Privacy Policy
The short version
- The app is a private, members-only directory for the Alcatraz chapter of YPO. Nothing in it is public.
- Your profile — name, photo, contact details, forum, events you attend — is visible to fellow signed-in members, like a chapter contact sheet. It is never shown to anyone else and never sold or used for advertising.
- There is no advertising, no analytics, no tracking, and no crash-reporting code in the app.
- A small number of service providers process limited data on our behalf — to host the database, text you a sign-in code, deliver notifications, and place home addresses on the member map. They are listed below, with exactly what each receives.
- Your phone stores only a disposable sign-in key. You can sign out at any time, and a chapter administrator can delete your data entirely.
1. Who we are
The Alcatraz YPO app (“the app”) is a members-only directory, events calendar, and notice board built for members and partners of the Alcatraz chapter of YPO (“the chapter”). It is operated by the chapter’s app administrators (“we”, “us”). This policy explains what information the app handles, why, who can see it, and the choices you have.
The app is not available to the general public. Only people whose phone number a chapter administrator has added to the member list can sign in.
2. Information we collect
Information from the chapter roster
Most of what appears on your profile was imported by chapter administrators from the chapter’s own master roster, which is why your profile may already contain details you never typed. Depending on what the roster holds, this may include your name, mobile phone number, email address, business email and phone, company and title, home and business addresses, forum, chapter join year, board positions, YPO member ID and status, partner or spouse, birthday, gender, and the name and email of your assistant.
Information you add in the app
- Profile details — a profile photo, a short “about me”, education, industries, and links to your social profiles. All optional.
- Family — you may add your children (first name, and optionally last name, birth date, and gender) so they can appear on your profile and be tagged in event photos. Optional, and entered only by you.
- Events — your RSVPs, and any events, announcements, or forum details you create if you have permission to.
- Photos — photos you choose to upload to an event, and any members or children you tag in them. The app asks for access to your photo library only when you choose to pick a photo; it never accesses your camera or microphone.
- Reactions — emoji reactions you leave on activity in the home feed.
Information collected automatically
- Sign-in session — when you sign in, the server issues a random session token, stored on your device, that expires after 30 days.
- Push notification token — if you allow notifications, the app registers an anonymous device token (and which operating system it belongs to) so the chapter can send you announcements and event reminders.
- Sign-in request timing — the time a sign-in code was last requested for a phone number, kept for about a minute to limit repeated requests, then deleted automatically.
- Activity — timestamps of chapter activity shown in the home feed, such as when a member first joins the app, RSVPs, or shares photos.
The app does not collect your device’s location. The member map places pins using the home address on the roster, not GPS. The app contains no analytics, advertising, or crash-reporting software, and does not read your contacts, calendar, or files beyond the photo you pick.
3. How we use it
- To run the chapter directory: show member profiles, contact details, forums, and board seats to fellow members.
- To run chapter events: publish the calendar, take RSVPs, show who is attending, and share event photos.
- To show the member map: place a pin at the approximate location of each member’s home address.
- To send announcements and event reminders by push notification, if you allow them.
- To verify your identity at sign-in and keep your session secure.
- To let members save each other’s contact details to their phone, or open an address in a maps app — actions you take on your own device.
We do not use your information for advertising, profiling, or any purpose unrelated to running the chapter, and we never sell it.
4. Who can see it
Everything on your profile is visible to signed-in members and partners of the chapter — and to no one else. Chapter administrators can additionally edit the roster. Nothing is visible to the public or to anyone who is not signed in.
| Information | Who can see it |
|---|---|
| Name, photo, forum, join year, board positions, company and title | All signed-in members |
| Phone number, email, business contact details, assistant contact | All signed-in members (this is the directory) |
| Home and business address | All signed-in members; your home also appears as a pin on the member map with your name and city |
| About me, education, industries, social links, birthday | All signed-in members |
| Partner or spouse | All signed-in members |
| Children you add | All signed-in members, on your profile and in photo tags |
| Events you RSVP to; photos you upload; reactions | All signed-in members |
| Session and push tokens, sign-in timing | No one — used only by the server to run the app |
Fellow members may save your contact details to their own phone’s contacts, as with a printed chapter directory. If you would rather not list a particular detail, edit your profile and leave that field blank.
5. Service providers
We do not share member data with third parties for their own use. A small number of providers process limited data strictly on our behalf to make the app work:
| Provider | Purpose | What it receives |
|---|---|---|
| Convex (convex.dev) | Hosts the app’s database, server functions, and file storage | All app data, encrypted in transit and at rest |
| Twilio Verify | Texts you a one-time sign-in code and checks the code you enter | Your mobile phone number and the code; contacted only by our server |
| Expo push service, delivering through Apple Push Notification service and Google Firebase Cloud Messaging | Delivers announcements and reminders to your device | Your anonymous device push token and the notification’s title and text |
| OpenStreetMap Nominatim | Converts roster addresses to map coordinates for the member map | The street address as text, sent by our server with no name or other identifier attached |
| Openverse and Wikimedia | Finds freely licensed cover images for events | The event’s name or location as a search term; never member data |
| Apple Maps, Google Maps, Waze | Directions to an event or a member’s address | Only when you tap to open one, from your own device, under that app’s own policy |
| Apple App Store, TestFlight, Google Play | Distribute and update the app | Governed by Apple’s and Google’s own policies |
We may also disclose information if required by law, or to protect the safety of members.
6. Storage and security
On the server. Chapter data is stored on Convex, a managed cloud platform based in the United States, which encrypts data in transit and at rest. The app communicates with the server only over encrypted connections (HTTPS and WSS). Every request for member data requires a valid session, and every session requires that a chapter administrator has first added your phone number.
On your device. The app stores only your session token — a random 256-bit value containing no personal information — in the operating system’s hardware-backed secure storage (iOS Keychain or Android Keystore). It is marked so that it is never included in a device or cloud backup and cannot be restored onto another phone. It expires after 30 days, and signing out deletes it immediately, on your device and on the server.
Sign-in. Codes are verified by Twilio, which enforces its own limits on guessing, and the sign-in screen is built so that it reveals nothing about whether a number belongs to a member.
An honest limitation. Profile and event photos are stored privately and are not listed or searchable, but they are served through long, unguessable links rather than being individually gated behind sign-in on every view. In practice a photo can be reached only by someone who already has its exact link. The app works fully without a profile photo if you prefer not to upload one.
7. Retention and deletion
- While you are a member, your profile is kept so the directory stays accurate. You can edit or blank most fields yourself in Account; what you set there is never overwritten by a later roster import.
- When a chapter administrator removes you, your profile, children, profile photo, push tokens, sessions, and sign-in records are permanently deleted from the server. Photos you uploaded to events may be removed by you or by an administrator.
- Sessions expire after 30 days or when you sign out. Sign-in request records are purged automatically within minutes.
- To request deletion of your account and data at any time, contact a chapter administrator (see Contact). Requests are honored promptly.
8. Your choices
- Notifications — allow or disable them at any time in your device’s Settings. The app works fully either way.
- Photos — the app requests photo-library access only when you choose to set a photo; you can decline, or revoke it in Settings.
- Profile fields — leave any optional field blank, or remove details already there, from Account.
- Sign out — from Account, which removes the session from your device and the server.
- Leave — ask a chapter administrator to remove you, which deletes your data as described above.
9. Children
The app is for adult members and partners of the chapter and is not directed to children. We do not knowingly collect information directly from anyone under 13. Members may choose to list their own children on their profile; that information is entered by the parent, is visible only to signed-in members, and can be removed by the parent at any time from Account.
10. Changes to this policy
If we change how the app handles information, we will update this page and its effective date, and note significant changes in the app. Continued use of the app after a change means you accept the updated policy.
11. Contact
Questions, corrections, or deletion requests can be sent to a chapter administrator through Contact in the app’s menu, or through the developer contact listed on the app’s Google Play or App Store page. A deeper technical walkthrough of how the app protects member data is available on request.