Privacy Guide

Your Privacy, Explained

A plain-English walkthrough of exactly what Aphilaty knows about you, what it never touches, and where you have a real choice. Not legal language — the actual picture.

Read the full Privacy Policy →

You're anonymous by default. Everywhere.

Aphilaty is built so that the businesses, schools, and teams you connect with can see what you do — your shopping list, your event RSVPs, whether you claimed a volunteer slot — without knowing who you are. That's true by default, everywhere in the app, for almost everything you do.

It is not true in a small number of specific places, and those places are always something you turn on, never something that happens automatically. This guide explains exactly where those places are, why they exist, and what you can do about each one.

Where you're completely anonymous

When you join a grocery store's org and put strawberries on your list, here's exactly what that store can see: a single, meaningless code that changes for every single org you belong to, attached to a count — "412 people in this area listed strawberries this week." That's it. They cannot see your name. They cannot see your email. The code cannot be reversed, even by Aphilaty's own engineers, to figure out who you are.

This applies to:

You don't have to do anything to get this protection. It's the floor everything else is built on top of, not a setting you opt into.

Worth knowing about small numbers: If only two people in a tiny zip code listed something unusual, showing "2 people" is close enough to identifying that it isn't really anonymous anymore. So Aphilaty has a rule: any count below a minimum threshold is shown as "fewer than [threshold] people" instead of an exact number. This isn't a missing feature — it's a deliberate floor that protects you in low-population areas.

Where things can get more identifiable, and why

There are exactly four places in Aphilaty where something more identifying than an anonymous code can come into play. Every one of them is something you choose, not something that happens by default.

1

Your display name, inside private groups

What it is
When you join a private group — your family, your kid's basketball team, a friend group — other members see a name you chose, not an anonymous code. That's the whole point of a private group: you already know these people.
Where it's stored
On your own account, visible only to people inside that specific group. Each group can have a different name — "Mom" in one, "Coach Sarah" in another. Changing one never changes another.
What you can do
Go to that group's settings → "Your name in this group" to set it per-group, any time, before or after you've joined.
Why it exists
Anonymous codes don't make sense inside a group where everyone already knows each other in real life. The privacy goal here isn't "hide from your own family" — it's "let you control which name shows up where."
2

Account recovery — stored with Google, never with us

What it is
By default, your account isn't tied to an email or phone number at all. If you lose your phone or reinstall the app, you start over. You can optionally add a recovery email or phone number so you can sign back in later.
Where it's stored
If you add a recovery method, it is stored by Google's Firebase system — the same secure login infrastructure that handles billions of accounts for apps across the internet. It is never copied into Aphilaty's own database. We don't have a table of user emails to lose, leak, or expose.
What you can do
Adding recovery is entirely optional. You can add or remove it at any time in Settings → Account → Recovery Method. If you never add one and you lose your device, there's no way for us — or anyone — to get your old account back. That's the trade-off, stated plainly.
Why you might want to
If your phone breaks or you upgrade, an account with no recovery method genuinely can't be recovered. If you've put real effort into your groups and lists, a recovery method is the difference between "annoying, but I'm back in five minutes" and "I have to rebuild all of this from memory."
3

Zip code, when linked to a specific group's membership

What it is
Your zip code is collected so Aphilaty can show useful local context and so retailers can plan inventory. On its own, in an aggregate report, your zip code is anonymous. In a very small or unusually specific group, your zip code combined with your membership could narrow down who you are more than a large public org would.
Where it gets more specific
This isn't a separate feature being turned on — it's a natural consequence of small numbers being more identifying than large ones, the same principle as the cohort-floor rule, just showing up in a different shape.
What you can do
Be aware that "very small group + zip code" is the least anonymous combination in the app, and decide accordingly whether to join very small public-facing groups versus keeping that kind of connection private.
Why your zip code is worth sharing
Aphilaty needs your general area to do what it's actually for. A buy-one-get-one offer on shoes at a store a thousand miles away isn't useful to you. Your zip code is what makes the offers, trends, and local information you see actually relevant to where you live — it's the one piece of information that isn't really a choice.
4

Linking a store loyalty / affinity card number

What it is
Some retailer orgs let you enter your store loyalty card number so it displays as a scannable barcode in the app — convenient at checkout, no need to dig out the physical card.
Where it gets identifying
This is the most identifying thing you can do in Aphilaty, and we want to say that as plainly as possible rather than softening it. The store already knows who that loyalty number belongs to from their own systems. The moment you link it inside Aphilaty, you're giving that specific store a way to connect your Aphilaty activity to their existing record of you. This breaks the anonymity guarantee, but only for that one store, and only because you chose to do it.
The safeguard
Aphilaty will never let you do this by accident. The first time you enter a loyalty code, you'll see a clear warning explaining exactly what you just read, and you have to make an explicit choice — not a checkbox buried in fine print, a real "do you want to do this" moment that can't be swiped past.
What you can do
Don't link it if showing the barcode in-app isn't worth this trade-off — the physical card still works fine. If you've already linked it and change your mind, remove it from that org's settings at any time; this immediately stops any future activity from being connected.

What Aphilaty hands off to your phone — never pulls in

Three features work by using something your phone already does, without ever bringing that data into Aphilaty's own systems.

📅

Your phone's calendar

When you turn on calendar sync, Aphilaty events get written to a dedicated "Aphilaty" calendar on your device — the same calendar app you already use. This is one-way: Aphilaty pushes events out to your phone's calendar. It does not read your existing personal calendar entries, and your other calendar events are never sent to Aphilaty. You control sync per-org in Settings → Calendar Sync, and you can remove all Aphilaty events from your calendar at any time with one tap.

🔔

Your phone's notification system

Notifications use your phone's own notification system — the same one every other app on your phone uses. Aphilaty doesn't have a separate, hidden way to reach you; if you turn off notifications for Aphilaty in your phone's settings, that's the end of it. You also have finer controls inside Aphilaty itself — mute a specific group forever, mute all public groups but keep your private ones, or just turn down how often you hear from any group.

📤

Contacts and invites

When you invite someone to a group, Aphilaty doesn't read your phone's contact list. Instead, it hands you a link and opens your phone's normal share screen — the same one you'd use to share a photo or a webpage — and you pick how to send it (text, email, whatever you already use). Aphilaty never sees who you sent it to or what their contact information is.

We can protect the app from misuse. We can't fully protect you from yourself.

This section exists because it's an honest risk, not because it's likely to happen often.

If you type your own phone number, email address, home address, or a friend's contact information into a list item, a message, or an event description, that information is now part of that content — visible to whoever else can see that list, message, or event, exactly like writing it on a physical sticky note that other people can read.

Aphilaty automatically checks for a small set of high-risk patterns — Social Security numbers, credit card numbers, phone numbers, and email addresses — and blocks them by default before they can be posted at all. SSNs and credit card numbers are always blocked with no exception. Phone numbers and email addresses are blocked by default but can be configured to a warning instead, since there are legitimate reasons to share those (a coach's number, a school office email).

This protection is narrow by design: it catches a few specific, well-defined patterns, not everything a person might consider sensitive. It will not catch a home address, a less-common formatting of a number, or anything written in a way our pattern-matching doesn't recognize. Use the same judgment you would in any shared chat or document.

  • Social Security numbers, credit card numbers, phone numbers, and email addresses are blocked by default — but a bank account number, or anything in a format our detection doesn't recognize, is not.
  • If an org you're in has chosen to allow phone numbers or emails through with a warning instead of blocking, be thoughtful before you post yours — a public school or store org may have many more people able to see it than you'd expect.
  • If you've already posted something sensitive, delete or edit it as soon as you notice — this removes it from the shared view, though anyone who already saw it has already seen it.

Most private to most identifiable

Every meaningful choice in the app, laid out on a single spectrum, so you can see exactly what you're trading for what.

🟢 Most private — the default for everyone

  • Browsing and joining public orgs (school, store, civic group) without linking anything
  • Adding items to lists, RSVPing to events, viewing offers
  • Using a different display name in every private group
  • Skipping account recovery entirely
Trade-off: None, really — this is the floor. The only "cost" is that if you lose your device with no recovery set up, you start over.

🟡 Middle of the road — identifiable to people you already know, not to businesses

  • Setting a real display name in a private family / friend / team group
  • Adding a recovery email or phone (stored with Google, not Aphilaty)
  • Sharing a list with a specific person via an invite link
  • Joining a very small public group where your zip code is more narrowing than it would be in a large one
Trade-off: People inside groups you've joined can know more about you than a stranger could. None of this is visible to any business or org you haven't personally let in.

🔴 Most identifiable — a deliberate choice, with a warning, for a specific business

  • Linking a store loyalty / affinity card number to a specific retailer org
Trade-off: That one specific store can now connect your Aphilaty activity to their existing loyalty account for you. No other org, ever, gets this — it's scoped to exactly the org you linked it to, and you have to explicitly do this for every org separately.

Outside this spectrum entirely: Anything you write into a list item, message, or event description is visible to whoever can see that content, regardless of where it falls on the spectrum above. This isn't a privacy setting — it's just what sharing content means. See Part 4.