A plain-English walkthrough of exactly what Aphilaty knows about you, what it never touches, and where you have a real choice. Not legal language — the actual picture.
Read the full Privacy Policy →Aphilaty is built so that the businesses, schools, and teams you connect with can see what you do — your shopping list, your event RSVPs, whether you claimed a volunteer slot — without knowing who you are. That's true by default, everywhere in the app, for almost everything you do.
It is not true in a small number of specific places, and those places are always something you turn on, never something that happens automatically. This guide explains exactly where those places are, why they exist, and what you can do about each one.
When you join a grocery store's org and put strawberries on your list, here's exactly what that store can see: a single, meaningless code that changes for every single org you belong to, attached to a count — "412 people in this area listed strawberries this week." That's it. They cannot see your name. They cannot see your email. The code cannot be reversed, even by Aphilaty's own engineers, to figure out who you are.
This applies to:
You don't have to do anything to get this protection. It's the floor everything else is built on top of, not a setting you opt into.
Worth knowing about small numbers: If only two people in a tiny zip code listed something unusual, showing "2 people" is close enough to identifying that it isn't really anonymous anymore. So Aphilaty has a rule: any count below a minimum threshold is shown as "fewer than [threshold] people" instead of an exact number. This isn't a missing feature — it's a deliberate floor that protects you in low-population areas.
There are exactly four places in Aphilaty where something more identifying than an anonymous code can come into play. Every one of them is something you choose, not something that happens by default.
Three features work by using something your phone already does, without ever bringing that data into Aphilaty's own systems.
When you turn on calendar sync, Aphilaty events get written to a dedicated "Aphilaty" calendar on your device — the same calendar app you already use. This is one-way: Aphilaty pushes events out to your phone's calendar. It does not read your existing personal calendar entries, and your other calendar events are never sent to Aphilaty. You control sync per-org in Settings → Calendar Sync, and you can remove all Aphilaty events from your calendar at any time with one tap.
Notifications use your phone's own notification system — the same one every other app on your phone uses. Aphilaty doesn't have a separate, hidden way to reach you; if you turn off notifications for Aphilaty in your phone's settings, that's the end of it. You also have finer controls inside Aphilaty itself — mute a specific group forever, mute all public groups but keep your private ones, or just turn down how often you hear from any group.
When you invite someone to a group, Aphilaty doesn't read your phone's contact list. Instead, it hands you a link and opens your phone's normal share screen — the same one you'd use to share a photo or a webpage — and you pick how to send it (text, email, whatever you already use). Aphilaty never sees who you sent it to or what their contact information is.
This section exists because it's an honest risk, not because it's likely to happen often.
If you type your own phone number, email address, home address, or a friend's contact information into a list item, a message, or an event description, that information is now part of that content — visible to whoever else can see that list, message, or event, exactly like writing it on a physical sticky note that other people can read.
Aphilaty automatically checks for a small set of high-risk patterns — Social Security numbers, credit card numbers, phone numbers, and email addresses — and blocks them by default before they can be posted at all. SSNs and credit card numbers are always blocked with no exception. Phone numbers and email addresses are blocked by default but can be configured to a warning instead, since there are legitimate reasons to share those (a coach's number, a school office email).
This protection is narrow by design: it catches a few specific, well-defined patterns, not everything a person might consider sensitive. It will not catch a home address, a less-common formatting of a number, or anything written in a way our pattern-matching doesn't recognize. Use the same judgment you would in any shared chat or document.
Every meaningful choice in the app, laid out on a single spectrum, so you can see exactly what you're trading for what.
Outside this spectrum entirely: Anything you write into a list item, message, or event description is visible to whoever can see that content, regardless of where it falls on the spectrum above. This isn't a privacy setting — it's just what sharing content means. See Part 4.