← back potluk

privacy policy

effective version 2026-08-13

welcome

This Privacy Policy explains how potluk, Inc. (operating as "potluk", and referred to here as "we," "us," or "our") collects, uses, shares, and retains your information when you use the potluk mobile application and related services (the "Service"). It is incorporated into our Terms of Service; by accepting the Terms you also accept this policy.

The short version: we collect what we need to seat you at a table of compatible people and help that table hang out in real life. We do not sell your personal information, we do not run ads, and we do not share your information for cross-context behavioral advertising.

1 · what we collect

Account information. Your mobile phone number (used for sign-in verification), your name, date of birth (to verify you are 18 or older), profile photo, city, and timezone.

City, not GPS. When you pick your city during onboarding, we geocode it once — using your device's built-in geocoder, which is provided by Apple on iOS — to place you in a metro area. We store the city name. We do not collect precise location, we do not track your location in the background, and the app does not request continuous location permissions.

Content you create. Your conversations with En, messages and reactions in your group chats, voice notes (the audio recording and a transcript generated on your device where supported), photos you upload, RSVPs and hangout activity, and reports you file.

Information we derive. To match you into a table, we extract signals from your conversations with En (things like interests, personality, values, and what you're looking for), turn them into short written summaries, and compute numerical representations (embeddings) of those summaries. AI features may also generate content derived from your inputs, such as memory captions.

Device and usage information. A push notification token, device model and OS version, product analytics events (screens and actions, associated with your account ID), crash and error reports (associated with a random installation ID that is not your account ID and that you can rotate in Settings; our crash tooling scrubs emails, phone numbers, tokens, and coordinates before anything leaves the device), and server logs.

What we do not collect: precise or background location, your contacts, advertising identifiers, and biometric identifiers. We do not create or store face templates, faceprints, or voiceprints, and we do not use your photos or voice notes to identify anyone.

2 · how we use it

  • To run the Service: create and manage your account, run your conversations with En, match you into tables, deliver messages, and support hangout coordination.
  • For safety: screen content with automated tools, review reports, enforce our Terms and Community Guidelines, and protect members.
  • To communicate: SMS verification codes for sign-in, and push notifications you can control in Settings and your device settings.
  • To improve the product: understand which features are used and where the experience breaks, using analytics and crash reporting.
  • For security: rate limiting, fraud and abuse prevention, and debugging.
  • For legal reasons: comply with law, respond to lawful requests, and establish or defend legal claims.

We do not use your information for advertising, and we do not train our own or anyone else's foundation models on your content.

3 · ai processing

En is software. Your conversations with En, automated screening checks on messages and on photos you upload, and the extraction of matching signals from your sessions are processed by OpenAI acting as our service provider. The written summaries derived from your signals (not your raw messages) are sent to Voyage AI to compute matching embeddings. Both providers process this data under terms that prohibit them from using it to train their models.

If we add or change AI providers, we will update this policy and the in-app disclosure before the change applies to you.

AI-generated content (like memory captions or summaries) is derived from your inputs and those of your table. If something AI-generated about you is inaccurate or you object to it, delete it where a delete control exists, or contact us at support@potluk.social and we will review it and, where appropriate, remove it.

4 · automated content screening

To keep tables safe, messages and voice-note transcripts are checked by automated tools before they are delivered, and profile photos and hangout photos are checked before they are stored. A small set of categories — sexual content, sexual content involving minors, graphic violence, and threatening harassment or hate speech — is blocked at the message layer, and a photo in one of those categories is refused at upload. Content flagged as severe, and any report you file, can be escalated to human review.

Content suggesting that someone may be at risk of self-harm is flagged for human review rather than hidden, so the people at your table still see it.

These tools are imperfect: they can miss harmful content and occasionally flag harmless content. Where United States law requires it, we report apparent child sexual abuse material to the National Center for Missing & Exploited Children (NCMEC).

Outside of automated screening and the review of reports and safety escalations, humans at potluk do not read your conversations.

5 · who we share it with

Your table. Members of your group see your profile (name, photo, city), your messages, voice notes, photos you share with the group, and AI-generated group content such as memory captions.

Service providers. We use a small set of vendors to operate the Service, each limited to what their role requires:

  • Supabase — database, authentication, file storage, and delivery of SMS verification codes to your phone number.
  • Twilio — the SMS provider Supabase uses to deliver those verification codes.
  • OpenAI — AI conversations, signal extraction, and automated screening of messages, voice-note transcripts, and photos.
  • Voyage AI — matching embeddings computed from derived summaries.
  • PostHog — product analytics.
  • Sentry — crash and error reporting.
  • Expo — push notification delivery and app updates.
  • Apple and Google — app distribution, push notification transport, and (on iOS) geocoding the city you pick.
  • Upstash — rate limiting.
  • Grafana Cloud — server logs and monitoring.

Safety and legal. We may disclose information to comply with law or legal process, to report apparent child sexual abuse material to NCMEC, to cooperate with law enforcement where we believe in good faith that disclosure is necessary to prevent harm, and to protect the rights, property, or safety of potluk, our members, or the public.

Corporate events. If we are involved in a merger, acquisition, financing, or sale of assets, your information may be transferred as part of that transaction, subject to this policy.

We do not sell your personal information, and we do not share it for cross-context behavioral advertising. We have not done either in the preceding 12 months.

6 · how long we keep it

We keep your information while your account is active. Some data has shorter lifetimes: data exports you request are automatically deleted after 24 hours, and certain interaction records (like dismissed nudges) are cleared after 30 days. Server logs and encrypted backups age out on a rolling basis.

We may retain limited records longer where required by law — for example, records of your acceptance of the Terms, safety reports and enforcement records, and information subject to a legal hold.

7 · deleting your account

You can delete your account any time from Settings. When you do:

  • Your profile, photos, voice notes, En session history, extracted signals, and matching embeddings are deleted.
  • Your messages in group chats are disassociated from your identity, because the other members of your table keep their copy of the shared conversation — the same way a text thread survives on your friends' phones.
  • Your data exports and push tokens are deleted.
  • Records we are required to keep (like Terms-acceptance records and safety enforcement records) are retained as legal records.

Residual copies clear from backups on a rolling basis after deletion.

8 · your controls

  • Export your data: Settings → privacy & data. You can request a machine-readable copy of your account data once per week.
  • Delete your account: Settings.
  • Edit your profile: name, photo, and city from the profile screen.
  • Notifications: per-category controls in Settings, plus your device's notification settings.
  • Diagnostics: opt out of crash and diagnostic reporting, and rotate the random installation ID, in Settings.
  • Block and report: block any member from their profile or Settings; report any message or profile in-app.

9 · your privacy rights

Depending on where you live (including under the California Consumer Privacy Act as amended by the California Privacy Rights Act, and similar state laws), you may have the right to know what personal information we hold about you, to access it in a portable format, to correct it, to delete it, and to not be discriminated against for exercising those rights.

You can exercise access, portability, correction, and deletion directly in the app (see section 8), or by emailing support@potluk.social. We will verify requests made by email against your account phone number. You may use an authorized agent where the law allows; we will ask the agent for proof of authorization.

Because we do not sell personal information or share it for cross-context behavioral advertising, there is nothing to opt out of under those provisions. We also do not use or disclose sensitive personal information for purposes that require a right to limit under the CCPA.

If we deny a request, you may appeal by replying to our decision; if your appeal is denied, you may contact your state attorney general.

10 · california disclosures

Categories of personal information we collect: identifiers (phone number, name, account ID); characteristics such as age; audio and visual information (photos, voice notes); coarse geolocation (city); internet or network activity (product interaction, diagnostics); inferences (matching signals derived from your En sessions); and other personal information you choose to include in your content.

Sources: you, your device, and other members of your table (for example, group photos they upload). Purposes: as described in section 2. Disclosures for a business purpose: to the service providers listed in section 5. Sale or sharing: none. Retention: as described in section 6.

Content you write may include information you consider sensitive. We use it only to operate the Service and for safety as described in this policy, not to infer characteristics for advertising.

11 · security

Your data is encrypted in transit. Database access is governed by row-level security policies scoped to your account, and our internal services run with least-privilege credentials. Crash and analytics pipelines are scrubbed of direct identifiers where feasible.

No system is perfectly secure, and we cannot guarantee the security of your information. If you believe you have found a security vulnerability, email support@potluk.social.

12 · children

The Service is for adults 18 and older. We do not knowingly collect personal information from anyone under 18. If we learn that an account belongs to a minor, we will terminate the account and delete its information. If you believe a minor is using the Service, email support@potluk.social.

13 · changes to this policy

When we make material changes to this policy, we bump its version, show you what changed in the app, and require you to accept the updated policy before you continue using the Service. The current version is always available in the app and at https://potluk.social/privacy.

14 · contact

Privacy questions, rights requests, and safety reports all reach us at support@potluk.social.

potluk
terms privacy support