Privacy policy

Last updated: 29 June 2026 · This is a starter policy. Have a solicitor review before launch.

Dion ("we", "us") takes your privacy seriously. This policy explains what we collect, why, and your rights under UK GDPR.

What we collect

  • Your university (.ac.uk) email address — to verify you're a student.
  • Your display name and university name.
  • Parties you host (name, time, area, capacity, vibe, description).
  • The exact address of parties you host — visible only to you and guests you approve.
  • Join requests, approvals, and reviews you write or receive.
  • Reports and blocks, kept for safety review.

What we don't collect

  • Payment information — Dion is free RSVP only.
  • Location data from your device.
  • Marketing or third-party tracking cookies.

Who sees what

Exact party addresses are only revealed to the host and guests the host has approved. This is enforced at the database level, not just in the app. Reviews, profile names, and party listings are visible to other signed-in students.

How long we keep your data

We keep your account data for as long as your account is active. Deleted accounts are permanently removed within 30 days, except where we're required to keep records (e.g. an active safety report).

Your rights

Under UK GDPR you can request a copy of your data, correct anything inaccurate, delete your account, or restrict how we use your data. Email us at hello@hauz.app (placeholder) and we'll respond within 30 days.

Where your data lives

We use Supabase as our database and authentication provider. Data is processed in the EU. We don't share your data with advertisers or sell it to anyone.

Changes

If we change this policy materially, we'll tell you in the app the next time you sign in.