Privacy Policy
Last updated 27 July 2026
Who we are
Howff is operated by Howff Ltd, a company registered in England and Wales (company number 17351482). Our registered office is 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ. Howff Ltd is the data controller for your personal data. For any privacy question or to exercise your rights, contact [email protected].
Who this applies to
Howff is available to people in the UK and around the world. This policy is written to meet the UK GDPR and, for users in the European Economic Area (EEA), the EU GDPR; if you're elsewhere, equivalent local data-protection rights may also apply.
What we collect
- Profile & account: the display name and @username you choose. If you create an account with email and password, your email address and a securely salted, hashed version of your password (we never store the password itself). If you sign in with Google, your Google email, name and profile picture.
- Location, only when you ask: if you tap “use my location” to find your city, your device asks permission and sends your coordinates once to our server, which looks up the city name (via the Photon geocoding service, EU-hosted) and returns it. We don't store your coordinates. Showing your position on the in-app map happens on your device only.
- Your taste & trips: the free-text vibe and taste descriptions you enter, the cities and dates you search, and the venues you save. We treat free-text you write as personal data. It's stored as part of your trip/profile and used only to generate your recommendations (never sold or used for advertising) and is removed when you delete the trip or your account. (Our usage analytics record only its length, never the text itself.)
- Planning with friends: when you plan a night with friends or join one via a shared link, we store who's invited and coming and each person's availability/RSVP for that night. If you join a friend's night as a guest without an account, we store only the first name you type and, if you choose to add your taste, the venues you pick (kept as a numeric vector), used to tune that night's picks and removed when the night is deleted. No account is created unless you choose to sign up.
- Ranking feedback: when you hide a recommendation (“not for me”, with an optional preset reason) or rate what a place was like after going (preset chips such as “lively” or “great food”), we store that choice (as a fixed category, never free text) so your future recommendations improve and, for place ratings, so the venue's character profile reflects real visits. This works regardless of your analytics choice, and it's included in your data export and deleted with your account.
- Safety: blocking & reports: if you block someone we record the block (it also unfriends you both and stops requests either way); if you report a user, a group plan, a review, a photo or a venue we record what you reported, the reason you picked and when, so a human can review it. Kept while needed for safety and moderation.
- Notifications: your notification preferences, and, if you allow push notifications, a device push token so we can deliver them. We also keep a short-lived log of what we sent you (type and time, not content) to avoid duplicates.
- Waitlist: if you join the waitlist on our website, the email address you enter (and optionally your city), used only to tell you about the launch. Unsubscribe or ask us and it's deleted.
- Usage analytics, only if you opt in: anonymous events such as which screens you open and whether a recommendation was saved, recorded by our own cookieless analytics and used to improve the product.
- Technical: standard server logs (IP address, request time) for security and abuse prevention, and, so we can fix crashes, server error reports (which don't include your message content).
Legal basis (UK & EU GDPR)
- Legitimate interest: running the core service (storing your profile, trips and saved venues), keeping it secure, and acting on blocks and reports to keep users safe.
- Consent: non-essential analytics (accept or decline, change any time), the optional location lookup, push notifications, and the launch waitlist.
- Legal obligation: handling illegal-content reports and safety duties that apply to us (for example under the UK Online Safety Act).
- Contract: if you take out a paid subscription, to provide and bill for it.
Who we share data with
We don't sell your data. To provide the service we send some data to processors:
- Anthropic: your vibe/taste text is sent to the Claude API to generate recommendations, under a data processing agreement. Anthropic does not use commercial API data to train its models.
- OpenAI: your vibe/taste text is sent to OpenAI's embedding API to match you to venues (it is converted into a numeric vector, not stored by us as text). OpenAI does not use API data to train its models.
- Resend: sends our emails (sign-in verification, password reset, and the notifications you've enabled). It processes your email address and the message.
- Expo, Apple & Google: if you enable push notifications, they're delivered through Expo's push service and your device platform's notification relay (APNs / Firebase).
- Sentry: server error monitoring, so we find and fix crashes; reports are technical (stack traces), not your content.
- Cloudflare: sits in front of our server (network security) and stores our encrypted database backups in EU-jurisdiction storage.
- Photon (Komoot): city name lookup for searches and the optional “use my location” button (EU-hosted).
- Map & venue data: OpenStreetMap, Overture Maps, Wikipedia/Wikivoyage (venue descriptions, CC BY-SA) and Ticketmaster (for events). These provide venue data; they don't receive your personal data.
- Hosting & payments: the app runs on our own server in the United Kingdom. For subscriptions, Stripe processes card details; we never see your full card number.
International data transfers
Some of our providers are based outside the UK and EEA. In particular, the vibe and taste text you enter is sent to Anthropic and OpenAI (United States) to generate and match recommendations, and Resend, Sentry, Expo and Stripe (United States) process the data described above. When we transfer personal data internationally we rely on appropriate safeguards, such as the UK International Data Transfer Agreement/Addendum and the EU Standard Contractual Clauses, or an adequacy decision where one applies, so your data keeps an equivalent level of protection.
Cookies
We use a strictly-necessary session cookie to keep you signed in, a cookie that records your analytics choice and, if you join a friend's night via a shared link without an account, a strictly-necessary cookie that remembers you on that night so you can update your answers. No advertising or cross-site tracking cookies. Analytics, if enabled, uses a privacy-respecting, cookieless provider. Where we link out to ticketing or booking partners using affiliate links, following one may let that partner set its own cookies under their own policy.
Retention
We keep your profile, trips and saved venues until you delete them or your account. Raw analytics events auto-expire after 180 days (only aggregate statistics are kept longer), records of the notification emails we sent you expire after about 120 days, and database backups are kept as a short rolling series (roughly two weeks) before being deleted.
Your rights
You can access, correct, export or delete your data: Account → Privacyin the app has one-tap “Download my data” and “Delete my account” options. Deleting your account removes your profile, trips, taste, saved venues, friendships, reviews and photos. You can also make any request by contacting [email protected]. You can complain to the UK ICO (ico.org.uk); if you're in the EEA you can instead complain to your local data protection authority.
Changes
We may update this policy; we'll change the date above and, for material changes, tell you in-app.