Privacy Policy

Effective Date: February 7, 2026

1. Introduction

Biome Collective, LLC, a Delaware limited liability company ("Biome Collective," "we," "us," or "our"), is committed to protecting your privacy and maintaining your trust. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our mobile application (the "App").

Please read this Privacy Policy carefully. By using the App, you agree to the collection and use of information in accordance with this policy.

2. Our Commitment: We Do Not Sell Your Data

WE DO NOT SELL, RENT, TRADE, OR OTHERWISE MONETIZE YOUR PERSONAL INFORMATION TO THIRD PARTIES. Period. Your data is not a product we sell.

We do not share your personal information with advertisers, data brokers, or any third parties for their marketing purposes. We do not participate in data exchanges or sell user lists. Your trust is more valuable to us than any revenue we could generate from selling your data.

The only sharing that occurs is: (1) information you choose to make public within the App, (2) with service providers who help us operate the App under strict confidentiality agreements, and (3) when required by law.

3. Information We Collect

3.1 Account Information

When you create an account, we collect:

Name and email address

Password (stored securely using industry-standard encryption)

Profile photo (optional)

Account preferences and settings

3.2 Profile Information

Information you choose to add to your profile:

Bio and personal description

Interests and preferences

Location (city/region you choose to display)

Social links (optional)

3.3 Events and Activities

When you interact with events:

Events you create, including title, description, date, time, and location

Events you mark as "Going" or "Interested"

Event searches and filters you apply

Comments and reactions on events

3.4 Groups and Organizations

When you participate in communities:

Groups and organizations you create or join

Posts, comments, and content shared within groups

Your role (member, admin, creator)

Group chat messages

3.5 Connections and Social Features

When you connect with others:

Connection requests sent and received

Your connections list

Direct messages with other users

Activity feed interactions (likes, comments, shares)

3.6 Messaging and Chat Servers

When you use messaging features:

Direct messages between you and other users

Chat server messages and channels you participate in

Media shared in conversations (photos, files)

Messages are stored securely and are only accessible to conversation participants. We do not read your private messages unless required by law or to investigate reported violations.

3.7 AI Assistant (Porter)

When you use Ask Porter:

Questions and prompts you submit

Conversation history within the session

Context from your profile to personalize responses

Porter conversations are used solely to provide you with helpful responses. We do not use your Porter conversations to train AI models or share them with third parties.

3.8 Location Information

With your explicit consent:

Precise location (GPS) for finding nearby events

City/region for search and discovery

Location entered manually for event searches

Location data is used only to show you relevant local events. You can disable location access at any time in your device settings. We do not track your location in the background or when the App is closed.

3.9 Device and Technical Information

Collected automatically:

Device type, model, and operating system

App version

Unique device identifiers (for push notifications)

Crash logs and performance data

IP address (for security and approximate location)

3.10 Usage Information

How you interact with the App:

Features and screens you access

Time spent in the App

Actions taken (taps, scrolls, searches)

Error logs and technical issues encountered

4. How We Use Your Information

4.1 Providing Our Services

Display events based on your location and preferences

Enable you to create, join, and manage events

Connect you with other users

Facilitate messaging and group communications

Power AI-assisted event discovery through Porter

4.2 Personalizing Your Experience

Recommend events based on your interests and activity

Suggest groups and organizations you might like

Customize your activity feed

Remember your preferences and settings

4.3 Communications

Send push notifications about events, messages, and connections (with your consent)

Email you about account activity and important updates

Respond to your support requests

4.4 Safety and Security

Detect and prevent fraud, abuse, and security threats

Enforce our Terms of Service and Community Guidelines

Investigate reported violations and harassment

Protect the safety of our users

4.5 Improving Biome Collective

Analyze usage patterns to improve features

Fix bugs and technical issues

Develop new features based on user needs

Conduct research using aggregated, de-identified data

5. Legal Basis for Processing (GDPR)

If you are located in the European Economic Area (EEA), United Kingdom, or Switzerland, we process your data based on the following legal grounds:

Contract Performance: Processing necessary to provide our services to you (account, events, messaging, connections)

Consent: For location data, push notifications, and optional features where you've given explicit permission

Legitimate Interests: Improving our services, ensuring security, preventing fraud, and analyzing usage (balanced against your rights)

Legal Obligation: When we must comply with applicable laws

6. Information Sharing and Disclosure

To be absolutely clear: WE DO NOT SELL, RENT, OR TRADE YOUR PERSONAL DATA TO ANYONE.

We only share information in these limited circumstances:

6.1 With Other Users (Your Choice)

Profile information you make public

Events you create (visible to attendees)

Posts in groups and organizations

Your connections (visible based on your privacy settings)

6.2 With Service Providers

We use trusted third-party services to help operate the App. These providers are contractually bound to protect your data and can only use it for the specific services they provide to us:

Cloud hosting and data storage (DigitalOcean)

Push notification delivery (Expo/Apple/Google)

Email delivery services

Error monitoring and crash reporting

Location services (OpenCage for geocoding)

6.3 For Legal Reasons

We may disclose information when required by law or when we believe in good faith that disclosure is necessary to:

Comply with legal process (subpoena, court order)

Protect the safety of any person

Prevent fraud or abuse of our services

Protect our legal rights

6.4 Business Transfers

If Biome Collective is involved in a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction. We will notify you of any change in ownership or uses of your personal information.

7. Data Retention

We retain your personal information only for as long as necessary to provide our services and fulfill the purposes described in this policy:

Account data: Retained while your account is active

Messages: Retained until you or the recipient deletes them

Event data: Retained for the duration of the event plus a reasonable period

Usage logs: Retained for up to 12 months for security and analytics

When you delete your account, we will delete or anonymize your personal information within 30 days, except where we are required by law to retain it (e.g., for legal claims or financial records).

8. Your Rights and Choices

8.1 All Users

Access and update your profile information at any time

Control your privacy settings (who can see your profile, send requests)

Manage push notification preferences

Enable or disable location services

Export your data through the Settings screen

Delete your account and associated data

8.2 EEA/UK/Swiss Users (GDPR Rights)

You have additional rights under GDPR:

Right of Access: Request a copy of all personal data we hold about you

Right to Rectification: Correct any inaccurate or incomplete data

Right to Erasure ("Right to be Forgotten"): Request deletion of your data

Right to Restriction: Limit how we process your data

Right to Data Portability: Receive your data in a machine-readable format

Right to Object: Object to processing based on legitimate interests

Right to Withdraw Consent: Withdraw consent at any time for consent-based processing

To exercise these rights, contact us at privacy@biomecollective.org. We will respond within 30 days. You also have the right to lodge a complaint with your local data protection authority.

8.3 California Residents (CCPA/CPRA Rights)

California residents have the right to:

Know what personal information we collect and how it's used

Request deletion of personal information

Opt out of the "sale" of personal information (we don't sell your data)

Non-discrimination for exercising your rights

We do not sell personal information as defined under CCPA/CPRA. We do not use or disclose sensitive personal information for purposes other than providing our services.

9. Data Security

We implement robust security measures to protect your information:

Encryption of data in transit (TLS/SSL) and at rest

Secure password hashing using industry-standard algorithms

Regular security assessments and monitoring

Access controls limiting employee access to user data

Secure cloud infrastructure with reputable providers

While we take extensive precautions, no system is 100% secure. We encourage you to use a strong, unique password and protect your account credentials.

10. International Data Transfers

Biome Collective is based in the United States. If you are accessing the App from outside the US, your information will be transferred to, stored, and processed in the United States.

For transfers from the EEA, UK, or Switzerland, we use appropriate safeguards including Standard Contractual Clauses approved by the European Commission to ensure your data receives adequate protection.

11. Children's Privacy

Biome Collective is not intended for children under 16 years of age (or the applicable age of digital consent in your jurisdiction). We do not knowingly collect personal information from children.

If you are a parent or guardian and believe your child has provided us with personal information, please contact us at privacy@biomecollective.org. If we discover we have collected information from a child, we will delete it promptly.

12. Third-Party Links and Services

The App may contain links to third-party websites, services, or content that are not operated by us. We have no control over and assume no responsibility for the privacy practices of these third parties.

Events listed on Biome Collective may include links to external websites or registration pages. When you leave our App, we encourage you to review the privacy policy of every site you visit.

13. Cookies and Similar Technologies

The Biome Collective mobile app does not use cookies in the traditional sense. However, we may use similar technologies:

Local storage to save your preferences and session data

Device identifiers for push notifications

Analytics tools to understand app usage

We do not use tracking technologies for advertising purposes. We do not participate in ad networks or serve targeted advertisements.

14. Do Not Track Signals

Some browsers include a "Do Not Track" (DNT) feature. Because there is no industry standard for DNT, we do not currently respond to DNT signals. However, as stated throughout this policy, we do not track you for advertising purposes or sell your data.

15. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors.

For material changes, we will provide prominent notice through the App or via email before the changes take effect. We encourage you to review this Privacy Policy periodically.

Your continued use of Biome Collective after the effective date of any changes constitutes your acceptance of the updated Privacy Policy.

16. Contact Us

If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:

Biome Collective, LLC
Email: privacy@biomecollective.org

For GDPR-related inquiries, EEA/UK residents may also contact your local data protection authority.

We are committed to working with you to resolve any concerns about your privacy and our data practices.