✦ hangpalprivacy policy
last updated: october 3, 2026
hangpal is made by Carkeek Labs LLC, a small software company based in Seattle, Washington. “we” and “us” below mean Carkeek Labs LLC. this page covers everything: joining the waitlist, signing in, connecting a calendar, chatting with the agent, and paying for it. it's written to be read, not to hide anything. if anything here is unclear, email us, a real person answers. see also the terms of service.
the short version
- we don't sell your data, ever, to anyone.
- your calendar is read-only. hangpal never creates, edits, or deletes events (aside from creating an importable calendar event file).
- your friends' names and hangout history stay inside your account, never shown to anyone else and never used to train big AI models.
- you can disconnect your calendar, export your data, or delete your account at any time (just email us to do the last two).
what we collect
if you're on the waitlist
- your email address. that's the only thing we ask for to join the waitlist.
- basic technical info. like most sites, our host logs the standard things your browser sends: rough city-level location, device and browser type, and the page you came from.
- analytics signals. aggregate page views and speed measurements, through Vercel Analytics. it sets no cookies, and it doesn't tell us who you are.
- how far you got. before you sign in, we count which screens of the site and the setup questions you reached, so we can see where people stop. it's tied only to a random id that lives in that browser tab and disappears when you close it. no cookie, no name, no email, and it isn't linked to your account if you make one. we delete these counts after 180 days.
- ad measurement. if you arrived from one of our ads, the Meta pixel sets cookies so we can tell the ad worked. it doesn't tell us who you are by name, and it does not load at all if you're in the eea, the uk or switzerland. if you then subscribe, our server tells Meta a purchase happened, using only those same Meta cookies, your browser type, your IP address and the amount paid. never your name, your email, or anything from inside your account.
once you sign in
- your Google account basics. name, email address, and profile photo, from signing in with Google.
- your calendar, read-only. if you connect Google Calendar (or paste an Apple/Outlook ICS link), hangpal reads event titles, times, and attendees to figure out who you've hung out with and when you're free. it never writes, edits, or deletes anything on your calendar. calendar access tokens are encrypted at rest.
- your friends roster. names, how you know them, notes you add, and how recently you've seen them, whether entered by hand or inferred from your calendar.
- hangout history. dates, activities, locations, and notes for hangouts you log or the agent identifies from your calendar.
- your chat messages. what you say to the hangpal agent, and its replies, so it has context across a conversation and can pick up where you left off.
- your home city and rough coordinates. used to check the weather and suggest nearby things to do; never a precise location.
- saved ideas and preferences. plans you've saved, dashboard suggestions you've interacted with, and settings like your digest email preference.
- pictures you snap for an idea, briefly. if you photograph a poster or share a screenshot to turn it into an idea, the picture is shrunk on your device, sent to OpenAI to be read, and discarded. we never store it, and it is not attached to the idea. only the words that come back are kept, and only if you save them.
- your voice, only while the mic is on. if you tap the mic to talk instead of type, your audio goes to OpenAI to be turned into text, along with your friends' names and the places you go so it spells them right. the recording passes through our server once on its way there and is never stored. only the text comes back, and it's sent as a chat message like anything you type.
- usage and cost logs. which features you use and how much the AI behind the scenes costs to run for your account. this is for keeping the service healthy and affordable, not for profiling you.
- payment information, if you subscribe. hangpal never sees or stores your card number. Stripe, our payment processor, handles that directly; we only keep a customer/subscription reference and your billing status.
how we use it
- to run the actual product: draft invite texts, suggest who you've been drifting from, find local things to do, and remember your friends and past hangouts.
- to check calendar availability when planning something with a friend.
- to send you the weekly digest, if you've opted in, and account or billing emails you need (like a receipt or a payment failure notice).
- to email you when your invite off the waitlist is ready, plus the occasional short note about the launch.
- to measure whether our ads are reaching the right people.
- to keep the service secure, spam-free, and within the usage limits that keep it affordable to run.
- to fix things that break, when you tell the agent something went wrong and agree to send it to us. see bug reports below for exactly what that sends.
that's the whole list. we don't use your information for anything you didn't sign up for.
google user data
hangpal's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. concretely: calendar data is used only to power the features described above, inside your own account. it is never sold, never shown to other users, never used for advertising, and never used to train big AI or machine-learning models, ours or anyone else's. you can revoke hangpal's calendar access at any time from your Google account permissions or from hangpal's settings page.
bug reports
if something goes wrong in a conversation, the agent may offer to send it to the small team that builds hangpal. it never sends anything without you saying yes, and it tells you what it's sending before you do.
- the basic report has what you said went wrong, in your words, and a list of the last few things the agent did (which tools it ran and what came back). every person in it, you included, is replaced by a placeholder before it's stored. your friends' names don't leave your account.
- if you also say yes to including the conversation, the report carries the recent messages as written, names and all. that's a separate question, asked separately, because the people in your conversations never signed up for hangpal. say no and only the basic report goes.
- the app can also file one on its own, when it checks a change it just made and finds the change didn't stick. those contain internal record ids and counts, never names or messages.
bug reports are stored in our own database, alongside the rest of your account. the conversation in a report is read by us inside hangpal and nowhere else, and is never sent to any of the services listed below. the rest of a report (its summary line and the list of what the agent did, with the names we know about replaced by placeholders and your friends' contact details and notes left out) and any feedback you send us may be read with the help of Anthropic's Claude, to find and fix what went wrong. the email that tells us a report exists contains only the summary line. reports are deleted with your account, or on request at any time.
who we share it with
we don't sell your data. ever. we rely on a small set of trusted services to operate hangpal, each of which only handles what it needs to do its job:
- Vercel and Neon, hosting and our database.
- Google, sign-in and calendar access, on your explicit consent.
- OpenAI, powers the AI agent. it receives your chat messages, the context needed to answer them, any picture you snap for an idea, and your voice while the mic is on.
- Anthropic, helps us read your feedback and bug reports so we can fix what broke.
- Tavily, web search the agent uses to find local events and activities.
- Visual Crossing, weather forecasts and city lookups; it receives the city you typed and rough coordinates, never a precise location and never your name.
- Resend, sends transactional email (digests, invites, billing notices).
- Stripe, processes payments if you subscribe; handles your card details directly, we never see them.
- Sentry, error monitoring, so we can catch and fix bugs. it's configured not to capture personal data or session recordings.
- Meta, ad measurement for people who arrive from one of our ads, outside the eea, the uk and switzerland.
how long we keep it
while you're on the waitlist, we hold your email until launch, plus a reasonable window after, so we can invite people in waves. once you have an account, we keep your data for as long as the account is active. if you delete your account, we delete your friends, hangouts, chat history, bug reports, and calendar tokens; a minimal record (like billing history) may be kept as long as the law requires. ask us to delete anything at any point and we will, no questions asked.
where hangpal is offered
hangpal is offered in the united states, and accounts are granted one at a time from an invite list rather than by open signup. if you're in the european economic area, the united kingdom or switzerland, our ad measurement is switched off for you entirely, and the rights below are yours to use. emailing us is enough to use them.
your rights over your data
whatever you're covered by, we handle these the same way and for everyone, because keeping one process is simpler than keeping several:
- get a copy of what we hold about you, in a portable format.
- correct anything that's wrong.
- delete your account and everything attached to it.
- object to, or restrict, a particular use of your data.
- withdraw consent where you gave it, such as calendar access or the digest email.
email hello@hangpal.app and we'll do it within 30 days, usually the same week. we won't charge you or make you justify the request.
why we're allowed to hold it
we hold your account, friends, ideas and hangouts because you asked us to plan with them: that's the service you signed up for, and we can't provide it otherwise. calendar access and the weekly digest are separate, and both are things you switch on yourself and can switch off. we keep a small amount of aggregate analytics to know whether the site works at all, and we measure whether our ads worked, which is the one place a cookie is involved and the reason that measurement is switched off entirely for visitors in the eea, the uk and switzerland. we don't sell your data, and we never share anything from inside your account for advertising.
your choices
- disconnect your calendar any time from settings, or by revoking access in your Google account.
- unsubscribe from any email using the link at the bottom of it.
- see, export, correct, or delete anything we hold by emailing us.
- cancel a subscription any time from the billing portal in settings.
- opt out of ad tracking through your browser, device settings, or your Meta ad preferences.
security
calendar access tokens, refresh tokens and any calendar feed url you give us are encrypted at rest with AES-256-GCM before they're written to the database, so a copy of the database on its own doesn't hand anyone access to your calendar. all traffic to and from hangpal is encrypted in transit. if we ever discover a breach that affects you, we'll email you directly, and we'll do it inside the deadlines the law sets rather than at our convenience.
housekeeping
hangpal isn't meant for anyone under 16, and we don't knowingly collect their information. if this policy changes, we'll update the date above. material changes will be obvious, and if you have an account we'll email you about anything that changes how your data is used.
contact
questions, or want your data gone? email hello@hangpal.app and a real person (hi) will answer. hangpal is operated by Carkeek Labs LLC, a limited liability company registered in Washington state, which is the party responsible for the data described above.
accessibility
hangpal aims to meet WCAG 2.1 AA guidelines. if you run into a color, contrast, keyboard, or screen-reader issue anywhere in the app, or need something in a different format, email hello@hangpal.app and tell us what you were doing. we'll fix it or find a workaround, and you'll hear back soon.