Privacy Policy

How we collect and use your information

Effective date: July 15, 2026

Introduction & Who We Are

Doogo Research, Inc. ("Doogo," "we," "our," or "us") operates Doogo, a released service for discovering local events and forming community in real life in DC, Maryland, and Virginia. Doogo is available by invitation through our mobile application and the website at www.doogo.app (together, the "Service"). Doogo Research, Inc. is a Delaware corporation with its principal place of business at 2451 Crystal Dr, 6th Floor, Arlington, VA 22202, United States, and is the controller responsible for your personal information.

This Privacy Policy explains what information we collect, how we use and share it, how long we keep it, and the choices and rights you have. You are asked to accept this Policy when you create an account, and we may ask you to accept updated Terms and Privacy Policy versions after material changes. If you have questions, contact us at [email protected].

Scope & Eligibility

The Service is intended only for users who are at least 18 years old. We do not knowingly collect personal information from anyone under 18. If we learn that we have collected information from a person under 18, we will delete that account and apply the same deletion, restricted-evidence, and tombstoned-content retention rules described in this Policy. Please do not use the Service if you are under 18.

Information We Collect

Account & Identity

  • Email address, password (stored only as an Argon2id hash — we never keep your plaintext password), display name, and username (your username forms part of your public profile address).
  • Date of birth, which we collect once to confirm you meet the 18+ requirement.
  • Phone number, if you choose to provide one. This is optional; we use it only as profile contact information and do not send you SMS text messages.
  • If you connect your Google Calendar — a fully optional integration you choose to enable — we use Google's OAuth with an app-created-calendar permission to create and manage only the dedicated Doogo calendar used for the integration. We store encrypted access and refresh tokens, the dedicated calendar's identifier, and the calendar entries we sync to that calendar; we do not receive your Google email or profile for this feature. You can disconnect it at any time. If you connected under an older, broader calendar permission, we require you to reconnect before calendar sync continues.
  • Consent records showing your acceptance of our Terms and this Privacy Policy, including timestamps, versions, and the IP address and device/user-agent recorded at the time of acceptance.

Profile & Social Graph

  • Optional profile details: first/last name, gender, a short bio, an avatar image, your interests, and a default/home location.
  • Your social connections: friends, follows, and pending friend/follow requests.
  • Your privacy settings controlling who can see each part of your profile.

User-Generated Content

  • Event comments ("Mingle") and any images you attach, your reactions (attending / interested / not interested), and content you choose to report.
  • Messages. Direct messages you send and receive, including text, images, and shared events.
  • Safety-processing records. For new avatar, comment, and direct-message images, we keep the moderation status and the policy, model, decision, retry, and audit metadata needed to apply and review our safety controls. We do not create a User Content record for text that is refused before a write.
  • Support feedback. If you submit support feedback, we collect the message text, private attachments you choose to include, attachment metadata, app and route context, diagnostic device metadata, analytics device IDs, notification device IDs, and private GitHub triage records created by admins. During admin triage, admins may open a private GitHub issue URL containing feedback text, which may itself contain personal information you entered, plus the feedback ID, non-identifying release and debugging context, an internal admin link, and an attachment summary. Opening that URL sends those fields outside Doogo to GitHub and may place them in browser history or proxy logs before the issue is submitted. It does not include reporter or account IDs, analytics or notification device IDs, device names or models, or attachment filenames. It does not include attachment files, signed URLs, or R2 object keys.

Usage & Behavioral

  • How you interact with the Service: events you view, open, bookmark, or mark as attending; feed impressions and how long cards are shown; video watch progress; your searches — including the raw search text and filters you apply (such as location and date) in our first-party product analytics and recommendation systems; and comment, reaction, and share activity. Raw search text is not sent to Amplitude.

Device & Technical

  • IP address, browser/user-agent and device information (model, operating system, app version, language, time zone), and screen/viewport size.
  • Authentication cookies and tokens, plus the IP address and device details associated with each sign-in session.
  • Security and audit logs. We keep a log of important account and security events — such as sign-ins, registration, password resets, profile changes, data exports, and account deletion — including the action, the full IP address, and the user-agent. We use these records to operate the Service securely, detect and investigate abuse, and meet our legal obligations.
  • On mobile: a push-notification token and a randomly generated analytics identifier.

Location

  • With your permission, your device or browser's location to show you nearby events. We ask for this only when you use a "near me" feature, and you can decline or turn it off at any time in your device or browser settings.
  • An approximate location (country, region, city, and approximate coordinates and postal code) derived from your IP address — see Analytics & Tracking.
  • The default/home location you enter for distance-based recommendations.
  • For waitlist sign-ups: the area or ZIP code you submit, together with your full IP address, an IP-derived approximate location (including approximate coordinates and postal code), and your browser/user-agent. Public campaign links redirect without recording a visit, and the waitlist form does not send referrer or campaign parameters.

Data Minimization & Sensitive Information

We collect only the information reasonably necessary to provide and improve the Service. We do not require special categories of "sensitive" personal information to use the Service, and we do not sell it or use it for targeted advertising. The one potentially sensitive category we may process is precise location — and only your device or browser geolocation, only with your permission, and only to show you nearby events. You can turn it off at any time in your device or browser settings.

How We Collect Information

  • Directly from you — when you register, build your profile, post content, message, search, or contact us.
  • Automatically — through your use of the Service (usage, device, cookies, and approximate location).
  • From third parties — from Google when you connect your Google Calendar, and event details from the public event sources we aggregate.

For aggregated event listings, we do not retain structured public-source contact names, email addresses, or phone numbers. Our ingestion boundary removes those fields and redacts obvious email and North American (NANP-formatted) phone identifiers from harvested event text before it enters our event cache, review queue, or repository.

Cookies, Local Storage & Similar Technologies

We use a small number of first-party cookies and browser-storage keys:

  • access_token and refresh_token — secure, HttpOnly cookies (not readable by JavaScript) that keep you signed in.
  • has_session — a non-sensitive, JavaScript-readable cookie indicating whether you have an active session.
  • Browser local storage for cached public configuration and, after an eligible user signs in, product-analytics device/session state.
  • Our analytics provider (Amplitude) sets its own device/session identifiers in browser storage only for eligible signed-in product analytics.

You can clear cookies and local storage in your browser settings; doing so may sign you out or reset preferences. We do not use third-party advertising cookies.

Analytics & Tracking

Signed-in first-party product analytics. Product analytics do not initialize before authentication. They start only after you sign in, the Service confirms that you accepted the exact current Terms and Privacy Policy versions, your analytics preference loads successfully, and Limit Analytics is off. We record search history (including raw search text), product interactions, an actor-scoped analytics device identifier, and app/session activity to improve the Service and personalize recommendations. Account-linked product analytics are retained for up to 24 months unless you delete your account sooner. Public pages, registration, stale-policy screens, preference-loading failures, logout, and account deletion do not start an anonymous product-analytics session. Before storing an analytics IP address, for IPv4 we zero the last octet (a /24 network), and for IPv6 we keep only the first 64 bits (a /64 network), after any configured IP-geolocation provider derives an approximate location. We do not record street-level location from an IP address.

Amplitude (web product analytics). For eligible signed-in use of the public website, we use Amplitude to understand an allowlisted set of feature-usage events and key funnels. The browser sends data to our authenticated first-party ingest endpoint; only the server holds the Amplitude project key. We send a random device/session identifier, your opaque internal account user ID, route names, approved event identifiers, and platform context. We do not send Amplitude raw search text, passwords, tokens, email, name, phone number, or free-form profile text. We do not associate pre-authentication activity with your account. The mobile app has no direct Amplitude transport, key, or project; its optional product analytics use only Doogo's authenticated first-party tracker and are revalidated by our server.

Sentry (mobile error reporting). Our mobile app uses Sentry to capture crashes and errors with scrubbed diagnostic context. Sentry receives no account identity: no internal user ID, public user reference, username, email, or name.

Limit Analytics. If you turn on Limit Analytics in Settings, we stop optional first-party recommendation/usage analytics and, on the public website, eligible Amplitude analytics. We discard pending local analytics events and remove local analytics identifiers. It does not disable security/audit logs, crash and error protection, operational logs, abuse prevention, legal records, or transactional records that we need to provide, secure, maintain, and administer the Service.

How We Use Your Information

We use your information to:

  • provide, secure, and maintain the Service and your account;
  • personalize your event recommendations (see Personalization);
  • enable the social and messaging features you choose to use;
  • send transactional and, where permitted, marketing messages;
  • keep the Service safe — preventing fraud and abuse, enforcing our policies, and reviewing reported content;
  • analyze and improve the Service; and
  • comply with our legal obligations.

User-Content Safety Screening

Doogo uses deterministic first-party safety rules to screen supported user-authored text, including comments, direct messages, and profile text, before it is stored. Text that matches a clearly objectionable-content rule is refused. The rules run within Doogo's server environment and do not send the text to an external moderation or AI provider.

New avatar, comment, and direct-message images are first stored in access-controlled private storage. They remain pending until an operator-scheduled batch runs ShieldGemma 2, an image-safety model developed by Google. ShieldGemma is third-party technology; it is not owned or developed by Doogo. The model is locally hosted on Doogo-controlled hardware and runs offline for this workflow, so user media is not sent to Google, Hugging Face, or another model provider. Its built-in checks cover sexually explicit, dangerous, and violence or gore imagery. Doogo also supplies fixed custom policies that screen for obvious hate and harassment imagery. Google has not published quality benchmarks for those custom policies, and no automated model covers every possible image-safety case.

Pending images have no server-issued viewing URL. The uploading device may keep its own local preview. Approved avatar and comment images become publicly available, and approved direct-message images become available only through recipient-authorized, time-limited links. Rejected images receive no viewing URL; an image-only comment or message displays Deleted, while a rejected avatar does not replace the last approved avatar. Automated screening can make errors and does not replace the in-app report and block controls.

Messaging

If you use messaging, we store the content of your messages (text and images) and shared events so we can deliver them and let you and the recipient access your conversation history. Messages are not end-to-end encrypted; they are stored on our systems and protected by the security measures described below. You can delete a message from your own view, though it may remain visible to the other participant. Approved images are served through temporary, time-limited links; pending and rejected images have no such link. When you share a link in a message, we may fetch it to generate a screened text preview, but we do not show the remote preview image or logo.

Doogo personnel do not routinely read direct messages. Human direct-message safety review occurs only for reports: authorized safety staff may review a reported direct message and its retained snapshot, and their access and resulting actions are audited. We retain each reported snapshot as safety evidence with live account references replaced by deletion-safe tombstones if an involved account is later deleted.

Personalization, Recommendations & Automated Profiling

We use your behavioral signals (such as the events you view, attend, bookmark, or dismiss) to rank and recommend events. We also use these signals — including events you mark as Interested or Attend, those you choose to see fewer of, and your searches — to identify and connect you with other people who share your interests. This personalization is a core function of the Service. Our recommendation engine runs on our own infrastructure. We also compute "interest tags" that describe events; those tags are generated from event text, not from your personal data.

We do not send your account data, direct messages, comments, profile data, or user uploads to an external AI provider. We do use externally hosted third-party AI providers to process public event information — for example to summarize and analyze event text and images, generate the interest tags that describe events, and create event imagery. That externally hosted processing involves only public event content and our own system event data. Separately, the locally hosted ShieldGemma workflow described above processes new user images on Doogo-controlled hardware without sending them to the model provider. We do not make decisions about you that produce legal or similarly significant effects through solely automated means.

Communications & Marketing

Transactional messages (such as email verification, password resets, and security notifications, which may include the IP address and time of the event) are part of the Service and cannot be turned off while you have an account.

Marketing and recommendation messages (announcements, promotions, event recommendations, and reminders) are sent by email and push notification according to your preferences. You can control these in your in-app notification preferences — by category and channel, including digest frequency and quiet hours (by default, 10:00 PM to 7:00 AM) — and you can unsubscribe from marketing email using the link in every such message. As required by the U.S. CAN-SPAM Act, our marketing emails include our postal mailing address.

Push delivery for recommendations, re-engagement nudges, announcements, and promotions is off by default. We send those categories by push only after you explicitly turn on that category's Push setting in the app. Granting the device's operating-system notification permission or registering a device does not, by itself, opt you into these marketing-like push categories.

Push notifications require a device push token delivered through Apple's and Google's push services; you can disable push notifications in your device settings at any time.

How We Share Information & Sub-Processors

We do not sell your personal information. We share it only as described here:

  • With service providers (sub-processors) that process data on our behalf under contract — listed below.
  • For safety and legal reasons — to enforce our Terms, respond to lawful requests, or protect the rights, safety, and property of Doogo, our users, or the public.
  • In a business transfer — in connection with a merger, acquisition, or sale of assets, subject to this Policy.
  • As aggregated or de-identified data that cannot reasonably identify you.

The sub-processors that may process your personal data are:

Sub-ProcessorPurposePersonal data involved
RenderCloud hosting, managed database and cacheAll Service data
Cloudflare R2Private and public object storageAvatars; comment and message images; temporary account-export archives containing requested account data; private support-feedback attachments; and restricted safety evidence
AmplitudeEligible signed-in public-web product analytics through Doogo's server-side ingest proxyDevice/session IDs, account user ID, truncated IP network, usage events
GoogleOptional Google Calendar sync for the dedicated Doogo-created calendarDedicated calendar ID, encrypted OAuth tokens, and the calendar entries we sync
Resend (and Postmark)Email deliveryRecipient email address and message content
Apple (APNs), Google (FCM), and ExpoPush-notification deliveryPush token, device info, notification content
SentryMobile crash and error reportingScrubbed diagnostic data; no account identity
GitHubPrivate engineering triage for support feedback opened by an authorized adminFeedback text, feedback ID, non-identifying release/debug context, internal admin link, and attachment summary
Grafana Cloud (Loki)Operational logging and metricsLogs that may include user IDs and IP addresses
IPLocateIP geolocation (when configured as our provider) for waitlist sign-ups and eligible signed-in analyticsIP address
Nominatim geocoding service (operator-configured, or the public OpenStreetMap Foundation service as fallback)Location search, autocomplete, reverse geocoding, and waitlist ZIP-locality resolutionLocation text, selected device coordinates, or the ZIP code you submit

We contractually require our sub-processors to provide the same or equivalent protection for user data described in this Policy, safeguard it, and use it only to provide services to us.

Location search uses OpenStreetMap data: © OpenStreetMap contributors, available under the Open Data Commons Open Database License (ODbL). Doogo sends user-originated location queries and waitlist ZIP-locality lookups to an operator-configured, permitted Nominatim service when one is configured. When no operator endpoint is configured, these lookups fall back to the public OpenStreetMap Nominatim service, rate-limited to its published usage policy, and the OpenStreetMap Foundation then processes the submitted query as described in its own privacy policy.

Separately, we use externally hosted third-party AI providers to process public event content (not your personal information). They are not listed above because they do not receive any of your personal data. The third-party ShieldGemma model is also not a sub-processor: Doogo runs the downloaded model locally, and its developer and distribution host do not receive user media. See Personalization, Recommendations & Automated Profiling.

International Data Transfers

The Service is operated from, and intended for users in, the United States. Your information is stored and processed in the United States.

Data Retention

We keep your account information for as long as your account is active. We retain other categories only as long as needed for the purposes described above or as required by law, including approximately:

  • product and usage analytics: up to 24 months;
  • security and audit logs: kept only as long as needed for security and to meet our legal obligations;
  • marketing campaign records: about 13 months;
  • audience and segment snapshots: 35 to 90 days;
  • username-change history: a 30-day reservation window;
  • support feedback records: retained after account deletion for product support, abuse-prevention, and engineering triage. We unlink the live account reference and remove analytics and notification device identifiers. We retain feedback text, private attachments, non-identifying diagnostic metadata, attachment metadata, update history, and private GitHub export audit hashes;
  • safety reports: when a comment, direct message, event, user, or avatar is reported, we keep the submitted reason and notes and any content or metadata snapshot needed to review the report and record our safety actions. If a reporter, content author, message sender, or reported account is deleted, we retain the evidence but remove its live account reference and replace any displayed identity with "Deleted user";
  • image-moderation storage: unattached image submissions expire through the existing upload cleanup. Approved private staging copies for avatars and comments are removed after verified public publication unless that exact pre-publication source was captured as restricted report evidence, while the canonical approved media remains available. Avatar roots captured by a report or report follow-up are likewise retained as restricted safety evidence. An approved direct-message image remains in access-controlled private storage for delivery to the intended participant. Attached rejected images are retained privately with the associated retained comment or direct message as safety evidence and never receive a user-facing URL. Operational failures are retried and never cause approval. After the bounded automatic retry limit, the unavailable submission remains pending with an operator-attention marker until an authorized operator investigates and explicitly requeues it or the user replaces it;
  • comments and direct messages, including associated text and media: retained indefinitely after account deletion for conversation and thread integrity, but marked deleted. Ordinary app responses show only a deleted placeholder and do not return the retained body, media, link preview, shared-event preview, or former identity;
  • waitlist and consent records: as long as needed for the purpose they were collected.

Transactional deletion replaces live account identity and revokes sign-in credentials before the request succeeds. It also removes live preferences, reactions, devices, calendar links, and analytics data. Retained text and media are immediately unavailable through ordinary app APIs. Those APIs omit the retained body and media and expose only a deleted-content state; ordinary app views render a deleted-user or deleted-content placeholder. Safety reports and support feedback remain available only to authorized staff with deleted identities anonymized. Media-moderation owner references are also anonymized, and pending avatar submissions are detached, when an account is deleted.

Durable, retryable cleanup jobs perform the external-storage work after that transaction commits. They delete account-data exports, avatars, unattached uploads, and other unretained media. Retained comment media is copied and verified in access-controlled private storage before its public object is deleted and custom-domain CDN caches are purged. Direct-message media remains in access-controlled private storage; its short-lived links expire and cannot be renewed. Failed copy, delete, or purge steps remain queued with backoff for another attempt. A cached copy may be served briefly while an asynchronous purge is pending, and copies saved independently by recipients remain outside our control. Some de-identified records required for security, audit, or legal purposes are retained for the periods above.

User data exports include non-binary support feedback records. They exclude attachment binaries, signed URLs, R2 object keys, generated GitHub issue URLs, and raw GitHub URLs.

Data Security

We protect your information with industry-standard measures, including encryption in transit (TLS) and at rest, hashing of passwords with Argon2id, and encryption of connected-calendar tokens with AES-256-GCM. On mobile, your sign-in credentials are kept in your device's secure storage, and you may enable biometric (Face ID or fingerprint) unlock — your biometric data stays on your device and is never sent to us. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

Privacy Rights and Choices

Wherever you live, you can:

  • Access / export — request a copy of your data. We prepare an export and notify you when it is ready to download.
  • Correct — edit your profile and account information in Settings.
  • Delete — delete your account and associated data at any time from Settings (see Data Retention for what deletion means).
  • Manage communications — set your notification preferences and unsubscribe from marketing email.
  • Limit location access — use device or browser settings to deny or revoke precise location permission.
  • Limit Analytics — use Settings to stop optional first-party analytics and eligible public-web Amplitude analytics as described in Analytics & Tracking.
  • Disconnect Google Calendar — remove the optional calendar integration from Settings.

To make a request, use your Settings page or email [email protected]. We may need to verify your identity before we act on a request. We respond to privacy requests within 45 days; where applicable law requires or permits a different response period, we will follow that law.

We do not currently sell personal information, share personal information for targeted advertising, or use personal information for targeted advertising. We also do not show ads. The Do Not Sell or Share setting records a preference we will honor if our practices change and if a privacy law that applies to us treats a new practice as a sale, sharing, or targeted advertising. If a privacy law that applies to us gives you additional rights, we will process your request as that law requires. We will not discriminate against you for exercising your privacy rights.

Children's Privacy

The Service is for adults 18 and older. We do not knowingly collect personal information from anyone under 18. If you believe a person under 18 has provided us with personal information, contact [email protected] and we will delete it.

Doogo aggregates event listings from public sources and may link to venue, organizer, or ticketing websites. We are not responsible for the content or privacy practices of those third parties; their own policies govern your interactions with them. We retain organization and publicly billed performer or presenter attribution as event content, but do not compile source contact fields.

Changes to This Policy

We may update this Policy from time to time. If we make material changes, we will notify you by posting a notice in the Service or by email. The "Effective date" at the top reflects when the current version of this Policy takes effect.

Contact Us

For questions or requests about this Policy or your personal information:

Doogo Research, Inc. Attn: Privacy 2451 Crystal Dr, 6th Floor Arlington, VA 22202, United States Email: [email protected]

The governing law for the Service is addressed in our Terms of Service.