Joyn helps small groups organize events and stay in touch. This Privacy Policy explains what personal data we use, why we use it, who receives it, how long we keep it, and the choices you have.
This policy covers the Joyn iOS app and joynevents.com. Joyn is operated by Joyn Events AS. In this policy, Joyn, we, and us refer to that company.
Privacy at a glance
- We use personal data to provide the account, event, messaging, safety, website, notification, calendar, and AI features described below.
- We do not sell personal data, show ads, profile you for marketing, or use third-party analytics or tracking SDKs. We do keep a simple count of active days and invite joins, described in section 1.
- Content is shared with the people you choose and with the service providers needed to run Joyn.
- When you delete content, Joyn removes it from the product and schedules its private files for permanent deletion instead of keeping a user-restorable copy, except for the narrow legal and safety cases described below.
- Joyn is not an end-to-end encrypted messenger. Messages are stored on our servers and on your device so they can sync and support the features you use, including AI features when they are triggered.
1. Information we collect
We collect information you provide, information created when you use Joyn, and limited technical information needed to operate and secure the service.
Account and profile
When you create an account, we process your email address and sign-in information. If you use Sign in with Apple, we may receive the name and email address Apple makes available. Your Joyn profile can include your full name, username, avatar, time zone, locale, notification settings, and selected assistant.
Joyn checks that you meet its 16+ account requirement before signup and once for an existing account that has no current eligibility decision. On iOS, Apple can provide only an age range around that threshold. If the range is unavailable or you decline to share it, you can submit a birth date for a one-time server calculation. Joyn does not retain the birth date or Apple's range. It keeps only the minimum age applied, the verification method, the policy version, and when the check was completed. When Apple supplied the qualifying range, Joyn also keeps Apple's opaque app transaction identifier so Apple can notify Joyn if you later withdraw consent. A verified withdrawal immediately restricts the account and removes its eligibility decision. These records are private and are not shown in your profile, analytics, or operator reports.
If you subscribe to Joyn Plus, we receive and store the product, original transaction identifier, subscription status, environment, and expiry information needed to provide and verify your entitlement. Apple handles your payment credentials; Joyn does not receive your card or bank-account number.
Messages, events, and connections
We process the content and event you create in Joyn, including messages, photos, selected videos, GIFs, stickers, reactions, mentions, replies, read and delivery status, event details, locations, dates and times, RSVPs, polls and votes, posts, comments, tasks, and event media.
We also process your Joyn social graph, including friend connections, requests, groups, and invites, as well as blocks, reports, and moderation records. Other people may provide information about you when they invite or mention you, include you in shared content, or report an interaction. Joyn does not read the contacts or address book stored on your device.
We process searches you perform in Joyn, including GIF and sticker searches and searches requested through the assistant. A search can also remain as part of the message, assistant conversation, or other content in which you made it.
When a message contains a web link, Joyn may request its title and image. A request from the iOS app can reveal standard connection information, including your IP address, to the linked website. On the web, Joyn requests the preview through its hosting service instead.
Location, photos, camera, and calendar
If you allow location access, Joyn can use your current location to suggest a nearby address through Apple MapKit. Locations you add to an event may include text and coordinates. Joyn does not collect continuous, background, or live location.
Joyn accesses the camera, selected photos or videos, and your calendar only when you use a feature that needs them and grant the relevant iOS permission. Calendar sync can add, update, and remove Joyn events in Apple Calendar. Joyn does not request access to your contacts, microphone, HealthKit data, or tracking permission.
Device, website, and waitlist data
We process a device identifier for push notifications, along with your time zone and locale. On signed-in physical devices, Joyn also uploads limited first-party reliability diagnostics so we can find crashes, hangs, abnormal exits, launch problems, performance exceptions, and errors shown in the app. These diagnostics can include the event time and type, app version and build, iOS version, device model, a random session identifier, normalized error codes, and a bounded call stack.
Diagnostic events are designed not to include your Joyn account ID, email address, messages, events, profile content, location, advertising identifier, or a persistent device identifier. Joyn uses a separate account-linked record for up to two hours only to limit diagnostic uploads; that record is not joined to the diagnostic events.
When you use the website, our hosting and backend providers receive standard request information such as your IP address, browser or device information, requested page, and date and time. If you join the waitlist, we store your email address, the date you agreed to receive updates, and the version of the consent wording.
Joyn does not use advertising, tracking identifiers, third-party analytics SDKs, or third-party crash-reporting SDKs. The first-party reliability diagnostics described above are used only to operate, secure, and improve the app.
Measuring whether Joyn is working
To understand whether people actually use Joyn and whether invites bring friends in, we record two deliberately small things. The first is that your account was active on a given day: one record per account per day, with no time, no screen, and no device details. The second is that a specific invite link was successfully used to join an event or connect as friends, which records who invited whom.
We do not record which screens you visit, what you tap, how long you look at something, or which features you use. There is no third-party analytics service, no advertising, and no profile built about you. These two records are used only in aggregate, to answer questions such as how many people used Joyn last week or how many joined through an invite.
Both are deleted when you delete your account. If you invited someone, the record that their join happened remains, but the reference to you is removed from it.
2. How we use your information
We use personal data to:
- Create, secure, and support your account.
- Deliver messages, events, media, notifications, and the other features you use.
- Run AI features and content moderation as described in section 3.
- Keep Joyn reliable, prevent abuse, respond to reports, and enforce our terms.
- Measure, in aggregate, whether Joyn is being used and whether invites work, as described in section 1.
- Respond to you and comply with legal obligations.
We do not use personal data for advertising or marketing profiles.
Legal bases for EEA and UK users
We rely on performance of our contract to create your account and provide Joyn; your consent or request for optional device permissions, waitlist updates, and sensitive booking details you choose to provide; our legitimate interests in securing and maintaining Joyn, supporting users, preventing abuse, and reviewing reports; and legal obligations where the law requires us to keep or disclose information. You can withdraw consent at any time without affecting earlier lawful processing.
Some information, such as an email address and profile name, is required to create and use a Joyn account. If you do not provide optional information or device access, the related feature may not work, but the rest of Joyn remains available where possible.
3. AI features and moderation
When AI uses your content
Joyn uses OpenAI to provide a private assistant, private help from a chat, assistants in group conversations, and an assistant-written Home brief. These features can help organize events, summarize, search Joyn information you can access, prepare drafts, and create actions for you to review.
When an AI feature runs, Joyn sends OpenAI the request and the context needed to answer it. Depending on the feature, this may include:
- Your request, recent assistant history, and relevant messages from conversations the feature is allowed to read.
- Participant names, time zone, locale, and relevant events, RSVPs, polls, friends, or messages.
- Personal AI memories available to your private assistant, or shared notes available to a conversation assistant.
- For the Home brief, short titles and snippets from recent event changes and relevant unread messages.
- Web search or booking details when you ask for those features.
OpenAI states that API inputs and outputs are not used to train its models by default. Joyn configures requests not to be stored for product use, but OpenAI may keep abuse-monitoring logs for up to 30 days unless a different retention control applies. See OpenAI's API data controls for details.
Joyn keeps a separate AI event log for safety and abuse prevention. It records operational details such as which assistant ran and where, but not your message or the assistant's reply. We delete these logs after 30 days.
Event suggestions in chats
In group chats and one-to-one chats, Joyn can notice when an event is forming (for example "beers tonight, anyone?") and pin it as a suggestion so everyone in the chat can see who's in. To do this, Joyn periodically sends a short window of recent messages from that chat to OpenAI to check for event-shaped messages and extract a short title, time, and place. It does not run in an event's own chat. Until August 3, 2026 this ran in group chats only.
- Names are not sent with this scan: senders are replaced with neutral placeholders before processing, and results that would echo a placeholder are discarded.
- The output is limited to structured event fields (title, time, place, who expressed interest). No AI-written content is added to your conversation.
- Scanning is rate-limited per chat per day, and suggestions expire on their own if the event doesn't happen.
- Any member can turn event suggestions off for a chat in the chat's settings, which also removes its active suggestions for everyone. You can also hide an individual suggestion just for yourself.
Memories, shared notes, and AI controls
A private assistant can save short personal memories to make future help more relevant. You can view, edit, delete, or clear these memories in the app. Personal memories stay with your account and are not given to an assistant replying publicly in a group chat.
Conversation assistants can use shared notes for that conversation. These notes are separate from personal memories and visible to conversation members. Members can manage notes they create, and the conversation owner may have additional controls.
You control whether you use the private assistant or add and trigger conversation assistants. Messages you share can still be processed when another participant uses private help on content they can see, or when a conversation assistant responds. The Home brief may be generated when you open or refresh Home and currently has no separate off switch.
Actions that would change Joyn data, such as sending a message or changing an event, are shown for review where the feature supports review. A conversation assistant can post its own reply when triggered.
Reports and automated moderation
When content is reported, we send the reported item and report details—not the wider conversation—to OpenAI's moderation tools to help assess whether it breaks our rules. Clear and serious violations may be hidden automatically. Unclear or higher-stakes reports are reviewed by a person, and automated hiding can be reversed. Suspected illegal content is handled separately and is not sent to these AI tools.
We keep a protected record of moderation decisions and their reasons. If an automated decision hides your content or affects your account, you can ask for human review by replying to the notice or contacting us.
6. How long we keep information
Most account and content data remains while your account is active, unless you delete it sooner. Deletion is the default: we do not impose a waiting period or keep a user-restorable copy of deleted content. A shared event or conversation container may continue for other participants, but that does not let Joyn keep the deleted message body, media, or departing account merely because it was shared.
- Deleting a message makes its content unavailable in Joyn and removes its text, media paths, GIF and mention data, search data, metadata, edit history, reactions, read receipts, polls, pending AI work, Home-brief source copy, and pending notification copy from the active database. A content-free marker with limited structural information can remain so replies and conversation order still make sense. Deleting the account removes the departing user's message rows instead.
- Deleted message media, event photos, assistant images, replaced covers, and replaced avatars are put into a server-side deletion queue. Joyn normally processes this queue within minutes and retries failures independently of your device. Completed queue records are removed after 7 days and contain object identifiers and operational status, not the deleted file itself.
- AI event logs, Home briefs, and the recent-change records used to create those briefs are deleted after 30 days. Temporary AI queue records are cleared within a day.
- First-party reliability diagnostic events are deleted after 90 days. The separate account-linked upload rate-limit record is deleted after two hours. Because diagnostic events are not linked to a Joyn account, account deletion removes the rate-limit record but cannot select individual diagnostic events by account; those events remain unlinked and expire automatically.
- An unbound age-eligibility grant expires after 10 minutes and is deleted within one day. Its keyed rate-limit record is deleted after two hours. The private durable eligibility decision and, for an Apple-verified account, Apple's opaque app transaction identifier remain while the Joyn account is active and are deleted with the account. If Apple reports that consent was withdrawn, Joyn marks that transaction mapping revoked and deletes the eligibility decision immediately. Joyn does not retain the submitted birth date or Apple's age-range bounds.
- The active-day and invite-join records described in section 1 remain while your account is active, because measuring whether people come back requires knowing what happened before. They are deleted with your account. If you invited someone, the record that their join happened remains, with the reference to you removed.
- After you delete your Joyn account, Joyn keeps only a disassociated App Store commerce record needed to reconcile renewals, expirations, refunds, and explicit recovery of a subscription you purchased directly. It cannot restore your profile or provide Plus access while the record is disassociated. If you recover the subscription to a new Joyn account, Joyn verifies the purchase directly with Apple before binding it. An unrecovered record is deleted after both the account deletion and subscription expiry are at least 180 days old. You can manage or cancel the subscription through Apple at any time.
- Waitlist emails remain until you unsubscribe or the launch-update purpose ends. We may keep a minimal suppression record after you unsubscribe so we do not email you again.
- Browser and waitlist rate-limit periods are described in section 5.
We may retain only limited information when necessary to comply with law, respond to a live legal claim, or investigate and prevent serious abuse. We separate that information from ordinary product use, limit access, and review whether continued retention is still necessary. We do not keep deleted content merely because it might be useful later.
The related content becomes unavailable in Joyn when the deletion request succeeds. Database payloads are removed in that transaction; private-file deletion is queued and retried until Supabase confirms removal. Encrypted database backups may contain an older copy until Supabase's configured backup window expires; backup data is not available in Joyn and is held only for disaster recovery. You can read about Supabase database backups. Copies another person saved outside Joyn and local device or browser data outside our control are not deleted from that person's device.
7. Your choices and rights
Delete your account
In the iOS app, go to Profile → Edit profile → Delete account. Joyn first deletes every private file owned by the account and verifies that none remain, then deletes the account, profile, messages, notification tokens, private age-eligibility decision and rate-limit record, personal AI history and memories, and data tied only to you. If you own an event with a co-host, Joyn transfers ownership to the longest-standing co-host so the shared event can continue; an event with no other host is deleted. Shared conversation containers stay available to remaining participants, with their creator role transferred, but your account and messages are removed. Only a narrowly necessary legal or serious-safety record may be retained as described in section 6.
Access, correction, deletion, and portability
Depending on where you live, you may have the right to access, correct, delete, or receive a copy of your personal data; withdraw consent; or object to or restrict certain processing. You can update much of your information directly in Joyn. For any other request, email privacy@joynevents.com. We will respond as required by law and will not discriminate against you for exercising your rights.
If you are in Norway or the EEA, you can complain to your local data-protection authority or to Datatilsynet, the Norwegian Data Protection Authority.
8. Security
We use safeguards designed to protect personal data, including encryption in transit, access controls that limit accounts to permitted data, private file storage, and platform-protected credential storage. No method of transmission or storage is perfectly secure, but we review and update these protections as Joyn develops.
9. Children
Joyn is not intended for anyone under 16, and we do not offer a parental-consent route for account registration below that age. If the law where you live requires a higher minimum age, you must meet that requirement before using Joyn.
We do not knowingly collect personal data from anyone below the applicable minimum age. If you believe a child has given us personal data, contact privacy@joynevents.com and we will take appropriate steps to remove it.
10. International data transfers
Joyn is operated from Norway, and some providers process data in other countries. Those countries may have different data-protection laws. Where required, we use a recognized legal safeguard, such as an adequacy decision or approved contractual terms. Contact us if you want more information about the safeguards used for your data.
11. Changes to this policy
We may update this policy as Joyn changes. We will revise the date at the top and provide a more prominent notice when a change is significant. If a change requires new consent, we will ask for it.
12. Contact us
Joyn's data controller is Joyn Events AS. Organisation number: 938 238 294. Organisation form: Aksjeselskap (AS). Register: Foretaksregisteret. Registered business address: TBD.
For privacy questions or requests, email Joyn Events AS at privacy@joynevents.com. Current company details are also available on the Company information page.