Privacy (plain language)
This site is mostly static pages: event write-ups, links, and a simple email sign-up. I keep it small on purpose.
What I collect on this website
If you subscribe on the home page, I send a confirmation email to the address you enter. Your address is only stored in Resend (my email provider) as a contact after you click the confirm link, so an address can't be added to the list by anyone who doesn't control that inbox (double opt-in). I use it to send a short weekly note on what's coming up, plus occasional bigger updates like a new series or a venue change. Meetup and WhatsApp remain the main channels for day-to-day news.
To stop emails, use the unsubscribe link when I send a broadcast, or ask me to delete your address via the contact page.
Payments and donations
If you pay for a ticket or donate via the support page, the payment itself goes through Stripe. I never see your full card number. I keep a record of the purchase or donation (your email and the amount) so entitlements and bookkeeping stay correct; bookkeeping records are kept as long as Norwegian accounting law requires. Donations are anonymous by default: a name only appears publicly if you choose to leave one for the supporter wall, and amounts and email addresses are never shown publicly.
Automated confirmation emails are not fully set up yet; when they are, they will go through Resend from a verified domain.
Accounts
If you make an account, I store: your email (used for one-time login links, no passwords), the profile you fill in (name, languages, interests, your one-liner), any contact info you choose to add, your RSVPs, your event check-ins, and your email settings. All of it lives in Supabase (EU region). Your profile is private by default; contact info is never public and is only ever shared when you accept a specific request. You see exactly what's shared before you do. If you switch your profile to visible, your name can show up in the "who's coming" list on events you RSVP to, and people who checked in at the same event as you can see your profile on their connections page. You can switch it off anytime.
Separately: whoever is hosting an event you RSVP to can always see that you're coming (your name and email), no matter what your profile visibility is set to. That's what it takes to actually run an event: knowing numbers for capacity, reaching people if something changes, following up on a safety report. That view is only ever pulled to run the event or handle a report, is never published anywhere, and is separate from the "who's coming" list other guests see (which does respect your visibility setting).
Contact requests are stored too: who asked whom, the optional message, the answer, and, when you accept one, a copy of exactly the contact fields you chose to share at that moment. If you block someone, that's recorded so it can be enforced; if you report someone, the report is stored and read by me. If you're a member, I keep the membership status and payment records (via Stripe) with your email.
If you host a community meetup, the meetup itself (title, description, date, place, and your profile name as the host) is public: it appears on this site and can appear in the weekly email. Updates you post to your attendees are stored and shown on the meetup page. If you add a WhatsApp group link, it is shown only to the host and to people with an RSVP; inside the group, WhatsApp's own terms apply. Meetups you host are deleted with your account.
Every meetup has a chat for the host and the people who RSVPed. Messages you write there are stored, shown with your profile name to that group (never publicly), and deleted with your account. How busy a chat is (the number of messages) shows on the meetup's page and cards, but never the messages themselves. If you send a host a private question instead, it goes to them by email with your address as the reply-to, so their answer reaches your inbox directly; that's stated on the form before you send. The question text is stored (to enforce the per-meetup limit) and deleted with your account.
The community chat works the same way: messages you write in the lounge or in an event's chat are stored and shown with your profile name to the people in that channel, never publicly. Visitors who aren't signed in only ever see how busy a channel is (a message count), not a word of it. Photos you post are re-encoded on your own device before upload, which strips hidden location data; they're stored privately, shown only to the people in the channel through short-lived links, and deleted automatically after about 90 days. You can remove your own messages and photos anytime, and blocking someone hides you from each other in the chat both ways. Everything you wrote is deleted with your account.
The chat has a "Make it a meetup" button that turns a plan into a meetup draft. When you press it, the recent messages of that one channel (first names, message text, and poll questions with their vote counts, never emails, account details, or who voted what) are sent to Mistral, an AI service running in EU data centers, to write the draft with you. That conversation is not stored anywhere: I only count that you used the helper, so limits work and I can see whether the feature is useful. Mistral does not use this traffic to train its models. Nothing is posted to the chat unless you press publish yourself.
If you turn on heads-up notifications, your browser creates a delivery address for itself (a push subscription) and I store it with your account, only to send short nudges like "someone planned a new meetup". Nothing about your browsing is collected through it. Turn it off with the same button, or by blocking notifications for this site in your browser settings; deleting your account deletes the subscription too.
You can delete your account yourself on the account page. That removes your login, profile, contact info, RSVPs, check-ins, contact requests (including what was shared through them), and any meetups you host, permanently. Records of purchases, membership payments, and donations are kept as long as Norwegian accounting law requires. If you want a copy of the data I hold about you, ask via the contact page.
Distance from you, and maps
The events pages can show how far away an event is. If you turn that on, your position is read once by your browser (with its own permission prompt), the distance is worked out on your device, and the position is kept only in your browser's local storage. It is never sent to me or anyone else, and you can turn it off with the same button. Maps are click-to-load: nothing is fetched from OpenStreetMap until you press "Show map"; when you do, your browser requests the map directly from openstreetmap.org, which sees your IP address like any website you visit.
Third-party services
When you RSVP or browse on Meetup, WhatsApp, Instagram, or other linked services, their privacy rules apply on their side. I do not control what they store.
Images
Event cover images on this site are AI-generated promos, labelled on the page. I sometimes use real photos elsewhere, or images based on real photographs. See the About page for how I handle photos.
If you do not want to be identifiable in an image I use, or you do not want me to use a photo at all, email me or use the contact page.
Cookies and analytics
This site does not run marketing trackers or ad analytics, and it does not set non-essential cookies for that purpose. The measurement tools are Vercel Speed Insights (how fast pages load for real visitors) and Vercel Web Analytics (which pages get visited and roughly where visitors arrive from, like "a link on Meetup"). Both are cookie-free, do not follow you across sites, and do not build a profile of you; what I see is anonymous, aggregated numbers.
Bug reports
If something breaks in your browser, a button that doesn't do anything, a page that gets stuck, this site can quietly record what happened so I can fix it. What's stored is technical: the kind of error, a short message, roughly where in the code it happened, and the page you were on. I never store what you typed anywhere on the site, and anything that looks like an email address or a password, key, or login token is automatically stripped out before it's saved. That filtering looks for those specific patterns, not for names in general, so treat a bug report as technical diagnostic detail rather than something guaranteed free of every possible personal trace. This is different from the anonymous, aggregated analytics above: a bug report is its own entry, kept until the bug is fixed and then deleted automatically after about six months. If you're signed in when it happens, the report can be linked to your account by an internal id (never your name or email) so I can tell how many people ran into the same thing; deleting your account removes that link.
Questions
For anything unclear here, or if you need more formal wording for a contract or insurance form, use the contact page and tell me what you need.