Withly
Explore Blog Log in Get Started

Legal

Privacy Policy

Last updated: August 23, 2026

This Privacy Policy explains how Withly ("Withly", "we", "us") collects, uses and protects your personal information when you use the Withly website, apps and services (the "Service"). We aim to collect only what we need to help you plan events with friends.

1. Information we collect

Information you give us

  • Account details: your name, email address, and password (stored only as a secure hash).
  • Profile details: anything you choose to add, such as a display name, avatar, or bio.
  • Content you create: events you organise, invitations and RSVPs, chat messages, groups, photos, and shared-cost details.
  • Contacts and connections: friends you add and people you invite. If you import or search contacts to find friends, we use that information only to help you connect.
  • Guest RSVPs: if you respond to an event through a shared invite link without creating an account, we store the display name you enter and your response, so the host can see who is coming. You can create an account afterwards to manage your RSVP.
  • Images you upload: event cover images and profile pictures. When you upload one, your browser sends the file directly to our image storage provider (see "How your information is shared" below), and we then convert it to a new file in a web format. That conversion deliberately discards the metadata cameras and phones embed in photos — including any GPS coordinates, capture time and device details — so the version we store and serve carries none of it. We keep only the converted versions; your original file is deleted once conversion succeeds, and within 24 hours if it never does. Cover images are shown to anyone who can see the event, including anyone with its invite link and, for a published event, anyone at all.

Information we collect automatically

  • Usage and device data: basic technical information such as your IP address, browser or device type, and how you interact with the Service, used to keep it working, secure and reliable.
  • Sign-in security data: when you sign in, we derive a coarse summary of your browser or device type and your approximate (city-level) location from your IP address, so we can recognise the devices and places you usually sign in from and email you if your account is signed in to from a new one. That location is worked out on our own servers, using an offline copy of a public geolocation database (GeoLite2, created by MaxMind and available from maxmind.com): your IP address is not sent to anyone else to do it. We store only this coarse summary (for example "Chrome on macOS, Amsterdam, Netherlands") together with a hashed fingerprint of it and when it was first and last seen; we do not store your IP address for this purpose. The alert email itself shows you the time, the device summary, the approximate location, and the IP address the sign-in came from, so you can judge whether it was you — which means a copy of that IP address reaches your mailbox, and our email delivery provider, and stays there for as long as you keep the message. If we cannot work out the approximate location we leave it out of the email rather than guess at it. We keep at most the 10 most recently used sign-in contexts per account, and they are deleted when your account is deleted. Because these alerts protect access to your account, they are sent regardless of your email notification preferences.
  • Usage analytics (first-party, cookieless): we count a small, fixed set of product events on our own servers, for example that an invite link was opened, an account was created, an event was created, an invite link was shared, an RSVP was submitted, a friend was added, or that a chat message was sent (a count only, never its content). Each counted event stores only the event name, the day it happened, at most a coarse label such as the page name or how an account was created, which of our apps it came from (web, Android or iOS), and a daily-rotating anonymous code. We record which app so we can tell how the mobile apps are doing next to the website; it is one word, and we do not record your device model, operating system version, or app build alongside it. The anonymous code lets us see how many different people used a feature on a given day, but it cannot be linked back to your account or connected across days. We use no analytics cookies, no fingerprinting, no session recording, no cross-site tracking, and no third-party analytics providers, and these aggregate events are deleted after at most 13 months.
  • Push notification tokens: if you allow the Withly app to send you notifications, your device is issued an anonymous delivery token by Google's Firebase Cloud Messaging (see "How your information is shared" below), and the app sends that token to us so we know where to deliver your notifications. We store the token together with which platform the device is (Android, iOS or web) and the language it is set to, so that notifications arrive in the right language. We do not store your device model, its operating system version, or any advertising identifier. A token identifies an installation of the app, not you: it changes when you reinstall, and it stops working when you uninstall.
  • Cookies and similar technologies: see "Cookies and sessions" below.

Information we generate

  • Safety and enforcement records: if we act on an account — for example suspending or restricting it for a breach of our Terms of Service — we keep a record of that action, including the reason, who took it, when, and any expiry. Actions our administrators take on the Service are also written to an internal audit log so we can keep the platform safe and accountable. These records may reference your account and are kept as described in "How long we keep your information" below.
  • Reports you make: when you report something, we record what you reported, the reason you picked, anything you wrote, and — unless you reported it without being signed in — that it was you. The person you reported is never told who reported them. We keep this record after the reported content is gone, because a report that disappears with the message it describes cannot show a pattern.
  • People you block: we record who you have blocked and when, so we can keep enforcing it. This is private to you: the person you blocked is never told, and nothing we show them reveals it.
  • Reading a reported message: if someone reports a chat message, a member of our team can read that message together with up to five messages either side of it in the same conversation, so that it can be judged in context — a single line often cannot be. We read nothing else in that conversation, and reporting one message does not open the rest of it. Every such read is written to our internal audit log with who read it, when, and whose messages were shown, so it can be accounted for afterwards. This is the only circumstance in which our team reads the content of your chat messages.
  • Image review decisions: when a member of our team reviews an uploaded image (see "Reviewing uploaded images" below), we record the outcome — whether it was kept or removed, which clause of the image policy it breached, who decided, and when — together with anything you write if you contest the decision. This record references your account and is kept after the image itself has been deleted.

2. How we use your information

  • To provide the Service: create and manage events, send invitations, track RSVPs, power chat and notifications, organise groups, and coordinate shared costs.
  • To send transactional messages such as invitations, reminders, RSVP updates, and account or security emails.
  • To send push notifications to your devices when something happens that involves you — someone invites you to an event, replies to an invitation, adds you to a group, or sends you a friend request. You can turn these off entirely in your settings, and turning them off stops us sending them; the same information still reaches you in the app.
  • To show public events on Explore when an organiser chooses to publish one (and it is approved).
  • To keep the Service secure and enforce our Terms: detect, prevent and respond to fraud, abuse, and technical issues, including suspending or restricting accounts that breach our Terms and keeping administrative records of those actions.
  • To review images you upload against our image policy, as described below.
  • To improve and develop features, and to comply with our legal obligations.

Reviewing uploaded images

Event cover images and profile pictures are shown to other people, and a cover on a published event can be seen by anyone. So that they do not contain things nobody should be shown, members of our team look at uploaded images and check them against the image policy in section 5 of our Terms of Service. This means a person at Withly may see a photo you uploaded, including one on a private event.

Two things this review is not. It does not happen before your image appears — images go live as soon as they finish processing, and we look afterwards. And it is not automated: no software classifies your images, and no decision about them is made without a person looking. Only administrators can carry out this review, and each decision they make is recorded (see "Image review decisions" above).

If we remove an image, we tell you in the app and by email, and say which clause of the policy it breached. You can contest the decision; if you do, a second person reviews it and we tell you the outcome. Our legal basis for this review is our legitimate interest in keeping the Service safe for the people who use it, and in meeting our own legal obligations as a platform.

3. How your information is shared

We do not sell your personal information. We share it only in these situations:

  • With other users, as you direct. When you invite people, RSVP, chat, join a group, or organise an event, the relevant details are visible to the others involved. For example, an invitee can see your name and your RSVP.
  • Via a shareable invite link. Every event has a single unguessable link that acts as the invitation: anyone who has the link can view the event and RSVP, for both public and private events. Private-event links are not indexed by search engines. People with the link can see the event details and who is going, shown by display name and avatar. As the organiser you can reset the link at any time to revoke access to previously shared copies.
  • Publicly, when you publish an event. Publishing an event makes its page (its title, description, cover image, category and host) viewable by anyone who has the link, straight away. We review public events before listing them: once approved, the event also appears on Explore and can be found by search engines. Until then its page is not listed and asks search engines not to index it. If we decline an event, its public page stops being viewable.
  • With service providers who help us operate the Service (such as hosting and email delivery), under obligations to protect your data.
  • With our push notification provider. Push notifications to Android, iOS and web devices are delivered by Google (Firebase Cloud Messaging), which acts as our processor under obligations to protect your data and to process it only on our instructions. Notifications to Apple devices are relayed by Firebase through Apple's own push service. This means the text of a notification passes through Google's servers, so it is worth being exact about what that text contains: the display name of the person whose action prompted it, and the title of the event, group or plan it concerns — both of which are already visible to you inside the app. It never contains the content of a chat message, an email address, a location, or who else is invited. Alongside the text we send the delivery token for your device and a small set of identifiers (the kind of notification and the id of the event, group or plan) so that tapping it opens the right screen. If you turn push notifications off, nothing about you is sent to Google at all.
  • With our image storage and delivery provider. Images you upload are stored and served by Cloudflare, Inc. (Cloudflare R2), which acts as our processor under obligations to protect your data and to process it only on our instructions. Uploads go from your browser straight to that storage, so the file itself does not pass through our own servers. We store the images in Cloudflare's European Union region.
  • For legal reasons: to comply with the law, enforce our Terms of Service, or protect the rights, safety and security of Withly, our users, or the public.
  • In a business transfer: if Withly is involved in a merger, acquisition, or sale of assets, with notice to you where required.

4. Cookies and sessions

We use a small number of strictly necessary cookies to keep you signed in and to operate the Service securely, such as a session cookie and an httpOnly refresh-token cookie used for authentication. These are essential to the Service and are not used for advertising. Our usage analytics (described in "Information we collect automatically" above) are cookieless: we set no analytics or advertising cookies at all.

The app also stores small, purely functional values in your browser's own storage. These never reach our servers, are never used for tracking or advertising, and are never shared with anyone. They are: your language and light/dark preferences; a copy of your own display name and avatar, so that returning to the app shows your account immediately instead of an empty header while we restore your session (removed when you sign out, or as soon as we find your session has ended); a short-lived copy of content you have already been shown, such as your groups list, so a page you return to appears at once; the guest RSVP record described under "Guest RSVPs" above, if you replied to an invite link without an account; whether the getting-started steps shown on a new account's home screen have been started and whether you have hidden them, so the checklist survives a reload and stays hidden once you have closed it; and, while you browse the public Explore listing, your place in the list for up to 30 minutes so that pressing "back" from an event returns you to the same spot (kept in that browser tab only, and discarded when it closes). You can clear all of it at any time by clearing your browser's site data.

5. How we protect your information

We use technical and organisational measures to protect your data, including encryption in transit (HTTPS) and encryption at rest for sensitive content such as chat messages. Passwords are stored only as secure hashes. No method of transmission or storage is completely secure, but we work to protect your information and to limit access to it.

What chat encryption does and does not mean. Chat messages are encrypted at rest, which protects them if someone gains access to our storage. It is not end-to-end encryption: we hold the keys, so we are technically able to read message content. We do not read your conversations routinely, and there is no way for our team to browse them. The one case where a member of our team reads a message is when somebody reports it, described under "Reading a reported message" below.

6. How long we keep your information

We keep your information for as long as your account is active or as needed to provide the Service.

You can delete your account at any time from within the app, or from the web at withly.app — you don't need to contact support. When you request deletion, your account is immediately deactivated and signed out, and is then permanently anonymised after a short grace period (currently 30 days) during which you can restore it by simply signing back in, or by asking us to restore it at support@withly.app. Once the grace period has ended and the account has been anonymised, neither you nor we can bring it back.

A push notification token is kept for as long as that device is registered. It is deleted when you sign out of the app on that device, when Google tells us the token no longer works (because the app was uninstalled or the token was replaced), and when your account is anonymised. A token that has stopped working is kept for a few months, marked as no longer usable, so we can answer "why did this device stop receiving notifications", and is then deleted. We do not keep a record of the individual notifications we send.

Images are deleted when you remove them, when you replace them, when we remove them for breaching our image policy, and when your account is anonymised. Because deleting the stored files is a separate step from deleting the record that points at them, removal from our image storage happens shortly afterwards rather than instantly — normally within a day.

An image we remove for a policy breach stops being visible immediately and is moved out of public storage at once, so it can no longer be reached by anyone, including by an old link. The file itself is kept for 3 days from when we tell you about the removal, and then deleted. That window is deliberate: it is your opportunity to contest the decision, and it is what lets us put the image back if you turn out to be right. If you do contest it, we hold the file until a second person has reviewed it, however long that takes. In the rare case where an image may need to be preserved for a legal obligation or for law enforcement, it is kept out of circulation but not deleted, for as long as that obligation requires. The record of the decision itself (see "Image review decisions" above) is kept after the image is gone, in the same way and for the same reasons as our other safety and enforcement records.

When the grace period ends, we irreversibly remove the personal information that identifies you — including your email address, display name, avatar, uploaded images, phone number and date of birth — so that the account can no longer be traced back to you. Because Withly is a shared, social Service, some content you created is intertwined with other people's data: events you organised, RSVPs, group plans and votes, shared-cost (bill) records, and messages others have already received are kept but de-identified, appearing as from a "Deleted user". Where you appear only as an invitee, your email is replaced with a non-deliverable placeholder. We never send email to these anonymised addresses.

We retain a limited amount of data beyond anonymisation only where we have a legal basis to do so — for example shared-cost records others rely on to settle up, and information we must keep to comply with legal obligations, resolve disputes, prevent fraud and abuse, or enforce our agreements. Retained records are de-identified wherever possible. A narrow exception is our safety, enforcement and administrative audit records (see "Information we generate" above): because their purpose is security and accountability, they may be kept in identifiable form, including after an account is anonymised, for as long as needed for those purposes or to meet a legal obligation.

7. Your rights and choices

  • Access and update: view and edit your profile and content in the app.
  • Delete: delete your account from within the app (or on the web), as described in "How long we keep your information" above. You can also ask us to delete your account by emailing support@withly.app.
  • Notifications: manage push and in-app notification preferences in your settings.
  • Data rights: depending on where you live, you may have rights to access, correct, export, restrict, or object to our processing of your personal data. To exercise these, contact us at privacy@withly.app.

8. Children

Withly is not intended for children under 16, and we do not knowingly collect personal information from them. If you believe a child has provided us with personal information, please contact us and we will take steps to delete it.

9. International transfers

Your information may be processed in countries other than the one you live in. Where it is transferred, we take steps to ensure it remains protected in line with this policy and applicable law.

Specifically, if you enable push notifications, the notification text and your device's delivery token are processed by Google (and, on Apple devices, relayed via Apple), which involves a transfer outside the European Economic Area. That transfer is covered by the European Commission's Standard Contractual Clauses in our agreement with the provider. You can avoid it entirely by leaving push notifications off.

10. Changes to this policy

We may update this Privacy Policy from time to time. If we make material changes, we will take reasonable steps to notify you, for example by updating the date above or notifying you in the app.

11. Contact us

Questions about your privacy or this policy? Email us at privacy@withly.app.

Withly
© 2026 Withly Blog Privacy Terms Child safety Support