Privacy Policy

Last updated July 27, 2026

Herd is a social calendar. It shows you where your friends are going by detecting ticket and reservation confirmations — so you don't have to post anything to keep your friends in the loop. Because that involves genuinely personal data, we've tried to write this policy plainly. It explains what we collect, why, who can see it, and the control you have. It applies to the Herd website, our mobile apps, and our email sync feature (Gmail and Outlook).

Who we are

Herd ("Herd," "we," "us") operates the Herd app and the website at herd.fyi. For any privacy question, or to exercise the rights described below, contact us at privacy@herd.fyi.

Information we collect

We collect only what we need to run the service:

  • Account details. Your phone number (used to sign in via a one-time code), and the profile you create — name, username, photo, and home city.
  • Events. Events you add manually, events you host, your RSVPs, and events detected from email sync (see below). Each event may include a title, date, time, venue, and location.
  • Connections. Your friend requests and accepted friends, and — if you choose to use contact-based friend suggestions — the contacts you share so we can match them to existing Herd users.
  • Mailbox data (only if you connect an account). Gmail, via Google's Gmail API, or Outlook, via Microsoft Graph. See the dedicated section below.
  • Device & usage data. Basic technical information needed to operate and secure the apps — for example a device push token if you enable notifications, plus standard logs (IP address, app version, timestamps).

Email sync — what it does and doesn't do

Email sync is optional, and you choose which mailbox to connect. Herd supports two providers, and asks each for the narrowest access that makes the feature work:

  • Gmail.Read-only access to your mail through Google's gmail.readonly scope. This is the only Google scope Herd requests.
  • Outlook. Read-only access to your mail through Microsoft Graph, using the Mail.Read scope, plus User.Read (so we can show you which mailbox is connected), openid, and offline_access (so syncing can continue in the background). These are the only Microsoft scopes Herd requests. The same connection covers Outlook.com, Hotmail, Live, and Microsoft 365 work or school accounts.

In both cases the purpose is single and specific: to find ticket, event, and reservation confirmation emails and turn them into events on your calendar. We do not ask for permission to send, delete, or modify your email, and we request no other Google or Microsoft data.

  • We only scan a fixed allowlist of senders. Herd looks only for booking and RSVP confirmations from a fixed list of official platforms, matched by the sender's verified domain: DICE, Resident Advisor, Eventbrite, Ticketmaster, AXS, Tixel, StubHub, SeatGeek, Live Nation, Universe, Fever, Shotgun, Luma, Partiful, Posh, Resy, OpenTable. We do not read your personal correspondence, and messages from senders outside that allowlist are not processed. On Outlook, Microsoft Graph's change feed hands our server your recent inbox messages so we can check who each one is from; anything not from an allowlisted sender is discarded immediately, never parsed for content, and never stored.
  • We extract event details, not your inbox. From a matching email we pull out structured details — event name, date, time, and venue — to create your event. That structured event, plus a reference to the source message so we don't create duplicates, is what we store; we do not store the full body of your emails or keep a copy of your mailbox.
  • How and where it's stored. The event details we extract are stored in our database (hosted on Supabase), encrypted in transit and at rest. Your Google and Microsoft access and refresh tokens are held encrypted in a dedicated secrets vault and are never exposed to other users.
  • Limited use — Google. Herd's use of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. We do not use Gmail data for advertising, we do not sell it, we do not transfer it to others except as needed to provide the feature to you, and we do not allow humans to read it except where you explicitly ask us to, for security or abuse-prevention, or where required by law.
  • Limited use — Microsoft. We apply the same limits to data received from Microsoft Graph, in line with the Microsoft APIs Terms of Use. We do not use Outlook mail data for advertising, we do not sell it, we do not transfer it to others except as needed to provide the feature to you, and we do not allow humans to read it except where you explicitly ask us to, for security or abuse-prevention, or where required by law.
  • You're in control. You can disconnect any connected mailbox at any time in Settings. When you do, we delete that account's stored access and refresh tokens and stop all syncing for it, typically within 24 hours. Events already created on your calendar remain yours to keep or delete — they are no longer linked to Google or Microsoft. You can also revoke access directly from your Google Account permissions or, for Outlook, from your Microsoft account's app permissions (personal accounts; work or school accounts).

How events are shared with friends

Herd is social by design, so it's important to be clear about who sees your events. Your Privacy Defaults control this:

  • Automatically share. Events you add or that are synced from your email become visible to your accepted friends.
  • Only share what I approve. Synced events start private and stay private until you choose to share each one.

Private events are never shown to other users. Friendship is mutual — only people whose friend request you've accepted can see the events you share. You can unfriend someone or delete an event at any time.

How we use your information

  • To provide the core service — your calendar, friends, and events.
  • To detect events from connected sources and keep your calendar up to date.
  • To send you notifications you've asked for (for example a friend's new event), which you can turn off.
  • To secure the service, prevent abuse, and debug problems.
  • To comply with legal obligations.

We do not sell your personal information, and we do not use it to serve you advertising.

Event images

When we show a cover image for an event detected from your email or imported from a link, we fetch that image once on our own servers and store a copy, then serve it from Herd. Your device loads event images from us — not from third-party ticketing or CDN servers — so those third parties don't receive your device's IP address or learn which events you're viewing.

Text messages (SMS)

We use your phone number to text you sign-in codes and, if you've consented, event invites and related notifications — for example when a friend invites you to an event before you've installed the app. You consent to these texts when you provide your number at sign-up, and you can withdraw consent any time by turning off text notifications in Settings or replying STOP to any invite text.

Message and data rates may apply, and message frequency varies. Your mobile number and opt-in status are not shared with third parties for their own marketing, and text-message consent is never a condition of any purchase.

Service providers

We share data with a small number of vendors who process it on our behalf, under contract, only to run Herd:

  • Supabase — our database, authentication, and backend hosting.
  • Google — Gmail API access, only if you connect a Gmail account.
  • Microsoft — Microsoft Graph (Outlook mail) access, only if you connect an Outlook account.
  • Vercel — hosting for the web app.
  • Twilio — to deliver your sign-in codes and event invite texts, and a push-notification provider to deliver alerts.

Data retention

We keep your information for as long as your account is active. When you delete your account, we delete your profile, events, and connections, and disconnect any connected mailbox. Data derived from Google user data — the tokens we hold and the event details extracted from Gmail — is deleted within 30 days of you disconnecting Gmail or deleting your account, except where a short-lived copy persists in encrypted backups or where retention is required by law. Data derived from Microsoft Graph — the tokens we hold and the event details extracted from Outlook mail — is deleted on the same terms.

Your rights & choices

  • Disconnect Gmail or Outlook, or change your sharing defaults, in Settings.
  • Turn off notifications at any time.
  • Access, correct, export, or delete your data — email privacy@herd.fyi and we'll help. Depending on where you live (for example the EEA, UK, or California), you may have additional rights, which we honor.

Security

We use industry-standard measures — encryption in transit and at rest, vault-encrypted access tokens, and row-level access controls — to protect your data. No system is perfectly secure, but we work to keep yours safe and to notify you if something goes wrong.

Children

Herd is not intended for anyone under 16, and we don't knowingly collect data from them.

Changes to this policy

We may update this policy as Herd evolves. If we make a material change, we'll update the date above and, where appropriate, notify you in the app.

Contact

Questions? Email privacy@herd.fyi.