Houseparty
PrivacyTerms

Privacy, clearly explained

Houseparty Privacy Policy

This notice explains what Houseparty processes, why we process it, who receives it, how long it is kept, and the controls available to you. It covers the iOS app, joinhouseparty.live, invitation pages, support, and the Android waitlist.

Effective July 17, 2026Nibble Audio, Inc.

On this page

  1. Who we are and scope
  2. Privacy at a glance
  3. Data we process
  4. Contacts and invitations
  5. How data is shared
  6. Providers and recipients
  7. Cookies and browser storage
  8. Legal bases
  9. Retention and deletion
  10. International transfers
  11. Your rights and choices
  12. United States disclosures
  13. Age and children
  14. Security and automated checks
  15. Changes and contact
01

Who we are and what this policy covers

Nibble Audio, Inc. ("Nibble," "Houseparty," "we," or "us") is the controller of the personal data described in this policy. Nibble is a Delaware corporation located at 1209 Orange Street, Wilmington, Delaware 19801, United States. Contact us at team@onlywidget.com with "Privacy Request" in the subject line.

This policy applies when you use Houseparty, visit our website or invitation pages, join a waitlist, contact support, or are the recipient of an invitation. It does not govern another user's independent use of content you share with them or a provider's own-controller activities described in its notice.

02

Privacy at a glance

Contacts are not stored as an address bookPermitted phone numbers are checked in transient, authenticated requests at session start or when you refresh Find Friends. Names and photos stay on-device in current versions.
No advertising profileWe do not sell personal data, run behavioral advertising, or use contact-book data for advertising.
Limited analytics, with a choiceProduct analytics is enabled by default, remains pseudonymous and filtered, and can be turned off at any time in Settings.
You stay in controlSettings includes export, profile controls, analytics choice, legacy-contact deletion, blocking, and account deletion.
03

Personal data we process and why

We receive data from you, your permitted device features, other users who interact with you, Apple or Google infrastructure used to provide the service, and providers acting for us. If another user invites you, the inviter is the source of the selected phone number and invite context.

CategoryExamplesPurposeLegal basis
Account and profileVerified phone number; Firebase account ID; legacy Sign in with Apple identifier and email or relay email; age-eligibility and Terms-acceptance records; username, display name, profile photo, biography, and settings.Create, authenticate, secure, and administer your account; display your profile; provide account recovery and support.Contract; legitimate interests in security and service administration; legal obligations where applicable.
Contacts and invitationsPhone numbers from contacts you permit the app to read; a selected invite recipient's phone number; invite token, source, status, and timestamps; limited onboarding completion state. Current versions keep contact names, photos, and device contact IDs on-device.Perform a real-time friend match, prevent duplicate actions, deliver an invitation you choose to send, attribute sign-up, and prevent abuse.Your affirmative choice to enable contacts; contract for requested invitations; legitimate interests in integrity and abuse prevention.
Social and service activityFriends, requests, blocks, groups, presence and last-online state, call and message activity, streaks, reactions, notification interactions, and battery or charging availability shared in the app.Provide friend, availability, group, room, messaging, and safety features and keep them synchronized.Contract; legitimate interests in operating, securing, and improving the service.
Content and communicationsPhotos, profile images, video and voice messages, captions, status posts, reactions, live audio/video, screen share you initiate, support messages, reports, and related delivery metadata.Deliver content to people and groups you select; operate live rooms; provide support; investigate reports and enforce rules.Contract; legitimate interests in safety and service integrity; legal obligations; consent where required for optional device access.
Device, network, and securityIP address; app, OS, device, and network attributes; push tokens; IDFV or pseudonymous device identifiers; App Attest or DeviceCheck assertions; OTP attempts; fraud signals; security events and diagnostic logs.Connect and deliver the service, send notifications, verify accounts and devices, rate-limit requests, detect fraud, troubleshoot, and protect users.Contract; legitimate interests in network and information security; legal obligations where applicable.
Product analyticsPseudonymous analytics identifiers, event names, timestamps, feature state, and coarse app/device attributes. Analytics filters exclude names, email, phone, username, Firebase UID, contact data, content, invite tokens, and friend/call/group/invite identifiers.Measure reliability, adoption, user journeys, and aggregate service performance so we can improve Houseparty.Legitimate interests in privacy-filtered audience measurement, reliability, and product improvement. Product analytics is enabled by default and can be disabled at any time in Settings; where applicable, you may also object to this processing.
Website and Android waitlistWaitlist email, submission timestamps, and limited invite attribution when provided; network and security logs generated when a page or API is requested.Operate the website, maintain the waitlist and invite flow, secure endpoints, and respond to requests.Your request; contract steps; legitimate interests in security. Website product analytics is currently disabled.

We do not intentionally collect precise location, health data, government ID, payment-card data, or biometric templates. Camera images are not used for face recognition. Live video is not used to infer race, religion, health, sexual orientation, or other sensitive traits.

04

Contact matching, invitations, and non-users

Contact access is optional. If you allow it, Houseparty reads the contacts iOS makes available, normalizes their phone numbers on your device, and submits those numbers in transient encrypted, authenticated requests when an app session starts or when you refresh Find Friends. The service returns matching Houseparty accounts and does not write the request body to Firestore, Redis, logs, or analytics. Results are cached in app memory for that session.

Current app versions do not upload contact names, contact photos, or device contact identifiers. During the compatibility period, an older app version may include a name or device contact identifier in the transient matching request; the server does not retain or log those fields. Legacy uploaded contact graphs are disabled, are no longer used for matching or notifications, and have been deleted through a verified purge. You can also request legacy-contact deletion in Settings.

We create an invitation record only when you choose a specific person and send an invitation. That record can contain the selected phone number, an opaque token, inviter account, status, source, and timestamps. It expires after 30 days. A limited onboarding record may remember which selected invite or friend-request actions were completed so older and current app versions do not repeat them; it is not used to build a contact graph and is removed with the account.

If you do not use Houseparty but received an invitation, you can ask us to delete the pending invite early by emailing us with the invited phone number. We will verify enough information to prevent an unauthorized deletion request.

05

How information is visible or disclosed

  • Other users. Your username, display name, photo, profile information, friendship state, presence, status, and content are visible to the audiences selected by the feature. Calls expose your media to participants while connected.
  • People you invite. An invite link or SMS may identify you as the inviter and disclose the information included in the invitation.
  • Service providers. Providers below process only the data needed for their contracted function, subject to contractual and security safeguards where required.
  • Safety and law. We may preserve or disclose relevant data where reasonably necessary to comply with law, respond to valid legal process, investigate abuse, protect a person from serious harm, or establish or defend legal claims.
  • Business transactions. Data may transfer in a merger, financing, reorganization, acquisition, bankruptcy, or sale of assets, subject to applicable notice and protection requirements.
  • Professional advisers. Lawyers, auditors, insurers, and security specialists may receive limited data under duties of confidentiality.

Recipients can save, copy, record, or screenshot content. Deleting content from Houseparty cannot remove independent copies another person made outside the service.

06

Providers and other recipients

These are the material third parties used by the current service. Links open each provider's own privacy information.

Google Firebase and Google Cloud

Cloud processor / service provider

Why: Authentication, Firestore database, Cloud Storage, Cloud Functions and Run, Firebase Cloud Messaging, App Check, hosting, logging, rate limiting, Pub/Sub, Redis/MemoryStore, and BigQuery analytics storage.

Data: Account, profile, social graph, content, device/security, notification, support, and analytics data as needed for each service.

Provider privacy information ↗

Apple

Platform provider and independent controller for its services

Why: App Store distribution and review prompts, Sign in with Apple, Apple Push Notification service, App Attest, DeviceCheck, and device permission controls.

Data: Apple account data you authorize, device/app assertions, push routing data, and App Store interactions.

Provider privacy information ↗

Agora

Communications processor

Why: Real-time audio, video, and screen-share transport for live rooms and calls.

Data: Pseudonymous participant/channel identifiers, audio/video streams in transit, IP address, and technical network/device data needed to connect the call.

Provider privacy information ↗

Prelude and telecommunications carriers

Verification and fraud-prevention processors

Why: Deliver and verify one-time codes and assess abusive or suspicious sign-up attempts.

Data: Phone number, verification/correlation identifiers, delivery result, device/network signals, and fraud indicators. Carriers receive what is needed to deliver a code.

Provider privacy information ↗

PostHog

Analytics processor

Why: Privacy-filtered product measurement, feature performance, funnels, and aggregate improvement analysis.

Data: Pseudonymous identifiers and filtered event/device attributes; not contact books, message content, phone numbers, invite tokens, or social identifiers.

Provider privacy information ↗

Slack (Salesforce)

Support workflow processor

Why: Route support requests and human-reviewed draft replies to the Houseparty support team.

Data: Support transcript and relevant account, app version, platform, and case context needed to respond.

Provider privacy information ↗

OpenAI

Support assistance processor

Why: Generate suggested support replies for review, editing, or rejection by a human support teammate. OpenAI does not send replies directly to users.

Data: The support transcript and limited relevant profile/app context included in the support request; not contact lists.

Provider privacy information ↗

Vercel

Website hosting processor

Why: Host and deliver joinhouseparty.live, invitation pages, legal pages, and Android waitlist endpoints.

Data: Website requests, network/security logs, waitlist submissions, and invite routing data required by the requested page.

Provider privacy information ↗

We may replace a provider with one offering a substantially similar function. We will update this policy before a material change in data use and provide additional notice or obtain consent where required.

07

Cookies and similar technologies on the website

joinhouseparty.live does not currently set or read advertising cookies, analytics cookies, tracking pixels, persistent local storage, session storage, or browser identifiers for product analytics. Web PostHog collection is disabled. Invitation routing and Android waitlist submission work without those technologies.

Our host and network providers still process ordinary request information such as IP address, requested URL, time, and security signals to transmit pages, prevent abuse, and maintain service integrity. That server-side processing does not place a tracking identifier in your browser. If a strictly necessary cookie or local setting is introduced for a feature you request, we will describe its purpose and keep it only as long as needed.

Why there is no cookie banner

The current website does not use any non-essential cookie or similar browser technology that requires approval. If we introduce non-essential analytics, advertising, personalization, or cross-service tracking, it will remain disabled until you make the required choice. Refusing will be as easy as accepting, withdrawal will remain available, and the core website will continue to work.

08

Legal bases and whether data is required

Contract

Account, messaging, calls, groups, invitations you request, and core delivery data are needed to provide Houseparty. Without account and service data, we cannot provide those features.

Legitimate interests

We pursue proportionate interests in security, fraud prevention, support, moderation, service integrity, and privacy-filtered audience measurement and product improvement. Product analytics is enabled by default on this basis and can be disabled in Settings. We consider necessity, reasonable expectations, and your rights; you may object where applicable.

Consent or affirmative choice

Optional contacts, camera, microphone, photos, screen share, and notifications begin only after your device choice. Device permission is not used as blanket consent for unrelated processing.

Legal obligation and legal claims

We process limited data when necessary to meet legal, regulatory, tax, law-enforcement, child-safety, or record-preservation duties, or to establish, exercise, or defend claims.

Vital interests

In rare emergencies, we may use or disclose limited information necessary to protect someone's life or physical safety where another basis is unavailable.

Profile fields beyond what the sign-up screen marks as required are optional. Contacts, camera, microphone, photos, and notifications can be declined, although the associated feature may not work. Product analytics can be disabled in Settings without affecting core app features. Username search and invite links remain alternatives to contact matching.

09

Retention and deletion

We use the following periods or criteria, then delete or de-identify data unless a documented legal or safety hold applies:

Real-time contact matchingRequest bodies are not retained. In-memory results last for the app session. Legacy uploaded contact graphs are disabled and have been deleted through a verified purge.
Phone invitations30 days from creation or latest send, unless claimed earlier and required for account attribution or a dispute.
OTP and rate-limit stateVerification sessions and routine rate-limit records generally expire within 24 hours. Narrow fraud/security evidence may remain up to 90 days or longer for an active incident or legal duty.
Status posts24 hours, unless you remove the status sooner. Associated stored media is deleted with the expired status.
Video-message mediaRemoved after the intended viewer marks a direct message seen, or after all intended group viewers have seen it. Delivery metadata, captions, reactions, or non-video messages may remain with the conversation until deletion or account cleanup.
Live callsAudio/video is transmitted in real time and is not recorded by us as call media. Call state, participant, duration, and safety metadata remain as needed for the feature, account history, abuse prevention, or deletion workflow.
Product analyticsEvent-level data is retained according to necessity-based criteria and applicable provider retention and deletion controls, subject to periodic review. PostHog is configured not to store client IP addresses with events. Aggregate statistics that no longer identify a person may be retained longer.
Support and reportsFor the life of the case and a proportionate period afterward. Reports involving a deleted account are de-identified and normally expire within 180 days unless subject to a legal or safety hold.
Android waitlist12 months after the latest submission, or earlier on a verified request.
Data exports and deletion jobsExport downloads expire within 24 hours. Operational account-deletion records normally expire within 30 days; processor-erasure tracking may remain up to 180 days to document follow-up and, when available, verified completion.
Account and profileWhile your account exists. Inactivity alone does not currently delete the account; you can delete it at any time in Settings. We periodically reassess whether inactive-account retention remains necessary.

Account deletion removes or de-identifies the account, profile, authored content, social memberships, phone identity, and tokens from active Houseparty systems, and creates a tracked processor-erasure follow-up for corresponding provider-linked analytics. Completion may require provider-specific action and verification; some provider copies may remain while that process completes, and data may remain briefly in access-restricted backups until ordinary rotation. Retained safety or legal records are isolated from ordinary product use. We do not restore deleted data to active service except where necessary for disaster recovery and permitted by law.

10

International transfers

Nibble is established in the United States. Providers may process data in the United States, EEA, United Kingdom, Switzerland, and other locations where they or their subprocessors operate. Firebase Authentication is hosted in the United States; other Google services can use global infrastructure.

Where required, restricted transfers must be covered by an applicable lawful mechanism, which may include an adequacy decision, the EU Standard Contractual Clauses, the UK Addendum or International Data Transfer Agreement, Swiss-recognized safeguards, or a provider's valid Data Privacy Framework certification, together with supplementary technical and organizational measures where appropriate. The mechanism for a particular provider or transfer depends on the relevant contracting entities, service configuration, and provider terms. A narrow statutory derogation is used only when legally available. Contact us to request information about the relevant safeguard, subject to necessary redactions.

11

Your rights and choices

Depending on your location, you may have rights to know or access data, correct it, delete it, receive a portable copy, restrict processing, object to processing based on legitimate interests, withdraw consent, and complain to a supervisory authority. Withdrawal does not affect processing already lawfully completed.

  • In the app: edit profile information, turn analytics off, control phone discoverability, delete legacy uploaded contacts, export a copy, block users, manage permissions, and delete the account.
  • By email: send a request to team@onlywidget.com. State the account phone number or username and the right you want to exercise. Do not email an OTP.
  • Verification: we may request information reasonably necessary to verify identity and authority. Authorized agents must provide proof of authority where law permits us to request it.
  • Appeal: if we deny a request, reply with "Privacy Appeal" and explain why you believe the decision should change. We will provide any regulator contact required by your state.

The in-app export is a quick, size-bounded JSON copy and identifies any truncated section. Contact us for a complete verified access or portability response or for processor data not included in that file. EEA, UK, and Swiss residents may complain to the authority where they live, work, or believe an infringement occurred. You may contact us first, but you are not required to do so.

12

United States state disclosures

The table in Section 3 is also our notice of categories collected, sources, business purposes, and retention criteria. During the preceding 12 months, we may have collected and disclosed to service providers the categories listed there: identifiers; California customer-record information; internet or network activity; audio/visual content; approximate location derived from IP; and inferences limited to product or security state. We use sensitive information such as account credentials and message content only for permitted service, safety, and security purposes—not to infer characteristics.

We do not sell or share personal information

We do not sell personal information for money, share it for cross-context behavioral advertising, provide targeted advertising, or disclose it to third parties for their own direct marketing. We do not knowingly sell or share data of anyone under 18. Because we do not engage in those practices, there is no separate "Do Not Sell or Share" link.

Residents of applicable states may request access/know, correction, deletion, portability, a list of categories or specific third parties where required, opt out of covered profiling or targeted advertising, limit certain sensitive-data uses, appeal a denial, and receive equal service. We do not use personal data to make decisions producing legal or similarly significant effects. California's "Shine the Light" law permits requests about disclosures for third-party direct marketing; we make none.

13

Age and children

Houseparty is intended only for adults aged 18 or older. New users must confirm that they meet this requirement and accept the current Terms before creating a profile. We retain the confirmation time and policy versions in an account-private record. We do not knowingly permit anyone under 18 to maintain an account and do not seek parental consent as a substitute for the age requirement. If you believe a person under 18 is using Houseparty, use Contact Us in Settings or email us with "Underage Report" in the subject line. We will investigate and delete or restrict the account and associated data as appropriate.

14

Security and automated checks

Safeguards include encrypted transport, scoped database and storage rules, hashed or keyed phone lookups, short-lived communication tokens, OTP expiry and rate limits, app-integrity signals including App Attest or DeviceCheck where supported, credential separation, access controls, monitoring, deletion jobs, and incident-response procedures. No internet service can promise absolute security. Never share an OTP, and tell us promptly if you suspect account compromise.

Automated fraud and rate-limit rules, including signals supplied by Prelude, may delay or reject an OTP request or suspicious action. These checks protect accounts and service availability; they are not used for advertising. If you believe a verification decision is wrong, contact support for review. We do not use automated decision-making to infer sensitive characteristics or make credit, employment, housing, insurance, education, or other legally significant eligibility decisions.

15

Changes and contact

We may update this policy when the service, providers, or law changes. We will post the revised policy, update the effective date, and provide prominent in-app or other notice before a material change where required. We will request consent before a new incompatible purpose when applicable law requires it.

ControllerNibble Audio, Inc.
Emailteam@onlywidget.com
Mail1209 Orange Street, Wilmington, Delaware 19801, USA
HousepartyLive Moments with friends
Privacy PolicyTerms of ServiceCommunity GuidelinesContact