Draft. Review before launch.
Privacy policy
Last updated 26 September 2026
This explains what midnite collects, why, and what you can do about it. midnite is for people aged 18 and over. If you have a question, email hello@midnite.fun.
What we collect
- Your account. Email address, name, date of birth (to check you are 18 or over), and optionally your university email to get a verified badge.
- Your profile. Interests, music, favourite venues, home area, photo and your settings, such as who can see that you are going.
- Area, not location. We only store a coarse home area, such as a neighbourhood or city. We never store or share your precise location, and nobody can see a stranger's live location.
- Going and plans. Events you say you are going to, plans you make or join, messages in plans, and replies to plan links. If someone replies to a plan link without an account, we keep the name they type and a one-way hash of their IP address for rate limiting.
- Friends. Friend requests and friendships. If you choose to find friends from your contacts, phone numbers are hashed on your phone before matching and we do not keep the list. We store a hash of your own number if you add one.
- Photos. Photos you add to event albums.
- Safety. Reports and blocks you make, reports about you, and actions our team takes on them.
- Payments. Records of ticket resale, split payments and payouts. Card details are handled by Stripe and never stored by midnite.
- Usage. In the app, product analytics about which features are used. This website has no analytics, cookies or trackers.
Why we use it
- To run the app: show what's on, which friends are going, your plans and your tickets.
- To keep people safe: enforce the 18+ rule, handle reports and blocks, and stop spam and fraud.
- To take and pass on payments, and to meet our legal and tax duties.
- To improve the app using analytics.
Under UK GDPR our lawful bases are the contract with you (running the service), our legitimate interests (safety, fraud prevention and improving the app) and legal obligations (payments records). Where we ask for consent, such as for notifications or contacts, you can withdraw it at any time in your phone settings.
Who sees what
- Friends see that you are going by default. Showing this to people who are not your friends is your choice, and you can go invisible at any time.
- The busy map only shows totals, and only when at least 10 people are going to a venue. It never shows names.
- People you block never see you anywhere in midnite.
- A plan link shows the plan and first names only of members who switched this on.
Who we share it with
We do not sell your data. We use these providers to run midnite:
- Supabase: hosting, database, sign in and file storage.
- Stripe: card payments and payouts to sellers.
- PostHog: product analytics in the app.
- Resend: sending emails, such as university verification codes.
- Expo: delivering push notifications.
- Vercel: hosting this website.
Some of these providers may process data outside the UK. Where they do, they use approved safeguards such as standard contractual clauses.
How long we keep it
We keep your data while your account is open. Reports are kept for up to 90 days after the thing reported is deleted. Payment records are kept as long as the law requires. Rate limiting records for plan links are deleted after 2 days.
Your rights
Under UK GDPR you can ask to access, correct, delete or move your data, and object to or restrict how we use it. You can delete your account in the app at any time from settings. For anything else, email hello@midnite.fun. If you are not happy with our answer, you can complain to the Information Commissioner's Office at ico.org.uk.
Changes
If we change this policy in a way that matters, we will tell you in the app before it takes effect.