Privacy Policy
Last updated: August 27, 2026 · Effective: August 27, 2026
Jaha ("we," "us") is the Jaha mobile app and this website, operated by Laird Oliver, an individual developer based in Arizona, USA. This policy explains what we collect, why, who we share it with, and what control you have over it. Questions go to [email protected].
Information you give us
- Account details. If you create an account, we store your email address, a password (stored only in hashed form by our authentication provider), the handle you choose, and any display name, short bio, or profile photo you add. Your handle, display name, bio, and profile photo are public. If you sign in with Apple, we receive the identifier Apple provides and, if you allow it, your email — which may be Apple's private relay address. We do not store the name Apple may offer to share.
- Content you post. Outings you create, reviews, ratings, comments, check-ins, photos, and reports you submit about places, content, or other users. Published outings, reviews, comments, check-ins, and photos are public and shown with your handle. Before a photo leaves your device we strip its embedded metadata (including any camera location tag).
- Requests to the AI planner. What you type to the planner is kept as a private chat history so the planner can follow the conversation, and is sent to our AI provider (see Service providers) to generate outings.
- Friends and messages. If you add friends, we store the friend requests you send and receive and your resulting friends list, which is private to you and each friend. Messages you send to friends in Jaha — including outings you share — are stored so both of you can read them. Messages are private between the two of you: we do not publish them, they are not reviewed by our automated moderation, and we only look at them if one of you reports a message or the law requires it. To deliver a notification, a short preview of a new message (up to the first 80 characters, or the title of a shared outing) is sent through Apple's push service.
- Group outings. If you invite friends to do an outing together, we store who invited whom and who joined, so check-ins from that outing can appear in one shared album. Check-ins in a shared album are ordinary check-ins: once published they are public, like any other check-in.
- Messages to us. Anything you send to our support or privacy addresses.
Information collected automatically
- Location. With your permission, we use your device's location to find places and outings near you, to show your position while you follow an outing, and — if you check in at a stop — to record a yes/no "GPS verified" result. We do not keep the coordinates from a check-in, only that yes/no result. When you browse the feed we log your location rounded to roughly 10 km with the outings you were shown, and keep that for 30 days to improve ranking. You can browse without granting location access, with reduced functionality (we assume downtown Phoenix). We only read your location while you are using the app; we do not track your location in the background.
- Anonymous account. You can use parts of Jaha without signing up. On first launch we create an anonymous account so the app works across sessions on your device. If you later sign up, it becomes your account and keeps your history.
- IP address. When you ask the planner to generate outings, we record your IP address alongside the request to enforce daily generation limits and prevent abuse. These records are deleted after 30 days.
- Push notification token. If you allow notifications, Apple gives us a device token so we can send them (for example, a new message, a friend request, or "your outing is live"). You can turn categories off in Settings → Notifications inside Jaha, or turn notifications off entirely in iOS Settings.
- Crash reports. If the app crashes, a report with the technical details of the crash, your device model, operating system version, and app version is sent to Sentry, our crash-reporting provider. Before it leaves your device we remove email addresses, usernames, IP addresses, account identifiers, and anything that looks like a coordinate. We do not collect performance or session-replay data.
- Usage events. Basic interaction events (for example "outing saved" or "check-in submitted") tied to your account, recorded by us — not by a third-party analytics service — to understand what people use and fix what doesn't work.
How we use it
- To generate and show outings and places relevant to where you are
- To publish content you choose to share, and to keep your saved and completed outings
- To deliver friend requests, messages, group-outing invites, and the notifications you've chosen to receive
- To review submitted content before it becomes public (see Moderation)
- To enforce rate limits, prevent abuse, enforce our Terms, and meet legal obligations
- To diagnose crashes and improve reliability
We do not sell or share your personal information for advertising, we do not serve third-party advertising, and we do not use advertising or tracking SDKs. We have not sold or shared personal information in the preceding 12 months, and we do not plan to.
Moderation
Outings, reviews, comments, check-ins, and photos (including profile photos) are reviewed by an automated system before they are published. Profile display names and bios appear immediately and are reviewed right after you save them; anything that fails review is taken down. Reports from other users are reviewed by us. Direct messages between friends are not scanned; see Friends and messages above.
Content that violates our Community Guidelines is rejected: any photos attached to it are deleted at that moment, and the text stays visible only to you as a rejected draft so you can edit and resubmit (rejected reviews are removed entirely). We keep a record of each moderation decision — the item, the outcome, and the reasons — for abuse prevention.
Submitted content, including photos, is processed by Anthropic solely to perform this review and to generate outings you request. Under Anthropic's commercial API terms, this data is not used to train their models.
Service providers
We share data only as needed with providers that operate parts of the service. Each processes it under its own terms and security commitments; we send only what the listed function needs:
- Supabase — database, authentication, file storage, and server functions (hosted in the United States)
- Google Maps Platform — the map you see, place search, and place details. The map runs on your device, so Google receives your device's requests directly when the map loads
- Anthropic — AI generation of outings and automated content moderation
- Apple — Sign in with Apple, app distribution, push notification delivery, and (if you have opted in to sharing analytics with app developers in iOS) Apple's own crash and usage reports
- Sentry — crash reporting, scrubbed as described above
- Resend — sends account emails such as sign-up confirmations and password resets
- Cloudflare — hosts this website and routes email sent to our @jahago.com addresses
- US National Weather Service — receives the coordinates of the area you're exploring, with no account identifier, so outings can account for heat and weather
- Other users — your published content and public profile are visible to everyone using Jaha and on this website's public outing pages
Retention
- We keep your account data while your account is active.
- Place information obtained from Google carries an expiry date. Expired place data is hidden from the app 30 days after it expires and is refreshed on demand; expired records that nothing references are deleted automatically.
- Outings you delete go to Recently deleted for 30 days, where you can restore them, and are then permanently deleted along with their reviews, comments, and check-ins. Reviews, comments, check-ins, and messages you delete are removed right away.
- When you delete a review, check-in, or outing, its photos stop appearing in Jaha. The underlying image files remain in our storage, at an address that is not listed anywhere, until you delete your account, at which point they are deleted.
- Photos attached to rejected content are deleted at moderation time.
- Feed logs (rounded location plus what you were shown) and generation logs (including IP address) are deleted after 30 days.
- Moderation records may be kept after the content or account they relate to is gone, for abuse prevention.
- Copies of data may persist for a limited time in our hosting provider's routine backups before they roll off.
Your choices
- Location. Revoke access anytime in iOS Settings.
- Your content. Delete individual outings, reviews, comments, and check-ins in the app. Deleted outings can be restored from Settings → Recently deleted for 30 days.
- Friends and messages. Remove a friend at any time from their profile; after that, neither of you can send the other new messages. Block a user to stop them contacting you or seeing your content, and to hide theirs from you. Report a message, a piece of content, or a user from its menu.
- Notifications. Choose which notifications you get in Settings → Notifications, or turn them off in iOS Settings.
- Your account. Delete your account and all associated data from Settings inside the app or from jahago.com/account. This permanently removes your profile, content, photos, friends, messages, chat history, notification tokens, and preferences. If you can't use either, email [email protected] and we will action it within 30 days.
- Access and correction. Email us to request a copy of your data or to correct it.
Your privacy rights
Depending on where you live, you may have rights to access, correct, delete, or port your personal information, and to not be discriminated against for exercising them. We honor these requests for everyone, regardless of location; email [email protected]. We may ask you to confirm the request from the email address on your account.
California. We do not sell or share personal information, and we do not use sensitive personal information (such as precise location) for anything other than providing the features you ask for. Jaha is a small, pre-revenue service that does not currently meet the thresholds that make the CCPA/CPRA apply, but we honor the rights above anyway.
Outside the United States. Jaha is offered in the United States and its places catalog covers the Phoenix area. Our providers store and process data in the United States. If you use Jaha from elsewhere, your information is transferred to and processed in the United States.
Children
Jaha is for people aged 13 and over (see our Terms). It is not directed to children under 13 and we do not knowingly collect their information. The app surfaces venues that may include bars and nightlife and is age-rated accordingly on the App Store. If you believe a child under 13 has provided us information, contact us and we will delete it.
This website
This website sets no cookies and uses no analytics. The account page keeps your sign-in session in your browser's session storage until you close the tab or sign out. Public outing pages show the same published content as the app.
Security
Data is transmitted over encrypted connections and session credentials are stored in the device keychain. No system is perfectly secure, but we work to protect your information and will notify you of any breach affecting it as required by law.
Changes
If we make material changes we will update the dates above and, where appropriate, notify you in the app. Earlier versions are available on request.
Contact
Laird Oliver, operator of Jaha — Arizona, USA
[email protected]