Privacy Policy

Last updated: August 4, 2026

Burnoff.fyi (“Burnoff,” “we,” “us”) helps people in the San Francisco Bay Area discover lectures, talks, salons, and similar events. This policy explains what information the Burnoff mobile app and website handle, and how.

We’ve tried to keep this short and plain, because the honest answer is: we collect very little.

The short version

  • You can browse all events without an account and without giving us any personal information. There are no accounts in Burnoff at all — not even for paying subscribers.
  • Events you save are stored only on your device — we never receive them.
  • Your preferences — the page you write about what you’re interested in — are stored on your device. They are sent with a request only when recommendations are made — by you, or by your phone on the weekly schedule you set — used once to answer it, and stored nowhere. We keep no copy, no profile, and no history of them.
  • If you use Ask AI, the text of your question is sent to Google’s Gemini service to generate the answer. We don’t store your questions or the answers — not even in logs. Google, on the paid plan we use, doesn’t train its models on them, but does hold them briefly to police abuse of its own service — the details are below, in plain terms.
  • Subscribing is anonymous. Payment is handled by Apple; we never see your name, email, or card. Our server checks a random subscription ID to confirm you’re subscribed — it isn’t linked to your identity.
  • If you turn on the weekly email, your device gives us its push token — the anonymous delivery address Apple uses to route notifications to one phone — so our server can send the Sunday wake-up. It is the only per-user record we keep, it says nothing about who you are, and turning the weekly off deletes it.
  • The only time we collect personal information is if you choose to use the “Submit an event” / “Missing an event? Let us know” form, which asks for your email so we can follow up.
  • We do not sell your data, show ads, or track you across other apps or websites.

What we collect, and when

Browsing (no personal data)

When you open the app or website and browse events, we serve the public event listings from our database over an encrypted (HTTPS) connection. We do not require a login, and we do not attach your identity to this activity.

Events you save (stored on your device only)

When you bookmark/save an event, that preference is stored locally on your device. It is not sent to us or to any server. If you delete the app, your saved events are removed with it.

App preferences (stored on your device only)

Settings such as your light/dark theme choice are stored locally on your device and are not sent to us.

Adding an event to your calendar (stored on your device only)

When you use “Add” to put an event on your calendar, the event is created by your device’s own calendar system (or by opening your calendar provider’s website). We receive nothing when you do this.

Asking the AI (not stored, not tied to you)

The optional Ask AI feature lets you describe what you’re in the mood for and get event suggestions. When you use it:

  • The text of your conversation (your questions and the AI’s replies so far) is sent to our server, which forwards it to Google’s Gemini API to generate the response. To answer, the AI may also run Google web searches.
  • Your questions are not tied to your identity — the feature works without an account. If you’re subscribed, the request carries the random subscription ID described under “Subscriptions and payments” so our server can confirm your subscription and count your monthly usage. That ID isn’t linked to your name or email, and the questions themselves are never stored against it.
  • We do not store your questions or the AI’s answers. Each conversation lives only on your device while you use it; our server keeps no copy and no session. Our internal usage log records anonymous technical metrics only (model name, token counts, response time, estimated cost) — never the question, the answer, the search queries, your IP address, or anything identifying.
  • Your IP address is briefly processed in memory to prevent abuse (rate limiting) and is not stored.
  • Google processes the conversation text as a service provider under its own terms. Don’t include personal or sensitive information in AI questions — the feature only needs to know what kind of events you’re looking for.

Your preferences (stored on your device only)

Burnoff can recommend events based on a page of preferences you write about yourself — the subjects you care about, formats you like, things you’d never want, and what you’re hoping to get out of a season. This is the most personal information in the app, and it is deliberately built so that we never hold it:

  • The page is stored on your device, in the app. It is not uploaded, backed up to us, or synced.
  • When you ask for picks, the page travels with that one request to our server, which passes it to Google’s Gemini API to generate the recommendations, then discards it. We do not store it, log it, or keep a profile built from it. Our server keeps no copy once the response is returned. Google’s own handling is described under “How Google handles what we send” below — it is not instantaneous, and we’d rather you know exactly what it is.
  • Because we keep no copy, we cannot show you, export, or delete your preferences for you — you hold the only copy. You can read, edit, export, or erase the whole page at any time from inside the app, and deleting the app removes it.
  • Feedback you give on picks (a thumbs up or down, or a note) is appended to that same on-device page. It is not sent to us separately.

You choose what goes on the page. We’d suggest keeping it to your interests rather than sensitive details about yourself — the feature only needs to know what kind of events you want to hear about.

Your recommendations (stored on your device only)

The picks you receive are kept on your device so you can look back at them, and they are removed automatically once the events have passed. We do not keep a record of what was recommended to you.

Subscriptions and payments

A subscription unlocks the personalized features. It works without an account, and we never see your payment details:

  • Apple processes the payment. Subscriptions are purchased through the App Store under your Apple ID. We never receive your name, email address, or card details, and we cannot see them.
  • We use RevenueCat, a subscription-management provider, to tell our server whether a subscription is active. When the app first runs, RevenueCat generates a random, anonymous subscription ID for your install. It is not derived from your Apple ID, your name, your email, or your device’s advertising identifier.
  • That ID is sent with personalized requests so our server can confirm your subscription is active and count your monthly usage against your allowance. If you turn on the weekly email, it is also kept beside your push token so we can stop sending wake-ups when a subscription lapses. That is all it is used for. It is not used for advertising, profiling, or tracking you across other apps or websites — and your preferences and questions are never stored against it.
  • Reinstalling the app generates a new ID; you can restore an existing subscription through “Restore purchases,” which asks Apple, not us.

See RevenueCat’s privacy policy ↗ and Apple’s privacy policy for how each handles subscription data.

Email drops (your address stays on your device)

You can optionally have a set of picks emailed to you. If you use this:

  • Your email address is stored on your device only, with your other app preferences. We do not keep a mailing list — there is no subscriber database to breach, and nothing for us to sell or lose.
  • When you send yourself a drop, your address travels with that one request to our server, which hands it to Resend, our email delivery provider, to deliver the message — and then discards it. We do not store it afterwards.
  • If you switch on the weekly email, your phone can send it without you opening the app. On Sunday morning our server sends your device a push notification — a wake-up call, nothing more — and iOS gives Burnoff a few seconds to build that week’s picks and hand the message to our relay. Your device — not a server of ours — still makes the recommendations. The information that travels is exactly the same as when you press the button yourself; only the alarm clock changed. Nothing about you is kept on our side between one week and the next, which is also why the work has to happen on your phone rather than ours.
  • Sending the wake-up requires one piece of routing information from your device — a push token, described in the Notifications section below. If you decline notification permission, the app falls back to asking iOS for opportunistic background time, which is best-effort and may not run every week.
  • We do not send you marketing email, and there is no list to unsubscribe from. Turn the switch off, or clear the address, and sending stops — there is nothing left on our side to remove.
  • Link and open tracking are turned off.

Resend processes the message in order to deliver it, under its own terms. See Resend’s privacy policy ↗.

Notifications (and the one routing address that makes them work)

The weekly reminder itself is scheduled locally by your own device. But if you are a subscriber and turn on the weekly email, your device also sends us its push token — the long, random string Apple assigns so that a notification can be routed to one particular phone. We store that token, next to the anonymous subscription ID, so our server can send the Sunday wake-up push. It is the only per-user record our server keeps, and it is a routing address, not an identity: it contains nothing about you, it is not derived from your name, email, or Apple ID, and only Apple can connect it to an actual device. We cannot.

Turn the weekly email off and your device withdraws the token; the record is deleted and there is nothing left on our side to remove. Tokens whose subscriptions lapse are pruned. Turning notifications off in iOS Settings stops delivery entirely.

How Google handles what we send

Ask AI and personalized picks are generated by Google’s Gemini API. We use it on a paid plan, which is meaningfully different from the free one, and we think you should know precisely what that does and doesn’t protect.

What the paid plan gets you:

  • Google does not use what we send to train or improve its models. Its terms state that for paid services, Google doesn’t use your prompts or responses to improve its products — including cached content.
  • Google acts as a data processor handling the text on our behalf, under its Data Processing Addendum, rather than as an independent owner of it.

What it does not mean — the part most policies skip:

  • It does not mean Google stores nothing. Google retains prompts and responses for a limited period — currently documented as up to 55 days — solely to detect and prevent abuse of its service, and for disclosures it is legally required to make. That retained copy is not used to train Google’s general-purpose models.
  • It does not mean no human could ever see it. If automated systems flag content as a possible policy violation, authorized Google employees may review the flagged content. This is for policy enforcement, not quality review.
  • It does not mean the text stays in any particular country — Google may process or temporarily cache it in any country where it operates facilities.

To make repeated requests faster and cheaper, our requests reuse a common prefix that Google may cache automatically. That caching is in-memory, isolated to our project, and expires within about 24 hours.

We have not enabled Google’s optional developer logging, and we do not share data with Google for product improvement. You can read the governing terms at ai.google.dev/gemini-api/terms ↗.

All of which is a long way of saying: your preferences are safest if they describe what you’re curious about, and not much else.

Submitting an event (the one time we collect personal data)

If you use the form to suggest an event, we collect:

  • Your email address (required) — so we can contact you about the suggestion if needed;
  • Your name (optional);
  • A comment (optional); and
  • The event link you provide.

We use this information solely to review and, where appropriate, add the suggested event, and to follow up with you about your submission. We do not use it for marketing.

How information is stored and processed

The event database and the event-submission form are hosted on Supabase, a third-party cloud database provider, which stores this information on our behalf. Data is transmitted over encrypted connections.

The Ask AI feature runs through our server (hosted on Vercel) and is powered by Google’s Gemini API, which processes conversation text to generate responses (see “Asking the AI” above). We do not store that text on either.

Personalized picks and email drops run through the same server. Your preferences and your email address are handled in memory, for the duration of a single request, and are never written to our database or our logs. Our internal usage log records anonymous technical metrics only (model name, token counts, response time, estimated cost).

RevenueCat stores the subscription status attached to the anonymous subscription ID described above, so that our server can verify it. Resend processes an email drop in order to deliver it. Neither receives your preferences.

The app delivers updates through Expo Application Services (EAS). When the app checks for or downloads an update, standard technical request information (such as device/OS type and app version) may be processed by Expo to deliver the correct update. See Expo’s privacy policy at expo.dev/privacy ↗.

The app is distributed through the Apple App Store. Apple may collect information related to downloads and usage as described in Apple’s privacy policy.

We do not currently use third-party advertising or analytics SDKs in the app.

The website (not the app) uses Cloudflare Web Analytics to count page views. It is a privacy-focused tool that sets no cookies, does not fingerprint devices, and does not track you across sites — it tells us how many people visited, not who they are.

Data retention

  • On-device data (saved events, app settings, your preferences page, your recommendations, your email address) remains on your device until you clear it in the app or delete the app.
  • Your preferences, questions, and email address are retained by us for no time at all — they exist on our server only in memory, while the request that carried them is being answered.
  • Event submissions are retained for as long as needed to review them and maintain the event listing. You may ask us to delete your submission and associated contact details at any time (see “Contact”).
  • Your push token is retained while the weekly email is switched on. Turning it off deletes the record, and tokens whose subscriptions lapse are pruned.
  • Subscription status is retained by RevenueCat and Apple for as long as needed to administer the subscription.

Children’s privacy

Burnoff is intended for a general adult audience and is not directed at children under 13. We do not knowingly collect personal information from children.

Your choices and rights

  • You can browse everything without providing any personal information — the submission form and Ask AI are both optional, and you control what you type into them.
  • You can request access to, or deletion of, any personal information you’ve submitted by emailing us (see below).
  • You can read, edit, export, or erase your preferences page at any time from inside the app. Because we never keep a copy, there is nothing on our side to request or delete — which is the point of building it this way.
  • You can remove all on-device data (saved events, settings, preferences, recommendations, email address) by deleting the app.
  • You can cancel a subscription at any time through the App Store; the app links you there.

Changes to this policy

If we change how we handle information — for example, if we add user accounts, analytics, or crash reporting in a future version — we will update this policy and revise the “Last updated” date above.

For material changes — anything that expands what we collect or how we use it — the date change alone isn’t enough notice. Before such a change takes effect we will say so conspicuously: a notice in the app and on this site, and for changes that expand data collection, the app will ask you to review the updated policy before you continue using the personalized features. Because there are no accounts, we can’t email you about changes — there is no address list to email — so the app and this page are where changes will always be announced.

Contact

Questions, or requests to access or delete your information:

hello@burnoff.fyi