Crew Privacy Policy
Effective date: August 8, 2026
Operator: Bradley Portnoy ("Crew," "we," "us")
Contact: privacy@crewfests.com
Crew is a festival companion app for coordinating with your friend group at music festivals. Anyone can create an account; crews themselves are private and invite-only. This policy explains what we collect, why, and your choices.
1. What we collect
Account information. When you sign in with Apple, we receive your name (or the name you choose to share), email address (which may be an Apple private-relay address), and an identifier. You may add a display name and avatar.
Android interest signup. If you join the Android waitlist on our website, we collect the email address you submit and the time you joined. This signup is not linked to a Crew account, and we do not retain your IP address with it.
Content you create. Votes on sets, set ratings, "vibe" reactions, statuses, check-ins, meeting-point pins, saved spots, emoji reactions, feedback (including screenshots you choose to attach), and festival requests (festival name, city, country, approximate dates, and an optional note). If you explicitly attach your exact spot to a meeting-point pin or saved spot, that content includes one fixed precise coordinate.
Safety reports and blocks. When you report content or a user, we collect the reason, any optional details you provide, a bounded snapshot of the reported content, and relevant crew or event context. We also store the user-block relationships you create. Other users cannot enumerate your reports or block list.
Presence information. Crew is built around manual and optional automatic presence. A check-in records the stage or set, time, source, and your account. A stage- or set-level check-in describes your approximate location at that moment. We do not continuously track your location.
Location (optional). Auto Check-In uses While-Using-the-App location permission and evaluates a current location fix on your device. Crew does not upload that live fix or create a route or continuous location history; it uploads only the resulting stage- or set-level check-in. That result describes approximate location. You can disable Auto Check-In in the app and location access in iOS Settings.
Separately, when creating a meeting point you may choose Attach My Exact Spot. That action uploads one fixed precise coordinate to the pin and, if you choose to save it, the saved spot. The coordinate is associated with your account when collected and is visible only to members of the selected crew. Exact-spot sharing starts off for every new pin and is not implied by granting location permission or enabling Auto Check-In.
Device and technical data. We collect push notification tokens to deliver notifications you enable. Sentry receives crash reports, sampled performance traces, handled errors, device model and OS version, connectivity and operation tags, and diagnostic breadcrumbs such as screen session duration and the number of zone changes during that session. These events are linked to your signed-in Crew account identifier so we can diagnose recurring failures. The iOS client disables Sentry's default collection of personal information and removes location coordinates from event fields and messages before transmission. Crew does not currently provide an in-app switch to disable this diagnostic reporting. Offline actions are stored locally on your device and synced when you reconnect.
Product analytics. When product analytics is enabled, Crew sends a bounded, closed set of product-interaction events to PostHog server-side through a first-party route. These events describe account and crew acquisition, onboarding progress, voting and lineup completion, invite timing, curated navigation actions, notification lifecycle, public-web traffic/acquisition, and wrap use. There is no PostHog client SDK. The server replaces your Crew account identifier with a random analytics pseudonym; notification-funnel events use a separate random UUID for one logical notification. Public-web events use only closed categories for the public page, source type (direct, search, social, or other), and funnel step. A homepage platform selection creates one random journey UUID in a timestamped destination URL fragment so that explicit attempt can be joined to its iOS or Android outcome. The fragment is removed on arrival, the UUID remains only in page memory, and both the browser and report expire it after 30 minutes; ordinary page views have no visitor or session identifier. Crew does not send PostHog a raw URL, query, referrer, cookie, session identity, persistent browser identifier, IP address, user agent, location, native APNs device token, notification text, advertising identifier, or account, crew, festival, stage, or set identifier. PostHog autocapture and session replay are disabled. This information is not used for tracking or advertising. Share product usage data controls authenticated, account-linked analytics only. Turning it off stops future authenticated, account-linked collection. Signed-out personless invite/wrap opens and public-web events remain default-on; they use no cookie, install identifier, account identifier, or persistent browser identifier.
PostHog processes these events in the United States, on PostHog's US Cloud. Events also carry the release channel of the app build they came from — TestFlight, App Store, or a development build — so we can tell whether a change in the numbers tracks a particular build. That value describes the build, not you: it is the same for everyone using that build.
Crew turns analytics on separately for TestFlight builds and App Store builds, and each has its own conditions.
TestFlight capture will not be enabled until the TestFlight build includes Settings → Privacy → Share product usage data, this policy describes the collection as it will actually run, effective one-year retention is evidenced, Crew has executed PostHog's Data Processing Agreement (DPA) incorporating the Standard Contractual Clauses, and Crew has published its App Store privacy answers for this collection. Because TestFlight testers are real users, this policy is accurate before that capture begins rather than after.
App Store capture will not be enabled until everything above is true and, in addition, Apple has accepted an App Store build declaring this collection.
Data we do not collect. We do not collect continuous or background location history, contacts, health data, or advertising identifiers. We do not sell personal information as defined by the CCPA/CPRA, and we do not serve ads. Section 3 describes the aggregated, de-identified statistics we may share or license; those statistics do not identify you.
2. How we use it
- Operate the core product: showing your crew where you've checked in, your statuses, votes, and ratings
- Attach an exact meeting spot only when you explicitly request it
- Use de-identified, aggregated presence observations to improve app functionality, including suggested festival stage boundaries
- Use de-identified, aggregated presence and vote observations to produce the aggregate insights described in Section 3
- Send push notifications you've enabled (each category is individually toggleable in Settings)
- Generate your post-festival recap ("wrap")
- Maintain streaks and other in-app features
- Debug, secure, and improve the service
- Respond to feedback and support requests
- Measure interest in an Android app and send Android availability and testing updates to people who join that waitlist
- Filter shared text before publication, investigate reports (including profile reports with exact current photo evidence), hide violating content, and enforce our Terms
We keep an append-only history of votes, ratings, vibes, and check-ins (changes create new entries rather than overwriting old ones). This history powers features like re-rating sets and your festival recap. Crew may retain location-derived observations for stage-boundary improvement and for the aggregate insights described in Section 3, in each case only after removing direct account, device, crew, pin, and check-in identifiers and preventing the retained aggregate from being joined back to account data. We do not use retained de-identified observations to identify or reconstruct anyone's movements.
3. Who can see your information
Your crew. Crew is a group product. Members of a crew you join can see your display name, avatar, statuses, check-ins, presence freshness, votes, ratings, and reactions within that crew, subject to any per-crew sharing toggles you set. An exact coordinate attached to a meeting point or saved spot is visible only to that pin's selected crew. If either of two users blocks the other, Crew hides their profiles and authored activity from each other across shared crews; blocking does not remove either person's crew membership.
Multi-crew privacy. If you belong to more than one crew at the same festival, membership in one crew is never revealed to another. Crew-membership badges are visible only to you.
Service providers. We use Supabase for database, authentication, storage, and backend services; Vercel for web hosting and app-server routes; Sentry for crash, performance, handled-error, and interaction diagnostics; Apple for Sign in with Apple, TestFlight, and push notifications; GitHub for TestFlight feedback and festival-request triage; and Resend for transactional support alerts. We plan to use PostHog (United States) for server-side product analytics only after the capture gates in this policy are complete for the release channel concerned.
Android waitlist emails pass through Vercel's app-server route and are stored privately in Supabase. We do not give either provider permission to use those addresses for its own marketing.
TestFlight-native feedback may send the tester's comment, name/email, device/OS/build metadata, and screenshots from App Store Connect to a private GitHub repository under the Crew operator's personal account. Festival requests may send the submitted name, city, country, dates, note, account identifier, and review metadata to that same repository. In-app feedback remains in Supabase unless separately moved through an operator workflow. Vercel-hosted routes receive open-text requests before Crew's deterministic shared-text filter runs. Shared text and profile photos are not sent to an AI provider, and festival requests are queued for manual review rather than AI review.
Apple receives the APNs token and notification payload needed for delivery. Some current presence and meeting notifications may include a display name, meeting-point name, or stage/set presence in that payload. Resend receives a report identifier, content-type label, and exact report creation timestamp; report details, snapshots, and evidence are never sent by email.
Aggregate insights. We may share or license aggregated, de-identified statistics (e.g., how many users voted for a set, or overall attendance patterns at an event) with festivals, organizers, or other partners, including on a paid or otherwise commercial basis. These insights never identify you, your crew, or your individual activity, and we apply minimum group sizes before sharing. We do not share individual location observations or exact crew-pin coordinates with these partners.
Legal. We may disclose information if required by law, or to protect the rights, safety, or security of users or the service.
We do not sell or share personal information for advertising purposes.
4. Data retention and deletion
- You can delete your account in Settings. Account deletion immediately removes your profile and personal activity from our active systems, except where retention is required by law. Shared crew content you created, such as saved spots, may remain after we remove its association with your account. Residual copies in encrypted database backups are purged as those backups age out.
- Open safety reports and their private evidence remain until resolution. After resolution, report evidence, alert metadata, and moderation-audit details are retained for 24 months, then deleted or de-linked. We may retain them longer under a documented legal hold or for a severe or repeat-abuse enforcement need. The minimal tombstone that keeps moderator-hidden content from reappearing may remain while that content exists, but its actor, reason, report link, and other audit metadata are scrubbed after the retention period. Account deletion de-links identifiers where the evidence contract permits; it does not erase evidence that is still inside this safety window.
- Aggregated or de-identified data may be retained while it supports app functionality or the aggregate insights described in Section 3. This can include spatial evidence derived from check-ins for suggesting festival stage boundaries. Retained evidence contains no account, device, crew, pin, or check-in identifier, and Crew does not attempt to re-link it. Because it no longer identifies an account, it cannot be located or removed through an individual account-deletion request.
- Local data on your device (offline cache) is removed when you delete the app.
- We retain an Android waitlist email while we evaluate demand and may contact that address about Android availability or testing. You can withdraw at any time by emailing privacy@crewfests.com, after which we will delete the current signup.
- Before analytics capture is enabled on any release channel, Crew will evidence an effective PostHog retention limit of no more than one year. Once enabled, account deletion will remove the private pseudonym mapping and de-link future use of retained events; it will not retroactively erase already retained de-linked analytics events.
5. Your rights
Depending on where you live, you may have rights to access, correct, delete, or export your personal information, or to object to or restrict certain processing.
European Economic Area / UK. We process your data on the following legal bases: performance of a contract (providing the app), your consent (the Android waitlist and optional features such as Auto Check-In, exact-spot sharing, location contributions for stage-boundary improvement, and push notifications), and legitimate interests (security, debugging, service improvement). We separately rely on your consent to contribute your presence and vote records to the de-identified aggregate insights described in Section 3, including where those insights are shared or licensed to partners on a paid or otherwise commercial basis. There is no in-app setting for that purpose: to refuse it, or to withdraw your consent to it later, email privacy@crewfests.com, and we will exclude your future records from those insights. Refusing or withdrawing it does not limit any part of the app — your votes and check-ins are still collected to operate the product under our contract with you. You may withdraw consent at any time and may lodge a complaint with your local supervisory authority. Withdrawing consent stops future collection and future use for the purpose you withdrew; it cannot identify or remove observations that were already converted into a non-identifying aggregate.
California. We do not sell or share personal information as defined by the CCPA/CPRA. You may request access to or deletion of your information by contacting us.
To exercise any right, email privacy@crewfests.com. We will verify requests from Crew users through their account. If you joined the Android waitlist without a Crew account, we will verify your request through control of the email address you submitted.
6. International transfers
Crew is operated from the United States. If you use Crew from outside the U.S., your information will be transferred to and processed in the U.S. and other countries where our providers operate, which may have different data protection laws than your country. PostHog product analytics is planned for its US Cloud, so those events are processed in the United States. For EU and UK data subjects, our approved transfer mechanism is PostHog's Data Processing Agreement (DPA) incorporating the Standard Contractual Clauses. Analytics capture will not be enabled on any release channel — TestFlight or App Store — until that DPA is executed.
7. Children
Crew is an adults-only service and is not intended for anyone under 18 (or the age of legal majority in their country, if higher). If we learn that an underage person has created an account or provided us information, we will close the account and delete the information except where retention is legally required. Contact us if you believe an underage person is using Crew.
8. Security
We use industry-standard safeguards, including row-level security on our database, transport encryption, and access controls. No system is perfectly secure; please use a strong device passcode and report any suspected issue to security@crewfests.com.
9. Festival and lineup information
Festival schedules displayed in Crew are factual, publicly available event information (artist names, stage names, set times). This content is not personal information about you. See our Terms of Use regarding festival names and trademarks.
10. Changes
We may update this policy as the Service evolves. Material changes will be announced in the app or by notification. Continued use after changes take effect constitutes acceptance.
11. Contact
Bradley Portnoy
privacy@crewfests.com