1. Who is responsible for your data
Hangouts Circle is operated by an individual. The identification details of the operator, together with a contact address for legal and privacy enquiries, are published in the Legal Notice. Some of those details are still pending publication and are shown there as placeholders.
This policy explains what personal data Hangouts Circle processes, why, who processes it on our behalf, and what rights you have. It describes the platform as it actually works today.
2. Account and authentication data
To create an account we process your email address and either a password (stored only as a hash by our authentication provider, never in readable form) or, if you choose to sign in with Google, the basic account information Google returns to us — typically your email address and your given or full name. We also process technical authentication records such as account creation and email confirmation timestamps and the sign-in method you used.
Purpose: creating and securing your account, signing you in, confirming your email address and recovering your password. Legal basis: performance of the contract with you (Art. 6(1)(b) GDPR) and our legitimate interest in account security (Art. 6(1)(f)).
Your email address is never shown on your public profile.
3. Profile data
Your profile can contain the following, all of it provided by you:
- Display name
- Self-reported age (a number you enter yourself — we do not verify it and we do not collect your date of birth)
- Country and city (selected by you; we do not use device geolocation)
- Bio
- Languages, interests and vibes
- Profile photo
- Your visibility preference for showing or hiding your age
- Your email notification preferences
Purpose: letting other users recognise you and decide whether to meet you, and showing you relevant hangouts. Legal basis: performance of the contract (Art. 6(1)(b) GDPR).
What other users can see: your display name, profile photo, city and country, bio, interests, languages, your age if you have chosen to show it, and your reviews. Nothing else from your profile is exposed to other users.
Profile photos are stored in a public storage bucket. This means the image file itself is reachable by anyone who has its direct link, even without an account. Please do not upload a photo you would not want to be publicly accessible. Hangout cover images, by contrast, are stored privately and are served through our own image endpoint.
4. Hangouts and participation
When you create or join a hangout we process:
- Hangout title, description, category, tags and cover image
- City, country, date and time
- Meeting point name, address and notes you choose to add
- Capacity, visibility and the hangout type (hangout or event)
- Your participation state — joined, left, removed or blocked by the host — and your attendance status
- Reviews you leave about a host, and reviews left about you as a host
- Who follows you and who you follow
Purpose: operating the core service. Legal basis: performance of the contract (Art. 6(1)(b) GDPR).
Be aware that meeting point details you enter are visible to the participants of that hangout. Choose what you disclose accordingly, and see our Safety Guidelines.
5. Messages and presence
Hangout chat messages are stored and are readable by the host and the accepted participants of that hangout. Direct messages are stored and are readable only by the two people in the conversation. The platform also generates system messages — for example when someone joins or leaves a hangout, or when a host makes a change.
While you have a hangout screen open, presence information (that you are currently viewing it, and that you are typing) is transmitted in real time to the other people in that hangout. This presence and typing information is ephemeral: it exists only for the duration of your connection and is not written to our database.
Message content is not read routinely. We may access specific messages when it is necessary to investigate a report or a serious safety or security issue. Legal basis: performance of the contract, and our legitimate interest in platform safety (Art. 6(1)(b) and (f) GDPR).
6. Reports, blocks and abuse prevention
We process:
- Reports you submit — the reason category, any details you write, who you reported, and the status of the report
- Reports about content such as reviews
- Blocks you create (who you blocked and when)
- Records of write actions used for rate limiting, consisting of your user identifier, the type of action and a technical fingerprint of the action
Reports are private: the reported user is not notified and cannot see the report. Blocks are also private.
Purpose: keeping the platform safe, preventing spam and abuse, and enforcing our Terms. Legal basis: our legitimate interest in the safety and integrity of the service and in preventing abuse (Art. 6(1)(f) GDPR), and compliance with legal obligations where applicable (Art. 6(1)(c)).
7. Notifications and email
In-app notifications are generated when something relevant happens — for example a new message, a new participant or an update to a hangout you are part of — and contain the notification text, a link and a read flag.
We also send transactional emails: account confirmation, password reset, and the notification emails you have enabled. To operate this reliably we keep a delivery log containing the recipient address, the template used, delivery status and any error returned, a list of addresses that must be suppressed (for example after a hard bounce or an unsubscribe), and single-use unsubscribe tokens.
You can turn notification emails off in your notification settings. Security and account emails such as password resets cannot be switched off while your account exists. Legal basis: performance of the contract and our legitimate interest in reliable email delivery.
8. Information that is public or visible to search engines
Public hangout pages can be indexed by search engines and, when a hangout link is shared on a messaging or social platform, that platform's crawler receives a preview containing public hangout metadata: the title, description, city, date, cover image and the host's display name.
Short share links of the form /h/<code> resolve to the same public hangout page. If you do not want a hangout and your host display name to be shareable in this way, do not publish it publicly.
9. Service providers and third parties
We do not sell your personal data and we do not share it with advertisers. We do rely on service providers who process data on our behalf, which is normal for any online service. Saying "we never share data with anyone" would not be truthful, so here is the actual list:
- Supabase — database, authentication, file storage, realtime messaging and server-side functions. This is where your account, profile, hangouts and messages are stored.
- Lovable — hosting and deployment of the application.
- Cloudflare — DNS and network delivery for our domain, including handling of link-preview requests.
- Our transactional email provider — delivery of account, security and notification emails.
- Google Fonts (fonts.googleapis.com / fonts.gstatic.com) — the web font used by the interface is loaded from Google's servers, which means your browser's IP address and user agent are visible to Google when a page loads.
- Google — only if you choose to sign in with Google, in which case Google processes that sign-in according to its own privacy policy.
- Messaging and social platforms — only when you or someone else shares a hangout link on them, in which case their crawler fetches the public preview described above.
We may also disclose information to competent authorities where we are legally required to do so.
10. No analytics, advertising or tracking
Hangouts Circle does not include any analytics SDK, advertising network, tracking pixel or third-party telemetry. We do not build advertising profiles, we do not use tracking cookies, and we do not carry out automated decision-making or profiling that produces legal effects for you.
Aggregate operational figures shown to the operator are calculated from data the platform already holds; no additional tracking is involved.
12. How long we keep data
Your account data, profile, hangouts and messages are kept for as long as your account exists, because they are needed to provide the service.
We have not yet established fixed retention periods for every category of data. Rather than state a number we do not actually apply, we describe our approach honestly: safety-related records such as reports and blocks are kept for as long as necessary for the safety of the platform and to enforce our Terms; email delivery logs and rate-limiting records are kept only as long as they are useful for operating and protecting the service; ephemeral presence information is not retained at all. Message content in a hangout or a conversation remains visible to the other people in it while that hangout or conversation exists.
If you would like your account and associated data deleted, contact us at the address in the Legal Notice. Some records may be retained where we have a legal obligation or a legitimate safety reason to do so; where that happens, we will tell you.
13. Your rights
Under the GDPR you have the right to:
- Access the personal data we hold about you
- Have inaccurate data corrected
- Have your data erased, subject to legal and safety limits
- Restrict or object to certain processing
- Receive your data in a portable format
- Withdraw consent where processing is based on consent
- Lodge a complaint with a supervisory authority — in Spain, the Agencia Española de Protección de Datos (AEPD)
You can exercise many of these directly in the app: edit or clear your profile fields, change your visibility and notification preferences, manage your blocked users, or delete content you have created. For anything else, use the contact address in the Legal Notice.
14. Age requirement
Hangouts Circle is intended exclusively for adults aged 18 or over. We do not knowingly process the personal data of anyone under 18. Age is currently self-reported and is not independently verified. If we have reasonable grounds to believe an account belongs to a minor, we may suspend or remove it.
15. International transfers
Some of the service providers listed above may process data outside the European Economic Area. Where that happens, the transfer relies on the safeguards those providers make available, such as the European Commission's standard contractual clauses or an adequacy decision.
16. Security
Data is transmitted over encrypted connections and access to it is restricted at the database level so that, as a rule, you can only reach your own data and the content of hangouts and conversations you belong to. Uploaded images are validated before being accepted. No online service can guarantee absolute security, and we do not claim to; if a breach affecting your rights occurs, we will notify you and the competent authority as required by law.
17. Changes to this policy
We may update this policy to reflect changes to the platform, to the service providers we use, or to legal requirements. The date at the top of this page shows when it was last updated.
Looking for your own controls instead? Manage visibility, blocked users and notifications in Privacy & safety settings.