Privacy Policy
Effective date: August 18, 2026
Hey Poppy is a tool for hosts to create a signup link, collect RSVPs, and keep a guest
list that remembers people for next time. This policy explains what information Hey Poppy handles,
why, and the choices you have. We do not sell personal information.
Plain-language summary: hosts use Hey Poppy to collect the details their guests
provide and to keep their own address book. We store that data with reputable providers to run
the app, we never sell it, and you can ask us to delete it.
Who this covers
- Hosts — people who create an account and build signup links or contact lists.
- Guests — people who fill in a host's signup form. Guests don't need an account;
their information is collected on behalf of the host who invited them.
Information we handle
- Host account: the email address you sign up with (directly or through Google
or Apple), and, if you choose, a phone number you save to get signup notifications or to see
events you're attending.
- Event and guest details: the names, phone numbers, email addresses, and answers
that guests enter on a host's signup form, plus any notes or tags the host adds.
- Your address book ("People"): Hey Poppy keeps a host's contacts across events so
they can invite people again. This can include facts derived from guests' own answers (for example,
a dietary need or drink preference) to help the host remember them. Some answers, including dietary
needs, may reveal sensitive personal information depending on what a guest chooses to share. This
information persists beyond a single event.
- Usage analytics: limited signals about which features are used
(for example, how often events are published or the voice option is used), to improve the product.
Some usage data may be associated with a host account when the host is signed in. These events do
not include guests' names, contact details, or answers.
- Technical data: information kept in your browser to make the app work (such as
drafts and your sign-in session) and standard server logs.
How we use it
- To run the signup, roster, messaging, and address-book features hosts use.
- To send confirmations, reminders, or notifications that a host or guest turns on.
- To keep the service secure and to improve it (using the limited usage analytics above).
Payments
Hey Poppy does not process payments. When a host adds a cost, Hey Poppy simply displays the
amount and any Venmo or Zelle handle the host chose, so guests can pay the host directly. No card,
bank, or payment-account details ever pass through Hey Poppy.
Service providers we share with
We use trusted companies to run Hey Poppy. They only handle data as needed to provide their service:
- Supabase — database hosting (where events, contacts, and accounts are stored).
- Vercel — application hosting and delivery.
- Google — sign-in, if you choose "Sign in with Google."
- Apple — sign-in, if you choose "Sign in with Apple."
- Anthropic — powers optional AI features. When you choose to use an AI feature,
such as "describe your event" or a guest summary, the text needed to provide that feature is sent
to Anthropic. Anthropic does not use API inputs or outputs to train its models by default.
- Twilio — text-message delivery, where and when SMS features are enabled.
We do not sell personal information, and we do not share it for advertising.
AI features
AI features are optional. If an AI feature uses guest information, such as names, answers, dietary
needs, drink preferences, or host notes, Hey Poppy will make that clear in the feature flow so the host
understands that the information needed for the summary or draft will be sent to Anthropic.
How long we keep it, and deletion
We keep information for as long as a host's account is active or as needed to provide the service.
Hosts can remove individual events and contacts inside the app at any time. Hosts can also use
Delete account in the app to delete their account, associated events, contacts, and other personal
data, except for information we must keep for legal, security, or operational reasons. You can email us
for help with access, correction, or deletion requests.
The host's role
Each host decides what to ask their guests and how to use the information they collect. If you're a
host, you're responsible for handling your guests' details appropriately and for any messages you
send them, including following applicable anti-spam and privacy laws.
Children
Hey Poppy is not directed to children under 13, and we don't knowingly collect their information for a
child's own account. A host may add a child to an event as a dependent of an adult; that entry is
made by the responsible adult.
Security
We store data with established providers and take reasonable measures to protect it. No method of
storage or transmission is completely secure, so we can't guarantee absolute security.
Your choices
You can view, correct, or delete much of your information directly in the app, or contact us for help
with access or deletion.
Changes to this policy
We may update this policy as Hey Poppy evolves. We will update the effective date when we make changes
and provide additional notice when appropriate.
Contact
Questions or privacy requests: privacy@heypoppy.fun.