Skip to content

Privacy Policy

Last updated: September 21, 2026

This Privacy Policy explains how Droozi ("we", "our", or "us") collects, uses, shares, and protects your personal information when you use the Droozi mobile application and the Droozi website at droozi.com, including features such as account-required event and trip email invitations, guest event RSVPs, and our contact form (together, the "Service"). It also describes your privacy rights and how to exercise them.

By using the Service you agree to this Privacy Policy. If you do not agree, please do not use the Service.

1. Who we are

The data controller responsible for your personal information is Droozi, the operator of the Service. You can reach us about privacy matters at privacy@droozi.com.

2. Information we collect

Information you provide

  • Name
  • Email address
  • Phone number
  • A timestamped confirmation that you are at least 16; a legacy or profile flow may also include date of birth (see "Age requirement" below)
  • Profile information and photos you choose to upload
  • Account credentials (your password is stored only in hashed form)
  • Content you create, such as events, trips, lodging stays, RSVPs, future locations, notes, messages, broadcasts, and photos

Sensitive information

We do not intentionally collect government IDs, racial or ethnic origin, health information, or biometric data. We do process exact or approximate coordinates for places you choose to save, and we store messages you choose to send through Droozi. Exact saved coordinates and message contents may be treated as sensitive personal information under applicable law. We use them only to provide the maps, planning, messaging, safety, and audience-control features you request.

Contacts you choose to import

Droozi lets you build your network from contacts you choose to import. You control whether to do this, and you should only import contacts you have permission to share.

  • Phone address book: if you grant contacts permission, we read contacts your operating system permits so you can choose people to import. We upload only contacts you select: names, phone numbers, email addresses, organization, and ZIP/postal codes. Contact photos, full street addresses, and unselected contacts are not uploaded. We send selected ZIP/postal codes to Google Maps Platform for approximate geocoding. Imported phone contacts are not sent to third-party data-enrichment providers and are not used to discover which contacts have Droozi accounts.
  • LinkedIn import: if you import LinkedIn connections through Droozi's connected LinkedIn import, we use Unipile as a service provider to provide the hosted authorization flow, receive connection-status webhooks, and retrieve the LinkedIn connection and profile information you authorize us to import. This may include names, LinkedIn profile URLs or public identifiers, headline, company, role, profile image URL, and location text. Droozi does not use Unipile to post to LinkedIn on your behalf or access your LinkedIn messages.
  • LinkedIn enrichment: for LinkedIn imports you initiate, we may use a third-party business-data provider (Apollo.io) to enrich LinkedIn information (for example, to add or confirm a name, role, company, or photo). This means some details about an imported contact may come from third-party sources rather than from you.

If you are an imported contact (a non-user) and want your information removed, contact privacy@droozi.com.

Guest event RSVPs

You may respond to an eligible event without creating an account. We collect the name, email address or phone number, and RSVP status you provide, together with the invite or public-event source needed to manage the response. If you use Google or Apple to verify the response, we receive the limited identity information described in the sign-in prompt. We do not create a Droozi account from a guest RSVP.

If SMS reminders are offered and you explicitly opt in, we send a confirmation message before enabling reminders and record the consent or opt-out status needed to honor your choice. The event host can see the guest list and response status needed to manage the event.

Event invitation emails

A host or cohost may provide your email address to invite you to an event even if you do not yet have a Droozi account. We use that address to deliver and manage the invitation, match it to the canonical email on an account only after you authenticate, prevent misuse, and show the host a delivery or response status. We do not tell the host whether the address was already registered before you claim the invitation.

Trip invitation emails

A trip host or cohost may provide your email address to invite you to a trip even if you do not yet have a Droozi account. We use that address to deliver and manage the invitation, match it to the canonical email on an account only after you authenticate, prevent misuse, and show the host a delivery or response status. We do not tell the host whether the address was already registered before you claim the invitation.

A trip invitation always requires a Droozi account, and opening the link never joins you to the trip. Before you sign in we show only a minimal preview — the trip name, the host's display name, the city-level destination, the date range, and a masked hint of the invited address. Signing in with the invited address connects the invitation to your account as a pending invitation; you then explicitly accept or decline, and only accepting makes you a traveler and reveals the full plan. Declining is recorded so the invitation cannot be used again.

Location data

Droozi does not collect or store your live location or track you in the background. On iOS, if you grant when-in-use location permission, the Google Maps SDK may process your device location to center the Add Future Location map and show a current-position dot under Google's own privacy practices. Droozi does not send that live position to its backend. A place is saved only when you manually select or approve it.

We store the places you choose: an address or label, exact or approximate coordinates, dates, location type, and sharing audience. This includes manual future locations and manually declared default locations. A default location may represent a city- or venue-level present-tense presence, but it does not update from your device position. When you search for a place or enter an address, the relevant query or coordinates may be sent to Google Maps Platform through Droozi's backend to convert it into usable map data. Trip-planning features may also use approved place coordinates, schedules, and travel preferences to request route estimates. They may request a Google Places photo after you explicitly review a confirmed place for an unsaved trip idea or when an eligible saved trip idea containing a Google place reference becomes visible. On Home, the selected future-location card may request a city thumbnail when visible, using the saved destination coordinates to resolve a city or town.

Usage and device data

  • App and site interactions
  • Device information and identifiers
  • Push notification tokens (to deliver notifications you enable)
  • Log data and IP address
  • Scrubbed error and performance diagnostics when backend monitoring is enabled

Google API Services

Droozi uses certain Google APIs (such as Google Sign-In and Google Calendar). Our use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

Google Calendar

When you sign in or connect with Google, Droozi requests read-only access to your primary Google Calendar. We can read future event title, time, location, and description to provide travel prompts and event-location notifications. Droozi cannot create, edit, or delete Calendar events. Other Droozi users do not automatically receive your raw Calendar feed.

What Droozi can and cannot see

DataWhat Droozi can useWhat it does not do
Device locationWith your permission, the iOS app can ask the Google Maps SDK to center the Add Future Location map and show a current-position dot.Droozi does not collect or store your live location or track you in the background. A place is saved only when you select or approve it.
Saved placesThe address or label, exact or approximate coordinates, dates, location type, and audience you choose.A saved place is not continuously updated from device GPS.
Phone contactsOnly contacts you select: names, phone/email values, organization, and ZIP/postal code.It does not upload contact photos, full street addresses, or unselected contacts.
Google CalendarFuture event title, time, location, and description after you authorize Google Calendar.It cannot create, edit, or delete Calendar events, and it does not share your raw Calendar feed with other users.
Authorized operatorsStored account/profile data, imported contacts, saved locations, notes, event records, and conversation records for approved operations.It does not give operators unselected contacts or current device GPS.

If you connect Google Calendar, you authorize read-only Calendar access. The current features read future events from your primary calendar, including event title, time, location, description, status, and the identifiers needed to process updates. We use that information to suggest future places and trips, notify you about eligible travel, and, after separate lodging consent, privately look for possible hotel or lodging reservations. Droozi cannot create, edit, share, or delete Google Calendar events.

Droozi stores encrypted Google access and refresh credentials and limited connection metadata while the calendar remains connected so authorized features can refresh and respond to Calendar updates. Other users do not automatically receive your raw Calendar feed.

Calendar-detected trip lodging

Lodging detection requires separate, versioned consent. Candidate results are private to you and returned with no-store controls. Droozi does not persist raw Calendar titles, descriptions, guest lists, confirmation codes, booking links, prices, or the unselected candidate feed. It may send a candidate's location text to Google Maps Platform to resolve the property before showing it for review.

Only after you review and import a stay does Droozi save the resolved property name, address, exact coordinates, dates and times, booker, selected occupants, consent records, and encrypted or one-way source references needed to detect changes. The saved stay is visible to current and future accepted participants in that trip. Occupants can remove themselves, the booker or an authorized trip manager can delete the stay, and you can review or erase lodging data from the app's Lodging data & privacy screen.

Wikipedia and Wikimedia Commons photos

Supported app versions can prefer reusable Wikimedia Commons photos for trip places and Home future locations. For Home, the backend sends the saved city name to English Wikipedia, then checks the returned article coordinates against the saved destination locally. It sends the selected public file title to Wikimedia Commons to retrieve the image and its author, source and license information. These Wikimedia requests do not include your account or trip identifiers, dates, sharing audience, full address or saved coordinates.

Droozi keeps a reusable public city-match cache keyed by a one-way hash of the city label and a coarse geographic cell. It stores public article coordinates and image metadata, not your precise saved point. Successful city matches refresh after seven days; unsuccessful matches may be retained for five minutes before retrying. Licensed Commons image bytes and attribution are cached separately in public photo storage and can be reused across accounts. They contain no account, trip or saved-location identifiers and are not personal photo uploads. The app displays source, author and license links. If a suitable Commons photo is unavailable, it may try the Google photo flow below.

Google Maps Platform place photos and routes

When you explicitly review a confirmed Google place for an unsaved trip idea, or when an eligible saved trip idea becomes visible, Droozi's backend may send Google only the selected or stored Google place identifier, followed by Google's opaque photo resource name, to retrieve a current place photo and required attribution. It does not send Google a Droozi user ID, trip ID or title, notes, votes, or membership information for that request. Requesting the visual does not save an unsaved draft. If you later save the idea, its selected place identifier may become part of the idea; Droozi does not add the Google photo name, media URL, or image bytes to the trip or idea record. When a photo is returned, the app displays its Google Maps provider attribution, available author attribution and source link. Trip photo details also provide a Google reporting link.

When a future-location card is visible on Home, Droozi may send its saved latitude and longitude to Google to resolve the city or town, then use that place identifier to retrieve a city photo. This uses your saved destination, not live device tracking. Google is not sent your Droozi user ID, location ID, dates, or sharing audience for these requests. Droozi may retain the resolved city place identifier and a one-way fingerprint of the saved address, city, and coordinates with the location. A changed destination invalidates that association. Photo names, media URLs, attribution, and image bytes are not saved with the location. Missing photos or provider limits leave a generic travel image in the card.

To provide trip route estimates, Droozi may send Google the origin and destination latitude and longitude, the requested travel mode, and, for public-transit estimates, the next stop's scheduled start instant as the requested arrival time. Google is not sent the Droozi user ID, trip ID or title, place names, notes, votes, or membership information for that route request. Results may include estimated time and distance and, where Google supplies them, fare, toll, warning, or route-option details. They are estimates and may differ from current conditions. If Google or provider cost controls make a photo, route, fare, or toll unavailable, Droozi omits that provider result or labels the value unavailable rather than creating or assuming one.

Droozi marks both response types private and no-store. The backend does not persist or server-cache Google place-photo references or route estimates. The mobile app holds the returned photo reference, attribution, and route data in volatile memory for the current Trip Details or Home screen session and discards those in-memory references when that screen ends or the app moves to the background. Home also discards photo references when you switch accounts or leave Home. Droozi does not copy the Google photo into trip or location records or app-controlled storage, although the mobile operating system or image-networking layer may keep a temporary cache under its own cache policies. A selected travel-preference value may remain with the trip. When you override one leg, Droozi also stores a one-way fingerprint derived from that adjacent stop pair's identifiers, coordinates, schedule, and time zones so a stale override is not applied after the itinerary changes. The provider estimate itself does not remain.

Google processes these requests under its own terms and privacy practices. Review the Google Terms of Service, Google Maps Additional Terms, and Google Privacy Policy.

Cookies and similar technologies (website)

The Droozi website uses cookies and similar technologies. Strictly necessary storage is always active. Vercel Web Analytics and Ahrefs Web Analytics remain active for cookieless aggregate site metrics. Microsoft Clarity records limited on-page interaction data in cookieless mode with storage denied. If you consent, Clarity may use analytics storage to connect page activity and provide session replays and usability insights. With consent, the Reddit Pixel may measure visits to public acquisition and content pages, attribute conversions, and help optimize our Reddit advertising. It does not run on private app, invite, event, trip, or authentication pages, and we do not send Reddit email, phone, or Droozi account IDs. If you reject optional processing, withdraw consent, or send a Global Privacy Control signal, the Reddit Pixel does not load and Clarity stays in or returns to limited cookieless mode. For details and how to change your choice, see our Cookie Policy.

3. How we use your data and our legal bases

We use your information for the purposes below. Where the EU/UK GDPR applies, the legal basis for each purpose is noted in brackets.

  • Create and manage your account [contract]
  • Provide core features — show your approved future locations and default location to your chosen audience, and find date and place overlaps with contacts or events [contract]
  • Convert addresses and places into map coordinates [contract / legitimate interests]
  • Read authorized Google Calendar events to provide travel prompts, notifications, and consent-gated lodging detection [consent / contract]
  • Store and share lodging stays you explicitly import with accepted trip participants [contract / consent]
  • Show attributed place and city photos and provide transient route estimates for trip planning [contract / legitimate interests]
  • Provide invitations, guest RSVPs, social features, notes, and messaging [contract / legitimate interests]
  • Send service communications and notifications you enable [contract / consent]
  • Improve and secure the Service, including aggregate Vercel Web Analytics metrics, and prevent misuse [legitimate interests]
  • Optional website analytics and ad measurement [consent]
  • Comply with legal obligations [legal obligation]

4. Age requirement

Droozi is intended only for people who are 16 years of age or older. We do not knowingly allow anyone under 16 to create an account or use the Service, and new signup flows record a timestamped explicit confirmation that the person is 16 or older. We may also process date of birth where it is provided through a legacy or profile flow. If we learn that someone under 16 has provided us personal information, we will delete it. If you believe someone under 16 is using Droozi, contact privacy@droozi.com.

5. How we share your data

We do not sell your personal data, and we do not share it for cross-context behavioral advertising. We share data only as described here:

  • Service providers / sub-processors who process data on our behalf, including: Google (Firebase authentication, database, file storage, and push messaging; and Google Calendar and Maps Platform for read-only calendar features, geocoding, attributed place photos, and route estimates), Amazon Web Services (infrastructure and file storage), database-hosting providers, Unipile (connected LinkedIn import, hosted authorization, and connection retrieval), Apollo.io (LinkedIn import enrichment only), communications providers (including Mailtrap or a configured SMTP provider for email and Twilio when SMS reminders are enabled), and Sentry when backend error monitoring is enabled. For Unipile's own privacy and security practices, see Unipile's Privacy Policy and Security & Compliance information.
  • Website measurement providers for the website: Vercel Web Analytics and Ahrefs for cookieless aggregate metrics, plus Microsoft Clarity in limited cookieless mode or with analytics storage after your consent, and Reddit for consented ad attribution and optimization on public content pages.
  • Other users, as part of the social features you use (see below).
  • When required by law, or to protect our rights, users' safety, or prevent fraud.
  • In connection with a merger, acquisition, or sale of assets, subject to this Policy.

Droozi does not collect or store your live location or track you in the background. If you grant the iOS map's when-in-use location permission, Google Maps may process the current position needed to center the map and display its location dot under Google's own privacy practices. Droozi does not send that live position to its backend.

6. Authorized operator access

Authorized admin and super-admin accounts can access stored account and profile data, imported contacts, saved locations, notes, event and trip records, guest RSVPs, lodging records, support submissions, and conversation records for approved support, safety, security, legal, and service-operation purposes. Access is role controlled and logged where the product's administrative controls provide audit records.

7. Information visible to other users

Droozi is a social planning app. Your profile, future locations, default location, events, trips, RSVPs, imported lodging stays, and messages may be visible to the audience for the feature you use, such as your contacts, accepted trip participants, event participants, or chat members. Public events and the limited details intentionally included on public or invitation landing pages may be visible without an account. People you share with may be able to save or re-share what they see. Please consider what you share and use the audience controls Droozi provides.

8. How we handle social logins

You can register or sign in using a third-party account (such as Google or Apple). If you do, we receive certain profile information from that provider — typically your name, email address, and profile picture. We use it only as described in this Policy. Social providers do not give us age information, so current signup asks you to confirm that you are at least 16. We may process date of birth where you provide it through a legacy or profile flow.

9. International data transfers

Droozi is available worldwide and our service providers (including those above) are located in the United States, the European Union, and other countries. Unipile states that its infrastructure for service data is hosted in France/the EU and that it acts as a data processor for customers. Where we transfer personal data out of the EEA, the UK, or other regions with transfer restrictions, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses. Contact us for more information about these safeguards.

10. Data retention and deletion

We keep personal data only as long as necessary to provide the Service, meet legal obligations, resolve disputes, and enforce our agreements. Data is kept while your account is active.

Non-default future locations are designed to expire when their date range is over. We keep expired non-default future locations for a limited grace period — currently 30 days — before purging them. Default locations remain until you change, delete, or remove them, or delete your account.

Guest RSVP records, including the guest's name, contact, response, and reminder preferences, expire 120 days after the most recent RSVP interaction. A new or updated response restarts that period so an active event can continue to use the response.

Event invitation links do not expire on a timer. They remain usable until the host revokes or replaces them, or until the event is deleted or removed through event-retention cleanup. Account-required links remain limited to the intended account. Invitation records are kept with their event; deleting the event removes its invitations immediately, and deleting an account erases invitations it created, claimed, or owned through one of its events.

Account-required trip invitation tokens follow the same rules against the trip's own dates: they expire at the earlier of the trip end/start boundary or 30 days after send or resend, resending rotates the token and its stored hash so the previous link stops working, and the invitation row is purged 30 days after the later of the token expiry or trip boundary. Deleting the trip removes its invitations immediately; deleting an account erases invitations it created, claimed, or owned through one of its trips.

Calendar candidate responses are not server-cached. Lodging candidate dismissal or suppression metadata contains one-way source identifiers, not raw calendar content, and expires 90 days after the trip ends. Imported lodging stays remain with the trip until an authorized person removes them, the trip is deleted, or an applicable account-deletion cascade removes them. Revoking lodging consent stops future lodging checks but does not silently remove stays you already shared; those can be reviewed and removed separately in the app.

You can delete your account in the app, or request deletion by emailing privacy@droozi.com. Your data will be permanently removed within a reasonable timeframe unless we are required to keep it by law.

If you use connected LinkedIn import, Droozi requests deletion or disconnection of the linked Unipile account after the import completes or fails. Droozi keeps the imported LinkedIn contact records needed to provide your network features until you remove those contacts, disconnect the feature, delete your account, or request deletion, subject to legal retention requirements.

Google place-photo references and route estimates are not saved to the trip or location record or persisted in Droozi's backend cache. Their app-level references are held only in volatile memory for the current Trip Details or Home screen session; the mobile platform may separately use temporary image caches as described above. Existing Google place identifiers and selected travel preferences remain part of the saved trip or idea until that content is changed or deleted. Resolved city place identifiers and destination fingerprints remain with their saved location until replaced or the location is deleted.

11. Your privacy rights

Everyone

  • Access the personal data we hold about you
  • Correct inaccurate data
  • Request deletion of your data
  • Withdraw consent at any time (where we rely on consent)

You can unsubscribe from marketing emails at any time using the unsubscribe link in those emails, or by contacting us. We may still send you service-related messages necessary to operate your account.

EEA / UK / Switzerland residents (GDPR)

In addition to the above, you have the right to data portability, restriction of processing, to object to processing, and not to be subject to a decision based solely on automated processing that produces legal or similarly significant effects (we do not currently make such decisions about you). You have the right to lodge a complaint with your local data protection supervisory authority — in Switzerland, the Federal Data Protection and Information Commissioner.

California and other U.S. state residents

If you reside in California, Colorado, Connecticut, Delaware, Florida, Indiana, Iowa, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, Utah, or Virginia, you may have rights to know, access, correct, delete, and obtain a copy of your personal information, and to opt out of any "sale" or "sharing." Droozi does not sell personal information. With your consent, Reddit may process public-page visit data for ad attribution and optimization, which some state laws may define as sharing or targeted advertising. You can reject or withdraw that consent at any time, and we honor recognized opt-out preference signals such as Global Privacy Control (GPC). We do not use personal information for profiling that produces legal or similarly significant effects, and we will not discriminate against you for exercising your rights.

Categories of personal information we collect

CategoryExamplesCollected
A. IdentifiersName, email, phone, account name, IP address, device identifiersYes
B. California Customer Records infoName, contact info, employer/company, professional detailsYes
C. Protected classification characteristicsTimestamped confirmation that a user is at least 16; a legacy or profile flow may also include date of birthYes
D. Commercial informationPurchase or transaction historyNo
E. Biometric informationFingerprints, voiceprintsNo
F. Internet / network activityApp and site interactions, log data, analyticsYes
G. Geolocation dataAddresses, labels, and exact or approximate coordinates for places you choose to save — not a live device-GPS trailYes
H. Audio / visual informationProfile photos and images you uploadYes
I. Professional / employment informationCompany, job title, LinkedIn profile details you importYes
J. Education informationStudent recordsNo
K. InferencesTravel, location-overlap, and itinerary suggestions derived from saved plans, calendars, contacts, and prior trip content — not advertising profilesYes
L. Sensitive personal informationExact coordinates for places you choose to save and the contents of messages between usersYes

We retain the categories we do collect for as long as you maintain an account, and afterward only as needed for the purposes described in "Data retention and deletion."

Exercising your rights, verification, and appeals

You may use an authorized agent to submit a request; we may require proof of authorization. To protect your data, we verify your identity before acting on a request, and may ask for additional information to do so. If we decline your request, you may appeal by emailing privacy@droozi.com; if your appeal is denied, you may contact your state attorney general.

California "Shine the Light." California residents may request, once a year and free of charge, information about personal information (if any) we disclosed to third parties for their direct marketing purposes. Droozi does not share personal information for third-party direct marketing.

How to exercise your rights

Email privacy@droozi.com. We aim to respond within the timeframes required by law (generally one month under the GDPR and 45 days under California law, each extendable where permitted).

12. Do-Not-Track

Some browsers offer a "Do-Not-Track" (DNT) signal. Because there is no finalized industry standard for how to respond to DNT, we do not currently respond to DNT signals. We do, however, honor recognized opt-out preference signals such as Global Privacy Control (GPC) on our website, and optional analytics and ad measurement load only after consent.

13. Data security

We take reasonable technical and organizational measures to protect your data, including HTTPS/TLS encryption, secure servers and firewalls, access restricted to authorized staff, and regular system monitoring. No method of transmission or storage is completely secure, so we cannot guarantee absolute security. If a data breach affects your personal data, we will notify you and the relevant authorities as required by law.

14. Changes to this Policy

We may update this Privacy Policy from time to time. Material changes will be posted on this page with an updated date.

15. Contact us

Questions about this Privacy Policy? Email privacy@droozi.com.

What Droozi actually does with location

Droozi is built around sharing future plans rather than broadcasting live GPS: you add the cities and dates you will be in and choose who can see them. See how it works, read who it is for, or review the developer-reported data disclosures on the App Store and Google Play listings.