KeenOut
Legal · Effective 19 August 2026

Privacy Policy

This policy explains how KeenOut handles personal information in the Australian context.

Information we collect

We collect account details and sign-in identifiers for Google and/or verified email; private date of birth; required onboarding gender and optional dating preferences; profile, preferences and participation information; payment status; messages; check-ins; reports; blocks; feedback and notification settings. We derive current age from date of birth for eligibility and group matching, but do not show full date of birth publicly or send it to analytics. Members choose Female or Male once during onboarding; we do not infer gender from a name, photo or sign-in provider. For security we process a first-party random device-risk identifier, keyed network-risk summaries, action timing, rate-limit events and limited Stripe references when available. Photos you choose to share are compressed before upload, stored with the private group conversation and available to confirmed members to view or download. For a public HTTPS link in a confirmed-group message, KeenOut may fetch limited page information and proxy its thumbnail to create a private preview; the destination does not receive the member's identity or browser address through that preview image. After a meetup ends, its conversation and photos are automatically deleted once the chat has been inactive for seven days. If you choose live location sharing in a confirmed group, we keep only your latest point until you stop or its 15, 30 or 60 minute period expires; we do not store a route history. We do not collect hardware fingerprints, full card details or a home address.

Why we use it

We use information to operate provider-backed Google and email authentication, verification and password recovery; one canonical profile; matching, friend pairs, payments, meetup logistics, private chat, notifications, support, moderation, promotion protection, spam prevention, account security, internal analytics and legal compliance. Age is one of several private group-quality signals: KeenOut prefers comfortable, reasonably similar life stages without rigidly fragmenting a small pool. Required onboarding gender can be a soft balance signal without quotas or hard exclusion, and dating preferences are considered only when both people choose dating as an intent. Device and network signals are supporting risk indicators; a shared IP address is never treated as proof that accounts belong to one person.

Promotion protection

A deterministic risk process may consider account age, action velocity, repeated claims, cancellations, no-shows, friend-invite patterns, moderation history and a pseudonymous first-party device signal. It does not use protected characteristics, invasive fingerprinting or an LLM. Most members are approved automatically; uncertain cases may receive a neutral verification step or standard-price option. Internal scores are not public.

Processors and sharing

Google provides optional account identity for sign-in and, in owner-only venue administration, transient Google Maps place information used to compare a venue against owner-verified records. Google place results are displayed live with attribution and are not added to KeenOut CSV exports or retained as KeenOut venue facts. Supabase provides provider-backed email verification and password recovery and supports application infrastructure, Cloudflare hosts the service and provides optional Turnstile verification, and Stripe processes paid confirmations. We share only what is needed. Confirmed group members never see your date of birth, gender, dating preferences, private matching score, device/network signals, private risk information or payment data.

Storage, security and retention

We use secure HttpOnly cookies, access controls, row-level security, encryption in transit, rate limits, audited privileged actions and verified payment webhooks. The web app may retain device-local installation choices, other non-sensitive device choices and a limited public asset cache. Private messages, payment details, auth tokens, admin data and unrevealed venues are not placed in its public offline cache. When an account is deleted, visible profile data, Google and custom avatar links, preferences and push credentials are removed or anonymised. We retain only records reasonably required for payment and refund reconciliation, accounting, promotion and one-time entitlement enforcement, attendance integrity, unresolved safety or fraud matters, disputes and legal obligations. Retained promotion identity is keyed and pseudonymous rather than an email or public profile. Where private disaster-recovery exports are enabled, they expire after 30 days; a minimal pseudonymous deletion manifest prevents a restore from reviving a deleted profile and expires after 90 days. Operational data is deleted or reduced to non-identifying aggregates when its configured purpose ends.

Your choices and rights

You may access and correct profile information, configure optional notifications, block users, log out, change a password where enabled, and delete your account from Profile → Account. Date-of-birth corrections are limited and may require recent sign-in or support to prevent restriction and promotion misuse. Deletion requires an intentional confirmation and recent authentication. Active confirmed plans, payments, refunds, organiser responsibilities or unresolved safety matters must be resolved first. Historical messages that must be retained show the sender as Deleted member. Contact [email protected] or the Office of the Australian Information Commissioner.

Cookies and analytics

We use essential session cookies and a first-party random device-risk cookie. It is a limited abuse signal, not marketed or treated as a permanent device identity. Device storage may remember dismissed app prompts and non-sensitive interface choices. Privacy-conscious first-party analytics may measure install eligibility, installation, standalone sessions, notification choices, notification opens and offline sessions. Optional marketing technologies are not required for core use.

Organisers and Community Events

Community Events are independent organiser listings, distinct from matched KeenOut Experiences. We process organiser profile and ownership information, event content, RSVP and save records, event reports, material-change history, and genuine event analytics such as views, saves, shares and external ticket-link clicks. Private organiser contact email is used operationally and is not published unnecessarily. KeenOut does not receive external-provider payment-card or purchase details.