Privacy Policy
Last updated: August 16, 2026
Plotify is built so that nothing about you leaves your device unless you choose it. Most of the app works with no account at all.
What stays on your device
- Your age. You can optionally enter a birth year so Plotify hides events you can't get into. It stays on your device, is used only for filtering, and is not an ID check or age verification.
- Your location. If you allow location access, it is used to sort tonight's events by distance and center the map. It is never transmitted anywhere. You can optionally allow background access (“Always”), which lets iOS hand Plotify an occasional rough location while the app is closed, so the map opens already centered on you instead of catching up. Only the most recent one is kept, rounded to about a kilometer, for at most six hours, and only on this device. Everything works without it. Change or revoke it any time under Account → Privacy → Location.
- Your contacts. If you allow contacts access, names and phone numbers are read on your device so you can pick people to invite. They are never uploaded, matched against other users, or used to build a social graph.
- Saved plots, filters, and preferences. Stored locally.
- Crash reports. Collected by iOS (MetricKit) and stored on your device. Plotify never transmits them; you can view, share, or delete them under Account → Diagnostics.
Invite links
When you share a party, the invite's details travel inside the link itself — in the part of a URL that browsers never send to any server, including ours. We can't read your invites, because we never receive them. The exact address is not in the link at all: it unlocks in the app, person by person, only when the host approves someone.
What requires an account (always optional)
You never need an account to browse events, save them on your device, or ask to come to a party you were invited to.
Today, Plotify's online features are not yet live, and the app sends nothing to any server. When accounts launch, an account (email + password) will store the following server-side, and this policy will be updated in the same release:
- Your email address and a securely hashed password.
- Which plots you saved, so they survive a reinstall.
- Your friendships, friend requests, and blocks.
- Direct messages with friends, party group-chat messages, and your going/maybe status on events.
Until then, all of that lives only on your device and is deleted with the app. The rules below describe how those features behave — they are the design the app already enforces locally.
Who can see what
- Friends and messages are mutual-consent only. Nobody can message you or see your plans unless you accepted their friend request. There is no public profile, no user search, and no directory.
- Your going/maybe status is visible only to accepted friends, only while "Share my plans with friends" is on (Account → Privacy). There is no public attendee count.
- Party addresses never travel in invite links and are never shown to anyone the host hasn't approved. Everyone else sees the neighborhood.
- Blocking someone cuts off messages, profile visibility, and suggestions in both directions, immediately.
What Plotify does not do
- No advertising, ad identifiers, or ad networks.
- No third-party analytics or tracking SDKs.
- No sale or sharing of personal data with data brokers — ever.
- No reading of your contacts, photos, or location beyond the uses above.
- No fabricated social signals: every count and every "X is going" reflects a real action by a real person.
Event data
Event listings come from public sources (venue calendars and ticketing APIs). Reporting a message hides it on your device immediately; once Plotify's online service is live, reports will also reach moderation.
Deleting your data
Account → Delete account permanently removes your account and everything attached to it (saves, friendships, messages, attendance) from the server. Data stored only on your device is removed by deleting the app.
Children
Plotify is not directed at children under 13, and you must be 13 or older to create an account. The optional age field filters what you see; it does not verify identity or unlock anything.
Changes
Material changes to this policy will be listed in the App Store release notes of the version that makes them.