Privacy Policy

How we collect and use your information

Effective date: September 16, 2026

Introduction & Who We Are

Doogo Research, Inc. ("Doogo," "we," "our," or "us") operates Doogo, a released service for discovering local events and forming community in real life in DC, Maryland, and Virginia. Doogo is available through our mobile application and the website at www.doogo.app (together, the "Service"). Doogo Research, Inc. is a Delaware corporation with its principal place of business at 2451 Crystal Dr, 6th Floor, Arlington, VA 22202, United States, and is the controller responsible for your personal information.

This Privacy Policy explains what information we collect, how we use and share it, how long we keep it, and the choices and rights you have. You are asked to accept this Policy when you create an account, and we may ask you to accept updated Terms and Privacy Policy versions after material changes. If you have questions, contact us at privacy@doogo.app.

Scope & Eligibility

The Service is intended only for users who are at least 18 years old. We do not knowingly collect personal information from anyone under 18. If we learn that we have collected information from a person under 18, we will delete that account and apply the same deletion, restricted-evidence, and tombstoned-content retention rules described in this Policy. Please do not use the Service if you are under 18.

Information We Collect

Account & Identity

  • Additional email addresses you verify for a membership (for example a university address). A verified additional address becomes part of your account, can be used to sign in, and is never shown to other members.
  • Email address, an optional password (stored only as an Argon2id hash — we never keep your plaintext password), display name, and username (your username forms part of your public profile address).
  • If you sign in with or connect Google or Apple, we receive and store the provider's stable account identifier, the email address and verification state the provider supplies, and any display name you choose to share. For Apple we also store the client identifier, private-relay forwarding state, and an encrypted refresh token used only to revoke Doogo's Apple authorization when you disconnect it, delete your account, or abandon an unfinished sign-up or connection. We do not store your Google sign-in token.
  • Date of birth, which we collect once to confirm you meet the 18+ requirement.
  • Phone number, if you choose to provide one. This is optional; we use it only as profile contact information and do not send you SMS text messages. Separately, you may select a contact destination for an invitation as described below; you control any SMS sent from your device.
  • If you connect your Google Calendar — a fully optional integration you choose to enable — we use Google's OAuth with an app-created-calendar permission, plus a read-only view of your calendar list that we use only to find that calendar again, to create and manage only the dedicated Doogo calendar used for the integration. We store encrypted access and refresh tokens, the dedicated calendar's identifier, and the calendar entries we sync to that calendar; we do not receive your Google email or profile for this feature. You can disconnect it at any time. If you connected under an older, broader calendar permission, we require you to reconnect before calendar sync continues.
  • Consent records showing your acceptance of our Terms and this Privacy Policy, including timestamps, versions, and the IP address and device/user-agent recorded at the time of acceptance.

Profile & Social Graph

  • Optional profile details: first/last name, gender, a short bio, an avatar image, your interests, and a default/home location.
  • Your social connections: friends, follows, pending friend/follow requests, and the members you block; the communities you join; and the group chats you belong to or are invited to, including your role and settings in each group.
  • Your privacy settings controlling who can see each part of your profile and activity (see What Other Members Can See).

Memberships

If you join a membership (for example a university or a gym), we store that membership, the types you choose, and, when the membership requires verification, the email address you verify. Memberships are private by default; you choose whether each one appears on your profile, with a per-membership visibility setting. Each membership automatically adds you to its members-only community and every type community, including types you do not choose or that are added later; other members can see what you post, and that membership's visibility setting controls whether you appear in their member lists.

People, Invitations & Private Organization

You can create an individual invitation or a shared link that several people can use, including in a messaging group. We store your chosen connection offer, self-chosen signature, optional inviter message, selected contact label and destination when applicable, and link creation, expiry, revocation and claim state. We do not match contact destinations against Doogo accounts or notify you when a person merely opens a link, signs up, or chooses not to connect. Your signature is something you choose to disclose; it is not a verified identity or permission to reveal other private profile details.

When you use the device contact picker, the app reads contacts on your device with your permission and sends Doogo only the contacts and destinations you select and confirm. We do not upload your whole address book, add contacts silently, or scan it for members. Limited device access is respected, and you can deny or revoke access in device settings and enter a destination yourself. The app does not write to your address book or read your SMS messages.

An inviter message is optional and visible to anyone with the link. A recipient can join without connecting or deliberately submit an offered friend or follow request, with an optional request note visible only to the request participants. The inviter must approve the request before a relationship is created; using a link or joining never connects people automatically. The direction of any follow is shown before submission and approval. The editable suggested request note is a convenience: it may be changed or removed before sending.

Your private People favorites, lists and notes (for example, where you met someone) sync between your devices and are visible only to you in ordinary product use. They are distinct from the inviter message and request note and are never included in invitations or shown to the person they describe. You may explicitly transfer this private organization to the approved account after reviewing who actually used the link; no contact destination, label or signature is transferred to their account. Removing a social connection does not by itself delete your saved private organization or make private profile fields visible. Blocking removes private entries for that pair and unblocking does not restore them.

Connection links expire 90 days after creation and can be revoked sooner. Individual links accept at most one account's request; shared links allow requests from different accounts, and each still requires approval. Revoking or expiring a link prevents new requests without undoing an approved connection or withdrawing an existing request. You can also remove the connection offer while leaving a join-only invitation.

If an invitation mentions an event, each recipient's access is checked independently. An invitation does not grant membership or event access, and unavailable event details are withheld. The link continues to work for its remaining purpose when event context is unavailable.

You can report an abusive invitation without creating an account. We collect the reason and details you submit and an encrypted, limited copy of the signature, inviter message, offer and necessary internal review references. The report does not copy the secret link, contact destination, private labels, private organization, other requesters or event details. Only authorized safety staff can access this evidence, and their access and actions are audited. Reporter identity, reporting activity and moderation notes are never shared with the inviter through invitation history, notifications or exports.

User-Generated Content

  • Event comments and community posts and replies, any images you attach, and likes on them.
  • Reactions and plans. Your reactions to events (attending / interested / not interested), the plans you make to go to events with other members, and, after an event, whether you confirm that you attended.
  • Messages. Direct messages you send and receive, including text, images, and shared events.
  • Group chats. Groups you create or join: the group's name and image, its members and invitations, and the messages, images, reactions, replies, shared events, and read and mute state in it.
  • Reports. Content or members you report, with the reason and notes you give.
  • Safety-processing records. For new avatar, comment, community, direct-message, group, and group-message images, we keep the moderation status and the policy, model, decision, retry, and audit metadata needed to apply and review our safety controls. We do not create a User Content record for text that is refused before a write.
  • Support feedback. If you submit support feedback, we collect the message text, private attachments you choose to include, attachment metadata, app and route context, diagnostic device metadata, analytics device IDs, notification device IDs, and private GitHub triage records created by admins. During admin triage, admins may open a private GitHub issue URL containing feedback text, which may itself contain personal information you entered, plus the feedback ID, non-identifying release and debugging context, an internal admin link, and an attachment summary. Opening that URL sends those fields outside Doogo to GitHub and may place them in browser history or proxy logs before the issue is submitted. It does not include reporter or account IDs, analytics or notification device IDs, device names or models, or attachment filenames. It does not include attachment files, signed URLs, or R2 object keys.

Usage & Behavioral

  • How you interact with the Service: events you view, open, bookmark, or mark as attending; feed impressions and how long cards are shown; video watch progress; your searches — including the raw search text and filters you apply (such as location and date) in our first-party product analytics and recommendation systems; comment, reaction, and share activity; the communities and groups you join or leave; and the members you share events with. Raw search text is not sent to Amplitude.

Device & Technical

  • IP address, browser/user-agent and device information (model, operating system, app version, language, time zone), and screen/viewport size.
  • Authentication cookies and tokens, plus the IP address and device details associated with each sign-in session.
  • Security and audit logs. We keep a log of important account and security events — such as sign-ins, registration, password resets, profile changes, data exports, and account deletion — including the action, the full IP address, and the user-agent. We use these records to operate the Service securely, detect and investigate abuse, and meet our legal obligations.
  • On mobile: a push-notification token, a randomly generated analytics identifier, and the app's version, runtime, and platform, which the app sends to Expo's update service to check for over-the-air updates.

Location

  • With your permission, your device or browser's location to show you nearby events. We ask for this only when you use a "near me" feature, and you can decline or turn it off at any time in your device or browser settings. If you choose your current location as your home base, we save that position with it.
  • An approximate location (country, region, city, and approximate coordinates and postal code) derived from your IP address — see Analytics & Tracking.
  • The default/home location you enter for distance-based recommendations. For a street address picked from Google Places, we retain the selected formatted street address and the place identifier while that selection remains your home base, and temporarily cache its coordinates so we can measure distance. Older app versions may retain the exact location text you entered together with the Google place identifier and temporary coordinates. Your saved address remains private to you and is included in an account-data export.

Device Calendar

With your permission, the mobile app lists the calendars on your device to find or create a dedicated Doogo calendar, and adds, updates, and removes entries for your plans in it. To keep those entries in sync the app reads calendar entries on your device only within the time windows of your plans and uses only the entries Doogo created; it does not upload your other calendar data. You can revoke calendar access in your device settings at any time.

Home-Screen Widgets and Shortcuts

If you add a Doogo widget to your device's home screen or use the app's shortcuts, the title and time of your next plan are shown there, outside the app. That content is drawn on your device from data the app already holds and is not shared with anyone else.

Data Minimization & Sensitive Information

We collect only the information reasonably necessary to provide and improve the Service. We do not require special categories of "sensitive" personal information to use the Service, and we do not sell it or use it for targeted advertising. One potentially sensitive category we may process is precise location, from two user-directed sources:

  • Your device or browser geolocation, only with your permission, to show nearby events or set the home base you ask us to set from it. You can turn this access off at any time in your device or browser settings.
  • Coordinates Google returns for a place you deliberately select as your home base. This place lookup does not access your device location or require geolocation permission. We temporarily cache those coordinates as described above so we can measure distance.

The memberships you choose to add can themselves reveal sensitive information (for example a religious affiliation). They are optional and user-supplied, private by default, never sold, and not used for advertising.

You can replace or clear either kind of saved home base at any time.

The communities you choose to join can also reveal information about you (for example an identity-based community). Joining is optional, and your membership is visible only to other members of that community.

How We Collect Information

  • Directly from you — when you register, build your profile, post content, message, join communities or group chats, make plans, invite others, search, or contact us.
  • Automatically — through your use of the Service (usage, device, cookies, and approximate location).
  • From third parties — from Google or Apple when you use that provider to sign in or connect an account, from Google when you connect your Google Calendar, from Google Places when you deliberately select a home base, and event details from the public event sources we aggregate.

For aggregated event listings, we do not retain structured public-source contact names, email addresses, or phone numbers. Our ingestion boundary removes those fields and redacts obvious email and North American (NANP-formatted) phone identifiers from harvested event text before it enters our event cache, review queue, or repository.

Cookies, Local Storage & Similar Technologies

We use a small number of first-party cookies and browser-storage keys:

  • access_token and refresh_token — secure, HttpOnly cookies (not readable by JavaScript) that keep you signed in.
  • has_session — a non-sensitive, JavaScript-readable cookie indicating whether you have an active session.
  • doogo_auth_intent — a JavaScript-readable counter used to order sign-in and sign-out attempts across browser tabs.
  • doogo_auth_credential_epoch — a JavaScript-readable counter used to keep refresh requests tied to the browser's currently active sign-in session.
  • doogo_browser_auth_context and doogo_social_session_provisional — secure, HttpOnly values used to reject stale browser auth changes and to finish social sign-in only after the initiating page confirms it is still current.
  • Temporary browser session storage for an invitation you deliberately open, so you can finish sign-in and return to review it. On mobile this handoff uses device-protected secure storage; signing out clears it, except when you explicitly choose the account-switch continuation and confirm the account before submitting. The secret link does not enter analytics or navigation history. Anonymous report protection uses a scoped session identifier and short-lived deduplication records to limit repeated submissions.
  • Browser local storage for cached public configuration and, after an eligible user signs in, product-analytics device/session state.
  • Our analytics provider (Amplitude) sets its own device/session identifiers in browser storage only for eligible signed-in product analytics.

You can clear cookies and local storage in your browser settings; doing so may sign you out or reset preferences. We do not use third-party advertising cookies.

Analytics & Tracking

Signed-in first-party product analytics. Product analytics do not initialize before authentication. They start only after you sign in, the Service confirms that you accepted the exact current Terms and Privacy Policy versions, your analytics preference loads successfully, and Limit Analytics is off. We record search history (including raw search text), product interactions, an actor-scoped analytics device identifier, and app/session activity to improve the Service and personalize recommendations. Account-linked product analytics are retained for up to 24 months unless you delete your account sooner. Public pages, registration, stale-policy screens, preference-loading failures, logout, and account deletion do not start an anonymous product-analytics session. Before storing an analytics IP address, for IPv4 we zero the last octet (a /24 network), and for IPv6 we keep only the first 64 bits (a /64 network), after any configured IP-geolocation provider derives an approximate location. We do not record street-level location from an IP address.

Amplitude (web product analytics). For eligible signed-in use of the public website, we use Amplitude to understand an allowlisted set of feature-usage events and key funnels. The browser sends data to our authenticated first-party ingest endpoint; only the server holds the Amplitude project key. We send a random device/session identifier, your opaque internal account user ID, route names, approved event identifiers, and platform context. We do not send Amplitude raw search text, passwords, tokens, email, name, phone number, or free-form profile text. We do not associate pre-authentication activity with your account. The mobile app has no direct Amplitude transport, key, or project; its optional product analytics use only Doogo's authenticated first-party tracker and are revalidated by our server.

Sentry (mobile error reporting). Our mobile app uses Sentry to capture crashes and errors with scrubbed diagnostic context. Sentry receives no account identity: no internal user ID, public user reference, username, email, or name.

Limit Analytics. If you turn on Limit Analytics in Settings, we stop optional first-party recommendation/usage analytics and, on the public website, eligible Amplitude analytics. We discard pending local analytics events and remove local analytics identifiers. It does not disable security/audit logs, crash and error protection, operational logs, abuse prevention, legal records, or transactional records that we need to provide, secure, maintain, and administer the Service.

How We Use Your Information

We use your information to:

  • provide, secure, and maintain the Service and your account;
  • personalize your event recommendations (see Personalization);
  • enable the social, community, group, and messaging features you choose to use, and introduce you to people and communities that match your interests;
  • send transactional and, where permitted, marketing messages;
  • keep the Service safe — preventing fraud and abuse, enforcing our policies, and reviewing reported content;
  • analyze and improve the Service; and
  • comply with our legal obligations.

User-Content Safety Screening

Doogo uses deterministic first-party safety rules to screen supported user-authored text, including comments, community posts, direct messages, group-chat messages, group names, and profile text, before it is stored. Text that matches a clearly objectionable-content rule is refused. The rules run within Doogo's server environment and do not send the text to an external moderation or AI provider.

New avatar, comment, community, direct-message, group, and group-message images are first stored in access-controlled private storage. They remain pending until an operator-scheduled batch runs ShieldGemma 2, an image-safety model developed by Google. ShieldGemma is third-party technology; it is not owned or developed by Doogo. The model is locally hosted on Doogo-controlled hardware and runs offline for this workflow, so user media is not sent to Google, Hugging Face, or another model provider. Its built-in checks cover sexually explicit, dangerous, and violence or gore imagery. Doogo also supplies fixed custom policies that screen for obvious hate and harassment imagery. Google has not published quality benchmarks for those custom policies, and no automated model covers every possible image-safety case.

Pending images have no server-issued viewing URL. The uploading device may keep its own local preview. Approved avatar and comment images become publicly available, approved direct-message images become available only through recipient-authorized, time-limited links, and approved group images become available only to that group's members through time-limited links. Rejected images receive no viewing URL; an image-only comment or message displays Deleted, while a rejected avatar does not replace the last approved avatar. Automated screening can make errors and does not replace the in-app report and block controls.

Messaging and Group Chats

If you use messaging, we store the content of your messages (text and images) and shared events so we can deliver them and let you and the recipient access your conversation history. Messages are not end-to-end encrypted; they are stored on our systems and protected by the security measures described below. You can delete a message from your own view, though it may remain visible to the other participant. Approved images are served through temporary, time-limited links; pending and rejected images have no such link. When you share a link in a message, we may fetch it to generate a screened text preview, but we do not show the remote preview image or logo.

Doogo personnel do not routinely read direct messages. Human direct-message safety review occurs only for reports: authorized safety staff may review a reported direct message and its retained snapshot, and their access and resulting actions are audited. We retain each reported snapshot as safety evidence with live account references replaced by deletion-safe tombstones if an involved account is later deleted.

Group chats work the same way, with these differences. Every member of a group can see its name, image, member list, messages, images, reactions, and shared events. If the group's history setting allows it, people who join later can see earlier messages. A group's owner and managers can invite, add, and remove members, change roles and settings, and transfer ownership; if an owner deletes their account, ownership passes to another member. Doogo may remove messages, lock a group, or retire it for safety reasons. When you leave a group, or delete your account, the messages and images you already sent remain visible to its members (after account deletion under a "Deleted user" label). Blocking a member prevents new invitations between you but does not hide content in a group you both already belong to. Group content is not end-to-end encrypted.

Communities

Except for membership communities described under Memberships, communities are shared spaces built around a place, interest, or identity. When you join one, its other members can see that you belong (your username, and your display name and avatar according to your privacy settings) and everything you post there. People who are not members see the community's description and activity counts, not its posts or member list. We keep a record of when you join or leave a community for abuse prevention; it is not shown to anyone and is removed when you delete your account.

Membership communities are visible only to eligible membership holders. Their member lists use the membership's visibility setting described above. You leave these communities by leaving the membership, not separately. Your existing posts stay attributed to you and visible to eligible co-members after you leave.

Doogo Host. Doogo operates an official account named Doogo Host in communities. Doogo staff may post and reply as Doogo Host using what is visible in that community, including the thread, members' usernames, and profile fields members have set to public. Doogo Host content may also be produced by software, including AI models that run on Doogo-controlled infrastructure; we do not send community content to an external AI provider to produce it.

What Other Members Can See

  • Your username and public profile address are visible to every signed-in member.
  • Your display name, avatar, bio, gender, reaction counts, and the lists of events you have reacted to are shown according to the privacy level you choose for each in Settings (public, followers, friends, or private). Your friend, follower, and following counts are always public.
  • Subject to those settings, members you are connected with may see the events you mark as Interested or Attending and the plans you make to go to them (in their feed, their plans list, and on your profile), whether you confirmed attending an event after it ended, the members you have in common, and your recent comments.
  • Aggregate counts, such as how many people are going to an event, never identify you.
  • Members of a community or group chat you belong to can see what you post there. They can also see your membership, except that membership communities use the per-membership visibility setting described above for their member lists.

Personalization, Recommendations & Automated Profiling

We use your behavioral signals (such as the events you view, attend, bookmark, or dismiss) to rank and recommend events. We also use these signals — including events you mark as Interested or Attend, those you choose to see fewer of, and your searches — to identify and connect you with other people who share your interests. This personalization is a core function of the Service. Our recommendation engine runs on our own infrastructure. To personalize recommendations and introduce you to people and communities that match your interests, we also process the profile text you write (your bio and interest description), your interests, and your gender with software that runs on our own infrastructure, including an open-source text model that converts that text into a numeric representation used only for matching. That text is not sent to the model's developer or to any external AI provider. We also infer interests from your activity; you can review and dismiss them on your profile. Separately, we compute "interest tags" that describe events; those tags are generated from event text, not from your personal data.

We do not send your account data, direct messages, comments, profile data, or user uploads to an external AI provider. We do use externally hosted third-party AI providers to process public event information — for example to summarize and analyze event text and images, generate the interest tags that describe events, and create event imagery. That externally hosted processing involves only public event content and our own system event data. Separately, the locally hosted ShieldGemma workflow described above processes new user images on Doogo-controlled hardware without sending them to the model provider, and community content used for Doogo Host is handled as described under Communities. We do not make decisions about you that produce legal or similarly significant effects through solely automated means.

Communications & Marketing

Transactional messages (such as email verification, password resets, and security notifications, which may include the IP address and time of the event) are part of the Service and cannot be turned off while you have an account.

Marketing and recommendation messages (announcements, promotions, event recommendations, and reminders) are sent by email and push notification according to your preferences. You can control these in your in-app notification preferences — by category and channel, including digest frequency and quiet hours (by default, 10:00 PM to 7:00 AM) — and you can unsubscribe from marketing email using the link in every such message. As required by the U.S. CAN-SPAM Act, our marketing emails include our postal mailing address.

Weekly membership digest. If you hold memberships and keep the digest enabled, we send one weekly email with upcoming events from your memberships. You can turn it off in Settings, Notifications, or with the unsubscribe link in every such message.

Push delivery for recommendations, re-engagement nudges, announcements, and promotions is off by default. We send those categories by push only after you explicitly turn on that category's Push setting in the app. Granting the device's operating-system notification permission or registering a device does not, by itself, opt you into these marketing-like push categories.

Push notifications require a device push token delivered through Apple's and Google's push services; you can disable push notifications in your device settings at any time.

Connection invitations. Email invitations are sent only after an inviter reviews and confirms the selected destinations; our configured email provider processes the destination and invitation content. Invitation emails include an opt-out, use no open or link tracking, and do not tell the inviter whether the email was delivered, suppressed, opened or reported. An opt-out is honored even if the source invitation later expires or is removed.

For a device message, you choose whether to send from the SMS composer or the system share sheet. Doogo does not send SMS through a server provider or treat the composer's result as proof of delivery. The app you choose and any messaging provider handle what you send under their own terms. A QR code or image of an invitation can be used by anyone who receives it, just like the original link. Review the displayed signature before exporting; a shared copy may be forwarded. Generated cards exclude contact labels and destinations, private organization, recipient request notes and event details. App-controlled temporary image files are cleared after sharing; a recipient's saved copy cannot be recalled, but the live link still enforces its expiry, revocation and current offer.

How We Share Information & Sub-Processors

We do not sell your personal information. We share it only as described here:

  • With service providers (sub-processors) that process data on our behalf under contract — listed below.
  • For safety and legal reasons — to enforce our Terms, respond to lawful requests, or protect the rights, safety, and property of Doogo, our users, or the public.
  • In a business transfer — in connection with a merger, acquisition, or sale of assets, subject to this Policy.
  • As aggregated or de-identified data that cannot reasonably identify you.
  • With other members, as described in What Other Members Can See.
  • Publicly, on your public profile page (see Public profile pages).

The service providers and other third-party recipients that may process your personal data are:

Sub-ProcessorPurposePersonal data involved
RenderCloud hosting, managed database and cacheAll Service data
Cloudflare R2Private and public object storageAvatars; comment, community, message, and group images; temporary account-export archives containing requested account data; private support-feedback attachments; and restricted safety evidence
AmplitudeEligible signed-in public-web product analytics through Doogo's server-side ingest proxyDevice/session IDs, account user ID, truncated IP network, usage events
GoogleAccount authentication; optional Google Calendar sync for the dedicated Doogo-created calendarFor authentication: stable account identifier, email and verification state, and display name; for Calendar: dedicated calendar ID, encrypted OAuth tokens, and the calendar entries we sync
Resend (and Postmark)Email deliveryRecipient email address and message content
AppleAccount authentication and Apple authorization revocation; APNs push-notification deliveryStable account identifier, email and verification state, display name, client identifier, relay state, encrypted revocation credential; push token, device info, and notification content
Google (FCM) and ExpoPush-notification delivery; over-the-air app updates (Expo)Push token, device info, notification content; app version, runtime, and platform for update checks
SentryMobile crash and error reportingScrubbed diagnostic data; no account identity
GitHubPrivate engineering triage for support feedback opened by an authorized adminFeedback text, feedback ID, non-identifying release/debug context, internal admin link, and attachment summary
Grafana Cloud (Loki)Operational logging and metricsLogs that may include user IDs and IP addresses
IPLocateIP geolocation (when configured as our provider) for eligible signed-in analyticsIP address
Nominatim geocoding service (operator-configured, or the public OpenStreetMap Foundation endpoint for throttled user-triggered reverse lookup only)Operator service: web location search and reverse geocoding; public endpoint: user-triggered reverse geocoding onlyLocation text or selected device coordinates
Google PlacesAddress autocomplete and compatibility location resolution for the home base you set in the mobile appThe address or location text you type and the place you pick; never your device coordinates

Where a provider acts as our contracted sub-processor, we require it to provide the same or equivalent protection for user data described in this Policy, safeguard it, and use it only to provide services to us. The public OpenStreetMap Foundation Nominatim endpoint is a public third-party recipient governed by its published usage and privacy policies, not a contracted Doogo sub-processor.

Location search uses OpenStreetMap data: © OpenStreetMap contributors, available under the Open Data Commons Open Database License (ODbL). Doogo sends web location queries, autocomplete traffic, and automated geocoding only to an operator-configured, approved Nominatim service. Those features are unavailable when no approved endpoint is configured. A user-triggered reverse lookup for “use current location” may instead use the public OpenStreetMap Foundation Nominatim endpoint. Public reverse lookups are shared-cache-backed, globally throttled to no more than one upstream request about every 1.1 seconds, and never used for autocomplete or background work.

In the mobile app, street-address suggestions you see while typing a home base come from Google Places. We send the text you type and, when you pick a suggestion, the identifier of the place you picked; Google then processes those as described in the Google Privacy Policy and under the Google Maps Platform Terms. We retain the selected formatted street address so you can see the home base you set. Older compatible app versions may send a city-or-address query to Google; for those versions we show and retain only the exact text you entered, not a Google-formatted display name. We do not send your device coordinates to Google. If you instead choose “use current location”, your device position goes to the Nominatim service described above and not to Google. Map coordinates we obtain from Google for a place you picked become due for refresh after 28 days. We remove expired content for dormant sessions then. For an active signed-in session, we first try to replace that content in the background beginning on day 27; login and session renewal also refresh it when it is expired. We clear expired active-session content after its required refresh attempt rather than purging it from the middle of an active session before that attempt. The place identifier remains until you change that home base or delete your account. We keep these coordinates in a non-durable server cache that is omitted from our portable database backups and may be emptied during database recovery or failover; the retained place identifier lets us refresh the cache when needed.

Public profile pages

Each member has a public profile page at www.doogo.app/u/<username> that anyone can view without signing in and that search engines may index. It shows your username and your friend, follower, and following counts and, only for the fields you have set to public, your display name, avatar, and bio, and it produces a link preview (title, description, and image) for that page. A username you change away from keeps pointing to your profile for 30 days.

Separately, we use externally hosted third-party AI providers to process public event content (not your personal information). They are not listed above because they do not receive any of your personal data. The third-party ShieldGemma model is also not a sub-processor: Doogo runs the downloaded model locally, and its developer and distribution host do not receive user media. See Personalization, Recommendations & Automated Profiling.

International Data Transfers

The Service is operated from, and intended for users in, the United States. Your information is stored and processed in the United States.

Data Retention

We keep your account information for as long as your account is active. We retain other categories only as long as needed for the purposes described above or as required by law, including approximately:

  • product and usage analytics: up to 24 months;
  • security and audit logs: while your account exists; when you delete your account we remove the IP address and user-agent from those records and keep the de-identified event;
  • marketing campaign records: about 13 months;
  • audience and segment snapshots: 35 to 90 days;
  • username-change history: a 30-day reservation window;
  • connected Google or Apple identity details: while connected to your account; when you disconnect or delete the account, the identity is removed. An encrypted Apple revocation credential may remain in a restricted retry queue until revocation succeeds or an operator resolves a repeated failure. The credential is then cleared, and completed cleanup metadata is retained for 30 days;
  • a pseudonymous key derived from an email address may remain for up to seven days to prevent an in-progress social sign-up from recreating an account after deletion. We do not store the email address in this fence record, and we remove the key when its safety window ends and no live sign-up references it;
  • support feedback records: retained after account deletion for product support, abuse-prevention, and engineering triage. We unlink the live account reference and remove analytics and notification device identifiers. We retain feedback text, private attachments, non-identifying diagnostic metadata, attachment metadata, update history, and private GitHub export audit hashes;
  • safety reports: when a comment, direct message, event, user, or avatar is reported, we keep the submitted reason and notes and any content or metadata snapshot needed to review the report and record our safety actions. If a reporter, content author, message sender, or reported account is deleted, we retain the evidence but remove its live account reference and replace any displayed identity with "Deleted user";
  • image-moderation storage: unattached image submissions expire through the existing upload cleanup. Approved private staging copies for avatars and comments are removed after verified public publication unless that exact pre-publication source was captured as restricted report evidence, while the canonical approved media remains available. Avatar roots captured by a report or report follow-up are likewise retained as restricted safety evidence. An approved direct-message image remains in access-controlled private storage for delivery to the intended participant. Attached rejected images are retained privately with the associated retained comment or direct message as safety evidence and never receive a user-facing URL. Operational failures are retried and never cause approval. After the bounded automatic retry limit, the unavailable submission remains pending with an operator-attention marker until an authorized operator investigates and explicitly requeues it or the user replaces it;
  • comments and direct messages (and community posts), including associated text and media: retained indefinitely after account deletion for conversation and thread integrity, but marked deleted. Ordinary app responses show only a deleted placeholder and do not return the retained body, media, link preview, shared-event preview, or former identity;
  • community membership: until you leave or delete your account; for membership communities, leaving the membership leaves its communities; the record that you joined or left: until you delete your account;
  • group chats: messages and images you sent stay with the group after you leave and, after account deletion, remain visible to its members under "Deleted user"; your live membership, invitations, and read/mute state are removed;
  • plans and attendance confirmations: until you change them or delete your account;
  • legacy registration-access records collected before open registration: retained for security and historical reporting while associated with your account, then de-identified when you delete it; email opt-out entries are kept so we honour them;
  • membership records: until you leave the membership or delete your account; a record that you joined or left is kept until you delete your account for abuse prevention and analytics;
  • membership verification codes and attempts: 30 days;
  • membership digest send records: 90 days;
  • consent records: as long as needed for the purpose they were collected, de-identified after account deletion.

People invitation and private-data lifetimes

These are separate limits; the end of one does not extend another:

  • Invitation source data — the selected contact label and destination, signature, inviter message, event reference, secret link material, batch payload and private invitation metadata are inaccessible and removed no later than 120 days after creation, or earlier on owner account deletion. New requests stop at the link's 90-day expiry or earlier revocation. Expiry is enforced even when scheduled cleanup is delayed.
  • Pending invitation requests and notes survive an expired, revoked or deleted source invitation until a decision, withdrawal, block or participant account deletion. They are not automatically declined at 90 or 120 days.
  • Terminal invitation request notes are removed after 30 days, or sooner on participant account deletion. A minimal record of the participants, direction, state, time and duplicate-prevention reference remains until a participant deletes their account; retrying an old request cannot recreate a relationship that has since been removed.
  • Private account-target favorites, lists and notes remain until you remove them or the owner or target account is deleted; blocking removes private entries for that pair. An explicitly transferred note has this same lifetime. Moving an individual invitation's metadata removes its source copy immediately; copying a shared invitation's metadata leaves its source copy only until the original source cutoff. Contact destinations, labels and signatures do not become permanent account metadata.
  • Minimal replay-protection records prevent an ambiguous retry from creating another invitation or restoring deleted notes. After invitation batches are purged, only your account reference and batch identifier remain until you delete your account. A private-operation receipt retains a protected body digest and navigation references for at most 24 hours or until earlier deletion of the referenced data; afterward only your account reference, operation identifier and tombstone time remain until account deletion.
  • Invitation email payloads are scrubbed after a terminal outcome or the sending window ends, and source-derived personal text is never kept beyond the source's 120-day limit. Restricted operational records may remain to reconcile an uncertain delivery. Global address-based unsubscribe suppression persists beyond invitation source retention until the existing valid removal process allows removal, so we continue to honor the recipient's choice.
  • Invitation reports, encrypted evidence and per-report actions expire 180 days after receipt, including unresolved reports. The deadline does not restart when an action is taken, and evidence is unavailable after it even if cleanup is delayed. Source cleanup at 120 days or account deletion removes live navigation links without deleting unexpired restricted evidence. This finite invitation-report policy does not change the retention rules for other report types. Anonymous report deduplication lasts at most 24 hours; rate-limit records expire with their short abuse-prevention window.

Transactional deletion replaces live account identity, removes connected social identities, and revokes Doogo sign-in credentials before the request succeeds. Apple authorization revocation is queued for durable retry. Deletion also removes live preferences, reactions, devices, calendar links, analytics data, your community memberships, your live group memberships and invitations, and your plans and attendance confirmations, and unlinks your identity from delivered group content. Retained text and media are immediately unavailable through ordinary app APIs. Those APIs omit the retained body and media and expose only a deleted-content state; ordinary app views render a deleted-user or deleted-content placeholder. Safety reports and support feedback remain available only to authorized staff with deleted identities anonymized. Media-moderation owner references are also anonymized, and pending avatar submissions are detached, when an account is deleted.

Deleting your account also revokes and removes owned connection invitations, selected contacts, pending delivery authority, private People organization and owner-linked replay records. Pending requests are closed before personal request history and notes are erased. Deleting a claimant never makes an individual link available for a second request. We do not search contact destinations to infer another member's identity during account deletion.

Durable, retryable cleanup jobs perform the external-storage work after that transaction commits. They delete account-data exports, avatars, unattached uploads, and other unretained media. Retained comment media is copied and verified in access-controlled private storage before its public object is deleted and custom-domain CDN caches are purged. Direct-message media remains in access-controlled private storage; its short-lived links expire and cannot be renewed. Failed copy, delete, or purge steps remain queued with backoff for another attempt. A cached copy may be served briefly while an asynchronous purge is pending, and copies saved independently by recipients remain outside our control. Some de-identified records required for security, audit, or legal purposes are retained for the periods above.

User data exports include non-binary support feedback records. They exclude attachment binaries, signed URLs, R2 object keys, generated GitHub issue URLs, and raw GitHub URLs. They include your communities, group memberships and invitations, and the messages you sent in group chats, but not other members' messages. For a Google Places home base, the export includes the durable place identifier, the owner-visible saved address, and whether that label was selected from Google or authored by you. It excludes temporary coordinates and all other Google presentation content. Coordinates are used server-side to measure distance, omitted from our portable database backups, and deleted no later than the provider's 30-day caching deadline. Google Maps Platform terms restrict us from exporting other Google Maps Content into a portable downstream copy.

People exports include your own private organization, authorized invitation source history before its cutoff, and explicit request history and notes where you are a participant. They exclude other people's private organization, hidden profile details, secret link material, email delivery or suppression results, opens, signup activity, private dismissals, reporter information and moderation evidence. Export access applies the same privacy and retention limits as the app; exporting does not revive expired content.

Data Security

We protect your information with industry-standard measures, including encryption in transit (TLS) and at rest, hashing of passwords with Argon2id, and encryption of connected-calendar tokens with AES-256-GCM. On mobile, your sign-in credentials are kept in your device's secure storage, and you may enable biometric (Face ID or fingerprint) unlock — your biometric data stays on your device and is never sent to us. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

Privacy Rights and Choices

Wherever you live, you can:

  • Access / export — request a copy of your data. We prepare an export and notify you when it is ready to download.
  • Correct — edit your profile and account information in Settings.
  • Delete — delete your account and associated data at any time from Settings (see Data Retention for what deletion means).
  • Manage communications — set your notification preferences and unsubscribe from marketing email.
  • Manage People invitations and private organization — revoke links or remove their connection offer, withdraw a request, decline an incoming request, and remove your own favorites, lists or notes. Revoke device contact permission at any time; you can continue with manual entry.
  • Limit location access — use device or browser settings to deny or revoke precise location permission, and replace or clear a saved home base at any time in the Service.
  • Limit Analytics — use Settings to stop optional first-party analytics and eligible public-web Amplitude analytics as described in Analytics & Tracking.
  • Disconnect Google Calendar — remove the optional calendar integration from Settings.
  • Manage sign-in providers — connect or disconnect Google and Apple in Settings, provided your account retains another usable sign-in method.
  • Control who sees your activity — choose a privacy level for each profile field and for your reactions and plans in Settings.
  • Leave a community or group chat: at any time, from within it, except that membership communities are left by leaving the membership.

To make a request, use your Settings page or email privacy@doogo.app. We may need to verify your identity before we act on a request. We respond to privacy requests within 45 days; where applicable law requires or permits a different response period, we will follow that law.

We do not currently sell personal information, share personal information for targeted advertising, or use personal information for targeted advertising. We also do not show ads. The Do Not Sell or Share setting records a preference we will honor if our practices change and if a privacy law that applies to us treats a new practice as a sale, sharing, or targeted advertising. If a privacy law that applies to us gives you additional rights, we will process your request as that law requires. We will not discriminate against you for exercising your privacy rights.

Children's Privacy

The Service is for adults 18 and older. We do not knowingly collect personal information from anyone under 18. If you believe a person under 18 has provided us with personal information, contact privacy@doogo.app and we will delete it.

Doogo aggregates event listings from public sources and may link to venue, organizer, or ticketing websites. We are not responsible for the content or privacy practices of those third parties; their own policies govern your interactions with them. We retain organization and publicly billed performer or presenter attribution as event content, but do not compile source contact fields.

Changes to This Policy

We may update this Policy from time to time. If we make material changes, we will notify you by posting a notice in the Service or by email. The "Effective date" at the top reflects when the current version of this Policy takes effect.

Contact Us

For questions or requests about this Policy or your personal information:

Doogo Research, Inc. Attn: Privacy 2451 Crystal Dr, 6th Floor Arlington, VA 22202, United States Email: privacy@doogo.app

The governing law for the Service is addressed in our Terms of Service.