← COORDIN8

Privacy Policy

Last updated: 15 August 2026

Effective: 15 August 2026

COORDIN8 shows you which days your friends are free, and turns one of those days into a plan. To do that it has to hold some information about you. This policy explains exactly what is stored, why, who else can see it, how long it is kept, and how to get rid of it.

The short version. Other people in COORDIN8 only ever see whether you are free or busy on a given day. They never see your event titles, locations, notes, or who you are with.

But "not shared" is not the same as "not stored". If you create an event inside COORDIN8, its title, location and notes are stored on our server, linked to your account. See Section 4.

There is no advertising in COORDIN8. We do not sell your personal information. There is no third-party analytics or tracking SDK in the product.

1. Who we are and how to contact us

COORDIN8 is built and run by an individual sole developer based in Sacramento, California, USA. There is no company, no staff and no investors. For data protection purposes, that individual is the data controller — the person who decides what is collected and why.

The service is available as a web app at https://coordin8-rho.vercel.app, and as an iOS app that has not yet been released.

Contact for anything in this policy, including privacy questions, data requests and deletion requests:
abasefi0207@gmail.com

There is no dedicated Data Protection Officer, and none is required for an operation this size. Emails go to the developer directly.

Words used in this policy

COORDIN8 uses a few words in a specific way. They are defined once here and mean the same thing everywhere below. Where a word is being used in this special sense it is written in bold.

Availability
Whether you are free or busy at a given time — and only that. It never includes what you are doing, where, or with whom. This distinction is the centre of how COORDIN8 works, and most of this policy turns on it.
Block
One stretch of time recorded as busy: a start, an end, and where it came from. A block carries no title. See Section 3.
Event
Something in your own calendar, with a title, and possibly a place and a note. Events are stored so the app can show them back to you. They are never shown to anyone else — see Section 4, which explains what that does and does not protect against.
Group
A named set of people you have added. Being in a group with somebody is what lets them see your availability; simply being connected does not. See Section 8.
Plan
A proposed or confirmed thing to do, with a date, people, and options people vote on.
Answer link
A link a user can send to somebody with no COORDIN8 account, asking whether they are free. The recipient answers on a web page and installs nothing. Section 6 is written for those recipients.
The service
The COORDIN8 web app, the iOS app, the widgets, and the server endpoints behind them — all of it, taken together.

2. Who this policy covers

It covers three groups of people:

3. What we collect and why

Here is everything, by category. Nothing is collected that is not on this list.

3.1 Account and profile

DataWhy
Email address and passwordTo sign you in. These are held by Supabase Auth, our authentication provider, not in our own profile records. We never see your password.
Handle / usernameSo friends can find and recognise you.
Display nameShown to your friends and to people in your plans.
Profile photo — either an uploaded image or a built-in emoji plus a colourSo people can tell you apart. Using the built-in emoji option means no photo of you is uploaded at all.
City, nearest airport, travel radius in milesTo suggest venues, events and trips that are actually reachable for you.
Budget bandTo keep suggestions in your price range.
Interests and preferences (stored as a preferences object)To rank suggested activities.
Dietary requirementsSo a plan does not land somewhere you cannot eat. Optional.
Accessibility needsSo a plan does not land somewhere you cannot get into. Optional.
Notification preferencesTo respect what you asked to be told about.
Created and updated timestampsRoutine record keeping.

A note on dietary and accessibility fields. These can reveal something about your health or your religious beliefs. Under UK and EU law that makes them "special category" data, and under California law "sensitive personal information". They are entirely optional, you choose what to type, they are used only to filter and rank suggestions, and you can clear them at any time in your profile. By filling them in you are giving explicit consent for them to be used for that purpose.

3.2 Availability

Availability is stored as blocks of time. Each block records a start time, an end time, whether it is an all-day block, and where it came from — created inside COORDIN8, or synced from Google, Microsoft, Apple, or an ICS calendar subscription. For synced blocks we also store the provider's own event ID, so that when the event changes on their side we can update the right block instead of duplicating it.

This is the core of the product: it is what lets your friends see that Thursday is open.

3.3 Events you create in COORDIN8

Titles, locations, notes and recurrence rules. This is important enough to have its own section — see Section 4.

3.4 Connected calendars

Access tokens, refresh tokens and related settings, only if you choose to connect a calendar. See Section 5.

3.5 Your social graph

This exists so the app knows whose availability to show you, and so that a plan can be sent to the right people.

3.6 Plans

For each plan: the title, the date and times, the location, who is taking part, the options being considered, the votes cast on those options, the chat messages between participants, and any checklist items and who ticked them off.

Plan content is visible to the people in that plan. Chat messages are not end-to-end encrypted — they are stored in our database and are technically readable by the operator, in the same way as any ordinary web app. Do not use plan chat for anything you would not want written down.

3.7 Push notification tokens

If you turn on notifications, we store the subscription token your browser or device issues. It identifies the device to the push service, not to us personally. See Section 20.

3.8 Answers from people without accounts

A name typed by the person answering, and their answer. See Section 6.

3.9 Technical and log data

The app is hosted on Vercel. Like any website host, Vercel's servers and edge network record standard request logs, which include IP addresses, the URL requested, timestamps, and browser user-agent strings. We use these for security, abuse prevention and debugging. We do not build advertising or behavioural profiles from them, and there is no third-party analytics or tracking SDK in the product.

4. Your events: stored, but never shown to others

When you create an event in COORDIN8, the title, location, notes and recurrence rule are stored on our server, in a record linked to your account.

Other users never see any of it. They see only that you are busy at that time. The app has no screen anywhere that shows another person's event title, location or notes.

But it is stored, not discarded, and it is not encrypted in a way that puts it beyond our reach. As the operator of the database, the developer is technically able to read it. Anyone with lawful compelled access to the database could read it too.

We are stating this plainly rather than saying "private" and leaving you to assume it means something stronger. Why it is stored at all: so that your own calendar view can show you what you had planned, so recurring events can regenerate, and so busy times can be edited rather than only deleted.

If you would rather COORDIN8 did not hold the details of something, put a vague title on it, or block the time out as busy without describing it. You can delete an event at any time, which deletes its stored details.

5. Connected calendars and their access tokens

Connecting a calendar is entirely optional. The app works without it — you can enter your availability by hand.

If you do connect one, we store:

These tokens are credentials. They are the equivalent of a key to your calendar. They let COORDIN8 read your calendar events in order to work out when you are busy, and — only if you leave write-back switched on — to add confirmed plans to your calendar.

An ICS subscription URL is also a credential: anyone holding it can read that feed.

How to revoke access. Two ways, and you can use either:

  1. Disconnect the calendar inside COORDIN8. This removes the connection and stops further syncing.
  2. Revoke COORDIN8's access from the provider directly — in your Google Account's security settings under third-party access, or in your Microsoft account's app permissions. This works even if you cannot get into COORDIN8.

Disconnecting stops future syncing. If you also want busy times that were already synced to be removed from our records, email us and we will remove them.

6. Answer links: people who do not have an account

This section is for you if someone sent you a COORDIN8 link and you do not have an account.

A COORDIN8 user can send a link asking whether you are free. Opening it shows you a small page where you type a name and tap an answer — Free, Busy or Not sure, or Coming, Can't or Maybe.

What is stored

That is all. You are not asked for an email address or a phone number, no account is created for you, and no password is set. Standard server logs (including your IP address) are recorded by our host, as for any web page you visit.

We are being upfront about this

This means COORDIN8 holds a small amount of personal data about people who never signed up and never agreed to anything. That is a real thing worth naming rather than burying. We keep it to the minimum needed to answer the question the sender asked, and we delete it on a fixed schedule.

How long it lasts

Link typeExpires afterThen
One-off ask ("are you free this Saturday?")30 daysThe expired record and its answers are deleted.
Weekly headcount link90 daysThe expired record and its answers are deleted.

How to get it removed sooner

Email abasefi0207@gmail.com. Tell us roughly when you answered, what name you typed, and if you still have it, the link itself — that identifies the record fastest. We will delete it. You do not have to prove who you are beyond what is needed to find the record, and we will not create an account for you in order to process the request.

You can also simply not answer. Nothing is stored until you tap an answer.

The link is the key. Answer links use a long random token in the URL. Anyone holding that link can open the page and answer, because there is no account to sign in with. Treat the link as semi-private and do not post it publicly.

7. Legal bases for using your data (UK/EU)

If UK or EU data protection law applies to you, we must have a legal basis under Article 6 of the GDPR for each use. Here they are.

WhatLegal basisWhy that one
Account, handle, display name, profile photoContract — Art. 6(1)(b)We cannot give you an account without it.
Availability blocksContract — Art. 6(1)(b)This is the service you signed up for.
Event titles, locations, notes, recurrenceContract — Art. 6(1)(b)Needed to show you your own calendar and to edit or repeat entries.
Friendships, requests, groupsContract — Art. 6(1)(b)Needed to know whose availability to show you.
Plans, votes, chat, checklistsContract — Art. 6(1)(b)The plan is the product.
City, airport, travel radius, budget, interestsContract — Art. 6(1)(b), or consent — Art. 6(1)(a) where optionalUsed to make suggestions useful; you choose what to fill in.
Dietary requirements, accessibility needsExplicit consent — Art. 9(2)(a), with Art. 6(1)(a)Special category data. Entirely optional, given by you, clearable by you.
Connecting a calendar and storing its tokensConsent — Art. 6(1)(a)You opt in per calendar and can revoke at any time.
Writing confirmed plans back to your calendarConsent — Art. 6(1)(a)Controlled by the write-back setting.
Push notification tokensConsent — Art. 6(1)(a)You must grant permission for these.
Answer-link names and answersLegitimate interests — Art. 6(1)(f)Answering a direct question you were asked by someone you know. Minimal data, short retention, easy removal. See Section 6.
Server logs, security, abuse prevention, debuggingLegitimate interests — Art. 6(1)(f)Keeping the service running and not broken or abused.
Responding to lawful requests, keeping required recordsLegal obligation — Art. 6(1)(c)Where the law requires it.

Where we rely on consent, you can withdraw it at any time — by disconnecting the calendar, turning off notifications, or clearing the field. Withdrawing consent does not undo processing that already happened lawfully.

Where we rely on legitimate interests, you can object. See Section 16.

8. What other users can see

Other users seeOther users never see
Your display name, handle and profile photo or emojiYour event titles
Whether you are free or busy on a day or at a timeYour event locations
Anything you write or vote on inside a shared planYour event notes
That you are in a group you both belong toWho you are with
Your friend request note, if you write oneWhich calendar a busy block came from
Your email address

Free/busy is the boundary. It is enforced in the database itself, not only in the app — see Section 15.

Some profile fields, such as your city or your dietary requirements, are used to shape suggestions for a group. Be aware that a suggestion tailored around a constraint can imply the constraint to the people in that plan.

9. Companies that process data for us

COORDIN8 is one developer plus a set of services. Below is every third party the app talks to, and what reaches them. Those marked "processor" handle your data on our instructions; the others are independent services we send a query to.

ServiceRoleWhat it receives
SupabaseProcessorEverything in Section 3 — it is our database, our authentication provider and where all account data lives. Your email address and password are held here.
VercelProcessorApplication hosting, serverless functions and edge caching. Standard server logs including IP addresses. All app traffic passes through Vercel.
Google Places APIIndependent serviceA city and a category, to fetch venue names, ratings, addresses and photos. It does not receive your identity — no name, no account ID, no email.
Google Calendar APIIndependent serviceOnly if you connect a Google calendar. We read events to derive busy times, and write confirmed plans back if write-back is on.
Microsoft GraphIndependent serviceOnly if you connect a Microsoft calendar. Same purpose as above.
Ticketmaster Discovery APIIndependent serviceA city, to list events happening there.
Anthropic (Claude API)ProcessorInterests and group size only, to rank and explain suggestions. See Section 10.
PexelsIndependent serviceStock photography requests. No user identity.
Travelpayouts, Duffel, HotellookIndependent servicesRoute, date and location parameters, to price flights and stays for trip planning.
Groupon Partner APIIndependent serviceLocation and category, to fetch deals.
Web Push (VAPID) and OneSignalProcessorsYour device push token and the content of the notification, in order to deliver it.
AppleIndependent serviceApp Store distribution, and Sign in with Apple if you use it. See Section 22.

Each of these companies has its own privacy policy governing what it does with what it receives. We do not sell your personal information to any of them, or to anyone else.

10. How AI suggestions work

COORDIN8 uses Anthropic's Claude API to rank suggested options and write the short explanations of why something was suggested.

What is sent: interests and group size.

What is not sent: names, and calendar data. The code explicitly excludes them.

So the model is asked something closer to "six people, into live music and cheap food" than anything that identifies you. Nothing you write in plan chat, no event titles, and no calendar contents go to the model.

Suggestions are ranking and explanation only. No decision with a legal or similarly significant effect on you is made by automated means.

11. Other sharing: legal, safety, business transfer

Beyond the processors in Section 9 and the other users described in Section 8, we may disclose data in three situations:

We do not sell personal information, share it for cross-context behavioural advertising, or hand it to data brokers.

12. Where your data is held and international transfers

COORDIN8 is operated from California, and its infrastructure — Supabase and Vercel — is hosted in the United States. Several of the services in Section 9 are also US-based.

If you use COORDIN8 from the UK, the EEA, or anywhere else with data export rules, your data will be transferred to and stored in the United States. US law does not offer the same protections as UK or EU law, and US public authorities may in some circumstances be able to access data held there.

Where our providers make them available, transfers rely on the European Commission's Standard Contractual Clauses (and the UK Addendum or UK International Data Transfer Agreement), which our providers include in their standard data processing terms. Some providers additionally participate in the EU–US Data Privacy Framework and its UK extension, which provides an adequacy route for transfers to those companies.

If you are not comfortable with your data being processed in the United States, please do not create an account.

13. How long we keep things

DataKept for
Account and profileUntil you delete your account.
Availability blocksUntil you delete them, or you delete your account. Synced blocks are refreshed from the source calendar.
Event titles, locations, notes, recurrenceUntil you delete the event, or you delete your account.
Calendar access and refresh tokens, ICS URLsUntil you disconnect that calendar, or you delete your account.
Friendships, requests, groupsUntil removed by you or the other person, or you delete your account.
Plans, votes, chat, checklistsUntil deleted, or you delete your account. See the note below on shared plans.
Push tokensUntil you turn off notifications, the token is rejected as invalid by the push service, or you delete your account.
One-off answer links and their answers30 days, then the expired records are deleted.
Weekly headcount links and their answers90 days, then the expired records are deleted.
Cached Google place data (names, ratings, addresses)25 days, then refreshed.
Google place photosNot stored. They are proxied live each time they are shown.
Pexels stock imageryMay be stored indefinitely. It is stock photography and contains no personal data of yours.
Server logs (Vercel)For the limited period set by our hosting provider's own retention policy.

Shared plans. A plan belongs to everyone in it. When you delete your account, your profile and your participation are removed. Where a message or a plan detail forms part of another participant's record, tell us and we will remove or anonymise your contribution.

Backups. Our database provider takes routine backups. Deleted data may persist in those backups for a short period before they are rotated and overwritten. Backups are not used to repopulate deleted accounts.

14. Deleting your account

How to delete your account. Use the delete option in the app's profile or settings area. If you cannot reach it, email abasefi0207@gmail.com from the address on your account and ask for deletion. We will action it within 30 days and confirm when it is done.

You do not need to give a reason, and we will not require a phone call, a form, or a retention offer first.

What deletion erases

What may remain

Deleting the app is not deleting your account. Removing the iOS app or clearing your browser only removes the local copy. Use the in-app deletion or email us.

Also worth doing: after deleting, revoke COORDIN8 from your Google or Microsoft account's third-party access settings, so you can see for yourself that the connection is gone.

15. How we protect your data

Honestly framed: these are the measures actually in place. No online service can promise perfect security, and we do not.

What we cannot promise: that no vulnerability exists, that our providers will never suffer an incident, or that a determined attacker with lawful or unlawful access to the underlying database could not read stored event details. Section 4 says plainly what is stored.

Your part: use a strong, unique password, and do not forward answer links or ICS URLs to people you would not want holding them.

If a breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority and affected users as required by law.

16. Your rights (UK and EU)

If the UK GDPR or EU GDPR applies to you, you have the right to:

To exercise any of these, email abasefi0207@gmail.com. We will respond within one month. If a request is genuinely complex we may extend by two further months and will tell you why. There is no charge, unless a request is manifestly unfounded or excessive. We may need to confirm you control the account before releasing data — usually by asking you to write from the account's email address.

17. Your rights in California and other US states

The operator is based in California. If you are a California resident, the CCPA as amended by the CPRA gives you the following rights.

Categories collected in the last 12 months, in CCPA terms: identifiers (email address, handle, display name, device push token, IP address); personal information under Cal. Civ. Code §1798.80 (name); characteristics of protected classifications, only if you volunteer them (dietary requirements that may reflect religion, accessibility needs that may reflect a disability); internet or network activity (server logs); geolocation at city level (the city and nearest airport you enter — COORDIN8 does not collect precise GPS location); and inferences drawn to rank suggestions. Sources: you, and the calendar providers you choose to connect. Business purposes: providing the service, security, and support.

Authorised agents. You may use an authorised agent to make a request. We will ask for proof of authorisation and may ask you to confirm the request directly.

Other US states. Comprehensive privacy laws in states including Virginia, Colorado, Connecticut, Utah, Texas, Oregon and others give residents broadly similar rights — to access, correct, delete, obtain a copy, and opt out of targeted advertising, sale, and certain profiling. We extend the rights in this section to residents of any US state with such a law, and there is no targeted advertising, sale, or profiling with legal effects to opt out of. Some of those states offer an appeal if we refuse a request; to appeal, reply to our decision and say you are appealing, and we will review it and respond in writing.

18. Children

You must be at least 13 years old to use COORDIN8. The service is not directed at children, it is not designed or marketed for them, and it contains no child-focused features.

We do not knowingly collect personal information from anyone under 13. If we discover that an account belongs to a child under 13, we will delete it and its data.

Some jurisdictions set a higher minimum age for consent to online services — up to 16 in parts of the EEA. If you are under the applicable age in your country, please do not use COORDIN8 without a parent or guardian's permission.

Parents and guardians: if you believe your child has created an account or has answered a COORDIN8 link, email abasefi0207@gmail.com with enough detail to find the record — the handle, the email address used, or the link. We will delete it and confirm, without requiring you to create an account.

19. Cookies, local storage and the service worker

COORDIN8 uses no advertising cookies, no tracking pixels, and no third-party analytics. There is no tracking SDK in the product.

What the app does use:

You can clear all of this at any time by clearing site data for the COORDIN8 domain in your browser settings. Doing so signs you out; it does not delete your account or anything held on the server.

Because we do not do advertising or analytics tracking, there is no consent banner to click through. There is also currently no response to browser "Do Not Track" or Global Privacy Control signals, for the simple reason that there is no tracking to switch off.

20. Push notifications

Notifications are optional. If you turn them on, your browser or device issues a subscription token, which we store so we can send you things like a friend request, a plan invitation, or a reminder about a plan you are in.

Delivery goes through Web Push using the VAPID standard, and through OneSignal. The delivery service receives the token and the notification content in order to deliver it.

To turn them off:

Revoking permission at the device or browser level stops delivery regardless of any in-app setting.

21. Device permissions on iOS

The iOS app may ask for the following. All are optional, all are refusable, and refusing one only disables the feature it belongs to.

PermissionUsed forWhat leaves your device
Calendar (EventKit)Reading your device calendar to derive busy times, and writing confirmed plans back if you leave write-back on.Busy times, and the event details described in Sections 3.2 and 4.
ContactsPicking a name to invite, and checking which of the people you already know are on COORDIN8.Never the address book itself. Names, numbers and email addresses stay on the device. If you use "See who you already know", irreversible one-way hashes of the email addresses and phone numbers are sent so we can check them against accounts — see Section 23, which explains what that does and does not protect.
CameraTaking a profile picture.Only the photo you choose to set as your profile picture.
Photo libraryChoosing an existing profile picture.Only the photo you choose.

You can change any of these later in iOS Settings. If you would rather not upload a photo at all, choose the built-in emoji and colour option for your profile instead.

22. Payments

There are none. COORDIN8 is free, nothing in it is for sale, and we do not collect, process or store any payment information about you at all.

23. Finding people you already know

COORDIN8 can tell you which of the people in your phone's contacts already have an account. This is optional, it only runs when you open that screen, and nothing happens if you never do.

Your address book is never uploaded. There is no table in our database that could hold one. Names, phone numbers and email addresses do not leave your device.

What is sent is a list of one-way hashes. Your device takes each email address and phone number, standardises it, and runs it through SHA-256 — a calculation that cannot be reversed to recover the original. The server compares those hashes against hashes of the contact details of people who have accounts, and returns only the matches: the same name, username and profile picture a username search would already show you.

What hashing does not do, stated plainly

Hashing is not encryption, and we would rather say so than let the word do work it cannot. Anyone who already holds a particular email address can hash it and check whether it matches — the range of possible email addresses is small enough that this is cheap to do. So this protects your contacts from being collected in bulk. It does not make an individual hash anonymous.

That limitation is why matching returns only information a username search already returns, never anything about somebody's calendar, plans or friends, and never a row for anyone who has turned discoverability off.

Your own details

So that your friends can find you the same way, hashes of your own email address — and your phone number, if you add one — are stored against your account. You can remove them by turning off discoverability in Settings, and they are deleted along with everything else when you delete your account (Section 14).

People who are not users

Hashes that do not match an account are used for the comparison and not stored. Somebody in your contacts who has never heard of COORDIN8 does not get a record here as a result of you opening that screen.

24. Changes to this policy

This policy will change as the product changes. When it does:

Continuing to use COORDIN8 after a change takes effect means the updated policy applies to you. If you disagree with a change, you can delete your account — see Section 14.

25. How to complain

Please email abasefi0207@gmail.com first. Most things can be sorted out directly and quickly.

If that does not resolve it, you also have the right to complain to a regulator:

You do not have to come to us first, though we would prefer the chance to fix it.