Legal

Privacy

What NoLodging collects, why, and how long it is kept.

Draft. This document reflects how the service is actually built and intended to operate, but it has not yet been reviewed by counsel. It is published for transparency, not as a final agreement.

Last updated October 5, 2026

What we collect right now

This site is currently a pre-launch page. If you post a trip through the form on the home page, we store:

  • Your email address, so we can tell you when there are people in that place.
  • The destination you typed, and a normalised version of it used for grouping.
  • Your arrival date, or the fact that you are already there.
  • The interests you selected.
  • A truncated network prefix of your IP address (the last part is discarded), used only to rate-limit abuse.
  • Your browser user-agent string, for the same reason.

If you create an account

You can sign in with Google, with Apple, or with a link sent to your email. We store:

  • Your email address, and the time it was confirmed.
  • If you sign in with Google or Apple: that provider’s ID for your account, the email address it shares with us (which may be an Apple relay address), whether it has confirmed that address, and the name on the account. We use the name only to fill in your profile form. We never receive your password and we never post anything anywhere.
  • Your legal name. It is private: other members never see it, and it is used only to confirm who you are — today by us if a safety issue needs it, later by identity checks you will be asked to agree to.
  • Whatever you choose to put in your public profile: what people should call you, a handle, a home base, a headline, a bio, languages, interests and what you might be up for. Other signed-in members can see it; it is never shown to search engines or visitors who are not signed in.
  • Photos you add to your profile, with the descriptions and captions you write. Every photo is re-encoded when you upload it, which removes its location and every other hidden detail your camera or phone recorded. Photos are stored with Hetzner in the EU, are shown only to signed-in members, and are deleted from storage when you remove them. Links you add are shown as links; we do not fetch or embed what they point to.
  • Your confirmation that you are 18 or over, and the version of these Terms and this Privacy notice you agreed to, with when and from what browser or app. Your date of birth is used only to check your age at that moment; it is not stored.
  • If you report something: what you reported, why, and a copy of it as it was at that moment, so the report still makes sense if it is later edited or deleted. A reported photo is hidden until a person reviews it. The person you reported never learns who reported them.
  • The members you block. They are not told; you simply stop appearing to each other.
  • What our staff decide about reports, and who decided, so decisions can be checked.
  • An audit log of security-relevant events on your account: signing in and out (with how you signed in), signing devices out, agreeing to the Terms, downloading your data, closing or reopening your account, trusted-contact changes and views, and safety alerts and check-ins. Each entry records when, a truncated network prefix (never your full IP address) and your browser. You can see these on your Devices and activity page. The log also records what our staff do and look at. Entries cannot be edited, and are deleted after two years.
  • If you add trusted contacts: who they are, and what you let each one see — your plans, your trips, your messages and safety alerts, each chosen separately. They see only that, read-only, and you can see every time they look. If you let someone read your messages, the people you talk to are told that a trusted contact of yours can read the conversation.
  • If you set a check-in or ask for help: when, and the note you add. Your trusted contacts with safety alerts are notified, on NoLodging and by email.
  • Trips you post: where (always a published town or airport, never an address), when, what you are hoping for and your interests. Signed-in members whose home base is near the destination see them until they expire or you close them.
  • Offers you make or receive, and every change to them, visible to the two people involved. Once an offer is accepted, the messages you exchange, visible only to the two of you. Emails about offers and messages say that something happened, never what was said.
  • For each sign-in link we send: when it was sent, when it was used, and a truncated network prefix of your IP address, to rate-limit abuse.
  • For each signed-in session: when it started, when it was last used, and your browser user-agent string, so you can recognise your own devices.

What we do not collect

We do not run third-party advertising or analytics trackers on this site. No advertising cookies, no session recording, no data brokers. If you sign in, the site sets one cookie to keep you signed in; otherwise it sets none. A theme preference, if you choose one, is stored in your browser and never sent to us.

If you arrive through a link we shared with a campaign tag in it (like nolodging.com/?ref=fb-wabasha), we count that one visit came through that tag on that day — only the tag and the date, nothing about you. Your browser keeps the tag until you close the tab, and if you sign up or post a trip during that visit, we note the tag on your account or trip so we can tell which links bring people. It is in your data download. We use it for nothing else, and share it with no one.

Some pages have a video player for a song or video hosted on YouTube. Nothing from YouTube loads until you press play. When you do, the video plays from YouTube’s privacy-enhanced service (youtube-nocookie.com), and YouTube receives your IP address and may store data in your browser under Google’s own privacy policy.

Precise location

We never publish a member’s exact location. Discovery works from coarse points — a city, an airport, a published place — and exact arrival details are only ever shared by the member, deliberately, with a specific person.

How long we keep it

Pre-launch trip postings are kept until the community in that area opens, or for 24 months, whichever comes first. You can ask us to delete yours at any time and we will do it.

An account and its profile are kept until you close it. Sign-in link records are deleted a week after they expire, and a session is deleted when you sign out or 30 days after you last used it. A trip leaves every feed when it expires or you close it, and is deleted 90 days after it expires, together with the offers made on it. Messages are kept until either of you closes your account.

You can close your account yourself, from your profile page. It disappears at once and you are signed out everywhere; 14 days later it is erased for good — profile, photos, trips, offers, messages, blocks and agreements — unless you sign in again before then, which reopens it. Conversations you were part of are erased too, for both sides.

Reports other members made about you are the one exception: they are kept for a year after your account is erased, unlinked from it, so that closing an account cannot erase a safety problem. Then they are deleted too. Records of what our staff decided are kept without your name.

Who sees it

Our own team, and the infrastructure providers needed to run the service. We do not sell personal data. We have no interest in being in that business.

Your rights

You can download a copy of everything we hold about you, and close your account, yourself from your profile page. For anything else — correcting data, or a question about what we hold — write to privacy@nolodging.com. If you are in the EEA or UK, you have the rights granted under the GDPR, including the right to complain to your supervisory authority.