Privacy Policy
How we collect and use your information
Effective date: September 1, 2026
Introduction & Who We Are
Doogo Research, Inc. ("Doogo," "we," "our," or "us") operates Doogo, a released service for discovering local events and forming community in real life in DC, Maryland, and Virginia. Doogo is available by invitation through our mobile application and the website at www.doogo.app (together, the "Service"). Doogo Research, Inc. is a Delaware corporation with its principal place of business at 2451 Crystal Dr, 6th Floor, Arlington, VA 22202, United States, and is the controller responsible for your personal information.
This Privacy Policy explains what information we collect, how we use and share it, how long we keep it, and the choices and rights you have. You are asked to accept this Policy when you create an account, and we may ask you to accept updated Terms and Privacy Policy versions after material changes. If you have questions, contact us at [email protected].
Scope & Eligibility
The Service is intended only for users who are at least 18 years old. We do not knowingly collect personal information from anyone under 18. If we learn that we have collected information from a person under 18, we will delete that account and apply the same deletion, restricted-evidence, and tombstoned-content retention rules described in this Policy. Please do not use the Service if you are under 18.
Information We Collect
Account & Identity
- Email address, password (stored only as an Argon2id hash — we never keep your plaintext password), display name, and username (your username forms part of your public profile address).
- Date of birth, which we collect once to confirm you meet the 18+ requirement.
- Phone number, if you choose to provide one. This is optional; we use it only as profile contact information and do not send you SMS text messages.
- If you connect your Google Calendar — a fully optional integration you choose to enable — we use Google's OAuth with an app-created-calendar permission, plus a read-only view of your calendar list that we use only to find that calendar again, to create and manage only the dedicated Doogo calendar used for the integration. We store encrypted access and refresh tokens, the dedicated calendar's identifier, and the calendar entries we sync to that calendar; we do not receive your Google email or profile for this feature. You can disconnect it at any time. If you connected under an older, broader calendar permission, we require you to reconnect before calendar sync continues.
- Consent records showing your acceptance of our Terms and this Privacy Policy, including timestamps, versions, and the IP address and device/user-agent recorded at the time of acceptance.
Profile & Social Graph
- Optional profile details: first/last name, gender, a short bio, an avatar image, your interests, and a default/home location.
- Your social connections: friends, follows, pending friend/follow requests, and the members you block; the communities you join; and the group chats you belong to or are invited to, including your role and settings in each group.
- Your privacy settings controlling who can see each part of your profile and activity (see What Other Members Can See).
User-Generated Content
- Event comments and community posts and replies, any images you attach, and likes on them.
- Reactions and plans. Your reactions to events (attending / interested / not interested), the plans you make to go to events with other members, and, after an event, whether you confirm that you attended.
- Messages. Direct messages you send and receive, including text, images, and shared events.
- Group chats. Groups you create or join: the group's name and image, its members and invitations, and the messages, images, reactions, replies, shared events, and read and mute state in it.
- Reports. Content or members you report, with the reason and notes you give.
- Invitations. If you invite someone by email, the address you enter, the invitation we send to it, and its delivery status. We keep a list of addresses that have asked not to receive invitations so we can honour that choice.
- Safety-processing records. For new avatar, comment, community, direct-message, group, and group-message images, we keep the moderation status and the policy, model, decision, retry, and audit metadata needed to apply and review our safety controls. We do not create a User Content record for text that is refused before a write.
- Support feedback. If you submit support feedback, we collect the message text, private attachments you choose to include, attachment metadata, app and route context, diagnostic device metadata, analytics device IDs, notification device IDs, and private GitHub triage records created by admins. During admin triage, admins may open a private GitHub issue URL containing feedback text, which may itself contain personal information you entered, plus the feedback ID, non-identifying release and debugging context, an internal admin link, and an attachment summary. Opening that URL sends those fields outside Doogo to GitHub and may place them in browser history or proxy logs before the issue is submitted. It does not include reporter or account IDs, analytics or notification device IDs, device names or models, or attachment filenames. It does not include attachment files, signed URLs, or R2 object keys.
Usage & Behavioral
- How you interact with the Service: events you view, open, bookmark, or mark as attending; feed impressions and how long cards are shown; video watch progress; your searches — including the raw search text and filters you apply (such as location and date) in our first-party product analytics and recommendation systems; comment, reaction, and share activity; the communities and groups you join or leave; and the members you share events with. Raw search text is not sent to Amplitude.
Device & Technical
- IP address, browser/user-agent and device information (model, operating system, app version, language, time zone), and screen/viewport size.
- Authentication cookies and tokens, plus the IP address and device details associated with each sign-in session.
- Security and audit logs. We keep a log of important account and security events — such as sign-ins, registration, password resets, profile changes, data exports, and account deletion — including the action, the full IP address, and the user-agent. We use these records to operate the Service securely, detect and investigate abuse, and meet our legal obligations.
- On mobile: a push-notification token, a randomly generated analytics identifier, and the app's version, runtime, and platform, which the app sends to Expo's update service to check for over-the-air updates.
Location
- With your permission, your device or browser's location to show you nearby events. We ask for this only when you use a "near me" feature, and you can decline or turn it off at any time in your device or browser settings. If you choose your current location as your home base, we save that position with it.
- An approximate location (country, region, city, and approximate coordinates and postal code) derived from your IP address — see Analytics & Tracking.
- The default/home location you enter for distance-based recommendations. For a street address picked from Google Places, we retain the selected formatted street address and the place identifier while that selection remains your home base, and temporarily cache its coordinates so we can measure distance. Older app versions may retain the exact location text you entered together with the Google place identifier and temporary coordinates. Your saved address remains private to you and is included in an account-data export.
- For waitlist sign-ups: the area or ZIP code you submit, together with your full IP address, an IP-derived approximate location (including approximate coordinates and postal code), and your browser/user-agent. Public campaign links redirect without recording a visit, and the waitlist form does not send referrer or campaign parameters.
Device Calendar
With your permission, the mobile app lists the calendars on your device to find or create a dedicated Doogo calendar, and adds, updates, and removes entries for your plans in it. To keep those entries in sync the app reads calendar entries on your device only within the time windows of your plans and uses only the entries Doogo created; it does not upload your other calendar data. You can revoke calendar access in your device settings at any time.
Home-Screen Widgets and Shortcuts
If you add a Doogo widget to your device's home screen or use the app's shortcuts, the title and time of your next plan are shown there, outside the app. That content is drawn on your device from data the app already holds and is not shared with anyone else.
Data Minimization & Sensitive Information
We collect only the information reasonably necessary to provide and improve the Service. We do not require special categories of "sensitive" personal information to use the Service, and we do not sell it or use it for targeted advertising. The potentially sensitive category we may process is precise location, from two user-directed sources:
- Your device or browser geolocation, only with your permission, to show nearby events or set the home base you ask us to set from it. You can turn this access off at any time in your device or browser settings.
- Coordinates Google returns for a place you deliberately select as your home base. This place lookup does not access your device location or require geolocation permission. We temporarily cache those coordinates as described above so we can measure distance.
You can replace or clear either kind of saved home base at any time.
The communities you choose to join can also reveal information about you (for example an identity-based community). Joining is optional, and your membership is visible only to other members of that community.
How We Collect Information
- Directly from you — when you register, build your profile, post content, message, join communities or group chats, make plans, invite others, search, or contact us.
- Automatically — through your use of the Service (usage, device, cookies, and approximate location).
- From third parties — from Google when you connect your Google Calendar, from Google Places when you deliberately select a home base, and event details from the public event sources we aggregate.
For aggregated event listings, we do not retain structured public-source contact names, email addresses, or phone numbers. Our ingestion boundary removes those fields and redacts obvious email and North American (NANP-formatted) phone identifiers from harvested event text before it enters our event cache, review queue, or repository.
Cookies, Local Storage & Similar Technologies
We use a small number of first-party cookies and browser-storage keys:
access_tokenandrefresh_token— secure, HttpOnly cookies (not readable by JavaScript) that keep you signed in.has_session— a non-sensitive, JavaScript-readable cookie indicating whether you have an active session.- Browser local storage for cached public configuration and, after an eligible user signs in, product-analytics device/session state.
- Our analytics provider (Amplitude) sets its own device/session identifiers in browser storage only for eligible signed-in product analytics.
You can clear cookies and local storage in your browser settings; doing so may sign you out or reset preferences. We do not use third-party advertising cookies.
Analytics & Tracking
Signed-in first-party product analytics. Product analytics do not initialize before authentication. They start only after you sign in, the Service confirms that you accepted the exact current Terms and Privacy Policy versions, your analytics preference loads successfully, and Limit Analytics is off. We record search history (including raw search text), product interactions, an actor-scoped analytics device identifier, and app/session activity to improve the Service and personalize recommendations. Account-linked product analytics are retained for up to 24 months unless you delete your account sooner. Public pages, registration, stale-policy screens, preference-loading failures, logout, and account deletion do not start an anonymous product-analytics session. Before storing an analytics IP address, for IPv4 we zero the last octet (a /24 network), and for IPv6 we keep only the first 64 bits (a /64 network), after any configured IP-geolocation provider derives an approximate location. We do not record street-level location from an IP address.
Amplitude (web product analytics). For eligible signed-in use of the public website, we use Amplitude to understand an allowlisted set of feature-usage events and key funnels. The browser sends data to our authenticated first-party ingest endpoint; only the server holds the Amplitude project key. We send a random device/session identifier, your opaque internal account user ID, route names, approved event identifiers, and platform context. We do not send Amplitude raw search text, passwords, tokens, email, name, phone number, or free-form profile text. We do not associate pre-authentication activity with your account. The mobile app has no direct Amplitude transport, key, or project; its optional product analytics use only Doogo's authenticated first-party tracker and are revalidated by our server.
Sentry (mobile error reporting). Our mobile app uses Sentry to capture crashes and errors with scrubbed diagnostic context. Sentry receives no account identity: no internal user ID, public user reference, username, email, or name.
Limit Analytics. If you turn on Limit Analytics in Settings, we stop optional first-party recommendation/usage analytics and, on the public website, eligible Amplitude analytics. We discard pending local analytics events and remove local analytics identifiers. It does not disable security/audit logs, crash and error protection, operational logs, abuse prevention, legal records, or transactional records that we need to provide, secure, maintain, and administer the Service.
How We Use Your Information
We use your information to:
- provide, secure, and maintain the Service and your account;
- personalize your event recommendations (see Personalization);
- enable the social, community, group, and messaging features you choose to use, and introduce you to people and communities that match your interests;
- send transactional and, where permitted, marketing messages;
- keep the Service safe — preventing fraud and abuse, enforcing our policies, and reviewing reported content;
- analyze and improve the Service; and
- comply with our legal obligations.
User-Content Safety Screening
Doogo uses deterministic first-party safety rules to screen supported user-authored text, including comments, community posts, direct messages, group-chat messages, group names, and profile text, before it is stored. Text that matches a clearly objectionable-content rule is refused. The rules run within Doogo's server environment and do not send the text to an external moderation or AI provider.
New avatar, comment, community, direct-message, group, and group-message images are first stored in access-controlled private storage. They remain pending until an operator-scheduled batch runs ShieldGemma 2, an image-safety model developed by Google. ShieldGemma is third-party technology; it is not owned or developed by Doogo. The model is locally hosted on Doogo-controlled hardware and runs offline for this workflow, so user media is not sent to Google, Hugging Face, or another model provider. Its built-in checks cover sexually explicit, dangerous, and violence or gore imagery. Doogo also supplies fixed custom policies that screen for obvious hate and harassment imagery. Google has not published quality benchmarks for those custom policies, and no automated model covers every possible image-safety case.
Pending images have no server-issued viewing URL. The uploading device may keep its own local preview. Approved avatar and comment images become publicly available, approved direct-message images become available only through recipient-authorized, time-limited links, and approved group images become available only to that group's members through time-limited links. Rejected images receive no viewing URL; an image-only comment or message displays Deleted, while a rejected avatar does not replace the last approved avatar. Automated screening can make errors and does not replace the in-app report and block controls.
Messaging and Group Chats
If you use messaging, we store the content of your messages (text and images) and shared events so we can deliver them and let you and the recipient access your conversation history. Messages are not end-to-end encrypted; they are stored on our systems and protected by the security measures described below. You can delete a message from your own view, though it may remain visible to the other participant. Approved images are served through temporary, time-limited links; pending and rejected images have no such link. When you share a link in a message, we may fetch it to generate a screened text preview, but we do not show the remote preview image or logo.
Doogo personnel do not routinely read direct messages. Human direct-message safety review occurs only for reports: authorized safety staff may review a reported direct message and its retained snapshot, and their access and resulting actions are audited. We retain each reported snapshot as safety evidence with live account references replaced by deletion-safe tombstones if an involved account is later deleted.
Group chats work the same way, with these differences. Every member of a group can see its name, image, member list, messages, images, reactions, and shared events. If the group's history setting allows it, people who join later can see earlier messages. A group's owner and managers can invite, add, and remove members, change roles and settings, and transfer ownership; if an owner deletes their account, ownership passes to another member. Doogo may remove messages, lock a group, or retire it for safety reasons. When you leave a group, or delete your account, the messages and images you already sent remain visible to its members (after account deletion under a "Deleted user" label). Blocking a member prevents new invitations between you but does not hide content in a group you both already belong to. Group content is not end-to-end encrypted.
Communities
Communities are shared spaces built around a place, interest, or identity. When you join one, its other members can see that you belong (your username, and your display name and avatar according to your privacy settings) and everything you post there. People who are not members see the community's description and activity counts, not its posts or member list. We keep a record of when you join or leave a community for abuse prevention; it is not shown to anyone and is removed when you delete your account.
Doogo Host. Doogo operates an official account named Doogo Host in communities. Doogo staff may post and reply as Doogo Host using what is visible in that community, including the thread, members' usernames, and profile fields members have set to public. Doogo Host content may also be produced by software, including AI models that run on Doogo-controlled infrastructure; we do not send community content to an external AI provider to produce it.
What Other Members Can See
- Your username and public profile address are visible to every signed-in member.
- Your display name, avatar, bio, gender, reaction counts, and the lists of events you have reacted to are shown according to the privacy level you choose for each in Settings (public, followers, friends, or private). Your friend, follower, and following counts are always public.
- Subject to those settings, members you are connected with may see the events you mark as Interested or Attending and the plans you make to go to them (in their feed, their plans list, and on your profile), whether you confirmed attending an event after it ended, the members you have in common, and your recent comments.
- Aggregate counts, such as how many people are going to an event, never identify you.
- Members of a community or group chat you belong to can see your membership and what you post there.
Personalization, Recommendations & Automated Profiling
We use your behavioral signals (such as the events you view, attend, bookmark, or dismiss) to rank and recommend events. We also use these signals — including events you mark as Interested or Attend, those you choose to see fewer of, and your searches — to identify and connect you with other people who share your interests. This personalization is a core function of the Service. Our recommendation engine runs on our own infrastructure. To personalize recommendations and introduce you to people and communities that match your interests, we also process the profile text you write (your bio and interest description), your interests, and your gender with software that runs on our own infrastructure, including an open-source text model that converts that text into a numeric representation used only for matching. That text is not sent to the model's developer or to any external AI provider. We also infer interests from your activity; you can review and dismiss them on your profile. Separately, we compute "interest tags" that describe events; those tags are generated from event text, not from your personal data.
We do not send your account data, direct messages, comments, profile data, or user uploads to an external AI provider. We do use externally hosted third-party AI providers to process public event information — for example to summarize and analyze event text and images, generate the interest tags that describe events, and create event imagery. That externally hosted processing involves only public event content and our own system event data. Separately, the locally hosted ShieldGemma workflow described above processes new user images on Doogo-controlled hardware without sending them to the model provider, and community content used for Doogo Host is handled as described under Communities. We do not make decisions about you that produce legal or similarly significant effects through solely automated means.
Communications & Marketing
Transactional messages (such as email verification, password resets, and security notifications, which may include the IP address and time of the event) are part of the Service and cannot be turned off while you have an account.
Marketing and recommendation messages (announcements, promotions, event recommendations, and reminders) are sent by email and push notification according to your preferences. You can control these in your in-app notification preferences — by category and channel, including digest frequency and quiet hours (by default, 10:00 PM to 7:00 AM) — and you can unsubscribe from marketing email using the link in every such message. As required by the U.S. CAN-SPAM Act, our marketing emails include our postal mailing address.
Invitation emails. When a member invites you by email, we send the invitation to that address on the member's behalf. Every invitation email includes an unsubscribe link, and an address that opts out is not emailed again.
Push delivery for recommendations, re-engagement nudges, announcements, and promotions is off by default. We send those categories by push only after you explicitly turn on that category's Push setting in the app. Granting the device's operating-system notification permission or registering a device does not, by itself, opt you into these marketing-like push categories.
Push notifications require a device push token delivered through Apple's and Google's push services; you can disable push notifications in your device settings at any time.
How We Share Information & Sub-Processors
We do not sell your personal information. We share it only as described here:
- With service providers (sub-processors) that process data on our behalf under contract — listed below.
- For safety and legal reasons — to enforce our Terms, respond to lawful requests, or protect the rights, safety, and property of Doogo, our users, or the public.
- In a business transfer — in connection with a merger, acquisition, or sale of assets, subject to this Policy.
- As aggregated or de-identified data that cannot reasonably identify you.
- With other members, as described in What Other Members Can See.
- Publicly, on your public profile page and on invitation pages (see Public profile and invitation pages).
The service providers and other third-party recipients that may process your personal data are:
| Sub-Processor | Purpose | Personal data involved |
|---|---|---|
| Render | Cloud hosting, managed database and cache | All Service data |
| Cloudflare R2 | Private and public object storage | Avatars; comment, community, message, and group images; temporary account-export archives containing requested account data; private support-feedback attachments; and restricted safety evidence |
| Amplitude | Eligible signed-in public-web product analytics through Doogo's server-side ingest proxy | Device/session IDs, account user ID, truncated IP network, usage events |
| Optional Google Calendar sync for the dedicated Doogo-created calendar | Dedicated calendar ID, encrypted OAuth tokens, and the calendar entries we sync | |
| Resend (and Postmark) | Email delivery | Recipient email address and message content |
| Apple (APNs), Google (FCM), and Expo | Push-notification delivery; over-the-air app updates (Expo) | Push token, device info, notification content; app version, runtime, and platform for update checks |
| Sentry | Mobile crash and error reporting | Scrubbed diagnostic data; no account identity |
| GitHub | Private engineering triage for support feedback opened by an authorized admin | Feedback text, feedback ID, non-identifying release/debug context, internal admin link, and attachment summary |
| Grafana Cloud (Loki) | Operational logging and metrics | Logs that may include user IDs and IP addresses |
| IPLocate | IP geolocation (when configured as our provider) for waitlist sign-ups and eligible signed-in analytics | IP address |
| Nominatim geocoding service (operator-configured, or the public OpenStreetMap Foundation endpoint for throttled user-triggered reverse lookup only) | Operator service: web location search, reverse geocoding, and waitlist ZIP-locality resolution; public endpoint: user-triggered reverse geocoding only | Location text, selected device coordinates, or the ZIP code you submit |
| Google Places | Address autocomplete and compatibility location resolution for the home base you set in the mobile app | The address or location text you type and the place you pick; never your device coordinates |
Where a provider acts as our contracted sub-processor, we require it to provide the same or equivalent protection for user data described in this Policy, safeguard it, and use it only to provide services to us. The public OpenStreetMap Foundation Nominatim endpoint is a public third-party recipient governed by its published usage and privacy policies, not a contracted Doogo sub-processor.
Location search uses OpenStreetMap data: © OpenStreetMap contributors, available under the Open Data Commons Open Database License (ODbL). Doogo sends web location queries, autocomplete traffic, automated geocoding, and waitlist ZIP-locality lookups only to an operator-configured, approved Nominatim service. Those features are unavailable when no approved endpoint is configured. A user-triggered reverse lookup for “use current location” may instead use the public OpenStreetMap Foundation Nominatim endpoint. Public reverse lookups are shared-cache-backed, globally throttled to no more than one upstream request about every 1.1 seconds, and never used for autocomplete or background work.
In the mobile app, street-address suggestions you see while typing a home base come from Google Places. We send the text you type and, when you pick a suggestion, the identifier of the place you picked; Google then processes those as described in the Google Privacy Policy and under the Google Maps Platform Terms. We retain the selected formatted street address so you can see the home base you set. Older compatible app versions may send a city-or-address query to Google; for those versions we show and retain only the exact text you entered, not a Google-formatted display name. We do not send your device coordinates to Google. If you instead choose “use current location”, your device position goes to the Nominatim service described above and not to Google. Map coordinates we obtain from Google for a place you picked become due for refresh after 28 days. We remove expired content for dormant sessions then. For an active signed-in session, we first try to replace that content in the background beginning on day 27; login and session renewal also refresh it when it is expired. We clear expired active-session content after its required refresh attempt rather than purging it from the middle of an active session before that attempt. The place identifier remains until you change that home base or delete your account. We keep these coordinates in a non-durable server cache that is omitted from our portable database backups and may be emptied during database recovery or failover; the retained place identifier lets us refresh the cache when needed.
Public profile and invitation pages
Each member has a public profile page at www.doogo.app/u/<username> that
anyone can view without signing in and that search engines may index. It shows
your username and your friend, follower, and following counts and, only for the
fields you have set to public, your display name, avatar, and bio, and it
produces a link preview (title, description, and image) for that page. When you share an
invitation link, the invitation page shows your username and, if public, your
display name and avatar to whoever opens it. A username you change away from
keeps pointing to your profile for 30 days.
Separately, we use externally hosted third-party AI providers to process public event content (not your personal information). They are not listed above because they do not receive any of your personal data. The third-party ShieldGemma model is also not a sub-processor: Doogo runs the downloaded model locally, and its developer and distribution host do not receive user media. See Personalization, Recommendations & Automated Profiling.
International Data Transfers
The Service is operated from, and intended for users in, the United States. Your information is stored and processed in the United States.
Data Retention
We keep your account information for as long as your account is active. We retain other categories only as long as needed for the purposes described above or as required by law, including approximately:
- product and usage analytics: up to 24 months;
- security and audit logs: while your account exists; when you delete your account we remove the IP address and user-agent from those records and keep the de-identified event;
- marketing campaign records: about 13 months;
- audience and segment snapshots: 35 to 90 days;
- username-change history: a 30-day reservation window;
- support feedback records: retained after account deletion for product support, abuse-prevention, and engineering triage. We unlink the live account reference and remove analytics and notification device identifiers. We retain feedback text, private attachments, non-identifying diagnostic metadata, attachment metadata, update history, and private GitHub export audit hashes;
- safety reports: when a comment, direct message, event, user, or avatar is reported, we keep the submitted reason and notes and any content or metadata snapshot needed to review the report and record our safety actions. If a reporter, content author, message sender, or reported account is deleted, we retain the evidence but remove its live account reference and replace any displayed identity with "Deleted user";
- image-moderation storage: unattached image submissions expire through the existing upload cleanup. Approved private staging copies for avatars and comments are removed after verified public publication unless that exact pre-publication source was captured as restricted report evidence, while the canonical approved media remains available. Avatar roots captured by a report or report follow-up are likewise retained as restricted safety evidence. An approved direct-message image remains in access-controlled private storage for delivery to the intended participant. Attached rejected images are retained privately with the associated retained comment or direct message as safety evidence and never receive a user-facing URL. Operational failures are retried and never cause approval. After the bounded automatic retry limit, the unavailable submission remains pending with an operator-attention marker until an authorized operator investigates and explicitly requeues it or the user replaces it;
- comments and direct messages (and community posts), including associated text and media: retained indefinitely after account deletion for conversation and thread integrity, but marked deleted. Ordinary app responses show only a deleted placeholder and do not return the retained body, media, link preview, shared-event preview, or former identity;
- community membership: until you leave or delete your account; the record that you joined or left: until you delete your account;
- group chats: messages and images you sent stay with the group after you leave and, after account deletion, remain visible to its members under "Deleted user"; your live membership, invitations, and read/mute state are removed;
- plans and attendance confirmations: until you change them or delete your account;
- invitation records: the address you invited and its delivery status while your account exists, de-identified when you delete it; opt-out entries are kept so we honour them;
- waitlist records: until you ask us to remove them or delete an account that uses the same email address;
- consent records: as long as needed for the purpose they were collected, de-identified after account deletion.
Transactional deletion replaces live account identity and revokes sign-in credentials before the request succeeds. It also removes live preferences, reactions, devices, calendar links, analytics data, your community memberships, your live group memberships and invitations, and your plans and attendance confirmations, and unlinks your identity from delivered group content. Retained text and media are immediately unavailable through ordinary app APIs. Those APIs omit the retained body and media and expose only a deleted-content state; ordinary app views render a deleted-user or deleted-content placeholder. Safety reports and support feedback remain available only to authorized staff with deleted identities anonymized. Media-moderation owner references are also anonymized, and pending avatar submissions are detached, when an account is deleted.
Durable, retryable cleanup jobs perform the external-storage work after that transaction commits. They delete account-data exports, avatars, unattached uploads, and other unretained media. Retained comment media is copied and verified in access-controlled private storage before its public object is deleted and custom-domain CDN caches are purged. Direct-message media remains in access-controlled private storage; its short-lived links expire and cannot be renewed. Failed copy, delete, or purge steps remain queued with backoff for another attempt. A cached copy may be served briefly while an asynchronous purge is pending, and copies saved independently by recipients remain outside our control. Some de-identified records required for security, audit, or legal purposes are retained for the periods above.
User data exports include non-binary support feedback records. They exclude attachment binaries, signed URLs, R2 object keys, generated GitHub issue URLs, and raw GitHub URLs. They include your communities, group memberships and invitations, and the messages you sent in group chats, but not other members' messages. For a Google Places home base, the export includes the durable place identifier, the owner-visible saved address, and whether that label was selected from Google or authored by you. It excludes temporary coordinates and all other Google presentation content. Coordinates are used server-side to measure distance, omitted from our portable database backups, and deleted no later than the provider's 30-day caching deadline. Google Maps Platform terms restrict us from exporting other Google Maps Content into a portable downstream copy.
Data Security
We protect your information with industry-standard measures, including encryption in transit (TLS) and at rest, hashing of passwords with Argon2id, and encryption of connected-calendar tokens with AES-256-GCM. On mobile, your sign-in credentials are kept in your device's secure storage, and you may enable biometric (Face ID or fingerprint) unlock — your biometric data stays on your device and is never sent to us. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
Privacy Rights and Choices
Wherever you live, you can:
- Access / export — request a copy of your data. We prepare an export and notify you when it is ready to download.
- Correct — edit your profile and account information in Settings.
- Delete — delete your account and associated data at any time from Settings (see Data Retention for what deletion means).
- Manage communications — set your notification preferences and unsubscribe from marketing email.
- Limit location access — use device or browser settings to deny or revoke precise location permission, and replace or clear a saved home base at any time in the Service.
- Limit Analytics — use Settings to stop optional first-party analytics and eligible public-web Amplitude analytics as described in Analytics & Tracking.
- Disconnect Google Calendar — remove the optional calendar integration from Settings.
- Control who sees your activity — choose a privacy level for each profile field and for your reactions and plans in Settings.
- Leave a community or group chat — at any time, from within it.
To make a request, use your Settings page or email [email protected]. We may need to verify your identity before we act on a request. We respond to privacy requests within 45 days; where applicable law requires or permits a different response period, we will follow that law.
We do not currently sell personal information, share personal information for targeted advertising, or use personal information for targeted advertising. We also do not show ads. The Do Not Sell or Share setting records a preference we will honor if our practices change and if a privacy law that applies to us treats a new practice as a sale, sharing, or targeted advertising. If a privacy law that applies to us gives you additional rights, we will process your request as that law requires. We will not discriminate against you for exercising your privacy rights.
Children's Privacy
The Service is for adults 18 and older. We do not knowingly collect personal information from anyone under 18. If you believe a person under 18 has provided us with personal information, contact [email protected] and we will delete it.
Third-Party Links & Event Sources
Doogo aggregates event listings from public sources and may link to venue, organizer, or ticketing websites. We are not responsible for the content or privacy practices of those third parties; their own policies govern your interactions with them. We retain organization and publicly billed performer or presenter attribution as event content, but do not compile source contact fields.
Changes to This Policy
We may update this Policy from time to time. If we make material changes, we will notify you by posting a notice in the Service or by email. The "Effective date" at the top reflects when the current version of this Policy takes effect.
Contact Us
For questions or requests about this Policy or your personal information:
Doogo Research, Inc. Attn: Privacy 2451 Crystal Dr, 6th Floor Arlington, VA 22202, United States Email: [email protected]
The governing law for the Service is addressed in our Terms of Service.