Legal

Privacy Policy

Last updated: October 2, 2026

This Privacy Policy describes how [COMPANY LEGAL NAME] (“Etraque”, “we”, “our”, or “us”) handles information when you use the Etraque website and mobile application (together, the “Service”). Etraque helps people create events, collect RSVPs, run groups, and send related notifications.

Registered address: [REGISTERED ADDRESS]. Privacy and support contact: support@etraque.com. [CONFIRM THIS INBOX IS MONITORED, OR REPLACE IT WITH A DEDICATED PRIVACY ADDRESS.]

Information we process

Account. When you create an account we collect:

  • Email address, and a password stored only as a cryptographic hash if you sign up with email.
  • Name, username, and profile photo, if you add them.
  • A public invite handle (a short name used in a personal invite link).
  • Timezone, notification settings, and an Expo push token if you allow notifications.
  • If you sign in with Google or Apple, the email address and name those services send us. We do not receive your Google or Apple password. Sign-in is separate from calendar sync.
  • If you open someone else’s invite link and then sign up, we store that they referred you.

If you turn on Face ID, Touch ID, or a similar unlock, the app stores a sign-in token in your device’s secure storage. We do not receive your fingerprint, face data, or device passcode.

Events, groups, and messages.

  • Event details you enter: title, description, start and end time, timezone, location text, category, capacity, recurrence, visibility, and an optional meeting link (such as Zoom, Google Meet, or Teams).
  • RSVPs (going, maybe, or not going) and messages an organizer sends to attendees.
  • Group name, description, logo, whether the group is public, membership, and roles. Group member lists include each member’s name, username, profile photo, and email address. Only members of that group can open the list.
  • Location text you type or pick from address suggestions. We do not collect GPS or precise device location. We keep a short history of place names you have used, so we can suggest them again.

Voice, text, and clipboard.

  • If you use voice capture, we send the audio recording to our servers and then to OpenAI to turn it into text and suggested event fields. We do not keep the audio after that request finishes. We do store a monthly count of how many AI captures you have used.
  • If you type or paste event text for AI capture, that text is sent the same way. If you turn on the clipboard helper, text already on your clipboard may be sent when it looks like an event.

The app does not read your phone’s contacts. We do not collect phone numbers, and we do not send SMS.

Technical data.

  • Sign-in session tokens. A refresh token lasts 7 days unless you sign out or delete your account.
  • If crash reporting is turned on for that build, Sentry receives crash reports and a sample of performance data. That can include device and app details needed to diagnose a crash. We do not use an advertising SDK.
  • Server logs may include IP address, time, and the request path, so we can operate and secure the Service.

People who are not users

Guests who RSVP in the browser. Anyone with an event link can RSVP without an account.

  • To say they are going, they must enter a name and email address.
  • To say maybe or not going, name and email are optional.
  • We store that RSVP with the event. If they are going, we email a confirmation through Resend. The browser also saves the email in local storage for that event so the page can recognize a later visit.
  • The organizer can see guest names and emails. Other attendees do not see guest email addresses.

People an organizer invites by email.

  • For an event invite, we email the address the organizer types. If that person does not already have an account, we do not save the address as a contact. We only store it if they later RSVP or create an account.
  • For a group invite, we save the invited email address, who invited them, and the invite status, until a group admin deletes the invite. Accepting or declining updates the status and keeps the email on that record.

What other people can see

Event and group links are not listed in our public search index, but anyone who has the link can open it. Messaging apps such as WhatsApp fetch a preview of the link.

Event links. Anyone with an active event link can see the title, date and time, location, description, meeting link, the host’s display name (not their email), and the group name and logo if the event was posted to a group. They can RSVP from the browser. The page does not list attendee names.

The link preview (the card WhatsApp and similar apps show) includes the title, date, and time. For an event that is not marked private, the preview can also include the location, the host’s first name, and a count of how many people are going, unless the organizer hid the attendee list. A private event’s preview omits the location and the going count. Opening the page still shows the location, description, and meeting link.

If the event is limited to group members, people who are not signed-in members do not see the event details. They see that it is members-only, the group name, and a link to the group page if that group is public. The link preview for that case says only that the event is for group members.

Public group links. A public group can have a share page. Anyone with that link can see the group name, description, member count, and the host’s first name. The link preview can also include the title and date of the next event that is not private and not members-only. The public page does not list member names or emails. Joining the group happens in the app. Private groups do not get a public share link.

Personal invite links. A link such as etraque.com/invite/your-handle shows your first name, display name, and profile photo. It does not show your email.

Inside the app.

  • Group members can see the group’s name, events, and the member list, including emails.
  • The organizer of an event can see every RSVP, including names and emails, and can export that list on Pro or Teams. Other people who can see the attendee list see names and profile photos, not email addresses. The organizer can hide the list from everyone except themselves.

How we use information

We use the information above to:

  • Run accounts, events, RSVPs, groups, share links, and notifications.
  • Sync calendars you choose to connect.
  • Suggest event details from voice or text you submit.
  • Suggest place names while you type a location.
  • Show organizers on Pro or Teams how many people are going and how many times a share link was opened, and let them export attendee rows.
  • Send account, invite, RSVP, reminder, and trial messages.
  • Protect the Service, fix crashes, and comply with law.

We do not sell personal information. We do not use your information for third-party advertising.

Google Calendar Data

Etraque’s use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

Connecting Google Calendar is optional and separate from signing in with Google. If you connect it, we request access to events on your primary Google Calendar so we can show them in Etraque and write Etraque events back to that calendar.

What we access: for events in a window from about 7 days ago through about 90 days ahead, we read title, description, location, start and end time, all-day status, and whether Google has cancelled the event. Cancelled Google events are not shown. We write title, description, location, and time for Etraque events you organize or have marked going or maybe, and we remove those copies when they are no longer eligible to sync.

How we store it: we store Google OAuth access and refresh tokens, their expiry, and a map of Etraque event IDs to Google event IDs, in our database (Supabase Postgres), so sync can continue. During a sync, our servers read the Google event details in order to send them to your app. We do not save those imported event details in our database. The app keeps them in memory until you close it, and refreshes them on the next sync. We do not send Google Calendar data to analytics, advertising, or AI services.

Who we share it with: Google, as the calendar provider, and Supabase, which stores the tokens and the ID map under our instructions. We do not sell or rent Google Calendar data.

Disconnecting: in Settings → Connected calendars, Disconnect deletes the tokens, stops sync, and tries to delete the Google Calendar copies Etraque created. If Google rejects a delete, that copy can remain in Google Calendar until you remove it there. Events that already lived in Google Calendar, and that we only read, are not deleted.

Deleting your account: deleting your account does not, in the current version, delete the Google Calendar connection row. Disconnect Google Calendar before you delete your account if you want those tokens removed.

Apple Calendar integration (iOS)

If you connect Apple Calendar on an iPhone, Etraque reads and writes calendars on that device through Apple’s EventKit, after you allow it. This is a device permission, not a Google-style sign-in. We do not receive your Apple ID password or iCloud credentials.

What we use it for.

  • Import. The app reads events on the device, typically from about 7 days ago through about 90 days ahead, except the Etraque calendar we create for exports. Fields can include title, start and end, all-day status, notes, and location. Those events stay on the device. We do not upload a copy of your Apple Calendar into our database.
  • Export. The app creates or updates events in an on-device calendar named Etraque, for events you organize or have marked going or maybe, and removes those copies when they should no longer sync.
  • Sync identifiers. We store a connection record and a map from Etraque event IDs to on-device event IDs, so later syncs update the same Apple event. We do not store your Apple Calendar contents on our servers.

We do not use Apple Calendar data for advertising or sell it.

How long we store it. The connection record and ID map stay until you disconnect. Imported events are held in the app and refreshed on each sync. Events written into the on-device Etraque calendar stay in Apple Calendar until you change or delete them on the iPhone or in Etraque.

How to revoke access. In the app, go to Settings → Connected calendars and tap Disconnect on Apple Calendar. You can also turn off Calendars for Etraque in iPhone Settings. Disconnecting stops future sync. It does not delete events already written on the device. Deleting your Etraque account does not, in the current version, delete the Apple Calendar connection row. Disconnect first if you want that record removed.

Notifications

We send messages about the Service, not a promotional newsletter.

  • Email, through Resend: verify your email, reset your password, a welcome note after you join, event and group invitations, guest RSVP confirmations, and reminders that a trial is ending. Invite and welcome mail is sent from an Etraque address such as hello@etraque.com.
  • Push, through Expo, and matching in-app notices: invites, RSVPs, event reminders, organizer messages, trial reminders, and messages our staff send about the Service. Push is sent only if you have allowed notifications and left push turned on.

You can turn push notifications and event reminders off in the app. The current email templates do not include an unsubscribe link. We do not send SMS. [IF WE ADD PROMOTIONAL EMAIL, DESCRIBE IT AND HOW TO OPT OUT.]

Payments

Paid plans are Pro and Teams. Purchases are made in the Apple App Store or Google Play and processed by Apple or Google. We use RevenueCat to learn whether a subscription is active, renewing, cancelled, or expired. We store your plan, status, which store billed you, and the current period dates. We do not store your card number.

Some older accounts have Stripe customer and subscription IDs stored from web billing we no longer offer in the app. We do not take new card payments on the website. If a Stripe charge continues, email support@etraque.com.

Prices, taxes, and renewals are shown by Apple or Google at purchase. Cancel in the App Store or Google Play subscription settings. Refunds are handled by Apple or Google. [ADD ANY REFUND WE OFFER OURSELVES.]

Service providers

These providers process personal information for us. Their own terms also apply.

  • Supabase — Postgres database. Region: [DATABASE REGION].
  • Our application host — runs the API. Region: [API HOST REGION].
  • Website host — serves etraque.com. Region: [WEBSITE HOST REGION].
  • Resend — sends email.
  • Expo — delivers push notifications.
  • OpenAI — transcribes voice and extracts event fields from text you submit. We do not send Google Calendar data to OpenAI.
  • Google — optional sign-in, optional Calendar sync, and Places address suggestions. The text you type for a location is sent to Google Places.
  • Apple — optional sign-in, App Store purchases, and on-device Calendar access.
  • Google Play — Play Store purchases on Android.
  • RevenueCat — subscription status. It receives your Etraque user ID and store purchase data.
  • Sentry — crash and performance reports, only when a project key is configured for that build.
  • Redis — optional cache. It is not used for analytics.

If file storage is not configured, a profile photo or group logo may be stored directly in the database. When storage is configured, the file is uploaded to [OBJECT STORAGE PROVIDER AND REGION] and we store the URL.

Etraque staff with admin access can view account and event records to operate and support the Service. Those actions can be written to an admin audit log.

Cookies and local storage

The website does not use advertising or analytics cookies. We do not run a cookie banner because we do not set tracking cookies. A guest RSVP page stores the email you typed in the browser’s local storage for that event. You can clear it in your browser settings. [CONFIRM WITH COUNSEL WHETHER ANY HOST-SET COOKIES, SUCH AS A LOAD BALANCER COOKIE, NEED A DISCLOSURE.]

Retention and account deletion

We keep information while we need it to run the Service, unless a shorter period is listed here.

  • Password-reset links expire after 1 hour. Email verification links expire after 48 hours. Refresh tokens expire after 7 days.
  • Voice audio is not stored after the transcription request finishes. The monthly AI-use count stays with the account.
  • Imported Google and Apple calendar events are not stored in our database.
  • Google and Apple connection records stay until you disconnect. See the calendar sections above for account deletion.
  • Guest RSVPs, share links, and link-view counts stay with the event. Deleting the event, or deleting the organizer’s account, removes the events that organizer created, including those RSVPs and links.
  • Recent place names stay with the account. The app shows up to 10 of them.
  • Group invitation emails stay until a group admin deletes the invite.
  • Server logs: [LOG RETENTION PERIOD].
  • An admin audit log entry can remain after an account is deleted, including the email address recorded at deletion. There is no automatic expiry. [AUDIT LOG RETENTION PERIOD.]

You can delete your account in the app under Settings → Delete account, or email support@etraque.com from the account email as described on our account deletion page.

Deleting the account removes the user record and, through database cascade, the following:

  • Password hash, session tokens, password-reset tokens, and email-verification tokens.
  • Events you organize, and with them their RSVPs, guest RSVPs, share links, messages, and link-view counts.
  • RSVPs you made on other people’s events, your notifications, saved place names, monthly usage counts, and subscription status row.

The current deletion step does not remove calendar connection rows, groups you created, your group memberships, group invitation rows, trial-reminder records, or admin audit logs. Groups you created can remain for the other members, without your user record.

App Store or Google Play subscriptions are not cancelled by deleting the account. Cancel them in the store first.

International transfers

We store account and event data in Supabase Postgres in [DATABASE REGION]. The API runs in [API HOST REGION]. The website is served from [WEBSITE HOST REGION]. Providers listed above may process data in other countries, including the United States, where companies such as OpenAI, Resend, Expo, RevenueCat, Sentry, Google, and Apple operate.

[COUNSEL TO COMPLETE: which transfer tools apply for people in the EU, the UK, and other countries we serve, such as standard contractual clauses, and whether we must appoint an EU or UK representative.]

Legal bases

[COUNSEL TO COMPLETE. For people in the EU, the UK, and any other country that requires a legal basis, state the basis for each use in this policy, such as contract, legitimate interests, consent, or legal obligation. Do not leave this placeholder in the published policy.]

Your requests

You can ask us to access, correct, or delete personal information, or to send you a copy, by emailing support@etraque.com from the email on the account. You can correct your name and photo in the app, and you can delete the account under Settings. There is no in-app download of every record we hold. Organizers on Pro or Teams can export attendee rows for their own events. That export is not a full copy of your account.

Depending on where you live, you may also have the right to object to certain uses, to restrict processing, to withdraw consent, and to complain to a privacy regulator. [COUNSEL TO COMPLETE: the rights that apply in each target country, how long we have to respond, and the regulator’s name and contact.]

Security

We use access controls, hashed passwords, and HTTPS in production. No method of transmission or storage is completely secure.

Children

The Service is not directed to children under [MINIMUM AGE]. The app does not ask for a date of birth and does not block sign-up by age. If you believe we have collected information from a child, email support@etraque.com and we will delete it. [MINIMUM AGE MUST BE SET FOR EACH COUNTRY WE SERVE.]

Changes

We may update this Privacy Policy. We will post the new version on this page and change the “Last updated” date. [NOTICE PERIOD AND HOW WE TELL EXISTING USERS — counsel to set.]

Questions about this policy: support@etraque.com. [COMPANY LEGAL NAME], [REGISTERED ADDRESS].