Privacy Policy
Introduction
Barsity ("we," "us," or "the app") is a social application that helps college students discover nightlife and coordinate plans with friends. This Privacy Policy explains what information we collect, how we use it, and the rights you have over your data.
Barsity is operated by Clint Murray as an individual developer. If you have questions about this policy, contact us at barsitycontact@gmail.com.
By using Barsity, you agree to the practices described here. If you don't agree, please don't use the app.
Information We Collect
We collect only the information needed to make Barsity work. Specifically:
Account Information
- Phone number — used to verify your identity at sign-in via SMS. This is your primary account identifier.
- Username — a unique handle you choose, visible to other users.
- Display name — what other users see (often the same as your username).
- First and last name — optional. Only visible to other users who view your profile.
- Avatar color — a visual identifier you select.
Location Data
- GPS coordinates — when you check in to a venue, we verify your location is within 150 meters of that venue using your device's GPS. Coordinates are used solely for this verification and are not stored long-term.
- Approximate location for the feed — when you open the app, we use your location to show nearby venues. This is processed but not stored.
You can deny location access in iOS Settings; however, you won't be able to check in to venues or see distance-based features without it.
Activity Data
- Check-ins — which venues you've been to, when you arrived, and when you left.
- Votes — your up/down votes on venues during your visits.
- Poll responses — which venue you've voted for in "Tonight's Plan."
- Friendships — who you're connected to within the app.
- Reviews — short (up to 120 characters) text posts you write about venues you've checked in to. Reviews are visible to other Barsity users alongside your username. They automatically expire when the plan_date rolls over at 10 AM the next day and are removed from the visible feed. A copy of removed reviews is retained in our system logs for up to 30 days for moderation and abuse investigation purposes.
- Review reports — when you report another user's review, we record which review you reported and when. This helps us identify patterns of abusive content and users.
Contacts (One-Time, Not Stored)
When you grant contacts permission during onboarding, the app uploads phone numbers from your iPhone's address book to our servers for a single one-time match against existing Barsity users. We use this to suggest friends who already have accounts.
We do not store contact phone numbers after the match completes. They exist on our servers only for the duration of the matching request (typically a few seconds), then are discarded. The numbers of people who don't have Barsity accounts are never persisted in any form.
You can deny contacts permission. The friend-matching feature will not work, but you can still find friends manually by phone number or username.
Push Notification Data
If you turn on notifications, we store a device push token — an anonymous identifier issued by Apple that lets us deliver notifications to your device. It cannot be used to identify you outside the app, read anything on your phone, or track you across other apps or websites.
We also record which notifications we've sent you and when. This is used only to enforce our own frequency limits — so you don't get the same alert twice, or more than three friend alerts in one night.
Barsity sends two kinds of notifications, and nothing else:
- Friends at a venue — when three or more of your friends are checked in at the same place. Friends who have Ghost Mode enabled are never included.
- Tonight's plan — a Thursday, Friday, and Saturday reminder that the plan is open for voting.
You can turn notifications off at any time in Account → Notifications, or in iOS Settings → Barsity → Notifications. Turning them off in the app stops us from sending anything; we delete your device token when you sign out.
Information We Don't Collect
To be specific, Barsity does not collect:
- Your email address
- Payment information (the app is free)
- Photos, videos, or other media files
- Browsing history outside the app
- Health, fitness, or biometric data
- Audio recordings
- Crash analytics or usage analytics (currently)
- Advertising identifiers (the push token described above is used only to deliver notifications, never for advertising or tracking)
- Information from other apps on your device
How We Use Your Information
We use the information we collect to:
- Authenticate your account via SMS verification
- Display venues, check-ins, and friend activity within the app
- Match contacts to existing Barsity users (one-time, not stored)
- Verify check-ins using GPS
- Coordinate "Tonight's Plan" polls
- Calculate your stats (check-ins, streaks, friend counts)
- Display user-submitted venue reviews to other users of the app
- Send the push notifications described above, if you've turned them on
- Investigate reports of inappropriate review content and take action against abusive users
- Operate, secure, and improve the app
- Respond to your requests for support or account deletion
We do not use your information for advertising, marketing emails, or sharing with data brokers.
How We Share Information
With Other Users
- Your username, display name, first/last name (if provided), and avatar color are visible to other Barsity users who view your profile.
- Your check-ins, votes, and activity are visible only to your accepted friends.
- Any reviews you post about venues are publicly visible to all Barsity users viewing that venue, alongside your username, until the reviews expire at 10 AM the following day.
- Your phone number is never shared with other users. It is used only as your private identifier for sign-in and friend-finding.
With Service Providers
We use the following third parties to operate Barsity. These services receive only the data they need:
- Twilio — sends SMS verification codes to your phone number. Twilio's privacy policy
- Render — hosts our backend infrastructure. Render's privacy policy
- Neon — hosts our database. Neon's privacy policy
- Expo — delivers push notifications to your device on our behalf. Expo receives your device push token and the text of the notification. Expo's privacy policy
- Apple — distributes the app via TestFlight and the App Store, and operates the Apple Push Notification service that delivers notifications to your device. Apple's privacy policy
We do not sell, rent, or trade your information to third parties for marketing purposes.
With Legal Requirements
We may disclose information if required by law, court order, or legal process — for example, to comply with a subpoena. We will resist overly broad requests and notify users when permitted.
Data Retention
- Account data — kept while your account is active.
- Check-ins — kept indefinitely to power your stats and history; you can delete your account to remove all of this.
- Location verification data — coordinates submitted with check-ins are stored as part of the check-in record. Live location queries (for the feed) are processed without storage.
- Contact phone numbers — never retained after the matching request completes.
- Reviews — visible in the app until the plan_date rolls over at 10 AM the next day, then removed from the visible feed. A copy is retained in our internal systems for up to 30 days after expiration for moderation and abuse investigation purposes, after which it is permanently deleted.
- Push tokens — kept while notifications are enabled and you're signed in. Deleted when you sign out, and automatically removed if Apple reports the device is no longer reachable (for example, if you delete the app).
- Notification records — the log of which notifications we sent you is kept for 30 days to enforce frequency limits, then deleted.
- Deleted accounts — when you delete your account, all associated data (profile, check-ins, votes, friendships, plans, reviews) is permanently removed within 24 hours. Backups may retain data for up to 7 days due to standard database backup retention.
Your Rights
Access and Correction
You can view and edit your profile information directly within the app. Use Account → Edit Profile.
Deletion
You can delete your account at any time. Use Account → Edit Profile → Delete my account. This permanently removes your profile and all associated data (check-ins, votes, friendships, etc.) from our active systems. Backups containing your data may persist for up to 7 days.
Ghost Mode
You can hide your check-ins from friends for 12 hours at a time using Edit Profile → Ghost Mode toggle.
Permissions
You can revoke iOS permissions (location, contacts, notifications) at any time through iOS Settings → Barsity.
California Residents (CCPA)
If you're a California resident, you have additional rights under the California Consumer Privacy Act:
- The right to know what personal information we collect about you
- The right to delete your personal information
- The right to opt out of the sale of personal information (we do not sell personal information)
- The right to non-discrimination for exercising these rights
To exercise CCPA rights, contact us at barsitycontact@gmail.com.
European Users (GDPR)
If you're in the European Economic Area, you have additional rights under the General Data Protection Regulation:
- The right to access your personal data
- The right to rectification
- The right to erasure ("right to be forgotten")
- The right to restrict processing
- The right to data portability
- The right to object to processing
The legal basis for processing your data is your consent (provided when you sign up) and contractual necessity (to operate the service you signed up for).
To exercise GDPR rights, contact us at barsitycontact@gmail.com.
Children's Privacy
Barsity is rated 17+ and is not intended for users under 17 years of age. We do not knowingly collect information from anyone under 13. If you believe a child under 13 has provided us with information, contact us at barsitycontact@gmail.com and we will delete it.
Data Security
We use industry-standard security practices:
- All communications between the app and our servers use HTTPS encryption (TLS 1.2+).
- Your sign-in token is stored securely on your device using iOS Keychain-equivalent encrypted storage.
- Our database requires authentication and is not publicly accessible.
- We use parameterized queries to prevent SQL injection.
- API endpoints are rate-limited to prevent abuse.
- Server credentials are stored as encrypted environment variables.
No security measures are perfect. We make reasonable efforts to protect your data but cannot guarantee absolute security. If we discover a data breach affecting your personal information, we will notify affected users via SMS or in-app notification within 72 hours of discovery.
International Data Transfers
Barsity's servers are located in the United States. By using the app from outside the U.S., you consent to your data being transferred to and processed in the United States.
Third-Party Links
Barsity may contain links to third-party services (e.g., venue websites). We are not responsible for the privacy practices of those services. Review their privacy policies before sharing personal information with them.
Changes to This Policy
We may update this Privacy Policy as Barsity evolves. When we do:
- We will update the "Last Updated" date at the top.
- Significant changes will be communicated via in-app notification before they take effect.
- Continued use of the app after changes means you accept the updated policy.
Contact Us
If you have questions, complaints, or requests related to this Privacy Policy or your data, contact:
Clint Murray
Email: barsitycontact@gmail.com
Subject line: "Barsity Privacy"
We aim to respond within 7 days.