MyOwnEvents

Privacy Policy

Last updated: July 24, 2026

MyOwnEvents, a platform operated by IdeateAI Inc. ("MOE," "we," "us," or "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our event management platform at www.myownevents.com and all related services (the "Platform"). This policy applies to all users, including adults and minors who use the Platform with parental consent.

By creating an account and checking the "I have read and agree" checkbox during registration, you consent to the practices described in this Privacy Policy. If you are a parent or guardian consenting on behalf of a minor, you agree to this policy on their behalf. Please read this policy carefully.

1. Information We Collect

We collect information that you provide directly to us, information collected automatically when you use the Platform, and information from third-party sources.

1.1 Information You Provide

  • Account information: Name, email address, password (stored as a cryptographic hash, never in plain text), profile picture, date of birth (optional, used for age verification and birthday features), phone number (optional), and home address (optional). Your date of birth is treated as especially sensitive: your birthday is visible only to your accepted friends (and only if you allow it), and your birth year is never shown to anyone — friends see only the month and day. The full date of birth is used only by you (for age-restricted features) and, where legally necessary, by our administrators, whose access is logged.
  • Profile information: Occupation, timezone preferences, notification settings (email, SMS, push, audio), theme preferences, privacy settings (field-level visibility controls for email, phone, address, birthday, and occupation), and custom invitation messages.
  • Event information: Event titles, descriptions, dates, times, locations (addresses and coordinates), images (with crop metadata), capacity limits, ticket pricing, recurrence settings, categories, and visibility preferences (private or public).
  • Attendance information: RSVPs, ticket purchases (including tickets bought for other people), check-in records, waitlist registrations, event feedback and survey responses.
  • Bio & event questions: Responses to questionnaires across 24 categories (interests, lifestyle, profession, etc.), with per-question privacy controls you configure.
  • Communications: Event chat messages, one-on-one and group chat messages, AI assistant conversations, support ticket messages, support inquiries, and feedback you submit.
  • Social information: Friend connections, friend request messages, custom friend groups with display ordering, host following relationships, user blocking preferences, and friend availability settings.
  • Organization profile information: If you create or manage an Organization profile, we collect the organization name, description, logo and cover images, public contact and social links, team-member roles and invitations, follower relationships, and the subscription tier of the organization. Organization profiles and their follower counts are publicly visible; team membership is visible to the organization's managers.
  • Tip Jar/Fee Free Payments handles: If you choose to publish them, we store the Venmo and/or PayPal usernames and the Zelle email address or phone number you provide, so we can render your tip buttons and let guests settle a share of a cost split with you directly. Money is sent straight to you through those services; MOE does not process, receive, hold, or take a fee on it, and cannot verify that any such payment was made. We log only anonymous button taps (never amounts) for your own analytics. Your Zelle contact is shown to guests of your events for them to copy, because Zelle has no link format — if that contact is a personal phone number or email, publishing it makes it visible to those guests.
  • Guest and invitee information you provide: When you invite people who do not have a MOE account (off-platform guests), you provide their name and contact details (email and/or phone) so we can deliver the invitation and let them RSVP without creating an account. Off-platform guests can see only the single event they were invited to, and each RSVP link is signed and tied to that one invitation.
  • Acquisition data: How you found the Platform (referral source), referral codes, and UTM campaign parameters captured during registration.

1.2 Information Collected Automatically

  • Usage data: Pages visited, features used, actions taken, timestamps, and interaction patterns.
  • Device information: Browser type, operating system, device type, screen resolution, and IP address.
  • Approximate location: We may use your IP address to work out roughly which city you are in, so we can show you events near you. This applies to visitors as well as signed-in members, it is city-level only, and we do not ask for or use your device's precise location to do it. If you are not signed in, we do not store it.
  • Error data: Crash reports, error logs, stack traces, and performance data collected through our error monitoring service (Sentry) to diagnose and fix technical issues. This may include your user ID and email for error correlation.
  • Consent records: When you register, we record your agreement to our Terms of Service and Privacy Policy, including the document version, timestamp, and browser user agent string.

1.3 Payment Information

When you purchase tickets or receive payouts, payment information (credit card numbers, bank account details) is collected and processed directly by Stripe, Inc., our third-party payment processor. MOE does not store, access, or process your full payment card information. We receive and store only transaction references, payment amounts, the processing and platform fees applied, the general payment-method type used (for example, "card," "bank account," or "buy now, pay later" — never your card number), transaction statuses, and Stripe customer/account identifiers from Stripe.

While payment processing is handled by Stripe, transaction-related data (such as purchase history, event revenue, fee breakdowns, payment-method-type summaries, and payout records) may be stored by MOE and used for Host sales reporting and aggregate platform analytics.

We are not responsible for financial losses resulting from:

  • fraudulent transactions initiated by users
  • chargebacks or disputes between users
  • failures or outages of payment processors

Users are responsible for reviewing transaction details and ensuring the accuracy of payment-related activity.

1.4 Location Information

When you create events or search for locations, address data is sent to HERE Technologies for geocoding and map display. We store event location data (addresses and geographic coordinates) that you provide. We also use location data for event discovery (distance-based filtering using Haversine calculations). We do not collect your real-time GPS location.

1.5 Calendar Information

If you choose to connect external calendars, we access your calendar data as follows:

  • Google Calendar: Connected via Google OAuth 2.0 authorization using the calendar.events, calendar.events.readonly, and userinfo.email scopes (the email scope is used only to identify which Google account you connected). With your consent, MOE reads your Google Calendar events to display busy/free times and power our optimal-scheduling features, and creates, updates, and deletes events on your Google Calendar that correspond to events you schedule, modify, or cancel in MOE. By default, only busy/free status is shown to other users (event titles are hidden); you may optionally enable title display. You can disconnect at any time from your profile settings or by revoking access at myaccount.google.com/permissions. On disconnect, we revoke the token with Google, delete the OAuth credentials we hold, and delete the calendar data we synced from Google (busy/free availability records and calendar event mappings).
  • Apple Calendar (iCloud): Connected via CalDAV protocol using your Apple ID email and an app-specific password. We read your calendar events for availability display. Two-way sync is off by default; you may optionally enable it in Connected Calendars settings, in which case MOE also creates, updates, and deletes events on your Apple Calendar that correspond to events you schedule, modify, or cancel in MOE. Credentials are stored securely. You can disconnect at any time from your profile settings.

Apple Calendar (iCloud) access is read-only by default — MOE does not modify your Apple calendar unless you explicitly turn on two-way sync in Connected Calendars settings. Google Calendar access is two-way: we read your events to display availability and we create, update, and delete events that correspond to your activity in MOE (see the Google bullet above and our Limited Use disclosure in Section 5 for details). Calendar sync covers 1 year past to 6 months future for non-recurring events.

1.6 SMS & Phone Information

If you opt in to SMS alerts, we collect and store your phone number in E.164 international format. Phone number verification is performed via Twilio's Verify service using a 6-digit one-time passcode sent to your phone. We store your verification status, SMS preferences (categories opted in/out), quiet hours settings, and the timestamp of your opt-in consent. SMS is only available to paid subscription users. Your mobile information and SMS opt-in data are never shared or sold for marketing (see Section 5.3.1), and you can opt out anytime by replying STOP. Full details are in our SMS Messaging Policy.

1.7 Email Engagement

For invitation emails we send you, we record whether the message was delivered, whether it was opened, and whether a link in it was clicked. We do this to tell the difference between an invitation that never arrived and one that arrived but went unanswered — and to detect when our email is being filtered as spam, which would otherwise fail silently. Open detection uses a small tracking image, and links in invitation emails are routed through links.invites.myownevents.com before forwarding you to the destination. Many mail apps block or pre-load tracking images, so open figures are an estimate rather than an exact count.

This applies to invitation emails only. Receipts, notifications, password resets and other account email are not tracked and their links are not rewritten. Event hosts see only aggregate counts for their own event (for example “18 of 30 opened”) — a host is never shown whether a specific named guest opened or clicked. Individual engagement records are deleted after 5 years; only aggregate totals are kept beyond that. Engagement data never affects whether you receive email: it cannot re-subscribe you, and it is never used to override an unsubscribe or a suppression.

2. How We Use Your Information

2.1 Information Collected

We use the information we collect for the following purposes:

  • Providing the Platform: Creating and managing your account, facilitating event creation, registration, ticketing, RSVP tracking, QR code check-in, calendar synchronization, friend management, and chat messaging.
  • Communications: Sending transactional emails (event invitations, ticket confirmations, RSVP updates, reminders, refund notifications, birthday wishes), SMS alerts (when opted in), push notifications, and account-related notifications (password resets, email confirmations, security alerts). We use 23 standardized email templates for various communications.
  • AI-powered features: Processing your interactions with the AI event assistant, generating event descriptions, scoring events for recommendations, generating birthday messages, and providing automated support chat. See Section 3 for detailed AI data usage.
  • Content moderation: Automatically analyzing user-generated content (chat messages, images, event descriptions, profile information) to detect and prevent harmful, abusive, sexually explicit, or otherwise inappropriate content and to protect minors.
  • Social features: Enabling friend connections, friend groups, host following, friend availability display (showing when friends are busy or free), and network-based user discovery.
  • Event discovery: Recommending public events based on a 13-signal scoring engine that considers your interests, location, social connections, past engagement, and other factors. Location data is hidden from non-attending users for privacy.
  • Payment processing: Facilitating ticket purchases, host payouts, subscription billing, affiliate commissions, and refund processing through Stripe.
  • Age verification: Verifying that users meet age requirements for specific features and events (for example, paid event hosting requires age 18+, and some public events are limited to 18+ or 21+ guests). This relies on the date of birth you provide; your birth year is not shown to other users.
  • Analytics and improvement: Understanding how users interact with the Platform to improve features, fix bugs, and enhance performance. We may use anonymized and aggregated data for this purpose. This never includes data obtained from connected Google or Apple calendars (see Section 5).
  • AI training: Using anonymized interaction data to improve our AI features and content moderation accuracy. This never includes data obtained from connected Google or Apple calendars, whether raw, aggregated, or derived (see Sections 3.3 and 5). See Section 3 for details.
  • Security and fraud prevention: Detecting and preventing fraudulent activity, abuse, security incidents, and other harmful activities.
  • Legal compliance: Complying with applicable laws, regulations, legal processes, governmental requests, and child protection obligations.

Google user data: Notwithstanding the general purposes listed above, data received from Google APIs (and calendar data received from Apple) is used only to provide and improve the user-facing calendar features you request — displaying your availability, suggesting optimal event times, and synchronizing events between MOE and your calendar — as described in Section 1.5 and the Google API Services User Data — Limited Use disclosure in Section 5. We do not use connected-calendar data for advertising, general analytics, profiling, event recommendations, AI or machine-learning training, or any other purpose.

2.2 Lawful Basis

We rely on different legal bases depending on the type of data processing:

  • Contractual necessity: account creation, event participation, ticket processing, messaging functionality
  • Legitimate interests: fraud prevention, platform security, analytics, product improvement, and moderation
  • Consent: SMS communications, AI assistant interactions, calendar integrations, and optional features
  • Legal obligations: child safety reporting, tax compliance, law enforcement requests

Where processing is based on legitimate interests, we conduct balancing tests to ensure that our interests do not override your fundamental rights. Google user data is processed solely on the basis of your consent and only for the user-facing calendar features described in Sections 1.5 and 5 — never under our legitimate interests in analytics, product improvement, or AI improvement.

2.3 Offline Interactions

The Platform facilitates real-world interactions between users. You acknowledge that:

  • MOE does not verify the identity, background, or conduct of users;
  • interactions at events occur entirely at your own risk;
  • MOE does not supervise or control offline interactions.

You are solely responsible for your conduct and safety when attending or hosting events.

2.4 Communications Monitoring and Use

Communications on the Platform may be stored, analyzed, and used for:

  • safety and moderation purposes
  • dispute resolution
  • enforcement of our Terms
  • compliance with legal obligations

Such data may be reviewed by automated systems and, where necessary, human moderators.

3. AI Features & Training Data

3.1 AI-Powered Features & Data Processing

The Platform uses artificial intelligence for several features. When you interact with AI-powered features, your data is processed by third-party AI providers (currently Anthropic) under their data processing agreements. As of the date of this policy, Anthropic does not use your data to train their general AI models. AI features include:

  • Event creation assistant: Generates event suggestions based on your conversation messages, event details, friend information, and calendar availability. Available to paid tier users. Up to 80 concurrent conversation sessions stored per user.
  • Auto-generated descriptions: Suggests event descriptions based on event titles. Available to all users. Triggered when you enter an event title.
  • Event interest scoring: Analyzes 13 signals (friend attendance, category preferences, location proximity, engagement history, survey ratings, and more) to rank and recommend public events. The core engine is deterministic (no LLM calls); paid tier users may receive enhanced AI-augmented scoring.
  • Birthday messages: Generates personalized birthday wishes and party planning suggestions using AI. Available to all users.
  • Content moderation: Chat messages are analyzed by AI for safety (using Anthropic Claude with up to 10 surrounding messages for context). Images are analyzed by Google Cloud Vision for safety classification.
  • Support chatbot: An AI-powered FAQ chatbot on our support page. May escalate to a human support ticket.

3.2 Data Sent to Third-Party AI Providers

When you use AI features, the following data may be sent to third-party providers:

  • Your conversation messages with the AI assistant
  • Event details (titles, descriptions, dates, locations, categories)
  • Friend names and aggregated availability information
  • Aggregated, anonymized free/busy availability derived from connected calendars (for example, the percentage of invitees free in a time window). Your raw calendar event content — titles, descriptions, attendees, and locations — is never sent to AI providers. This aggregate is transmitted transiently and solely so the provider — acting as our data processor, under terms that prohibit it from using the data to train its models — can generate the specific scheduling suggestion you requested. We do not store this aggregate with the AI conversation or anywhere else, and it is never used for any other purpose (see Section 5).
  • Chat message content (for content moderation, including surrounding context)
  • Uploaded images (for safety analysis via Google Cloud Vision)
  • Event descriptions and profile text (for safety analysis)

This data is transmitted securely and processed by the AI provider solely for the purpose of generating the requested response or moderation decision.

3.3 MOE's Internal AI Training Data Collection

We collect and store data from your interactions with AI features to improve our own AI systems. This data is organized into six categories:

  • Event scoring data: Input context (anonymized user preferences, event details), heuristic scores, AI scores, and your feedback (thumbs up/down ratings).
  • Moderation training data: Flagged content, automated scan results, AI review decisions, human review decisions, and feedback signals.
  • Event description data: Event titles paired with AI-generated descriptions and your final edited text.
  • Assistant conversation data: Conversation histories, tool calls made by the AI, user edits to AI suggestions, and satisfaction ratings.
  • Birthday message data: Friend name input, AI-generated messages or party suggestions, and user edits.
  • Support chatbot data: User questions, FAQ answers provided, escalation decisions, and resolution status.

The content you create within MyOwnEvents — such as event titles, descriptions, chat messages, and your edits to AI suggestions — may be used to train custom AI models operated by MOE. Data obtained from connected third-party calendars (Google or Apple) is never included in this training data, whether in raw or aggregated form (see the Google API Services User Data — Limited Use disclosure in Section 5). Before training data is used, we minimize and, where practicable, pseudonymize the identifiers stored with it; certain account identifiers may be retained where necessary to honor your deletion requests. The data may be exported in JSONL format to fine-tune these models and is retained indefinitely by default unless you request deletion.

3.4 Your Rights Regarding AI Training Data

You have the right to request deletion of your AI training data at any time by contacting us at support@myownevents.com. Upon receiving your request, we will delete training data records associated with your account. Please note that: (a) data already incorporated into trained models cannot be retroactively removed from those models; (b) anonymized and aggregated data that can no longer be linked to you may be retained; and (c) when you delete your account, associated training data records are included in the cascade deletion process.

3.5 AI Transparency and User Responsibility

AI-powered features are designed to assist users but do not replace human judgment. You acknowledge that:

  • AI outputs may be incomplete, biased, or incorrect;
  • AI recommendations are probabilistic and not guaranteed outcomes; and
  • you remain solely responsible for decisions made based on AI-generated outputs.

We do not use AI to make solely automated decisions that produce legal or similarly significant effects without human involvement.

We may update AI systems over time, which may result in changes to outputs or behavior without prior notice.

4. Images & Media

4.1 Image Collection & Storage

We collect and store images you upload to the Platform in the following categories:

  • Event images: Stored in our cloud storage. We store the image along with crop metadata (dimensions and crop coordinates). Event images are retained until the event is deleted or you remove them.
  • Profile photos: Your avatar image, cropped to a 1:1 aspect ratio. Retained until you change your photo or delete your account.
  • Chat media: Images shared in chat are compressed to WebP format (maximum 2 MB, 1920px max dimension). EXIF metadata (including GPS coordinates) is stripped before storage to protect your privacy. Chat images are subject to a 7-day automatic deletion period unless explicitly saved (bookmarked) by a recipient. Saved images are retained until unsaved or the conversation is deleted.

Media storage is subject to your subscription tier's quota (Free: 100 MB, Pro: 500 MB, Organization: 2 GB, Enterprise: 5 GB). Images exceeding your quota cannot be uploaded until storage is freed.

4.2 Image Safety Scanning

All uploaded images (event images, profile photos, and chat media) may be automatically scanned for content safety using Google Cloud Vision's SafeSearch API. This analysis detects potentially unsafe content including adult, violent, medical, and otherwise inappropriate imagery. Images flagged by the automated system may be reviewed by AI (Anthropic Claude) for additional context, and significant cases may be reviewed by human moderators. Images found to violate our content policies will be removed.

4.3 AI-Generated Content & Images

The Platform may generate text-based content using AI (event descriptions, birthday messages, party suggestions). Regarding AI-generated content:

  • AI-generated content may be inaccurate, inappropriate, or unsuitable. You are responsible for reviewing all AI-generated content before publishing.
  • AI-generated content may not be eligible for copyright protection under current U.S. law.
  • While we employ safety measures, AI-generated outputs may occasionally contain inappropriate or offensive material. We provide indicators (such as a sparkle badge) to identify AI-generated content, which disappear when you edit the content.
  • MOE may use AI-generated outputs and your edits to them as training data to improve future AI quality, as described in Section 3.3.

4.4 Images of Minors

If images uploaded to the Platform depict identifiable minors (under 18), the uploader must have obtained consent from the minor's parent or legal guardian. Images of minors must not contain any sexually suggestive, exploitative, or otherwise inappropriate content. MOE has zero tolerance for child sexual abuse material (CSAM). Any CSAM will be immediately removed, the uploading account permanently terminated, and the content reported to the National Center for Missing & Exploited Children (NCMEC) and applicable law enforcement authorities.

4.5 Image Deletion

You may delete your uploaded images at any time. Chat images are automatically deleted after 7 days if not saved. When you delete your account, all associated images (profile photos, event images, and chat media) are permanently deleted as part of the cascade deletion process. Images that have been reported for moderation review may be retained for the duration of the review process and any subsequent legal proceedings.

5. Third-Party Services & Data Sharing

5.1 List of Third Party Services

We share information with the following third-party service providers who process data on our behalf or as necessary to provide our services. Each provider is bound by their own privacy policies and data processing agreements:

Supabase (Database & Authentication)

Our database and authentication provider. Stores user accounts, event data, and all platform data in PostgreSQL databases with row-level security. Handles password hashing, session management, and authentication emails. Data is hosted in secure cloud infrastructure (US region).

Stripe, Inc. (Payments)

Payment processing for ticket purchases, subscription billing, host payouts via Stripe Connect, and affiliate payouts. Stripe is PCI DSS Level 1 certified. We share transaction details (amounts, user identifiers) with Stripe. Stripe's privacy policy: stripe.com/privacy

Venmo, PayPal & Zelle (Tip Jar/Fee Free Payments)

If a Host publishes these handles, MOE renders buttons that deep-link to the Host's own Venmo or PayPal account, and displays their Zelle contact for you to copy — Zelle publishes no link format, so there is nothing to open. Money is sent directly between you and the Host through those services, whether it is a tip or a share of a cost split; MOE does not process, receive, hold, or take a fee on it, cannot verify that it was sent or received, and does not share your data with Venmo, PayPal or Zelle beyond opening their app or page. We log only an anonymous tap event (never an amount) for the Host's analytics. Your use of Venmo, PayPal or Zelle is governed by their own privacy policies.

HERE Technologies (Location Services)

Address autocomplete, geocoding, map display, and travel time calculations. When you search for or enter an event location, the address query is sent to HERE's API. HERE's privacy policy: legal.here.com/privacy

Google (Calendar API & Cloud Vision)

Optional two-way calendar synchronization via Google OAuth 2.0 using the calendar.events and calendar.events.readonly scopes. We read your existing Google Calendar events to display availability and power optimal-scheduling features, and we create, update, and delete events on your Google Calendar that mirror events you schedule, modify, or cancel in MOE. Image content moderation via Google Cloud Vision SafeSearch API. See the Google API Services User Data — Limited Use disclosure immediately below. Google's privacy policy: policies.google.com/privacy

Google API Services User Data — Limited Use Disclosure

MyOwnEvents' use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:

  • We use Google Calendar data only to provide and improve user-facing features of MyOwnEvents that are visible and prominent in the app's UI — namely, displaying your availability, suggesting optimal event times, and synchronizing events you create or modify in MOE with your Google Calendar.
  • We do not transfer Google user data to third parties except as necessary to provide or improve these user-facing features, to comply with applicable law, or as part of a merger, acquisition, or sale of assets with notice to users.
  • We do not use Google user data to serve advertisements, including retargeting, personalized, or interest-based advertising.
  • We do not allow humans to read Google user data unless (a) we have your affirmative consent for specific messages, (b) it is necessary for security purposes such as investigating abuse, (c) it is necessary to comply with applicable law, or (d) the data has been aggregated and anonymized for internal operations.
  • We do not retain or use Google user data — including any data aggregated, anonymized, or derived from it — to develop, improve, or train any artificial intelligence or machine-learning models, including non-personalized, generalized, or foundational models. We never send your raw Google Calendar event content — event titles, descriptions, attendees, or locations — to our AI providers (such as Anthropic) or any other third-party AI system. Our optimal-scheduling assistant uses aggregated, anonymized free/busy availability derived from connected calendars (for example, the percentage of invitees free in a given time window) solely to power that user-facing scheduling feature; that aggregate contains no event content and is never retained or used to develop, improve, or train any AI or machine-learning model.
  • You may revoke MyOwnEvents' access to your Google Calendar at any time from your MOE profile settings or from myaccount.google.com/permissions. Upon revocation or disconnect, we revoke the token with Google, delete the OAuth credentials we hold, and delete the calendar data we synced from Google — busy/free availability records and calendar event mappings. Events you created in MyOwnEvents itself remain in your MOE account (they originate in MOE, not from Google APIs), and you may delete them at any time via your account settings.

This Limited Use disclosure controls. If any other statement in this Privacy Policy could be read to permit a broader use of Google user data, this section governs, and the broader use does not apply to Google user data. In particular, the general analytics, profiling, AI-training, product-improvement, and data-retention practices described elsewhere in this policy never apply to data received from Google APIs.

Apple (CalDAV Calendar Sync)

Optional iCloud calendar synchronization via CalDAV protocol. Requires your Apple ID email and an app-specific password (not your main Apple password). We access your calendar events in read-only mode by default; you may optionally enable two-way sync in Connected Calendars settings to mirror your MOE events to your Apple Calendar.

Anthropic (AI Features & Moderation)

AI-powered features including the event assistant (Claude Sonnet), auto-generated descriptions (Claude Haiku), birthday messages, event scoring, content moderation, and support chatbot. Conversation messages, event context, and chat content may be sent to Anthropic for processing. Anthropic does not use your data to train their general models. Anthropic's privacy policy: anthropic.com/privacy

Resend (Email Delivery)

Transactional email delivery for event invitations, ticket confirmations, reminders, refund notifications, birthday wishes, support responses, and other communications. We share your email address and name with Resend for delivery. Resend's privacy policy: resend.com/legal/privacy-policy

Twilio (SMS & Phone Verification)

SMS delivery for event reminders (paid tier only) and phone number verification via Twilio Verify (6-digit OTP). We share your phone number with Twilio for delivery and verification. Twilio's privacy policy: twilio.com/legal/privacy

Sentry (Error Monitoring)

Error monitoring and crash reporting. Sentry collects error logs, stack traces, browser information, and limited user context (user ID, email) to help us identify and fix technical issues. Sentry's privacy policy: sentry.io/privacy

5.2 User Data Misuse

We are not responsible for how other users collect, use, or share your information. If you share personal information with other users (including through events, messaging, or profiles), you do so at your own risk.

Shared event links. When you or another user shares a link to an event, the messaging or social app that receives it may display a preview that includes the event's cover image. For public events the preview may also include the event name and description; for private events the preview shows only the cover image (no name, date, or location). Anyone who receives a shared link may see this preview, so share event links only with people you intend to invite.

5.3 No Sale of Personal Information

We do not sell, rent, or trade your personal information to third parties for their marketing purposes. We do not share your personal information with advertisers. We do not engage in "sharing" of personal information for cross-context behavioral advertising as defined under the California Privacy Rights Act (CPRA).

5.3.1 Mobile Information & SMS Opt-In Data

Mobile information — your phone number and your SMS opt-in and consent records — is never shared with or sold to third parties or affiliates for marketing or promotional purposes, and is never transferred to third-party marketers or lead generators. We share your phone number only with our messaging service provider (Twilio) for the sole purpose of delivering the messages you have requested and verifying your number, and only under confidentiality obligations. Your SMS opt-in consent is kept private and is used solely to send you the categories of messages you enabled. You may opt out at any time by replying STOP to any message or by turning off SMS in your notification settings. See our SMS Messaging Policy for full details.

5.4 Legal Disclosures

We may disclose your information if required by law, court order, subpoena, or governmental request; if we believe disclosure is necessary to protect our rights, your safety, or the safety of others; to enforce our Terms of Service; to investigate fraud or security incidents; or to protect the rights, property, or safety of MOE, our users, or the public, particularly when a risk of harm to minors is involved.

6. Cookies & Local Storage

We use browser local storage and session storage (not traditional advertising cookies) for the following essential purposes:

  • Authentication: Storing secure JWT session tokens (1-hour expiry with automatic rotation) to keep you logged in across page loads.
  • User preferences: Saving your theme preference (light/dark/auto mode), timezone settings, calendar view preferences, and display preferences.
  • Application state: Caching event data, profile data, store state (via Zustand persist), and navigation state to improve performance.
  • Push notification subscriptions: Storing Web Push subscription endpoints for browser notification delivery.

Analytics. On our public marketing pages only — our home page, features pages, and legal pages — we use Google Analytics to understand how people find and use MyOwnEvents. It sets cookies to count visits and recognize returning visitors. These analytics cookies are off until you accept them: you are asked on your first visit, and declining is remembered.

Analytics does not run on any signed-in page, on the sign-in or registration screens, or on shared event links. That means your events, your guests, your friends, and anything from a connected Google or Apple calendar are never sent to Google Analytics — not their names and not their contents. We only ever send the address of the public marketing page being viewed, with any referral or campaign codes removed. If you open a shared event link and then continue to one of our marketing pages, Google may see that public link as the page you came from; it contains no names or personal details.

We do not use advertising cookies or tracking pixels, and we do not track you across third-party websites. Our error monitoring service (Sentry) may set a minimal session identifier for error correlation purposes only.

7. Data Retention & Deletion

  • Active accounts: Your personal data is retained for as long as your account remains active.
  • Deleted content: When you delete events or other content, the data is soft-deleted (marked as deleted) and may be retained for up to 90 days before permanent removal for backup and recovery purposes.
  • Chat images: Unsaved chat images are automatically deleted after 7 days. A daily cleanup process runs at 3 AM UTC.
  • Email engagement records: Individual delivery, open and click records for invitation emails are automatically deleted after 5 years. Aggregate counts derived from them (for example, how many invitees opened a given event's invitation) are retained beyond that point. See Section 1.7.
  • Connected calendar data: Calendar data synced from Google or Apple (busy/free availability records and calendar event mappings) is deleted when you disconnect that calendar; stored credentials are deleted and Google OAuth tokens are revoked with Google (see Sections 1.5 and 5).
  • Account deletion: When you delete your account, your personal data is permanently removed through a cascade deletion process. This includes your profile, events, friend connections, chat messages, media files, push subscriptions, AI conversation history, and associated training data records.
  • AI training data: Training data, with identifiers minimized and pseudonymized where practicable, is retained indefinitely for model improvement unless you request deletion. Data already incorporated into trained models cannot be retroactively extracted.
  • Historical event data: Anonymized or aggregated event data (attendance counts, event statistics) may be retained for analytical purposes even after account deletion. This never includes data synced from connected Google or Apple calendars.
  • Financial records: Transaction records, payment histories, and affiliate commission records may be retained as required by applicable tax and financial regulations (typically 7 years per IRS requirements).
  • Email logs: Transactional email records are retained by our email provider (Resend) per their retention policies, typically for 30 days.
  • Moderation records: Content moderation decisions, admin audit logs, and content reports may be retained for platform safety and legal compliance purposes.
  • Legal obligations: We may retain certain data for longer periods as required by applicable law, court orders, or to resolve disputes.

8. Children's Privacy & COPPA

8.1 Our Commitment to Children's Privacy

MOE takes the privacy of children seriously. We comply with the Children's Online Privacy Protection Act ("COPPA", 15 U.S.C. §§ 6501–6506) and its implementing regulations (16 C.F.R. Part 312).

8.2 Children Under 13

Children under the age of 13 may not create an account or use the Platform without verifiable parental consent. If a parent or legal guardian creates an account for a child under 13 and provides verifiable consent, the following applies:

  • We collect only the minimum information necessary to provide the Platform services.
  • The parent or guardian may review, modify, or request deletion of the child's personal information at any time by contacting us at support@myownevents.com.
  • The parent or guardian may revoke consent and request deletion of the child's account and all associated data at any time.
  • We will not condition the child's participation on disclosing more information than is reasonably necessary.
  • The child's information will not be shared with third parties except as necessary to provide the Platform services (as described in Section 5) and as required by law.
  • AI training data will not be collected from children under 13 unless the parent has provided explicit consent for such use.

8.3 Dependent Attendees

MOE allows parents and legal guardians to register their children under 13 as “dependents” who attend events with them. Dependents do not have their own MOE account. The information we collect about dependents is limited to the minimum needed to facilitate event attendance:

  • First name and last name (so you and any tagged co-guardian can identify them).
  • Date of birth (optional — we use it only to remind you ~30 days before your child turns 13 so they can create their own account).
  • Whether the dependent is attending each event (so the host can plan capacity) and which guardian / co-guardian added them.

Visibility scope (load-bearing): A dependent’s name is visible to the guardian who created the dependent record, to any co-guardian that guardian has tagged, and to the host and co-hosts of an event the guardian brings that dependent to. A dependent’s age and date of birth are visible ONLY to the guardian and their tagged co-guardians — never to hosts, co-hosts, or any other attendee. Other attendees of an event see only the NUMBER of dependents accompanying a given guest (e.g., “+2”) and never a name. Dependent names are also shown on the bouncer / check-in screen at the moment a guardian presents their QR pass, and only for the event being scanned. MOE never displays dependent details to the public.

To add a dependent, the parent must affirmatively confirm at creation time that the child is under 13 and that they are the child's parent or legal guardian. We retain the timestamp of this attestation as part of our COPPA-compliance records. When the child turns 13, we contact the parent and the dependent record can no longer be used for new events — the family converts the record into a friend account or removes it. Past event records remain intact for the host's historical reference.

8.4 Users Ages 13 to 17

Users between 13 and 17 may use the Platform with parental or guardian consent. While COPPA's specific requirements apply to children under 13, we take additional care with data from all minors. Minor users (13–17) cannot create paid events, connect Stripe accounts, or participate in the affiliate program. The data we collect from minors is used solely to provide Platform services and is subject to the same security measures as adult user data.

8.5 Discovery & Notification

If we discover that we have collected personal information from a child under 13 without verifiable parental consent, we will promptly: (a) cease using the information; (b) attempt to notify the parent or guardian; and (c) delete the child's information and account within a reasonable time. If you believe we have inadvertently collected information from a child without appropriate consent, please contact us immediately at support@myownevents.com.

8.6 Child Safety

MOE maintains zero tolerance for child sexual abuse material (CSAM) and any content that exploits or endangers children. We employ automated content moderation systems to detect such material. Any CSAM or exploitative content involving minors is immediately removed, the associated account is permanently terminated, and the content is reported to the National Center for Missing & Exploited Children (NCMEC) and applicable law enforcement authorities.

9. Your Rights (GDPR)

If you are located in the European Economic Area (EEA), the United Kingdom, or Switzerland, you have the following rights under the General Data Protection Regulation (GDPR):

  • Right of access: Request a copy of the personal data we hold about you.
  • Right to rectification: Request correction of inaccurate or incomplete personal data. You can update most information directly in your profile settings.
  • Right to erasure: Request deletion of your personal data. You can delete your account at any time through profile settings.
  • Right to data portability: Request your personal data in a structured, commonly used, machine-readable format.
  • Right to restrict processing: Request that we limit the processing of your personal data under certain circumstances.
  • Right to object: Object to the processing of your personal data for certain purposes, including AI training and profiling for event recommendations.
  • Right to withdraw consent: Withdraw your consent at any time without affecting the lawfulness of processing based on consent before its withdrawal.
  • Right regarding automated decisions: You have the right not to be subject to a decision based solely on automated processing that produces legal effects or similarly significant effects. Our content moderation includes human review for significant decisions such as account suspension.

Lawful basis for processing: We process your personal data on the following legal bases: (a) performance of our contract with you; (b) your consent (optional features like calendar sync, AI features, and SMS); (c) our legitimate interests (platform security, analytics, fraud prevention, AI improvement); and (d) compliance with legal obligations (child protection, financial reporting). Google user data is processed solely under basis (b), your consent, and only for the user-facing calendar features described in Sections 1.5 and 5 — it is never processed under our legitimate interests in analytics or AI improvement.

To exercise any of these rights, contact us at support@myownevents.com. We will respond within 30 days.

10. Automated Processing & Profiling

10.1 How We Use It

The Platform uses automated processing and profiling in the following ways:

  • Event recommendations: A 13-signal scoring engine analyzes your interests, location, social connections, and engagement history to rank public events. This profiling helps personalize your event discovery experience.
  • Content moderation: Automated AI systems scan user-generated content for policy violations. Content flagged by automated systems may be temporarily removed pending human review. Significant account actions (suspension or termination) always include human review.
  • Friend engagement scoring: We calculate engagement scores based on invitation history, attendance patterns, and interaction frequency (180-day lookback) to help prioritize friend suggestions and availability display.

You may contest automated moderation decisions by contacting us at support@myownevents.com. Under GDPR, you have the right to request human intervention in automated decisions that significantly affect you.

10.2 Profiling Disclosure

We may build behavioral profiles based on your activity, including:

  • event attendance patterns
  • response to invitations
  • social interactions and friend networks
  • pricing sensitivity and engagement behavior
  • geographic and temporal participation trends

These profiles are used to improve recommendations, optimize event discovery, and enhance platform efficiency. Profiles are built only from your activity within MyOwnEvents itself; data from connected Google or Apple calendars is never used for profiling or event recommendations (see Section 5).

Profiling does not result in decisions that have legal or similarly significant effects without human oversight.

11. California Privacy Rights (CCPA/CPRA)

If you are a California resident, you have the following rights under the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA):

  • Right to know: Request information about the categories and specific pieces of personal information we have collected, the sources, our purposes for collecting it, and the categories of third parties with whom we share it.
  • Right to delete: Request deletion of your personal information, subject to certain exceptions (such as legal obligations and fraud prevention).
  • Right to correct: Request correction of inaccurate personal information we maintain about you.
  • Right to opt-out of sale/sharing: We do not sell your personal information. We do not "share" your personal information for cross-context behavioral advertising as defined under CPRA.
  • Right to limit use of sensitive personal information: We use sensitive personal information (precise geolocation, date of birth) only as reasonably necessary to provide the Platform services (location-based event discovery, age verification).
  • Right to non-discrimination: We will not discriminate against you for exercising any of your CCPA/CPRA rights.

11.1 Categories of Information Collected

In the preceding 12 months, we have collected the following categories of personal information as defined by the CCPA: identifiers (name, email, phone, IP address); personal information under Cal. Civ. Code § 1798.80 (name, address, phone, financial information via Stripe); characteristics of protected classifications (date of birth, age); commercial information (purchase history, ticket transactions); internet/electronic activity (usage data, device information); geolocation data (event locations, address coordinates); audio/visual information (profile photos, event images, chat media); and inferences (event interest scores, engagement profiles).

11.2 Do Not Track

Our Platform does not respond to "Do Not Track" or Global Privacy Control (GPC) browser signals, as we do not track users across third-party websites for advertising purposes. However, we respect your communication preferences as configured in your profile settings.

To exercise your California privacy rights, contact us at support@myownevents.com. We will verify your identity before processing your request. You may also designate an authorized agent to make requests on your behalf.

12. Additional U.S. State Privacy Rights

Residents of certain U.S. states have additional privacy rights under state laws, including but not limited to the Virginia Consumer Data Protection Act (VCDPA), Colorado Privacy Act (CPA), Connecticut Data Privacy Act (CTDPA), Utah Consumer Privacy Act (UCPA), and similar state laws. If you are a resident of one of these states, you may have rights similar to those described in Sections 9 and 11, including rights to access, correct, delete, and opt out of certain processing. To exercise these rights, contact us at support@myownevents.com.

13. Security Measures

We implement industry-standard security measures to protect your personal data, including:

  • Encryption in transit: All data transmitted between your browser and our servers is encrypted using TLS 1.2 or higher (HTTPS).
  • Encryption at rest: Database data is encrypted at rest using AES-256 encryption provided by our infrastructure provider.
  • Password security: Passwords are hashed using bcrypt and are never stored in plain text.
  • Authentication: Secure JWT-based authentication with 1-hour token expiry, automatic rotation, and refresh token management.
  • Row-level security: Database access controls enforce that users can only access data they are authorized to view, enforced at the PostgreSQL database level.
  • Payment security: Payment data is handled exclusively by Stripe (PCI DSS Level 1 certified). MOE never stores full card numbers.
  • Image privacy: EXIF metadata (including GPS coordinates) is stripped from chat images before storage to protect your location privacy.
  • Admin audit trail: All administrative actions (moderation decisions, account suspensions, content removals) are logged to an immutable, append-only audit log.
  • Phone verification: Phone numbers are verified via Twilio's Verify service before SMS features are enabled.

While we strive to protect your personal data, no method of transmission over the Internet or electronic storage is 100% secure. In the event of a data breach that affects your personal information, we will notify you and the relevant authorities as required by applicable law (including state breach notification laws).

14. International Data Transfers

The Platform is operated from the United States. If you access the Platform from outside the United States, your information may be transferred to, stored, and processed in the United States and other countries where our service providers operate. By using the Platform, you consent to such transfers. We take appropriate safeguards to ensure your data receives an adequate level of protection regardless of where it is processed, including standard contractual clauses where applicable.

You acknowledge that data protection laws in the United States and other jurisdictions may differ from those in your country of residence and may provide a lower level of protection.

By using the Platform, you expressly consent to such transfers and associated risks.

15. Changes to This Policy

We may update this Privacy Policy from time to time. When we make material changes, we will: (a) update the "Last updated" date at the top of this policy; (b) post the updated policy on the Platform; and (c) where appropriate, notify you by email or through a prominent in-app notification. For material changes affecting the collection or use of children's information, AI training data practices, or data sharing with third parties, we will provide at least thirty (30) days' advance notice and, where required by COPPA, obtain renewed parental consent. We encourage you to review this Privacy Policy periodically.

16. Contact Information

If you have any questions, concerns, or requests regarding this Privacy Policy, our data practices, or your privacy rights, please contact us at:

MyOwnEvents — Privacy Inquiries

Email: support@myownevents.com

Website: www.myownevents.com

For COPPA-related requests (parental consent, data review, data deletion for children under 13), please email support@myownevents.com with the subject line "COPPA Request."

For California privacy rights requests (CCPA/CPRA), please email with the subject line "California Privacy Request."

If you are located in the EEA and believe we have not adequately addressed your data protection concerns, you have the right to lodge a complaint with your local data protection supervisory authority.

17. Business Transfers

In the event of a merger, acquisition, restructuring, or sale of assets, your information may be transferred as part of that transaction.

We will ensure that any such transfer is subject to appropriate confidentiality and data protection safeguards.