make requests on your behalf by providing written permission.
Shine the Light
California residents may request information about disclosure of personal information to third parties for direct marketing purposes. We do not share personal information with third parties for their direct marketing purposes.
10. Data Security
We are a small company, and we do not claim controls we cannot evidence. Here is what we actually do:
- Encryption in transit. All connections use TLS.
- Encryption at rest. Provided by our database and storage platform, Supabase.
- Database-enforced authorization. Access rules are enforced by the database itself through row-level security policies, not by application code alone, and those policies are covered by an automated database test suite that runs before every release.
- Automated security testing on every change. Every code change must pass static application security testing and a dependency vulnerability audit before it can be merged. These are blocking checks, not advisory ones.
- Least-privilege database grants. Privileged database functions are explicitly revoked from anonymous and general authenticated access, and that restriction is enforced by an automated test.
We are a small technical team. We are not SOC 2 audited, and we have not commissioned a third-party penetration test. We conduct internal security reviews of our own codebase and track findings to resolution.
No system is 100% secure. Please help protect your account by keeping access to your phone number and email secure, and by reporting suspicious activity to safety@anyone.social.
11. International Users
We do not offer the Services in the EU or the UK and do not target users there. Registration requires a U.S. phone number. Information you provide is stored in the United States, and if you access the Services from outside the U.S. your information is transferred to and processed in the United States.
12. Third-Party Services
Our app integrates with:
- Google Sign-In: if you choose to register or sign in with Google
- Google Maps Platform: for maps, geocoding, and place search
- Amplitude: for product analytics
- Sentry: for crash and error reporting
- Supabase: for database hosting, authentication, and file storage
- Twilio: for delivering one-time sign-in codes and optional event texts by SMS
- Resend: for delivering transactional email
- Expo: for push notification delivery and app updates
These services have their own privacy policies. We are not responsible for their practices.
13. Children's Privacy
Our Services are strictly 18+. We do not knowingly collect data from anyone under 18. If we discover an account belonging to a minor, we terminate it and delete the associated data.
Parents: Contact privacy@anyone.social if you believe we have your child's data.
14. Changes to This Policy
This policy describes our practices as they exist today. If we introduce a feature that involves collecting, using, or sharing personal information in a way this policy does not already describe, we will update this policy before that feature becomes available to you, rather than relying on general language written in advance.
For material changes we provide at least 30 days' advance notice by email or in-app notification, along with an opportunity to review the change before continuing to use the Services, and the option to delete your account if you disagree.
Check the "Last Updated" date above for the current version.
15. Contact Us
Privacy Team
Anyone, Inc.
1500 N Grant St, Ste R
Denver, CO 80203
Email Contacts:
Privacy Inquiries: privacy@anyone.social
Safety Issues: safety@anyone.social
Legal Requests: legal@anyone.social
Response Time: We aim to respond to privacy requests promptly.
Related Documents:
- Terms of Service
- Community Guidelines
- Safety Resources (available in the app)