This Privacy Policy describes how Zero1 Ventures, LLC ("we," "us," or "our") collects, uses, and handles information when you use HeyCrew, a product of Zero1 Ventures, LLC ("the App"). By using the App, you agree to the practices described in this policy.
HeyCrew is designed to be privacy-forward. You do not need to create a traditional account, and we do not ask for a login, to use the core features of the App. Instead, your identity within the App is represented by a device-based, pseudonymous identifier generated and stored securely on your device. We explain below what this means and the limited information we do collect.
Information We Collect
Information you provide directly
- A display name you choose when setting up the App. You can set this to anything; it does not have to be your legal name.
- Event content you create: event names, dates, descriptions, availability, ideas, poll responses and votes, checklist items, and chat messages.
- An optional email address, if you choose to sign up for product updates through our website.
- If you choose to sign in with Apple or Google: the name and email address released to us by that provider. With Sign in with Apple, you may also choose Apple's private email relay, in which case we receive only the relay address.
- The contents of any support request you send us.
Information collected automatically
- A randomly generated device identifier (UUID) stored in your device's secure storage (iOS Keychain or Android Keystore). This identifier is the spine of your identity in the App. Because your display name and event content are associated with it, we treat this identifier as pseudonymous rather than fully anonymous.
- Encrypted device credentials (a synthetic email and password generated by the App, not chosen by or shown to you) stored in your device's secure storage to keep you signed in without a traditional account.
- A push notification token, if you grant notification permission, used to deliver event updates.
- Product interaction and usage analytics (for example, app opens, screens viewed, and features used) collected through Firebase Analytics. This is aggregate behavioral data used to improve the App.
If you sign in with Apple
When you link Sign in with Apple, our backend securely stores the Apple refresh token associated with your sign-in. We store the refresh token only (not your Apple password and not a long-lived access token), and it is held in a restricted, server-only table that is not accessible from the App. We retain it for one purpose: so that, if you delete your account, we can call Apple's token revocation endpoint on your behalf as Apple requires. See Account Deletion.
Information about guests and event participants
When an event creator invites participants, the App stores the display name assigned to or chosen by each participant, along with their event activity (availability, RSVPs, ideas, votes, and messages). Event creators are responsible for ensuring that any participants they invite are comfortable having this information stored and shared with other members of that event. We do not independently verify participant consent.
๐ก No login required for core features. You can create and join events without giving us your real name, email, or phone number. We only receive a name or email if you choose to sign in with Apple or Google, or sign up for our email updates.
Summary of Data We Collect
The table below summarizes the categories of data associated with the App and is intended to be consistent with the privacy information shown on our App Store and Google Play listings. "Linked to you" means the data is associated with your device-based identity. We do not use any of this data to track you across other companies' apps or websites.
| Data type | Linked to your identity? | Used to track you? | Primary purpose |
|---|---|---|---|
| Name (display name; name from Apple/Google sign-in) | Yes | No | App functionality |
| Email address (sign-in or email-update signup) | Yes | No | App functionality |
| Device ID (the pseudonymous device identifier) | Yes | No | App functionality & analytics |
| Other user content (events, messages, ideas, availability, etc.) | Yes | No | App functionality |
| Purchase history (subscription status via RevenueCat) | Yes | No | App functionality |
| Product interaction (aggregate usage events via Firebase Analytics) | No | No | Analytics |
We do not collect precise location, photos or media, contacts (see below), health data, financial account information, or crash/diagnostic data. We do not knowingly collect any data category not listed above. If we add a new category in the future, we will update this policy and our store listings together before doing so.
Contacts. If you use the optional invite feature that reads your device contacts, that access happens only at your request and entirely on your device, to help you pick people to invite. Your contacts are used only to pre-fill a text message, email, or your device's share sheet. We do not upload, store, or receive your contacts on our servers.
How We Use Information
We use the information collected to:
- Operate and provide the App's features, including event creation, scheduling, and group coordination
- Maintain your pseudonymous session and identity across your sessions and, on supported platforms, across reinstalls
- Deliver push notifications about events you are part of (with your permission)
- Process in-app purchases through the Apple App Store or Google Play, via RevenueCat
- Understand how the App is used in aggregate, in order to improve performance and features
- Respond to support requests if you contact us
- Send product updates if you opted into our email list
- Detect, investigate, and act on reports of objectionable content or abusive behavior, and otherwise enforce our Terms of Service
We do not sell your personal data. We may use aggregated or de-identified data to operate and improve our services.
Analytics & No Cross-App Tracking
We use Firebase Analytics to understand, in aggregate, how the App is used. This helps us fix problems and decide what to build.
We do not track you across apps or websites owned by other companies. The App does not use Apple's Identifier for Advertisers (IDFA), does not request App Tracking Transparency permission, and does not use your data for cross-app advertising or ad measurement. Because of this, our App Store privacy information reports that we do not use your data to "track" you as Apple defines that term.
If we ever change this and introduce tracking or advertising identifiers, we will update this policy, present the App Tracking Transparency prompt where required, and update our App Store and Google Play privacy information before that change takes effect.
Data Storage & Security
Event data is stored on Supabase-managed servers located in the United States. If you are located outside the United States, your data will be transferred to and processed in the United States. By using the App, you consent to this transfer.
Your device credentials (the synthetic identifier that represents your pseudonymous identity) are stored in your device's hardware-backed secure storage: the iOS Keychain on iPhone and the Android Keystore on Android devices. On iOS, this data persists across App reinstalls. On Android, credentials may also be backed up to Google's Block Store service, associated with your Google account, to enable recovery after reinstallation.
We implement reasonable technical and organizational measures to protect your data. However, no method of transmission over the internet or method of electronic storage is 100% secure, and we cannot guarantee absolute security.
Push notification tokens are stored in our database solely to deliver event notifications. You can revoke notification permission at any time in your device settings.
Data Retention
We retain data for as long as it is needed to provide the App's services, subject to the following:
- Active event data (events, availability, messages, ideas, polls, checklists) is retained for the life of the event. Events on the free tier expire and are scheduled for deletion after a limited period, as described in the App.
- Device credentials and identity data are retained until you delete your account through the in-app deletion feature or ask us to delete them.
- Push notification tokens are retained while you are an active member of at least one event. Tokens may persist after uninstall until they are cleaned up on a failed delivery attempt.
- Apple refresh tokens are retained only until you delete your account, at which point they are used to request revocation of your Apple sign-in and then deleted.
- Analytics data collected through Firebase Analytics is retained according to Firebase's configured retention period.
- Email-update signups are retained until you unsubscribe or request deletion.
- Support communications are retained for a reasonable period to help with ongoing and follow-up issues.
To delete all data associated with your identity, use the in-app account deletion feature (Settings → Delete Account) or contact us at support@heycrewapp.com. See the next section for what deletion does.
Account Deletion
You can permanently delete your identity and associated data from within the App at Settings → Delete Account. Deletion is immediate and cannot be undone. When you delete your account:
- Events you created are deleted for everyone. Because an event you own cannot exist without you, deleting your account permanently removes those events and their content for all members, not just for you.
- Events you only joined continue to exist, but your contributions to them (your messages, ideas, votes, availability, and your participant entry) are removed. Other members keep their own content and the event itself.
- Your device record, push tokens, and pseudonymous credentials are deleted, and your underlying authentication record is removed from our system.
- If you signed in with Apple, we attempt to revoke the connection between your Apple ID and HeyCrew via Apple's token revocation endpoint, then delete the stored Apple refresh token. You can also remove HeyCrew from your Apple ID at any time in your device's Apple ID settings.
- Your subscription record with RevenueCat is deleted. This removes your subscriber profile from our subscription management provider but does not cancel an active subscription โ subscriptions are billed and must be canceled through the Apple App Store or Google Play, independent of account deletion.
- We reset the analytics identifier on your device so future analytics are not linked to your prior activity.
Some records may persist briefly in encrypted backups or logs and are overwritten or purged in the ordinary course. Any residual analytics data held by our analytics provider is not linked to a new identifier and ages out automatically under our retention period (14 months).
Requesting deletion from the web
You do not need to reinstall the App to delete your data. To request account and data deletion from the web:
- Email support@heycrewapp.com with the subject line "Delete my account."
- Include the display name and, if you have one, the email or Apple/Google sign-in associated with your use of the App, so we can locate your data.
- We will delete your identity and associated data, as described above, and confirm by reply. We process web deletion requests within 30 days.
What is deleted: your device identity and credentials, your event contributions, push tokens, your authentication record, your RevenueCat subscriber profile, and (for Sign in with Apple) the stored Apple refresh token, with a revocation request sent to Apple. Deleting your account does not cancel an active subscription; cancel through the Apple App Store or Google Play. Events you created are removed for all members; events you only joined remain, minus your content. What may be retained: aggregate analytics not linked to your identity, and limited records we must keep for security, fraud-prevention, or legal-compliance reasons.
Children's Privacy
HeyCrew is not directed to children under the age of 13, and we do not knowingly collect personal information from children under 13. If you believe a child under 13 has provided information through the App, please contact us at support@heycrewapp.com and we will promptly delete it.
Users between 13 and 18 must have the involvement and consent of a parent or legal guardian to use the App, as described in our Terms of Service.
Your Rights
Depending on your location, you may have the right to:
- Access the data associated with your device identity
- Request correction of inaccurate data
- Request deletion of your data (see Sections 7 and 8 for how to do this)
- Opt out of push notifications through your device settings
- Opt out of analytics collection through your device's privacy settings
- Unsubscribe from product-update emails through the unsubscribe link in any such email
To exercise any of these rights, contact us at support@heycrewapp.com. We will respond to data-rights requests within the time required by applicable law, and in any case within 30 days. We will not discriminate against you for exercising these rights.
GDPR & CCPA
European Economic Area, UK, and Switzerland (GDPR). If you are located in these regions, we process your data on the following legal bases:
- Contract performance for processing necessary to provide the App's core features you have requested
- Legitimate interests for aggregate analytics and for keeping the App safe and functional, where those interests are not overridden by your rights
- Consent for push notifications and optional email updates, which you may withdraw at any time
Your data is transferred to the United States, which may not provide the same level of data protection as your home jurisdiction. Where required, we rely on appropriate safeguards such as Standard Contractual Clauses and our vendors' data processing terms as transfer mechanisms. You have the right to lodge a complaint with your local supervisory authority if you believe your data has been processed unlawfully.
California (CCPA/CPRA). California residents have the right to:
- Know what personal information we collect and how it is used
- Request access to, or deletion of, your personal information
- Opt out of the sale or sharing of personal information. We do not sell or share personal information as those terms are defined under the CCPA/CPRA
- Not be discriminated against for exercising your rights
To exercise California rights, contact us at support@heycrewapp.com.
Third-Party Services
The App currently uses the following third-party services, each governed by its own privacy policy:
- Supabase โ database, authentication, and backend (supabase.com/privacy)
- Firebase Analytics โ aggregate usage analytics (firebase.google.com/support/privacy)
- Firebase Cloud Messaging (FCM) โ push notification delivery (firebase.google.com/support/privacy)
- RevenueCat โ subscription and in-app purchase management (revenuecat.com/privacy)
- Google Block Store โ on Android, optional credential backup and recovery via your Google account (policies.google.com/privacy)
- Sign in with Apple โ optional authentication via Apple ID (apple.com/legal/privacy)
- Sign in with Google โ optional authentication via Google account (policies.google.com/privacy)
- Apple App Store / Google Play โ app distribution and in-app purchase processing
We are not responsible for the data practices of these third-party services, and this list may change over time as our service providers change.
Changes to This Policy
We may update this Privacy Policy from time to time. When we do, we will update the effective date at the top of this page. For material changes, we will provide additional notice, such as a notice on our website at heycrewapp.com or within the App. Your continued use of the App after an update takes effect constitutes your acceptance of the updated policy.
Contact Us
Questions about this Privacy Policy, a data request, or a content concern? Reach Zero1 Ventures, LLC at 4511 W. Dale Ave, Tampa, FL 33609, or by email below.
support@heycrewapp.com