Privacy Policy
Last updated: August 29, 2026
Hovi helps small groups find a meeting spot by calculating the midpoint between everyone's locations and showing nearby venues. We've built it to collect as little personal data as possible. This policy explains what we collect, how we use it, and how long we keep it.
What we collect
When you use Hovi we may collect:
- An anonymous user identifier (a random UUID generated on first launch). Used only to associate you with sessions you join.
- A location you submit to a session — either your GPS coordinates (only if you tap "Use my location") or an address you type into the search field.
- A display name you enter when joining a session. Shared with other participants in the same session so they can tell who's in. Deleted when the session ends.
- Chat messages you send within a session. Visible only to participants of that session. Deleted when the session ends or after 24 hours, whichever comes first.
- Session metadata: the 6-character session code, search tags you choose (e.g. "Food", "Bowling"), an optional meet-up time, and timestamps.
- Your votes on venues. When your group runs a swipe round, each yes/no you give is stored against your anonymous identifier for that session so the app can work out the group's choice. Deleted with the session.
- Your approximate location when you browse Discover or the "near you" row on the home screen. This happens outside any session, and only after you grant location permission. See the note under "How we use your data" about how little of it is stored.
- Planned meetups. If your group sets a meet-up time, we store the chosen venue (name, address, photo, coordinates), the time, a share code, and the first names of the people attending. Unlike a session, a plan is meant to outlive the day it was made — see "How long we keep it".
- Anything you send us through the in-app support form: your message, the email address you optionally give us for a reply, and your app version and platform so we can reproduce the problem.
- Crash reports. If the app crashes, technical details (device model, OS version, and a stack trace) are sent to Firebase Crashlytics so we can find and fix the bug. Crash reports are not linked to your name, email, or account.
If you sign in
Sign-in is optional. You can use Hovi anonymously by tapping "Skip for now" on the welcome screen. If you do sign in with Apple or Google we additionally store:
- The display name from your Apple ID or Google account. Used to fill in your name automatically when joining a session — you can edit it before submitting.
- The email address from your Apple ID or Google account. Used only for account recovery; never shown to other participants and never used for marketing.
- Your profile photo URL (Google only — Apple does not share this). Used only on your own device for the profile screen avatar.
- Your meetup history: the winning venue (name, address, photo), the date, and the first names of the people you met with. Stored against your account so your history follows you across devices. You can remove single entries (swipe left on a card), clear the whole list ("Clear" on the home screen), or wipe it permanently with "Delete account".
You can sign out from the profile screen at any time, or tap "Delete account" to permanently remove your account and every record tied to it.
What we don't collect
Hovi does not collect or store:
- Your phone number, photos, contacts, calendar, or microphone audio.
- Advertising identifiers (IDFA / GAID).
- Background location. We only ever read your location while you are using the app, and only after you ask us to — by tapping "Use my location" in a session, or by turning on Discover.
- Behavioural analytics. We do not track screen views, taps, or session duration for marketing purposes.
How we use your data
Submitted locations are used solely to:
- Compute the geographic midpoint of your group.
- Search for nearby venues that match your group's tags.
- Show each participant their personal distance to a venue, calculated on your own device.
To be precise about what the group can see: Hovi's screens never display anyone's address or coordinates — only the midpoint and each person's own distance. But the location you submit is stored on the session, and everyone in that session can read it, because the app on each phone needs every submitted point to compute the midpoint. So treat a submitted location as shared with the people you gave the code to. It is never visible to anyone outside the session, and it is deleted with the session.
Discover and the "near you" row work differently, because there is no group and no midpoint — they use your own location directly. To keep that from becoming a location history, the results are cached against a coarse grid square roughly a kilometre across rather than against your actual position, and that cache is shared between everyone in the same square. It is not linked to you, your device, or your account. Your phone additionally keeps its own copy of those results for up to 24 hours, stored with the position they were fetched for, so reopening the app doesn't re-request them. That copy stays on your device and is removed when you delete the app.
How long we keep it
Sessions are temporary by design:
- Every session expires automatically 24 hours after it is created. It becomes unreachable at that moment, and a cleanup job running every hour permanently deletes the session, all participant locations, all display names, all chat messages and all votes from our database.
- When the host ends a session, every participant's submitted location and every chat message in that session is deleted immediately.
- When you leave a session, your submitted location is cleared immediately. Your name and chat messages are kept until the session ends so other participants still see what was said.
- Planned meetups are the exception to the 24-hour rule, deliberately: a plan for next Friday has to still exist next Friday. A plan is kept until it passes. Cancelling it hides it from everyone immediately, though the record itself is retained so attendees aren't left wondering where it went; it is removed with your account. Anyone attending can remove themselves at any time, and "Delete account" removes every plan you created.
- Reminders for a planned meetup are scheduled on your own device. They are never sent to us and never leave your phone.
- Messages you send through the support form are kept until the issue is resolved, so we have a record of the conversation. Ask us and we will delete yours.
- If you signed in, your account (name + email) is kept until you tap "Delete account" on the profile screen.
Third-party services
To provide the app we send certain data to trusted third-party services. Only the data described below is sent. None of these requests carry your name, email or account id, with one exception — the support form, where you choose what to write and which address to give us. Some of them do receive location: precise coordinates can be personal data even without a name attached, so they are listed explicitly below rather than folded into "anonymous".
- Supabase — stores session and participant rows (including submitted locations, display names, and chat messages), account profiles and meetup history for signed-in users, and handles authentication. supabase.com/privacy
- Google Firebase Crashlytics — receives crash reports (device model, OS version, technical stack traces) so we can diagnose and fix bugs. We do not attach your name, email, or user ID to crash reports. firebase.google.com/support/privacy
- Apple Sign in with Apple — optional. If you choose this, Apple returns your name and email to Supabase, where it's stored against your account. apple.com/legal/privacy
- Google Sign-In — optional. If you choose this, Google returns your name, email, and profile photo URL to Supabase. policies.google.com/privacy
- Google Maps Platform (Places API) — receives the group midpoint and your search tags to return matching venues, plus typed text when you use address autocomplete. policies.google.com/privacy
- OSRM (router.project-osrm.org) — receives your own submitted coordinates together with the candidate venue coordinates, to compute your estimated driving time to each one. Your position is the starting point of that calculation, so it is sent rather than the midpoint.
- OpenStreetMap Nominatim — receives GPS coordinates only when you tap "Use my location", in order to convert them to a human-readable address. osmfoundation.org/wiki/Privacy_Policy
- CARTO — serves the dark map tiles displayed on the results screen. carto.com/privacy
- Resend — delivers the notification email when you send us something through the in-app support form. This means your message, and the reply address you gave us, pass through Resend on the way to our inbox. Nothing else in the app uses it. resend.com/legal/privacy-policy
Children
Hovi is not intended for children under 13. We do not knowingly collect data from children under 13.
Your rights
If you use Hovi anonymously, no personal identity is linked to your account — the simplest way to remove your data is to leave or end any active session (your submitted locations are deleted immediately), and sessions you are no longer part of expire and are deleted within 24 hours. "Clear my data" on the profile screen does all of this in one tap.
If you signed in, everything tied to your account — name, email, avatar, and meetup history — can be permanently removed at any time with "Delete account" on the profile screen. This works immediately and cannot be undone.
If you'd like us to delete data manually or have any questions, contact us at support@hoviapp.com.
Changes to this policy
We may update this policy as the app evolves. The "Last updated" date at the top reflects the most recent version. Material changes will be communicated in-app on next launch.