Last updated: 15 August 2026
Effective: 15 August 2026
COORDIN8 shows you which days your friends are free, and turns one of those days into a plan. To do that it has to hold some information about you. This policy explains exactly what is stored, why, who else can see it, how long it is kept, and how to get rid of it.
The short version. Other people in COORDIN8 only ever see whether you are free or busy on a given day. They never see your event titles, locations, notes, or who you are with.
But "not shared" is not the same as "not stored". If you create an event inside COORDIN8, its title, location and notes are stored on our server, linked to your account. See Section 4.
There is no advertising in COORDIN8. We do not sell your personal information. There is no third-party analytics or tracking SDK in the product.
COORDIN8 is built and run by an individual sole developer based in Sacramento, California, USA. There is no company, no staff and no investors. For data protection purposes, that individual is the data controller — the person who decides what is collected and why.
The service is available as a web app at https://coordin8-rho.vercel.app, and as an iOS app that has not yet been released.
Contact for anything in this policy, including privacy questions, data requests and deletion requests:
abasefi0207@gmail.com
There is no dedicated Data Protection Officer, and none is required for an operation this size. Emails go to the developer directly.
COORDIN8 uses a few words in a specific way. They are defined once here and mean the same thing everywhere below. Where a word is being used in this special sense it is written in bold.
It covers three groups of people:
Here is everything, by category. Nothing is collected that is not on this list.
| Data | Why |
|---|---|
| Email address and password | To sign you in. These are held by Supabase Auth, our authentication provider, not in our own profile records. We never see your password. |
| Handle / username | So friends can find and recognise you. |
| Display name | Shown to your friends and to people in your plans. |
| Profile photo — either an uploaded image or a built-in emoji plus a colour | So people can tell you apart. Using the built-in emoji option means no photo of you is uploaded at all. |
| City, nearest airport, travel radius in miles | To suggest venues, events and trips that are actually reachable for you. |
| Budget band | To keep suggestions in your price range. |
| Interests and preferences (stored as a preferences object) | To rank suggested activities. |
| Dietary requirements | So a plan does not land somewhere you cannot eat. Optional. |
| Accessibility needs | So a plan does not land somewhere you cannot get into. Optional. |
| Notification preferences | To respect what you asked to be told about. |
| Created and updated timestamps | Routine record keeping. |
A note on dietary and accessibility fields. These can reveal something about your health or your religious beliefs. Under UK and EU law that makes them "special category" data, and under California law "sensitive personal information". They are entirely optional, you choose what to type, they are used only to filter and rank suggestions, and you can clear them at any time in your profile. By filling them in you are giving explicit consent for them to be used for that purpose.
Availability is stored as blocks of time. Each block records a start time, an end time, whether it is an all-day block, and where it came from — created inside COORDIN8, or synced from Google, Microsoft, Apple, or an ICS calendar subscription. For synced blocks we also store the provider's own event ID, so that when the event changes on their side we can update the right block instead of duplicating it.
This is the core of the product: it is what lets your friends see that Thursday is open.
Titles, locations, notes and recurrence rules. This is important enough to have its own section — see Section 4.
Access tokens, refresh tokens and related settings, only if you choose to connect a calendar. See Section 5.
This exists so the app knows whose availability to show you, and so that a plan can be sent to the right people.
For each plan: the title, the date and times, the location, who is taking part, the options being considered, the votes cast on those options, the chat messages between participants, and any checklist items and who ticked them off.
Plan content is visible to the people in that plan. Chat messages are not end-to-end encrypted — they are stored in our database and are technically readable by the operator, in the same way as any ordinary web app. Do not use plan chat for anything you would not want written down.
If you turn on notifications, we store the subscription token your browser or device issues. It identifies the device to the push service, not to us personally. See Section 20.
A name typed by the person answering, and their answer. See Section 6.
The app is hosted on Vercel. Like any website host, Vercel's servers and edge network record standard request logs, which include IP addresses, the URL requested, timestamps, and browser user-agent strings. We use these for security, abuse prevention and debugging. We do not build advertising or behavioural profiles from them, and there is no third-party analytics or tracking SDK in the product.
When you create an event in COORDIN8, the title, location, notes and recurrence rule are stored on our server, in a record linked to your account.
Other users never see any of it. They see only that you are busy at that time. The app has no screen anywhere that shows another person's event title, location or notes.
But it is stored, not discarded, and it is not encrypted in a way that puts it beyond our reach. As the operator of the database, the developer is technically able to read it. Anyone with lawful compelled access to the database could read it too.
We are stating this plainly rather than saying "private" and leaving you to assume it means something stronger. Why it is stored at all: so that your own calendar view can show you what you had planned, so recurring events can regenerate, and so busy times can be edited rather than only deleted.
If you would rather COORDIN8 did not hold the details of something, put a vague title on it, or block the time out as busy without describing it. You can delete an event at any time, which deletes its stored details.
Connecting a calendar is entirely optional. The app works without it — you can enter your availability by hand.
If you do connect one, we store:
These tokens are credentials. They are the equivalent of a key to your calendar. They let COORDIN8 read your calendar events in order to work out when you are busy, and — only if you leave write-back switched on — to add confirmed plans to your calendar.
An ICS subscription URL is also a credential: anyone holding it can read that feed.
How to revoke access. Two ways, and you can use either:
Disconnecting stops future syncing. If you also want busy times that were already synced to be removed from our records, email us and we will remove them.
This section is for you if someone sent you a COORDIN8 link and you do not have an account.
A COORDIN8 user can send a link asking whether you are free. Opening it shows you a small page where you type a name and tap an answer — Free, Busy or Not sure, or Coming, Can't or Maybe.
That is all. You are not asked for an email address or a phone number, no account is created for you, and no password is set. Standard server logs (including your IP address) are recorded by our host, as for any web page you visit.
This means COORDIN8 holds a small amount of personal data about people who never signed up and never agreed to anything. That is a real thing worth naming rather than burying. We keep it to the minimum needed to answer the question the sender asked, and we delete it on a fixed schedule.
| Link type | Expires after | Then |
|---|---|---|
| One-off ask ("are you free this Saturday?") | 30 days | The expired record and its answers are deleted. |
| Weekly headcount link | 90 days | The expired record and its answers are deleted. |
Email abasefi0207@gmail.com. Tell us roughly when you answered, what name you typed, and if you still have it, the link itself — that identifies the record fastest. We will delete it. You do not have to prove who you are beyond what is needed to find the record, and we will not create an account for you in order to process the request.
You can also simply not answer. Nothing is stored until you tap an answer.
The link is the key. Answer links use a long random token in the URL. Anyone holding that link can open the page and answer, because there is no account to sign in with. Treat the link as semi-private and do not post it publicly.
If UK or EU data protection law applies to you, we must have a legal basis under Article 6 of the GDPR for each use. Here they are.
| What | Legal basis | Why that one |
|---|---|---|
| Account, handle, display name, profile photo | Contract — Art. 6(1)(b) | We cannot give you an account without it. |
| Availability blocks | Contract — Art. 6(1)(b) | This is the service you signed up for. |
| Event titles, locations, notes, recurrence | Contract — Art. 6(1)(b) | Needed to show you your own calendar and to edit or repeat entries. |
| Friendships, requests, groups | Contract — Art. 6(1)(b) | Needed to know whose availability to show you. |
| Plans, votes, chat, checklists | Contract — Art. 6(1)(b) | The plan is the product. |
| City, airport, travel radius, budget, interests | Contract — Art. 6(1)(b), or consent — Art. 6(1)(a) where optional | Used to make suggestions useful; you choose what to fill in. |
| Dietary requirements, accessibility needs | Explicit consent — Art. 9(2)(a), with Art. 6(1)(a) | Special category data. Entirely optional, given by you, clearable by you. |
| Connecting a calendar and storing its tokens | Consent — Art. 6(1)(a) | You opt in per calendar and can revoke at any time. |
| Writing confirmed plans back to your calendar | Consent — Art. 6(1)(a) | Controlled by the write-back setting. |
| Push notification tokens | Consent — Art. 6(1)(a) | You must grant permission for these. |
| Answer-link names and answers | Legitimate interests — Art. 6(1)(f) | Answering a direct question you were asked by someone you know. Minimal data, short retention, easy removal. See Section 6. |
| Server logs, security, abuse prevention, debugging | Legitimate interests — Art. 6(1)(f) | Keeping the service running and not broken or abused. |
| Responding to lawful requests, keeping required records | Legal obligation — Art. 6(1)(c) | Where the law requires it. |
Where we rely on consent, you can withdraw it at any time — by disconnecting the calendar, turning off notifications, or clearing the field. Withdrawing consent does not undo processing that already happened lawfully.
Where we rely on legitimate interests, you can object. See Section 16.
| Other users see | Other users never see |
|---|---|
| Your display name, handle and profile photo or emoji | Your event titles |
| Whether you are free or busy on a day or at a time | Your event locations |
| Anything you write or vote on inside a shared plan | Your event notes |
| That you are in a group you both belong to | Who you are with |
| Your friend request note, if you write one | Which calendar a busy block came from |
| Your email address |
Free/busy is the boundary. It is enforced in the database itself, not only in the app — see Section 15.
Some profile fields, such as your city or your dietary requirements, are used to shape suggestions for a group. Be aware that a suggestion tailored around a constraint can imply the constraint to the people in that plan.
COORDIN8 is one developer plus a set of services. Below is every third party the app talks to, and what reaches them. Those marked "processor" handle your data on our instructions; the others are independent services we send a query to.
| Service | Role | What it receives |
|---|---|---|
| Supabase | Processor | Everything in Section 3 — it is our database, our authentication provider and where all account data lives. Your email address and password are held here. |
| Vercel | Processor | Application hosting, serverless functions and edge caching. Standard server logs including IP addresses. All app traffic passes through Vercel. |
| Google Places API | Independent service | A city and a category, to fetch venue names, ratings, addresses and photos. It does not receive your identity — no name, no account ID, no email. |
| Google Calendar API | Independent service | Only if you connect a Google calendar. We read events to derive busy times, and write confirmed plans back if write-back is on. |
| Microsoft Graph | Independent service | Only if you connect a Microsoft calendar. Same purpose as above. |
| Ticketmaster Discovery API | Independent service | A city, to list events happening there. |
| Anthropic (Claude API) | Processor | Interests and group size only, to rank and explain suggestions. See Section 10. |
| Pexels | Independent service | Stock photography requests. No user identity. |
| Travelpayouts, Duffel, Hotellook | Independent services | Route, date and location parameters, to price flights and stays for trip planning. |
| Groupon Partner API | Independent service | Location and category, to fetch deals. |
| Web Push (VAPID) and OneSignal | Processors | Your device push token and the content of the notification, in order to deliver it. |
| Apple | Independent service | App Store distribution, and Sign in with Apple if you use it. See Section 22. |
Each of these companies has its own privacy policy governing what it does with what it receives. We do not sell your personal information to any of them, or to anyone else.
COORDIN8 uses Anthropic's Claude API to rank suggested options and write the short explanations of why something was suggested.
What is sent: interests and group size.
What is not sent: names, and calendar data. The code explicitly excludes them.
So the model is asked something closer to "six people, into live music and cheap food" than anything that identifies you. Nothing you write in plan chat, no event titles, and no calendar contents go to the model.
Suggestions are ranking and explanation only. No decision with a legal or similarly significant effect on you is made by automated means.
Beyond the processors in Section 9 and the other users described in Section 8, we may disclose data in three situations:
We do not sell personal information, share it for cross-context behavioural advertising, or hand it to data brokers.
COORDIN8 is operated from California, and its infrastructure — Supabase and Vercel — is hosted in the United States. Several of the services in Section 9 are also US-based.
If you use COORDIN8 from the UK, the EEA, or anywhere else with data export rules, your data will be transferred to and stored in the United States. US law does not offer the same protections as UK or EU law, and US public authorities may in some circumstances be able to access data held there.
Where our providers make them available, transfers rely on the European Commission's Standard Contractual Clauses (and the UK Addendum or UK International Data Transfer Agreement), which our providers include in their standard data processing terms. Some providers additionally participate in the EU–US Data Privacy Framework and its UK extension, which provides an adequacy route for transfers to those companies.
If you are not comfortable with your data being processed in the United States, please do not create an account.
| Data | Kept for |
|---|---|
| Account and profile | Until you delete your account. |
| Availability blocks | Until you delete them, or you delete your account. Synced blocks are refreshed from the source calendar. |
| Event titles, locations, notes, recurrence | Until you delete the event, or you delete your account. |
| Calendar access and refresh tokens, ICS URLs | Until you disconnect that calendar, or you delete your account. |
| Friendships, requests, groups | Until removed by you or the other person, or you delete your account. |
| Plans, votes, chat, checklists | Until deleted, or you delete your account. See the note below on shared plans. |
| Push tokens | Until you turn off notifications, the token is rejected as invalid by the push service, or you delete your account. |
| One-off answer links and their answers | 30 days, then the expired records are deleted. |
| Weekly headcount links and their answers | 90 days, then the expired records are deleted. |
| Cached Google place data (names, ratings, addresses) | 25 days, then refreshed. |
| Google place photos | Not stored. They are proxied live each time they are shown. |
| Pexels stock imagery | May be stored indefinitely. It is stock photography and contains no personal data of yours. |
| Server logs (Vercel) | For the limited period set by our hosting provider's own retention policy. |
Shared plans. A plan belongs to everyone in it. When you delete your account, your profile and your participation are removed. Where a message or a plan detail forms part of another participant's record, tell us and we will remove or anonymise your contribution.
Backups. Our database provider takes routine backups. Deleted data may persist in those backups for a short period before they are rotated and overwritten. Backups are not used to repopulate deleted accounts.
How to delete your account. Use the delete option in the app's profile or settings area. If you cannot reach it, email abasefi0207@gmail.com from the address on your account and ask for deletion. We will action it within 30 days and confirm when it is done.
You do not need to give a reason, and we will not require a phone call, a form, or a retention offer first.
Deleting the app is not deleting your account. Removing the iOS app or clearing your browser only removes the local copy. Use the in-app deletion or email us.
Also worth doing: after deleting, revoke COORDIN8 from your Google or Microsoft account's third-party access settings, so you can see for yourself that the connection is gone.
Honestly framed: these are the measures actually in place. No online service can promise perfect security, and we do not.
What we cannot promise: that no vulnerability exists, that our providers will never suffer an incident, or that a determined attacker with lawful or unlawful access to the underlying database could not read stored event details. Section 4 says plainly what is stored.
Your part: use a strong, unique password, and do not forward answer links or ICS URLs to people you would not want holding them.
If a breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority and affected users as required by law.
If the UK GDPR or EU GDPR applies to you, you have the right to:
To exercise any of these, email abasefi0207@gmail.com. We will respond within one month. If a request is genuinely complex we may extend by two further months and will tell you why. There is no charge, unless a request is manifestly unfounded or excessive. We may need to confirm you control the account before releasing data — usually by asking you to write from the account's email address.
The operator is based in California. If you are a California resident, the CCPA as amended by the CPRA gives you the following rights.
Categories collected in the last 12 months, in CCPA terms: identifiers (email address, handle, display name, device push token, IP address); personal information under Cal. Civ. Code §1798.80 (name); characteristics of protected classifications, only if you volunteer them (dietary requirements that may reflect religion, accessibility needs that may reflect a disability); internet or network activity (server logs); geolocation at city level (the city and nearest airport you enter — COORDIN8 does not collect precise GPS location); and inferences drawn to rank suggestions. Sources: you, and the calendar providers you choose to connect. Business purposes: providing the service, security, and support.
Authorised agents. You may use an authorised agent to make a request. We will ask for proof of authorisation and may ask you to confirm the request directly.
Other US states. Comprehensive privacy laws in states including Virginia, Colorado, Connecticut, Utah, Texas, Oregon and others give residents broadly similar rights — to access, correct, delete, obtain a copy, and opt out of targeted advertising, sale, and certain profiling. We extend the rights in this section to residents of any US state with such a law, and there is no targeted advertising, sale, or profiling with legal effects to opt out of. Some of those states offer an appeal if we refuse a request; to appeal, reply to our decision and say you are appealing, and we will review it and respond in writing.
You must be at least 13 years old to use COORDIN8. The service is not directed at children, it is not designed or marketed for them, and it contains no child-focused features.
We do not knowingly collect personal information from anyone under 13. If we discover that an account belongs to a child under 13, we will delete it and its data.
Some jurisdictions set a higher minimum age for consent to online services — up to 16 in parts of the EEA. If you are under the applicable age in your country, please do not use COORDIN8 without a parent or guardian's permission.
Parents and guardians: if you believe your child has created an account or has answered a COORDIN8 link, email abasefi0207@gmail.com with enough detail to find the record — the handle, the email address used, or the link. We will delete it and confirm, without requiring you to create an account.
COORDIN8 uses no advertising cookies, no tracking pixels, and no third-party analytics. There is no tracking SDK in the product.
What the app does use:
You can clear all of this at any time by clearing site data for the COORDIN8 domain in your browser settings. Doing so signs you out; it does not delete your account or anything held on the server.
Because we do not do advertising or analytics tracking, there is no consent banner to click through. There is also currently no response to browser "Do Not Track" or Global Privacy Control signals, for the simple reason that there is no tracking to switch off.
Notifications are optional. If you turn them on, your browser or device issues a subscription token, which we store so we can send you things like a friend request, a plan invitation, or a reminder about a plan you are in.
Delivery goes through Web Push using the VAPID standard, and through OneSignal. The delivery service receives the token and the notification content in order to deliver it.
To turn them off:
Revoking permission at the device or browser level stops delivery regardless of any in-app setting.
The iOS app may ask for the following. All are optional, all are refusable, and refusing one only disables the feature it belongs to.
| Permission | Used for | What leaves your device |
|---|---|---|
| Calendar (EventKit) | Reading your device calendar to derive busy times, and writing confirmed plans back if you leave write-back on. | Busy times, and the event details described in Sections 3.2 and 4. |
| Contacts | Picking a name to invite, and checking which of the people you already know are on COORDIN8. | Never the address book itself. Names, numbers and email addresses stay on the device. If you use "See who you already know", irreversible one-way hashes of the email addresses and phone numbers are sent so we can check them against accounts — see Section 23, which explains what that does and does not protect. |
| Camera | Taking a profile picture. | Only the photo you choose to set as your profile picture. |
| Photo library | Choosing an existing profile picture. | Only the photo you choose. |
You can change any of these later in iOS Settings. If you would rather not upload a photo at all, choose the built-in emoji and colour option for your profile instead.
There are none. COORDIN8 is free, nothing in it is for sale, and we do not collect, process or store any payment information about you at all.
COORDIN8 can tell you which of the people in your phone's contacts already have an account. This is optional, it only runs when you open that screen, and nothing happens if you never do.
Your address book is never uploaded. There is no table in our database that could hold one. Names, phone numbers and email addresses do not leave your device.
What is sent is a list of one-way hashes. Your device takes each email address and phone number, standardises it, and runs it through SHA-256 — a calculation that cannot be reversed to recover the original. The server compares those hashes against hashes of the contact details of people who have accounts, and returns only the matches: the same name, username and profile picture a username search would already show you.
Hashing is not encryption, and we would rather say so than let the word do work it cannot. Anyone who already holds a particular email address can hash it and check whether it matches — the range of possible email addresses is small enough that this is cheap to do. So this protects your contacts from being collected in bulk. It does not make an individual hash anonymous.
That limitation is why matching returns only information a username search already returns, never anything about somebody's calendar, plans or friends, and never a row for anyone who has turned discoverability off.
So that your friends can find you the same way, hashes of your own email address — and your phone number, if you add one — are stored against your account. You can remove them by turning off discoverability in Settings, and they are deleted along with everything else when you delete your account (Section 14).
Hashes that do not match an account are used for the comparison and not stored. Somebody in your contacts who has never heard of COORDIN8 does not get a record here as a result of you opening that screen.
This policy will change as the product changes. When it does:
Continuing to use COORDIN8 after a change takes effect means the updated policy applies to you. If you disagree with a change, you can delete your account — see Section 14.
Please email abasefi0207@gmail.com first. Most things can be sorted out directly and quickly.
If that does not resolve it, you also have the right to complain to a regulator:
You do not have to come to us first, though we would prefer the chance to fix it.