Privacy Policy
Last updated: June 2025
Jump to: This website · Told app
This website
told-app.com - waitlist, shared links, and marketing pages
Who we are
Told is a private place recommendation network for friends. This website is the public home for Told and handles waitlist sign-ups and shared recommendation links. References to “we”, “us”, or “Told” in this policy refer to the Told app and this website.
What we collect and why
Waitlist email address
When you join the waitlist we collect your email address and the time you signed up. We use this solely to notify you when Told launches. We will not send you marketing emails or share your address with third parties. You can ask us to remove you at any time by emailing us at the address below.
IP address (rate limiting)
When you submit the waitlist form, your IP address is temporarily used to prevent abuse. This is processed by Upstash (a Redis provider) and is not stored permanently or linked to your email address.
Shared recommendation links
If you visit a shared recommendation link (e.g. told-app.com/s/…), we display the place name and the name of the person who shared it. No personal data about you as a visitor is collected or stored when you view these links.
Cookies and consent
We use Cookiebot to manage cookie consent. Only strictly necessary cookies are loaded before you give consent. You can review or change your cookie preferences at any time using the cookie settings link in the footer.
Third-party services
We use the following third-party services to operate this website:
- Supabase - Stores waitlist email addresses. Hosted in the EU.
- Google reCAPTCHA Enterprise - Bot and spam protection on the waitlist form. Processes your interaction with the form and assigns a risk score. Subject to Google's Privacy Policy.
- Upstash - Rate limiting via Redis. Temporarily processes IP addresses to prevent abuse.
- Cookiebot - Cookie consent management.
- Netlify - Hosts this website. Netlify may log standard server access data (IP address, browser, pages visited) for operational purposes.
Legal basis for processing
We process your email address on the basis of your consent, given when you submit the waitlist form. You can withdraw that consent at any time by contacting us. IP addresses used for rate limiting are processed on the basis of our legitimate interest in preventing abuse of the service.
How long we keep your data
We keep waitlist email addresses until Told launches or until you ask us to remove yours, whichever comes first. Rate-limiting data expires automatically after 60 minutes.
Told app
iOS app - recommendations, friends, and your account
What we collect and why
Phone number
We collect your phone number when you create an account. It is used solely to verify your identity via a one-time SMS code. We do not use your phone number to contact you for marketing purposes or share it with third parties outside of what is needed to deliver the verification SMS.
Profile information
You may optionally provide your full name and a profile photo. These are visible to your accepted friends within the app.
Recommendations and photos
When you log a place, we store the place name, category, your personal note, a rating, the city and country, and geographic coordinates. You may also upload photos. This content is visible only to your accepted friends - it is never public.
Location (when in use)
If you grant location access, the app uses your current position to show where you are on the map. Location is accessed only while the app is in the foreground and only when you trigger the “find me” function. We do not track your location in the background or store a history of where you have been.
Friends and connections
We store records of friend requests you send or receive, and the connections you accept. Friend lists are visible only to you.
Third-party services
The app uses the following third-party services:
- Supabase - Stores your account data, recommendations, and photos. Hosted in the EU.
- Twilio - Delivers the SMS verification code to your phone number. Twilio receives your phone number for this purpose only.
- Google Places API - Powers place search when you add a recommendation. Your search query is sent to Google. Subject to Google's Privacy Policy.
- Mapbox - Renders the map and handles location search. Your device's location (when granted) and map interactions are processed by Mapbox.
Data retention
Your account and all associated data are retained for as long as your account is active. You can request deletion of your account and all associated data at any time by contacting us at the address below. We will action deletion requests within 30 days.
Your rights
You have the right to access, correct, or delete the personal data we hold about you. You also have the right to withdraw consent at any time, to object to processing, and (where applicable) to data portability.
To exercise any of these rights, email us at privacy@told-app.com. We will respond within 30 days. If you are in the EU or UK and are not satisfied with our response, you have the right to lodge a complaint with your local data protection authority.
Changes to this policy
If we make material changes to this policy we will update the date at the top of this page. For significant changes that affect how we use your data, we will notify you within the app.
Contact
Questions or requests: privacy@told-app.com