Privacy Policy

Last updated: May 9, 2026

1. Introduction

HumbleOS, Inc. ("we," "our," or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our festival scheduling and social platform.

2. Information We Collect

2.1 Personal Information

We may collect personal information that you provide directly to us, including:

  • Name and contact information (email address)
  • Profile information (username, display name, profile picture)
  • Account credentials
  • Festival preferences and schedules
  • Reviews and ratings you submit
  • Discussion posts and replies on festival, set, and show pages, including upvotes and downvotes
  • Comments and replies on reviews, including likes
  • @username mentions you make and mentions of you by other users
  • Social connections and interactions
  • Content reports and safety information
  • User blocking and preferences settings
  • Subscription and billing information for Humble VIP (such as plan, billing cycle, billing status, and a Stripe customer identifier; we do not store your full payment card details)
  • Photos and short videos you upload to reviews, discussions, or comments, along with derived metadata (file dimensions, video duration, processing status, and a Mux playback identifier for video). EXIF and GPS metadata are stripped from photos before upload, and video is normalized by our processing pipeline.

2.2 Automatically Collected Information

We automatically collect certain information when you use our Service:

  • Device information (IP address, browser type, operating system)
  • Usage data (pages visited, time spent, features used)
  • Location data (if you enable location services)
  • Cookies and similar tracking technologies

2.3 Third-Party Information

We may receive information about you from third parties, including:

  • Authentication providers (Google and Apple) when you choose to sign in with that account
  • Festival organizers and venues

3. How We Use Your Information

We use the information we collect to:

  • Provide, maintain, and improve our Service
  • Create and manage your account
  • Personalize your feed using your preferences and the people you follow
  • Enable social features and connections
  • Send you notifications and updates
  • Respond to your inquiries and provide customer support
  • Analyze usage patterns and improve our Service
  • Moderate content and maintain community safety
  • Process content reports and enforce community guidelines
  • Comply with legal obligations

4. Content Moderation and Safety

To maintain a safe community environment, our Service includes content moderation features that apply to reviews, discussion posts and replies, comments and replies on reviews, votes, mentions, and any other Content you submit:

4.1 Content Reporting

  • Users can report inappropriate content, harassment, or policy violations
  • Reports include the reported content, reason for reporting, and reporter information
  • We review reports to determine appropriate action and ensure community safety
  • Report data is retained for moderation purposes and may be shared with law enforcement if required

4.2 User Blocking

  • Users can block other users to prevent seeing their content
  • Blocking preferences are stored with your account to maintain effectiveness across sessions
  • Blocked user lists are private and not shared with other users

4.3 Moderation Actions

We may take moderation actions on Content, including:

  • Hiding a discussion post, reply, or comment so it is not visible to other users
  • Soft-deleting Content (the original text is removed but a placeholder may remain when replies exist, so thread structure is preserved)
  • Pinning selected discussion posts to the top of a thread
  • Banning a user from posting, replying, voting, or mentioning others — temporarily or permanently — when they violate our community guidelines

4.4 Community Guidelines

Our Service is designed for users 13 and older. We maintain community guidelines to ensure respectful discussions about festivals and live music experiences.

4.5 Photos and Videos

Media you attach to a review, discussion, or comment is treated as Content under our Terms of Service and is subject to the same reporting and moderation processes described above. In addition:

  • EXIF and GPS metadata are stripped from photos before upload so location and device data are not published alongside the image.
  • Reported photos and videos may be hidden pending admin review. We may delete the underlying storage object and any associated Mux video asset to enforce takedowns, copyright notices, or other legal requests.
  • Copyright owners can submit a notice through the DMCA process described in our Terms of Service; repeated infringers will have their accounts terminated.

5. How We Share Your Information

5.1 Public Information

Certain information you provide may be publicly visible, including your profile information, festival schedules (if set to public), reviews, and social interactions.

5.2 Service Providers

We share information with third-party service providers who perform services on our behalf. Our key sub-processors include:

  • Supabase — database hosting, authentication, realtime infrastructure, and storage of user-uploaded photos
  • Mux — ingest, transcoding, hosting, and streaming of user-uploaded video clips
  • Vercel — web application hosting
  • Stripe — payment processing and billing portal for Humble VIP subscriptions
  • RevenueCat — subscription state synchronization across web and mobile platforms
  • Apple App Store — in-app purchases and subscription billing for iOS users (governed by Apple's privacy policy)
  • Google Play Billing — in-app purchases and subscription billing for Android users (governed by Google's privacy policy)
  • PostHog — product analytics and session-level usage data. EU, UK, EEA, Swiss, Brazilian, and Canadian residents are routed to PostHog Cloud EU (Frankfurt) when an EU-region project is configured; otherwise data is processed by PostHog's US instance under the EU–U.S. Data Privacy Framework.
  • Sentry — error monitoring and diagnostics
  • Resend — transactional email delivery
  • Google (Tag Manager & Analytics) — tag management container that loads measurement and advertising pixels for users who have accepted analytics cookies
  • Meta Platforms (Facebook Pixel) — advertising attribution for users who have accepted analytics cookies

5.3 International Data Transfers

Several of our sub-processors are based in the United States and process personal data outside the European Economic Area, the United Kingdom, and Switzerland. We rely on the following transfer mechanisms under Articles 45–46 of the GDPR / UK GDPR:

  • EU–U.S. Data Privacy Framework (DPF) certifications maintained by participating sub-processors (including PostHog, Sentry, Vercel, Stripe, Google, and Meta).
  • Standard Contractual Clauses (Module 3 — processor to sub-processor) executed with sub-processors that are not DPF-certified, combined with a transfer impact assessment where required.
  • UK International Data Transfer Addendum for transfers from the United Kingdom.

5.4 Legal Requirements

We may disclose your information if required by law or in response to valid legal requests, such as subpoenas or court orders.

5.5 Business Transfers

In the event of a merger, acquisition, or sale of assets, your information may be transferred as part of the business transaction.

6. Data Security

We implement appropriate technical and organizational measures to protect your personal information against unauthorized access, alteration, disclosure, or destruction. However, no method of transmission over the internet or electronic storage is 100% secure.

7. Data Retention

We retain your personal information for as long as necessary to provide our Service and fulfill the purposes outlined in this Privacy Policy. Our retention periods include:

  • Account Data: Until you delete your account or request deletion
  • Festival Schedules & Reviews: Until account deletion or manual removal
  • Analytics Data: Up to 24 months in aggregated, anonymized form
  • Subscription & Billing Records: Retained for the life of the subscription and afterward as required by tax, accounting, and chargeback rules (typically up to 7 years). Stripe and RevenueCat retain their own records under their respective policies.
  • Photo and Video Uploads: Original photo files are purged 30 days after processing. Processed photos and video assets (hosted with our storage providers and Mux) are retained until you remove them or delete your account. Removing a review, comment, or discussion deletes its attached media; deleting your account removes all media you have uploaded.
  • Marketing Communications: Until you unsubscribe or opt-out
  • Legal Compliance Data: As required by applicable laws and regulations

7.1 Account Deletion Process

When you request account deletion through the app settings, the following process applies:

  • Immediate: Your profile information (name, avatar, username) is cleared and your account is deactivated. You are signed out of all sessions.
  • 30-Day Grace Period: You have 30 days to cancel the deletion by signing back into your account. If you sign back in during this period, you will be prompted to cancel the deletion and restore your account data.
  • Permanent Deletion: After 30 days, all of your data is permanently and irreversibly deleted, including your profile, reviews, ratings, festival schedules, social connections, notifications, and authentication credentials.

You may also request account deletion by contacting privacy@tryhumble.com. The same 30-day grace period applies.

8. Your Rights and Choices

Depending on your location, you may have the following rights:

  • Access to your personal information
  • Correction of inaccurate information
  • Deletion of your personal information
  • Restriction of processing
  • Data portability
  • Objection to processing
  • Withdrawal of consent

You can exercise these rights by contacting us at privacy@tryhumble.com or through your account settings.

9. Cookies and Tracking Technologies

We use cookies and similar technologies to enhance your experience, analyze usage, and provide personalized content.

9.1 Types of Cookies We Use

  • Strictly Necessary: Authentication session cookies (Supabase) and security cookies. Always on; required to deliver the Service.
  • Functional: Theme, language, calendar view, and consent-state cookies / local storage entries that remember your preferences.
  • Analytics & Performance: PostHog (product analytics), Sentry (error monitoring; session-replay sampling only when you accept the "Session Recording" toggle), and Vercel Speed Insights (page-load metrics). All are off by default in opt-in regions until you accept via the consent banner. Sentry's basic error monitoring continues for everyone under our legitimate interest in service integrity, with no personal identifiers attached.
  • Marketing & Measurement: Google Tag Manager and Meta (Facebook) Pixel are loaded only after you accept analytics cookies. They power conversion attribution for paid acquisition.
  • Third-Party Cookies: Stripe sets a session cookie when you open the billing portal (set on Stripe's domain, governed by Stripe's privacy policy).

9.2 Managing Cookies

In opt-in regions (EU, UK, EEA, Switzerland, Brazil, and Canada) we display a consent banner on first visit and do not load analytics or marketing cookies until you accept. You can change your preferences at any time at Settings → Privacy. We honor browser Do Not Track and Global Privacy Control (GPC) signals — when either is detected we treat it as an opt-out from analytics and marketing cookies. You can also manage cookies through your browser settings; disabling strictly necessary cookies will prevent the Service from functioning correctly.

10. Third-Party Links and Services

Our Service integrates with third-party services to enhance your experience:

  • Analytics Services (PostHog): We use PostHog to understand usage patterns and improve our Service
  • Stripe (payment processing): Secure handling of payment information and billing-portal access for Humble VIP. Card details are entered directly into Stripe's hosted checkout — Humble does not see or store full card numbers.
  • RevenueCat (subscription sync): Synchronizes Humble VIP subscription state from Stripe, the Apple App Store, and Google Play to your account so VIP features unlock across web and mobile.
  • Apple App Store / Google Play: If you purchase Humble VIP through the iOS or Android app, that purchase is processed by Apple or Google under their respective terms and privacy policies. Apple and Google share limited transaction information with us (such as subscription status and a platform user identifier) so we can unlock VIP features for your account; we do not receive your full payment card or bank information from them.
  • Sign-In Providers (Google, Apple): Optional sign-in via Google or Apple OAuth (handled by Supabase Auth). We receive your verified email address and name from the provider to create or link your Humble account; we do not access your contacts, posts, or other provider data.

These third-party services have their own privacy policies and terms of service. We are not responsible for their privacy practices. We encourage you to review their policies before using these features.

11. Children's Privacy

Our Service is intended for users 13 years of age and older. We do not knowingly collect personal information from children under 13 without parental consent.

Users between 13 and 18 years old may use our Service under parental supervision. We encourage parents and guardians to monitor their children's online activities and help enforce our Privacy Policy.

If we become aware that we have collected personal information from a child under 13 without parental consent, we will take steps to remove that information from our servers promptly.

If you are a parent or guardian and believe your child has provided personal information to us, please contact us at privacy@tryhumble.com.

12. International Data Transfers

Your information may be transferred to and processed in countries other than your own. The transfer mechanisms we rely on for transfers from the EEA, UK, and Switzerland to the United States are listed in Section 5.3 (International Data Transfers) above.

13. California Consumer Privacy Act (CCPA)

If you are a California resident, you have additional rights under the California Consumer Privacy Act:

13.1 Your CCPA Rights

  • Right to Know: Request information about the personal information we collect, use, and share
  • Right to Delete: Request deletion of your personal information
  • Right to Opt-Out: Opt-out of the sale of personal information (we do not sell personal information)
  • Right to Non-Discrimination: We will not discriminate against you for exercising your rights

13.2 Exercising Your Rights

To exercise these rights, contact us at privacy@tryhumble.com with "CCPA Request" in the subject line. We may need to verify your identity before processing your request.

14. Location-Based Features

Our Service may use location-based features to enhance your festival experience:

  • Default Location for Shows: A city or metro area you save in your preferences to default the show discovery feed. This is a stored setting on your profile, not your device's GPS location.
  • Find Nearest City: When you tap "Use my location" in the city filter on mobile, we ask your device for its current location once to pick the closest city in our list. The coordinates are used in-memory for that lookup and are not stored on our servers.

You can control device location permissions through your operating system settings. Humble does not track your live location and does not share location data with other users.

15. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. We will notify you of any material changes by posting the new Privacy Policy on this page and updating the "Last updated" date.

16. EU/UK Representative and Data Protection Contact

HumbleOS, Inc. is established in the United States. For questions about this Privacy Policy or to exercise your rights under the GDPR, UK GDPR, or other applicable data protection laws, you may contact our data protection team at privacy@tryhumble.com.

Humble does not currently engage in large-scale or high-risk processing of personal data within the meaning of GDPR Article 37, and is therefore not required to designate a Data Protection Officer (DPO). We will appoint a DPO and / or an Article 27 EU representative if our processing activities expand to require one. EU and UK residents retain the right to lodge a complaint with their local supervisory authority at any time.

17. Contact Us

If you have any questions about this Privacy Policy or our privacy practices, please contact us at: