Privacy (plain language)
This site is mostly static pages: event write-ups, links, and a simple email sign-up. I keep it small on purpose.
What I collect on this website
If you subscribe on the home page, I send a confirmation email to the address you enter. Your address is only stored in Resend (my email provider) as a contact after you click the confirm link, so an address can't be added to the list by anyone who doesn't control that inbox (double opt-in). I use it to send a short weekly note on what's coming up, plus occasional bigger updates like a new series or a venue change. Meetup and WhatsApp remain the main channels for day-to-day news.
To stop emails, use the unsubscribe link when I send a broadcast, or ask me to delete your address via the contact page.
If you put your hand up to host or co-host on the helping-out page, I store your name, email, the events you picked, your optional note, and when you agreed to be contacted in Supabase (EU region). I use it only to follow up about volunteering; it does not subscribe you to marketing and it does not create an account or portal access. Ask through the contact page if you want the request deleted.
If you go on to help run something, I keep only the team records needed to organise the work and keep it safe. That can include your contact details, interests, agreed tasks, guides you have read, access you were given or had removed, and short handover notes. Putting your hand up does not give you access or make you responsible for anything.
Team conversation is in Slack. The media register points to originals in the company Google Drive and records where each photo may be used. I do not use Slack as an archive for attendee details, incidents or original photos.
If you pause or stop, I record what is finished and what access still needs to be removed. I only call access removed after somebody checks it. You can download your contributor record from the portal and ask through the contact page to delete or redact what I can. Some agreement, safety, access, payment or accounting records may need to stay. If they do, I will tell you what and why.
Payments and donations
If you pay for a ticket or donate via the support page, the payment itself goes through Stripe. I never see your full card number. I keep a record of the purchase or donation (your email and the amount) so entitlements and bookkeeping stay correct; bookkeeping records are kept as long as Norwegian accounting law requires. Donations are anonymous by default: a name only appears publicly if you choose to leave one for the supporter wall, and I check every name before it goes up. Email addresses are never shown publicly. Neither is what you gave, unless you tick the separate box asking for it to be shown.
Automated confirmation and reminder emails go through Resend from a verified domain.
Accounts
If you make an account, I store: your email (used for one-time login links, no passwords), the profile you fill in (name, languages, interests, your one-liner), any contact info you choose to add, your RSVPs, your event check-ins, and your email settings. All of it lives in Supabase (EU region). Your profile is private by default; contact info is never public and is only ever shared when you accept a specific request. You see exactly what's shared before you do. If you switch your profile to visible, your name can show up in the "who's coming" list on events you RSVP to, and people who were at the same event as you can see your profile on their connections page. An RSVP is enough to count as being there, so this isn't limited to people who used a check-in code. You can switch it off anytime.
Separately: whoever is hosting an event you RSVP to can always see that you're coming (your name and email), no matter what your profile visibility is set to. That's what it takes to actually run an event: knowing numbers for capacity, reaching people if something changes, following up on a safety report. That view is only ever pulled to run the event or handle a report, is never published anywhere, and is separate from the "who's coming" list other guests see (which does respect your visibility setting).
Contact requests are stored too: who asked whom, the optional message, the answer, and, when you accept one, a copy of exactly the contact fields you chose to share at that moment. If you block someone, that's recorded so it can be enforced; if you report someone, the report is stored and read by me. If you're a member, I keep the membership status and payment records (via Stripe) with your email.
If you host a community meetup, the meetup itself (title, description, date, place, and your profile name as the host) is public: it appears on this site and can appear in the weekly email. Updates you post to your attendees are stored and shown on the meetup page. If you add a WhatsApp group link, it is shown only to the host and to people with an RSVP; inside the group, WhatsApp's own terms apply. Meetups you host are deleted with your account.
Every meetup has a chat for the host and the people who RSVPed. Messages you write there are stored, shown with your profile name to that group (never publicly), and deleted with your account. How busy a chat is (the number of messages) shows on the meetup's page and cards, but never the messages themselves. If you send a host a private question instead, it goes to them by email with your address as the reply-to, so their answer reaches your inbox directly; that's stated on the form before you send. The question text is stored (to enforce the per-meetup limit) and deleted with your account.
The community chat works the same way: messages you write in the lounge or in an event's chat are stored and shown with your profile name to the people in that channel, never publicly. Visitors who aren't signed in only ever see how busy a channel is (a message count), not a word of it. Photos you post are re-encoded on your own device before upload, which strips hidden location data; they're stored privately, shown only to the people in the channel through short-lived links, and deleted automatically after about 90 days. You can remove your own messages and photos anytime, and blocking someone hides you from each other in the chat both ways. Everything you wrote is deleted with your account.
The chat has a "Make it a meetup" button that turns a plan into a meetup draft. When you press it, the recent messages of that one channel (first names, message text, and poll questions with their vote counts, never emails, account details, or who voted what) are sent to Mistral, an AI service running in EU data centers, to write the draft with you. That conversation is not stored anywhere: I only count that you used the helper, so limits work and I can see whether the feature is useful. Mistral does not use this traffic to train its models. Nothing is posted to the chat unless you press publish yourself.
If you turn on heads-up notifications, your browser creates a delivery address for itself (a push subscription) and I store it with your account, only to send short nudges like "someone planned a new meetup". Nothing about your browsing is collected through it. Turn it off with the same button, or by blocking notifications for this site in your browser settings; deleting your account deletes the subscription too.
You can delete your account yourself on the account page. That removes your login, profile, contact info, RSVPs, check-ins, contact requests (including what was shared through them), and any meetups you host, permanently. Records of purchases, membership payments, and donations are kept as long as Norwegian accounting law requires. If you want a copy of the data I hold about you, ask via the contact page.
Distance from you, and maps
The events pages can show how far away an event is. If you turn that on, your position is read once by your browser (with its own permission prompt), the distance is worked out on your device, and the position is kept only in your browser's local storage. It is never sent to me or anyone else, and you can turn it off with the same button. Maps are click-to-load: nothing is fetched from OpenStreetMap until you press "Show map"; when you do, your browser requests the map directly from openstreetmap.org, which sees your IP address like any website you visit.
Third-party services
When you RSVP or browse on Meetup, WhatsApp, Instagram, or other linked services, their privacy rules apply on their side. I do not control what they store.
Images
Event cover images on this site are AI-generated promos, labelled on the page. I sometimes use real photos elsewhere, or images based on real photographs. See the About page for how I handle photos.
For an event photo where you are identifiable, I ask before taking it and ask again before publishing it for a named destination. Agreeing to the photo being taken is not agreement to put it online. Full-size event originals go to the company Drive, while selected public copies may appear on this site or the agreed social/event platform. I keep a record of each controlled publication destination so a takedown does not depend on memory.
You can change your mind without giving a reason. Email me or use the contact page and I stop new use and remove the image from the surfaces I control. I will tell you honestly if an outside repost, cache, backup or existing code history means I cannot promise that every copy everywhere has been erased.
Cookies and analytics
This site does not run marketing trackers or ad analytics, and it does not set non-essential cookies for that purpose. The measurement tools are Vercel Speed Insights (how fast pages load for real visitors) and Vercel Web Analytics (which pages get visited and roughly where visitors arrive from, like "a link on Meetup"). Both are cookie-free, do not follow you across sites, and do not build a profile of you; what I see is anonymous, aggregated numbers.
Bug reports
If something breaks in your browser, a button that doesn't do anything, a page that gets stuck, this site can quietly record what happened so I can fix it. What's stored is technical: the kind of error, a short message, roughly where in the code it happened, and the page you were on. I never store what you typed anywhere on the site, and anything that looks like an email address or a password, key, or login token is automatically stripped out before it's saved. That filtering looks for those specific patterns, not for names in general, so treat a bug report as technical diagnostic detail rather than something guaranteed free of every possible personal trace. This is different from the anonymous, aggregated analytics above: a bug report is its own entry, kept until the bug is fixed and then deleted automatically after about six months. If you're signed in when it happens, the report can be linked to your account by an internal id (never your name or email) so I can tell how many people ran into the same thing; deleting your account removes that link.
The feedback form after an event
After an event you may get a link to a short form asking how it went, whether you paid anything and how, and whether anything went wrong. It's anonymous, and this is how: the link is the same link for everyone who was there, so it holds nothing that says which person you are. What gets stored is your answers, which event and date they were about, and the day you sent them. There is no name, no email, no account, no IP address, and not even a clock time, only the date.
Two honest limits, because I'd rather write them here than let you assume otherwise. If it was a small group and you describe something very specific, I may be able to work out who wrote it, and nothing technical fixes that. And because nothing links an answer to a person, I cannot find it again to show you or delete it if you ask later, which is exactly the same fact as it being anonymous. Answers are deleted on a schedule anyway: three years after I've read one and closed it, and one that nobody has dealt with yet is never deleted automatically at all.
The one part that isn't anonymous is the optional "you can contact me" box. If you fill it in, that contact detail is stored with your answers and comes to me by email so I can reply. It's erased as soon as I close the response, and automatically after 90 days whatever happens. Leave it empty and there's nothing to erase.
If you write anything at all, rather than only ticking a rating, a copy is emailed to me straight away so that something serious doesn't sit unread for a week. That email is a second copy of what you wrote, it sits in my inbox with the time it arrived on it, and it lasts as long as my inbox does. It still carries no name and nothing that says which person sent it.
One more thing that is true and worth knowing. I do keep a record that I sent you the invite, because otherwise I'd send it to you twice, and if something serious ever happened I could still send an alert about it by email. So I know who was asked. What I don't have, anywhere, is a way to connect that to what anyone wrote. The only case where those two collapse into each other is if barely anyone was sent the form at all, so the site simply doesn't ask about an event unless at least three people will get the link.
Whatever you write is read by me and isn't shown to hosts, to other guests, or anywhere on this site. One thing I won't dress up: for now I'm the only person reading these, including the ones that are about me. I'm setting up a second person for exactly that reason and I'll say so here once it's real. If something happened that needs the police, please do not wait on me.
Questions
For anything unclear here, or if you need more formal wording for a contract or insurance form, use the contact page and tell me what you need.