Legal / privacyEffective August 13, 2026

Privacy Policy

What Friendpalooza knows, why it needs it, and where private-group data actually goes.

Audience
18 and older
Ads
None
Data sales
None

Before the fine print

Friendpalooza is built around private groups, but “private” means limited to the people admitted to a group—not invisible to those people, immune from screenshots, or stored only on your device.

We use account, group, content, media, and device information to run the Service. We do not currently sell personal information, run ads, or use private-group content for targeted advertising.

Scope and who we are

This Privacy Policy describes how John Polacek, who operates the Friendpalooza service (“Friendpalooza,” “we,” “us,” or “our”) collects, uses, discloses, and retains personal information when you use friendpalooza.com, the Friendpalooza progressive web application, and related features, communications, and services (collectively, the “Service”).

This Policy applies to information we process as the operator of the Service. It does not control what other group members do with content they receive, or the independent privacy practices of websites and services you reach through links. Our service providers may also process information under their own notices where they act independently.

Information we collect

The information we collect depends on the features you use. In the preceding 12 months, we may have collected the following categories:

Account and profile information
Your Clerk account identifier, name, email address, profile image, account status, and any group-specific nickname. Clerk processes the credentials and verification data used to sign you in; Friendpalooza does not receive your password. If you choose Google sign-in, Google provides your basic Google profile information—including your name, email address, and profile image—to Clerk, which provides those details to Friendpalooza for your account. Friendpalooza does not receive your Google password or request access to Gmail, Google Drive, Google Contacts, Google Calendar, or other Google account content.
Group and relationship information
Groups you create or join, group names and images, invite codes, membership roles, join and activity times, group timezone and posting cadence, rotation assignments, participation and streak information, and member-removal or role actions.
Content and communications
Messages, replies, captions, text posts, comments, reactions, photos, videos, GIF files, voice recordings, check-ins, and information about the people, places, or events shown or discussed in that content. We also process messages you send to us for support, legal, privacy, or safety reasons.
Media and activity metadata
Content type, file size, storage key, upload and creation time, video or audio duration, playback and processing identifiers, message and entry counts, notification status, and similar operational records. Some of this information is used to understand and control service costs.
Device, network, and technical information
IP address and request information received by our hosting and infrastructure providers; browser and device type; operating system; language and general technical settings; push-notification endpoint, encryption keys, and user-agent string; service-worker state; and error, security, and access logs.
Preferences and device permissions
Notification permission and subscription state, installation and notification-prompt dismissal times stored on your device, group settings, and a timezone selected by you or suggested from your browser. If you grant camera, microphone, or photo-library access, the Service receives only the media you choose to capture or upload—not your entire library.

Content in a private group may reveal information that some laws treat as sensitive, including the substance of private communications or information about health, beliefs, relationships, race or ethnicity, sexual orientation, or precise whereabouts. We do not ask you to provide those details and do not use private content to infer sensitive traits for advertising. Please do not share sensitive information unless you are comfortable sharing it with every current member of the group.

Where information comes from

We collect personal information from:

  • You, when you create an account, join or manage a group, post content, enable notifications, or contact us.
  • Your use of the Service and your device, when the app records an action, stores a local preference, uploads selected media, or receives ordinary network and security information.
  • Other group members, when they invite you, use your name or nickname, include you in content, reply to you, react to your content, or take an administrative action affecting your membership.
  • Service providers, such as Clerk when it sends us your verified account profile and Mux when it reports that a video upload is processed and ready.
  • Google, if you choose Google sign-in, when it provides your basic Google profile information to Clerk for authentication.

How we use information

We use personal information to:

  • provide, personalize, maintain, and troubleshoot the Service, including authentication, private-group access, chat, media delivery, group rotations, timelines, comments, reactions, check-ins, and notifications;
  • display content and profile information to the people you share it with and preserve a group's shared archive;
  • process media, measure file size and duration, attribute infrastructure usage, prevent abandoned or abusive uploads, and manage capacity and costs;
  • protect accounts, groups, members, and the Service; authenticate requests; detect abuse, fraud, or security incidents; enforce our Terms; and investigate complaints;
  • communicate with you about the Service, including account, safety, privacy, legal, and support matters, and deliver notifications you enable;
  • analyze aggregate or de-identified operational patterns, test and improve features, and develop the Service; and
  • comply with law, respond to lawful process, establish or defend legal claims, and complete a merger, financing, acquisition, reorganization, bankruptcy, or sale of all or part of the Service.

We may create aggregate or de-identified information and use or disclose it for any lawful purpose. We will not attempt to reidentify information that applicable law requires us to maintain in de-identified form.

Google sign-in data

If you choose Google sign-in, we use the name, email address, and profile image derived from your Google account only to create, authenticate, secure, support, and display your Friendpalooza account and provide features you request. Friendpalooza does not use a Google OAuth access token to access other Google services. We do not sell Google-derived account data, use it for advertising, or use it to train generalized artificial-intelligence or machine-learning models. We store and disclose this account information only as otherwise described in this Policy, including through Clerk and the providers needed to run the Service.

Where applicable law requires a legal basis for processing, we rely on performance of our contract with you to provide requested features; our legitimate interests in operating, securing, improving, and protecting the Service; your consent for device permissions or other processing where consent is requested; and compliance with legal obligations. Our legitimate interests do not override your rights where the law provides otherwise.

How we disclose information

People in your groups

Current group members can see content, profile details, nicknames, reactions, comments, participation, and other activity made available inside that group. Group administrators can manage invitations, settings, roles, memberships, nicknames, and content as the Service permits. Someone removed from a group should lose in-app access, but we cannot erase copies they made while they had access.

Vendors that run the Service

We disclose information to contractors and service providers that host, authenticate, store, process, secure, or deliver the Service. They include:

  • Clerk for accounts, authentication, session cookies, and profile synchronization;
  • Convex for application data, realtime updates, scheduled jobs, and server functions;
  • Amazon Web Services and CloudFront for photo, audio, GIF, and chat-video storage and delivery;
  • Mux for direct video upload, processing, playback, thumbnails, and related metadata;
  • Vercel for web hosting and network delivery; and
  • browser and operating-system push services to deliver notifications to devices where you enable them.

These providers receive the information reasonably needed for their role. Their infrastructure may generate its own security, access, and delivery logs.

Legal, safety, and business disclosures

We may disclose information when we reasonably believe it is necessary to comply with law or valid legal process; protect rights, safety, and property; investigate fraud, abuse, or security incidents; enforce our agreements; or respond to an emergency. We may also disclose information in connection with a financing, corporate transaction, insolvency, or transfer of the Service, subject to appropriate confidentiality protections where practicable. We may disclose information at your direction or with your consent.

No sale or targeted advertising

Friendpalooza does not sell personal information for money. We do not share personal information for cross-context behavioral advertising, use private-group content to target ads, or knowingly sell or share the personal information of anyone under 18. The Service does not currently display third-party advertising.

We also have not disclosed personal information to third parties for their own direct-marketing purposes. If these practices change, we will update this Policy and provide any choices required by law before the new practice begins.

Cookies, local storage, and permissions

Clerk and our hosting infrastructure use cookies and similar technology that are necessary to authenticate you, keep sessions secure, route requests, and operate the Service. Friendpalooza also uses local storage on your device to remember whether notifications were previously enabled and when you dismissed notification or home-screen-install prompts. We do not currently use advertising cookies or third-party behavioral analytics.

You can block or clear cookies and local storage through your browser, and revoke camera, microphone, photo-library, or notification permission through your device settings. Doing so may sign you out, reset prompt preferences, stop notifications, or prevent affected features from working.

Some browsers send “Do Not Track” signals. Because there is no accepted standard for those signals and we do not track your activity across unrelated services for advertising, the Service does not respond differently to Do Not Track. We likewise do not engage in a sale, sharing, or targeted-advertising practice that would require a change in response to a Global Privacy Control signal.

How long we keep information

We retain information for as long as reasonably necessary to provide and protect the Service, maintain a group's shared history, comply with law, resolve disputes, enforce agreements, and support the other uses described in this Policy. Retention depends on the nature of the information and why we hold it:

  • Account and profile information is generally kept while your account is active. You may start permanent account deletion from the Account page. We record the verified request before deleting the authentication account, then remove the active profile and other application data.
  • Account deletion removes content you authored and media associated with that content from our active systems. A group you created is transferred to another member if one remains; a group with no other member is deleted. Leaving a group without deleting your account does not itself delete what you previously shared.
  • An available delete control removes a post, comment, or entry from normal app views. When the item has stored media, we queue deletion from the relevant storage or video provider and retry transient failures. Deletion is not necessarily instantaneous: cached copies, backups, logs, and provider records may persist for a limited period. Information may also be retained for safety, fraud prevention, legal compliance, enforcing our agreements, or dispute resolution.
  • Upload records may persist even if an upload is abandoned, because the Service records certain metadata when it issues an upload authorization.
  • Push-subscription data is removed when you delete your account and may otherwise be kept until you disable notifications, the endpoint expires, or we determine it is no longer needed. Device-only preferences remain until they expire, are overwritten, or you clear site data.

We may retain aggregate or de-identified information without a fixed end date. We may also delete information, including group content, at any time as permitted by our Terms; Friendpalooza is not a guaranteed backup or permanent archive.

Your choices and privacy rights

Depending on where you live and subject to legal exceptions, you may have the right to request access to, a copy of, correction of, or deletion or portability of personal information; to learn the categories of personal information, sources, purposes, and recipients involved; to restrict or object to certain processing; to withdraw consent where processing relies on consent; to appeal a denied request; to complain to a competent privacy regulator; and not to receive discriminatory treatment for exercising a privacy right. Withdrawing consent does not affect processing that was lawful before withdrawal.

You can update certain profile information through your Clerk account, manage group settings and content through available app controls, leave a group, disable push notifications, or clear local site data. To make a privacy request, email us at johnpolacek@gmail.com. Describe the right you want to exercise and the email address tied to your account.

If you use Google sign-in, you can review or revoke Friendpalooza's connection through your Google Account permissions. Revoking the connection stops future Google sign-ins but does not automatically delete information already stored in your Friendpalooza account. You can permanently delete that account and its active application data from the Account page. If Google sign-in is your only sign-in method, add another method through your Clerk account before revoking access if you want to keep using the account.

We may verify your identity and authority before acting, including by asking you to confirm control of your account or email address. An authorized agent may submit a request where the law allows, but we may require proof of authorization and direct identity verification. We may deny or limit a request when an exception applies, when we cannot verify it, or when fulfilling it would adversely affect another person's rights. Shared group content may be retained or de-identified where deletion would impair other members' records, the integrity of a conversation, safety, legal compliance, or another legitimate purpose permitted by law.

Additional U.S. state notice

State privacy laws define categories differently and apply only when statutory thresholds and other conditions are met. To the extent an applicable law requires a category-based notice, the categories we may collect are identifiers; customer-record information; internet or other electronic-network activity; audio, electronic, and visual information; and inferences limited to operational matters such as timezone, participation, or preferences. Private communications and account credentials may be treated as sensitive personal information in some states.

We collect these categories from the sources described in Section 3, use them for the purposes in Section 4, and disclose them to the categories of recipients in Section 5. We do not use or disclose sensitive personal information to infer characteristics about you. We do not offer a financial incentive for personal information. Because we do not sell or share personal information for cross-context behavioral advertising, there is no separate “Do Not Sell or Share” opt-out needed for our current practices.

Children

The Service is for people who are at least 18 years old. It is not directed to children, and we do not knowingly collect personal information from anyone under 13. If you believe a child under 13 has provided personal information to the Service, email us promptly at johnpolacek@gmail.com. We may request information reasonably necessary to locate and address the account or content.

Security and international processing

We use reasonable administrative, technical, and physical safeguards designed for the nature of the Service, including authenticated access controls, scoped upload authorizations, transport encryption, private object storage, and signed webhook verification. No method of storage, transmission, or account protection is completely secure. You use the Service and share content at your own risk, and you should protect your account and invite links.

Friendpalooza is operated from the United States. We and our providers may process and store information in the United States and other countries whose privacy laws may differ from those where you live. By using the Service, you understand that your information will be transferred to and processed in those locations, subject to safeguards required by applicable law.

Changes and contact

We may update this Policy to reflect changes to the Service, our practices, or the law. We will post the revised Policy here and update the effective date. If a change is material, we may also provide notice through the Service or another reasonable channel. Your continued use after the revised Policy takes effect is subject to the updated Policy; where law requires consent, we will request it separately.

Questions, complaints, and privacy requests may be sent to John Polacek, who operates the Friendpalooza service at johnpolacek@gmail.com.

Keep reading

The Terms of Use

Read terms