Privacy Policy

Last updated: September 16, 2026

Hit Me Up is a private membership community operated by Hit Me Up, LLC, a New York limited liability company based in New York City ("Hit Me Up", "we", "us").

This policy explains what we collect, why, who we share it with, how long we keep it, and the choices you have. It covers our website, our member app at app.joinhitmeup.com, and our iOS and Android apps.

We built this platform to be private by default. We do not sell your personal information, we do not run advertising, and we do not embed third-party advertising or cross-site tracking technology in the member app.

Who we are

Hit Me Up, LLC New York, NY Questions about this policy: hello@hitmeupnyc.com

Information we collect

Information you give us

  • Account. Your email address. We do not use passwords — you sign in with a one-time link or code sent to your email.
  • Phone number — only if you opt in to text messages. Optional, and you can withdraw it at any time.
  • Membership application. Your name, birth year, links to your social media (or a note that you have none), how you heard about us, who referred or sponsored you, where we may have met, a description of your experience and interests, your acknowledgment of our consent policy, and any additional notes you choose to add. You may optionally record a short introduction video.
  • Profile. Your username, display name, pronouns, bio, profile photo, and any links you add.
  • Content you create. Messages, posts, comments, reactions, and any photos or files you upload.
  • Correspondence. Emails you send us, venue inquiries, sponsorship requests, and reports you submit about other members or content.

Information we generate

  • Membership records. Your tier, application status, sponsorship history, and administrative notes made by our membership team.
  • Safety and moderation records. Reports you make or that are made about you, moderation actions, and related administrative logs.
  • Usage analytics. A deliberately narrow, first-party record of how the app is used — see "Analytics" below.
  • Technical records. Security and delivery logs generated by our service providers in the ordinary course of running the service.

Information from third parties

  • Patreon. Only if you choose to connect your Patreon account. We receive your Patreon identity and current pledge tier so we can apply the benefits attached to it. We never receive your payment card or billing details.

Analytics — what we deliberately do not do

Our usage analytics are first-party and intentionally minimal. They are enforced in code, not merely by policy:

  • Only a fixed, pre-declared list of events is accepted. Anything else is discarded before it is stored.
  • We never record the content of messages or posts, and never record whose profile you viewed.
  • We do not store IP addresses or user-agent strings. Our analytics tables have no columns for them.
  • Raw analytics events are automatically deleted after 180 days. Only anonymous aggregate counts, which are not linked to any member, are kept longer.
  • You can turn analytics off entirely in Settings → Usage analytics. The opt-out is enforced on our servers, not just in your browser, and we honor the Do Not Track and Global Privacy Control browser signals.
  • Deleting your account immediately deletes your raw analytics events.

Our public marketing website uses Vercel Web Analytics, which is cookieless and aggregate. The member app does not use it.

How we use your information

  • To operate the platform: to sign you in, show your profile, deliver messages and posts, and run events.
  • To evaluate membership applications and sponsorships, and to administer membership tiers.
  • To keep the community safe: to review reports, enforce our community and consent policies, and prevent people we have removed from returning.
  • To communicate with you about your account, applications, and community announcements.
  • To send you marketing email or text messages only if you have opted in.
  • To understand how the platform is used in aggregate, so we can improve it.
  • To comply with law and to establish, exercise, or defend legal claims.

If you are in the UK or EEA, our legal bases are: performance of a contract (operating your membership), legitimate interests (safety, moderation, security, and product improvement), consent (marketing messages and optional features), and legal obligation.

Safety, moderation, and image scanning

This is a community platform, so safety processing is a core part of how it works.

  • Members can report content and block other members from within the app.
  • Our membership and moderation team can review reported content, profiles, and account history, and can restrict, suspend, or remove accounts.
  • Safety screening and illegal content. We use automated safety technologies, including hash- and fingerprint-matching services provided by child-protection organizations (Arachnid Shield, a service of the Canadian Centre for Child Protection), to screen media uploaded to the Service for known or suspected child sexual abuse material and other harmful or abusive content. This is not optional and applies to profile photos, posts, and chat attachments. Content identified through these systems may be blocked, removed, or preserved in a restricted evidence system. Where required or permitted by law, we may preserve and disclose relevant content, account information, technical information, IP addresses, and related records to the National Center for Missing & Exploited Children (NCMEC), law-enforcement agencies, or other authorized entities. We may suspend or terminate accounts associated with prohibited content.
  • We maintain an internal list of people who are not permitted to join or return. It exists solely for safety and admissions screening.

Who we share information with

We do not sell personal information and we do not share it for cross-context behavioral advertising. We share it with service providers who process it on our behalf, under contract:

Provider What it handles
Supabase Our database, authentication, and file storage
Stream Chat: messages, channels, attachments
Resend Transactional email (sign-in codes, notifications)
Klaviyo Marketing email and, if you opt in, text messages
Patreon Membership-tier sync, only if you connect your account
Arachnid Shield (Canadian Centre for Child Protection) Automated scanning of uploaded images
Eventbrite Public event listings we display in the app
Vercel Website and app hosting; cookieless analytics on the marketing site only
Cloudflare R2 Encrypted off-site backups
Google Workspace / Google Identity Our staff email; identity re-verification for administrators only

We may also disclose information when we believe in good faith that it is required by law or legal process, or where necessary to protect the safety of a person or the community.

Note that other members see what you choose to share: your profile, your posts, and the messages you send them. Members with administrative or moderation roles can see more, including your application and account history, in order to run the community.

How long we keep it

  • Your account and profile: for as long as your account exists.
  • Raw analytics events: 180 days, then automatically deleted.
  • Backups: we keep encrypted off-site backups. Uploaded media is removed from backups within about 24 hours. Database, chat, and configuration snapshots expire automatically after up to 90 days. Backups are the one place where deletion is deferred rather than immediate — nothing is retained beyond that window, and no manual step is required for it to expire.
  • Safety and moderation records: retained after account deletion where necessary for community safety, to enforce removals, and to comply with law. See What we keep after you delete for exactly what this covers.

Deleting your account

You can delete your account yourself, at any time, in Settings → Delete Account. No email to support is required, and no one has to approve it.

Deletion is permanent and cannot be reversed. Here is exactly how it runs:

  • When you confirm, we schedule the deletion, hide your profile immediately, and sign you out. The app tells you the date your account will be deleted.
  • We then hold the account for 30 days before erasing it, so that an accidental or regretted deletion can be undone. During those 30 days you can sign in and choose Cancel deletion, which restores your account exactly as it was. Signing in by itself does not cancel the deletion — you have to choose to cancel it. If you do nothing, the deletion goes ahead.
  • On that date we erase your profile, photos, application, contact details, phone number, and raw analytics events, we remove you from our email and text lists, and we delete your sign-in credentials so the account can no longer be accessed. This step is automatic and irreversible.
  • If you want your account gone sooner than 30 days, email hello@hitmeupnyc.com and we will erase it on request. You do not need to do this for deletion to happen — it happens on its own.

What we keep after you delete

Deletion removes you from the community and erases the personal information above. A small number of records outlive the account, and we think you should know which:

  • The text of messages you sent stays visible to the people you sent them to, shown as coming from a hidden user with your name and photo removed. We do this because deleting the text would leave holes in other members' conversations. If this matters to you, delete individual messages before deleting your account.
  • Safety and moderation records. If you were reported, restricted, or removed, we keep a record of what happened, when, and what we decided — including, where the report concerned a chat message, a copy of that message. If you were placed on our membership deny list, that entry — your name, the email you used, and the reason — is kept so the decision can be enforced if an application is made again later.
  • Our internal log of administrative actions, which records actions taken on accounts, including yours.
  • Reports of illegal content, which we retain for as long as the law requires and provide to the authorities where we are required to.
  • Backups, until they expire on the schedule described above (uploaded media within about 24 hours, database and chat snapshots within 90 days). Nothing is kept beyond that window and no manual step is needed for it to expire.
  • Anonymous aggregate counts that are not linked to you and cannot be used to identify you.

We keep the safety and moderation records above because deleting them would let someone harm another member, delete their account, and return as a stranger. Data protection law provides for this: both the GDPR and the CCPA/CPRA permit retaining the minimum information necessary to protect against harmful or illegal activity, to enforce our rules, and to establish or defend legal claims. We keep no more than is needed for that purpose, we do not use these records for anything else, and they are visible only to the small number of people who handle safety and membership decisions.

Your rights and choices

Depending on where you live, you may have the right to access, correct, delete, or receive a copy of your personal information, to object to or restrict certain processing, and to withdraw consent. California residents have rights under the CCPA/CPRA, including the right to know, delete, correct, and opt out of sale or sharing — we do not sell or share personal information as those terms are defined. We will not discriminate against you for exercising any of these rights.

You can exercise most of these directly in the app: edit your profile, adjust your privacy settings, turn analytics off, unsubscribe from marketing, or delete your account. For anything else, contact hello@hitmeupnyc.com and we will respond within the time the applicable law requires.

Marketing communications

We send marketing email only to members who have opted in, and you can unsubscribe from any marketing message. Text messages are opt-in only; reply STOP to any message to stop them. Transactional messages — sign-in codes, security notices, and messages about your application or account — are part of the service and are not marketing.

Cookies and local storage

We use browser storage for the things the app needs to work: keeping you signed in, remembering your preferences, and holding your analytics opt-out. We do not use advertising cookies or third-party tracking cookies in the member app.

Age requirement

Hit Me Up is for adults only. You must be at least 21 years old to apply or hold an account. We do not knowingly collect information from anyone under 21; if we learn that we have, we delete it and remove the account.

Security

We protect member data with encryption in transit and at rest, database-level access rules that restrict every member to their own data, encrypted off-site backups, and mandatory additional identity verification for administrator accounts. No system is perfectly secure, but we treat member data as sensitive by default and design for that.

International transfers

We operate in the United States, and our service providers may process data in the United States and elsewhere. If you access Hit Me Up from outside the United States, you understand that your information will be processed in the United States, where data protection law may differ from your own.

Changes to this policy

We will update this page when our practices change and revise the "Last updated" date above. If a change materially affects your rights, we will tell you in the app or by email before it takes effect.

Contact

Questions, requests, or complaints: