← Back to Night Cap

Privacy Policy

Last updated: August 27, 2026 · This policy is a working draft and has not yet had a full legal/compliance review. Contact us with questions before relying on it for compliance purposes.

What we collect

Night Cap collects the minimum information needed to run the app:

  • Account info — if you create an account: email address, password (stored as a salted hash, never in plain text), and an optional display name.
  • Saved plans — "Build a Night" plans you save, including the venues, times, and any label you add.
  • Anonymous engagement events — aggregate, non-identifying counts of views, saves, and plan reuses used to power the Popular/Sleepers/New lists. These are never tied to an individual's real-world identity or location, and we do not track real-time foot traffic or crowd levels.
  • Basic technical data — standard web server logs (IP address, browser type, request timestamps) kept briefly for security and abuse prevention (e.g. rate limiting).
  • Group location sharing (opt-in, per plan) — inside a "Build a Night" plan you created or joined, you can choose to share your Approximate (~1.1 km fuzzed) or Live (precise) location so other members of that specific plan can see your position on a map. This is off by default every time you open a plan — you must tap Approximate or Live to turn it on. Only people who are the plan's owner or a confirmed joined member can see it. This location data is held in server memory only, is never written to a database or disk, automatically disappears after about 6 minutes without an update, and is permanently cleared whenever the server restarts. We keep no history or log of where you've been.

What we don't collect

We do not sell personal information. We do not use third-party ad-tracking pixels. Outside of the opt-in group location sharing described above (which you control and which is only ever visible to your own plan's members), we do not track your real-time location, and we never track in-venue crowd levels or foot traffic.

How we use it

To operate the core features of the app (saving and sharing plans, signing in, showing aggregate trending lists), to keep the service secure (rate limiting, fraud/abuse prevention), and to improve the app over time.

Your rights (California residents)

Under the California Consumer Privacy Act (CCPA/CPRA), California residents have the right to know what personal information we hold, request deletion of it, and request a copy of it. You can do both directly in the app: open the account menu while signed in and use Download my data or Delete my account. For any other request, contact us at the address on our Contact page.

Data retention

Account and saved-plan data is kept until you delete your account or the specific plan. Anonymous engagement events are kept in aggregate form and are not linked back to an individual account.

Changes to this policy

We'll update the "last updated" date above when this policy changes. Material changes will be called out on the app's home screen.

Contact

Questions about this policy or your data: see the Contact page.

See also: Terms of Service · Age Policy · Contact