Huddle privacy
what the app keeps, and why
In short
- Huddle needs your phone number and a display name. It asks for nothing else about you.
- Only the people in an event can see that event, its chat and its itinerary.
- No one else in Huddle can see your phone number.
- Huddle does not upload your contacts, track your location, show ads or sell data.
- You can delete your account in the app at any time.
Who runs Huddle
Huddle is made and run by [Your full name], a software engineer in Singapore. In this policy, "I" and "me" mean [Your full name]. I decide how Huddle uses your data.
Write to hello@papersalt.dev with any question about this policy or your data.
What Huddle stores
Your phone number
You sign in with your phone number. Huddle sends each sign-in code to it on WhatsApp. It also makes guest invites safe, because only the account with the invited number can open an invite.
How long. As long as your account exists. Deleting your account erases it from your account. Copies stay in sign-in code records and in guest invites, as described below.
Your display name
You choose a name of 1 to 40 characters. People who share a group or an event with you see it. People in an event also see it next to your messages there after you leave.
How long. Until you change it or delete your account.
Groups and events
Huddle stores group names, event titles, the kind of event, its dates and its time zone. It also stores who is in each group and event, who added them, when they joined, and who owns each group and manages each event. If a group owner removes you, Huddle records when, so an invite link made before the removal no longer lets you back in.
How long. A group lasts until its last member leaves, and an event lasts until its last member leaves. Huddle then deletes it with everything in it, including its chat and itineraries. Deleting a group deletes its events.
Chat messages
Huddle stores the text you send in an event's chat and when you sent it, exactly as you wrote it.
How long. As long as the event exists. This version of Huddle cannot delete a single message. Your messages stay in the event after you leave it or delete your account.
Itineraries
When someone in a trip taps Generate, Huddle makes a copy for the itinerary request. The copy holds the event title, the trip dates and time zone, the current itinerary, and the chat messages with each author's display name and the time they were sent. If someone pastes a plan instead, the copy holds the pasted text. Huddle sends this copy to Anthropic and stores the itinerary that comes back.
How long. As long as the event exists. Each request keeps its copy of the chat, with the display names as they were at the time. Deleting an account later does not change those copies.
Guest invites
To invite a guest, a member of the event enters the guest's phone number and a label such as "Aunty Mei". Huddle stores the number, the label, who sent the invite and whether it was used. Other people in the event see only the label and the last 4 digits. The person invited may not have a Huddle account yet.
How long. An invite stops working after 14 days. Huddle keeps the record, used or not, as long as the event exists. If you delete your account, Huddle cancels any pending invites to your number.
Your devices
When you sign in, the app sends three things. It sends a random ID the app made when it was installed, the device name set on your phone, such as "Ana's iPhone", and whether the phone is an iPhone or Android. Huddle stores these with the time you signed in and the last time the device was used. Settings lists your devices, so you can sign out one you do not recognise. When a new device signs in, your other devices get a notification.
The device keeps a random session token. The server stores only a keyed hash of it (HMAC-SHA256), so the stored value cannot sign anyone in.
How long. A device's session is deleted when it signs out. Sessions do not expire on their own. Huddle keeps the random device ID and when it was first seen, even after sign-out, so it can tell a new device from one that signed in before. This version does not delete that record when you delete your account.
Notification tokens
If you allow notifications, the app registers a push token from Expo. Huddle stores it with the device it belongs to and whether the phone is an iPhone or Android.
Huddle also keeps a queue record for each notification. The record holds who it is for, the event it is about, the kind of notification and whether it was delivered. It holds no message text.
How long. A token is deleted when its device signs out, when you delete your account, or when Expo reports that the app is gone from the phone. If another account signs in on the same phone, the token moves to that account. Queue records about an event are deleted with the event. This version keeps the other queue records, such as new sign-in alerts.
Sign-in codes and IP addresses
Each time you ask for a code, Huddle stores the phone number, a keyed hash of the code, your IP address, the number of tries, and when the code was asked for and used. The code itself is never stored. The IP address is used only to limit how many codes one network can ask for in an hour. These limits stop abuse and cap the cost of WhatsApp messages. The Huddle database keeps IP addresses nowhere else.
How long. This version of Huddle does not delete these records automatically, and deleting your account does not remove them. [Retention period for sign-in records, once automatic deletion is built.]
When you last used Huddle
Huddle notes the last time your account was used, at most once an hour. It needs this for two rules. If a group owner or event manager is idle for 30 days, the role passes to the longest-standing member who is still active. If an account is idle for 180 days, its number may have a new owner, as described under "Recycled phone numbers".
How long. As long as your account record exists.
What Huddle does not collect
- Your contact list. If you pick a number from your contacts, your phone gives the app that one number. Huddle never uploads your contacts.
- Your location.
- An email address, a password or payment details.
- Analytics, advertising IDs or crash reports. The app has no analytics or advertising code.
Huddle does not sell personal data and does not use it for advertising.
Who can see what
- Only the people in an event can see it, its chat, its itinerary and its people. Being in the same group is not enough. The database checks this rule on every request.
- Someone who is not in an event cannot tell that it exists.
- Group members see the group's name and its members.
- A guest sees only the event they joined and the people in it.
- Your phone number is visible only to you.
- Someone added to an event later can read its whole chat history. This includes guests.
- Notifications carry no message text and no event names. The app loads the content after you open it.
Services that help run Huddle
Huddle shares data with these companies only to run the features above.
- Meta (WhatsApp Cloud API). Meta receives your phone number and your sign-in code, and delivers the code to you on WhatsApp.
- Anthropic (Claude API). Anthropic receives the itinerary request described above when someone taps Generate, and returns the itinerary. It does not receive phone numbers.
- Expo (push notifications). Expo receives the push token, the short notification text and the ID of the event it is about. Expo passes the notification to Apple or Google, who deliver it to your phone.
- Cloudflare. Every connection between the app and the Huddle server goes through Cloudflare Tunnel, so Cloudflare handles your IP address and your requests in transit. Cloudflare R2 also stores Huddle's backups, which are encrypted before they leave the server.
These companies may process data outside Singapore. Their own privacy policies apply to what they do with it.
Where your data is kept
The Huddle server is a computer I run myself in Singapore. Your data lives in its database.
Every night the server makes an encrypted backup. It keeps backups for 14 days, and a copy goes to Cloudflare R2, which keeps them for 30 days. The key that decrypts them is not on the server or at Cloudflare. Data you delete can remain in backups for up to 30 days.
How Huddle protects your data
- Sign-in codes and session tokens are stored only as keyed hashes.
- The database itself decides who can read each event. A missed check in the app's code shows nothing instead of everything.
- The server opens no ports to the internet. The only way in is Cloudflare Tunnel.
- Backups are encrypted, and the key is kept offline.
A signed-in phone stays signed in until someone signs it out. If you lose a phone, sign it out from another device in Settings.
Your choices
- Change your display name or phone number in Settings.
- Leave any group or event at any time.
- Sign out any of your devices in Settings.
- Delete your account in Settings.
- Ask me for a copy of your data, or ask me to correct or delete it. Write to hello@papersalt.dev. I will reply within [30 days].
Deleting your account
When you delete your account in Settings, Huddle does this at once.
- It erases your display name and phone number.
- It signs out every device and deletes their notification tokens.
- It removes you from every group and event.
- An event where you were the last member is deleted for everyone, guests included, with its chat and itineraries.
- An event you managed passes to its longest-standing member.
- A group you owned passes to its longest-standing member. A group where you were the last member is deleted.
- It cancels pending guest invites to your number.
Some data stays.
- Your messages stay in their events. Others see the author as "Deleted user".
- Itinerary requests keep the copy of the chat made at the time, which may include your display name. They are deleted with their event.
- Sign-in code records keep your phone number, and guest invite records keep the number they were sent to.
- The device record and notification queue records stay, linked to an account with no name or number.
- Backups keep a copy for up to 30 days.
Recycled phone numbers
Phone companies give abandoned numbers to new people. Say an account has not been used for 180 days, and its number then signs in from a device that account never used. Huddle treats the number as having a new owner. The new person gets a new, empty account, and the old account is deleted as described above. The new owner never sees the old account's data.
Children
Huddle is not for children under [minimum age]. If you think a child under [minimum age] is using Huddle, write to me and I will delete the account.
Changes to this policy
I will post any change on this page and update the date at the top.
Contact
[Your full name], Singapore. hello@papersalt.dev. This address also reaches the person responsible for data protection at Huddle.