Privacy Policy
Owl Social Limited · Last updated 31 August 2026
Owl Social Limited makes two apps. Owl lets you meet people at the venue you are already in, and includes a party game called Owl's Cup. Owl Planner helps a group of friends agree on a time to meet and keeps that plan in everyone's calendar. This policy covers both, and explains what we collect, why, where it goes, and how to get it deleted.
1. Who we are
Owl is operated by Owl Social Limited, a company registered in Hong Kong. For any privacy question, or to ask us to delete your data, contact info@theowlsocial.com.
2. What we collect
| Data | Why we need it |
|---|---|
| Phone number | It is your account identity. We verify it by one-time code. |
| Name and profile photo | So friends recognise you on an invitation, and so people at the same venue can see who you are. |
| Your profile details | The age and interest tags you choose to add, shown to other people checked in at the same venue. |
| Venue check-ins | The venue you scan into and when, so the app can show you the other people checked in there. |
| Requests and messages | So you can ask to connect with someone and chat once they accept. |
| Hangouts you create or join | Titles, times, locations and who replied, so the plan works. |
| Camera access | To scan a venue's QR code and to take a profile photo. Images are only captured when you choose to. |
| Google Calendar data | See section 3. |
| Google Contacts data | See section 3. |
| Basic device and usage logs | Diagnosing errors and preventing abuse. |
3. Google user data
Connecting Google is optional. Owl works without it, and you can disconnect at any time from the Profile screen. If you do connect, Owl requests only the narrowest permissions that make the feature work.
Google Calendar
- View and edit events on all your calendars (calendar.events) — when you confirm a hangout, Owl creates a single event on your primary calendar, and updates or removes that same event if the plan changes or is cancelled. Owl only ever modifies the event it created, identified by the event ID it stored. It does not read, change or delete any of your other events.
- See the availability on your calendars (calendar.events.freebusy) — when you are choosing dates, Owl asks Google which time ranges you are already busy in, so those slots can be greyed out. This returns busy and free time ranges only. Owl never receives the titles, guests, locations or descriptions of the events behind them.
Google Contacts
- See and download your contacts (contacts.readonly) — so you can search your own address book to pick who to invite, and so Owl can tell you which of your contacts already use Owl.
- Owl reads only each contact's name and phone number. It does not read addresses, notes, birthdays, photos or any other contact field.
- When you tap Sync on the Friends screen, those names and phone numbers are stored on Owl's servers against your account, so your friend list survives reinstalling the app or switching device. If you only browse the invite picker without syncing, the contacts stay on your device for that session and are not uploaded.
Your Google account details
If you choose to sign in with Google, Owl receives your email address and basic profile information (your name and profile picture) to identify your account.
Your Google sign-in token
To keep your calendar in sync without asking you to sign in every time, Owl stores the refresh token Google issues. It is encrypted at rest and used only to call the Google APIs described above.
Limited Use commitment
Owl's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. Specifically, we do not sell Google user data, we do not use it for advertising or to build advertising profiles, we do not allow humans to read it except with your explicit permission, for security purposes, to comply with the law, or where the data has been aggregated and anonymised, and we do not use it to develop, improve or train generalised artificial intelligence or machine learning models.
4. Who we share your data with
We do not sell your data, and we do not share it for advertising. We share it only in the four situations below.
a. Other people using Owl
Your name, photo and your reply to a hangout are visible to the other people invited to that same hangout. Your name, photo, age and interest tags are visible to other people checked in at the same venue at the same time. Your Google Calendar data is never shown to anyone else. When Owl checks your availability, other guests see only that a slot does or does not suit you, never what is in your calendar. Your synced contacts are never shown or offered to other users.
b. Service providers who run Owl for us
These companies process data strictly on our instructions, under contract, and for no purpose of their own:
| Provider | What it handles | Google user data? |
|---|---|---|
| Supabase Inc. | Our database, sign-in and server functions | Yes — synced contact names and phone numbers, and your encrypted Google token |
| Amazon Web Services | Hosting the app and storing profile photos | No |
| Cloudflare, Inc. | Domain routing and protecting the service from abuse | No |
| Meta Platforms (WhatsApp) | Delivering your sign-in code and invitations you choose to send | No |
Beyond these providers, Owl does not transfer, disclose or otherwise make Google user data available to any third party, and does not transfer it to any other company, advertiser, data broker or analytics service.
c. Legal obligations
We may disclose data where the law requires it, or to investigate fraud, abuse or a threat to someone's safety.
d. A change of ownership
If Owl is acquired or merged, data may transfer to the new owner. We will tell you before that happens, and the new owner remains bound by this policy or gives you notice of a new one.
5. How long we keep it
- Account data is kept while your account exists.
- Synced contacts are kept until you disconnect Google, clear them, or delete your account.
- Your Google token is deleted immediately when you tap Disconnect on the Profile screen.
- After you delete your account, we erase your personal data within 30 days, except where the law requires us to keep a record.
6. Your choices and rights
- Disconnect Google. Profile → Disconnect Google. This deletes the stored token and stops all further access.
- Revoke at Google. You can remove Owl's access at any time at myaccount.google.com/permissions. Doing so does not delete data already synced — email us to have that erased too.
- Delete your account. Use accountdeletionrequest.theowlsocial.com, or email us.
- Access, correct or export. Email info@theowlsocial.com and we will respond within 30 days.
7. Security
Data is encrypted in transit. Google tokens are encrypted at rest. Access to production data is limited to the people who need it to run the service. No system is perfectly secure, but if a breach affects your data we will notify you and the relevant regulator as the law requires.
8. Children
Owl is not for anyone under 18. We do not knowingly collect data from children. If you believe a child has an account, email us and we will remove it. Our standards against child sexual abuse and exploitation are published at csae.theowlsocial.com.
9. International transfers
Owl is operated from Hong Kong and our providers run servers in other countries, so your data may be processed outside where you live. We rely on our providers' standard contractual protections for those transfers.
10. Changes
If we change this policy in a way that materially affects you, we will notify you in the app before the change takes effect. The date at the top always shows the current version.
11. Contact
Owl Social Limited, Hong Kong — info@theowlsocial.com