PRIVACY POLICY
How we handle your data.
Data we collect
Waitlist site. Right now, the only data we collect through this site is what you give us when you join the waitlist:
- Your email address
- Your first name (optional)
- The city you signed up from, if you told us
- The referral code that brought you, if any
- Basic technical metadata: a hashed version of your IP address (we do not store the raw IP), your browser type, and which page on our site you came from. We use this only to prevent spam signups.
We do not collect anything else through the site. No cookies for advertising. No third-party tracking pixels. No session replay tools.
Mobile app users. The HAOT mobile app collects more information than the waitlist site because the product requires it. Specifically:
- Display name: the handle you choose in the app. Not your legal name.
- Date of birth: used to enforce the 18-and-over age requirement.
- Location: foreground location for PULSE proximity matching and check-in at the activity venue. Background location is collected only while the Share-My-Walk safety feature is actively running, and stops the moment that feature is turned off.
- Photos: profile photos (visible only after your bond is completed) and activity cover photos uploaded by Hosts.
- Vibe quiz answers: your responses to the vibe quiz, used as input to the matching algorithm.
- Payment information: processed directly by Stripe for paid activities and identity verification. HAOT never sees or stores raw card data; we receive only Stripe’s tokenized references and payment status.
- Subscription status: tier (Plus, Founding Plus, Host, Founding Host), renewal state, and entitlement, validated through RevenueCat.
- Emergency contact information: optional. Collected only if you add it post-onboarding in Settings, and used only to send SMS alerts via Twilio when you trigger the Silent SOS feature.
What we do with it
We use your email to send you waitlist updates and the eventual invite to the app. We send at most one email per week.
We use your first name and city only to personalize those emails and to sort the waitlist by city when we open access.
We use the technical metadata only for spam prevention and never share it with anyone.
When you click a link in one of our emails, we use a privacy-preserving link redirect to count clicks in aggregate. We do not track which specific links you clicked, only counts.
Data processors
Each provider listed below is bound by a data processing agreement and processes data only on our instructions. For the two machine-learning vendors we use, read the AI subprocessors section.
Waitlist site.
- Supabase (Singapore, with U.S. infrastructure) — Hosts the waitlist database and, post-launch, the mobile app database.
- Resend (United States) — Sends transactional email — the waitlist confirmation, the welcome, and the eventual invite.
- Vercel (United States) — Hosts the haot.app website and serverless functions.
- PostHog (United States) — Records anonymous product analytics events (page views, form submissions, scroll depth). Session recording is disabled. No third-party advertising integrations are enabled.
- Sentry (United States) — Receives error reports when something on the site or in the app crashes. We scrub email addresses, names, and IP addresses before reports leave the user.
Mobile app users. The HAOT mobile app adds the following processors:
- Stripe (United States) — Payment processing for paid activities and identity verification for Hosts. HAOT never sees or stores raw card data.
- Mapbox (United States) — Renders map tiles for activity venues and check-in.
- Twilio (United States) — SMS delivery for emergency contact alerts. Opt-in. Triggered only by Silent SOS.
- RevenueCat (United States) — Validates App Store subscription receipts for Plus and Host tiers.
- Apple (Worldwide) — Sign in with Apple identity tokens for authentication.
- Stream Chat (United States) — Group messaging inside activity groups.
- Upstash (United States) — Real-time queue infrastructure for live activity events and rate-limiting.
We do not sell your data. We do not share it with advertisers. We do not let any other third party access it.
AI subprocessors and what they do
Two of the processors above use machine-learning models. We treat them as a separate category because they are powerful enough to warrant their own disclosure. OpenAI and Anthropic process specific, limited categories of HAOT data on our instructions. They do not train any model on what we send them. Both have signed our data processing agreement. Both rely on Standard Contractual Clauses for transfers out of the EU.
Vibe matching
We turn your vibe-quiz answers into numerical embeddings and compare them to activity descriptions. The model never sees your name, photos, location, or contacts.
You control this by: Skip the quiz, or retake it. We delete previous embeddings when you retake.
Content moderation
Every activity title, description, and chat seed message runs through a moderation classifier before publication. We block hate speech, sexual content, and obvious solicitation.
You control this by: If your post is blocked you can appeal. A human reviews every appeal.
Report triage
When someone files a report, a classifier scores its severity. High-severity reports skip the queue and route to a human on the safety team within fifteen minutes.
You control this by: Every account action is decided by a human, never by the model.
Host application review
Short-answer responses on Host applications are classified for red flags. A human still reads every Host application before approval.
You control this by: Decline to apply. Existing accounts work without Host status.
What we do not do with AI
- We do not create fake users, fake activities, or fake reviews with AI.
- We do not let a model suspend, ban, or shadow-limit any account. Humans make every account decision.
- We do not send your photos, your emergency contacts, your payment data, your precise location, or your private messages to any AI vendor.
- We do not use AI to rank you in any visible leaderboard. Trust Mesh tiers are earned through real activity, not predicted.
Mobile app users — Legal basis for processing
For users covered by the EU General Data Protection Regulation, the UK GDPR, or equivalent frameworks, we rely on the following lawful bases under GDPR Article 6:
- Contractual necessity (Art. 6(1)(b)): email, name, payment information, subscription status, and location data necessary to deliver the core HAOT service.
- Consent (Art. 6(1)(a)): push notifications, optional emergency contact information, and photo uploads. You may withdraw consent in-app at any time.
- Legitimate interest (Art. 6(1)(f)): crash reporting and anonymized product analytics, used to keep the app stable and improve it without identifying individual users.
Mobile app users — Data retention
- Account data: retained until you delete your account, plus a 30-day legal hold to handle disputes or chargebacks.
- Financial records: retained for 7 years to satisfy tax and regulatory requirements.
- Crash reports and product analytics: retained for 90 days, then aggregated and anonymized.
- Deleted accounts: when you delete your account, we anonymize your personal information and leave a tombstone row. Foreign-key references are preserved so that other users’ ratings, attendance history, and group integrity remain intact.
Mobile app users — Apple App Privacy categories
The list below mirrors the “App Privacy” disclosure we file in App Store Connect. HAOT does NOT track users across other apps or websites owned by other companies.
Data Linked to You:
- Contact Info: Email, Name
- Identifiers: User ID
- Location: Precise Location, Coarse Location
- User Content: Photos, Other User Content (vibe quiz answers). User-generated text (activity titles, descriptions, abuse reports, Host application answers) is also processed by OpenAI and Anthropic as described in AI subprocessors above.
- Diagnostics: Crash Data, Performance Data
- Usage Data: Product Interaction
- Financial Info: Payment Info, Purchase History
What you can ask for
Email privacy@haot.app and we will do any of the following within 30 days, free of charge:
- Send you everything we have on file about you
- Data portability: export everything we have on file in a machine-readable format (JSON)
- Correct anything that is wrong
- Delete your record entirely
- Unsubscribe you from all emails
If you are in the European Union, United Kingdom, California, or any other jurisdiction with stronger data rights, those rights apply to your data with us regardless of where we are based. The General Data Protection Regulation, the California Consumer Privacy Act, and similar frameworks are honored.
Children
HAOT is for adults. We do not knowingly collect data from anyone under 18. Age is verified at signup via date of birth. If we discover that an account belongs to someone under 18, we delete the account within 7 days and notify the user by email. If you believe we hold data about someone under 18, email privacy@haot.app and we will delete the record.
International users
HAOT is operated from San Juan, Puerto Rico, USA. If you are outside the United States, your data is transferred to and stored in the United States and Singapore through our data processors. By using this site, you consent to that transfer. The data protection laws of those jurisdictions may differ from those of your country of residence. Regardless of where the data sits, the rights listed in this policy apply to your data with us.
Changes to this policy
If we change this policy, we will update the date at the top of this page. For changes that affect what data we collect or how we use it, we will email everyone on the waitlist before the change takes effect.
Contact
HAOT is operated from San Juan, Puerto Rico, USA. For any privacy question, email privacy@haot.app. We answer within one business day.