What we know, and what we refuse to.
Last updated July 28, 2026 · Applies to the Crowded iOS app and crowded.nyc
Crowded is a real-time crowd map for New York City. This policy describes exactly what data we handle and why. The short version: we collect the minimum needed to run a crowd map, we never sell personal data, there are no ads, there are no third-party analytics or tracking SDKs in the app, and you can delete everything in one tap.
What we collect and why
Account
The app works without any sign-up: on first launch we create an anonymous account so your Cred and reports have somewhere to live. If you use social features (finding friends), you verify a phone number, which attaches to that same account. Your phone number is used for verification and friend matching — it is never shown to other users.
Location
While using the app: location centers the map, sorts nearby venues and bounties, and — most importantly — verifies you're physically at a venue when you report its crowd level. A report stores the venue, your crowd rating, any vibes you selected, a timestamp, and the coordinates you reported from.
Arrival Asks (optional — off until you turn it on): if you enable Arrival Asks and grant "Always" location access, iOS's built-in visit detection tells the app when you've arrived and stayed somewhere during evening hours. The app then asks our server which venues are near that spot, purely so the notification can name the place — and shows you a local notification asking how crowded it is. The visit itself is never stored: prompts are capped at two per night, the decision happens on your device, and nothing is reported unless you open the app and choose to report. You can turn Arrival Asks off anytime in Settings. There is no continuous location tracking, with or without it.
Contacts (optional, processed on your device)
If you use "Sync Contacts," your contacts are read on your device only. Phone numbers are converted to a one-way cryptographic hash (SHA-256) on your device; only those hashes are sent to our server, compared against registered users to find your friends, and not stored. Your address book — names, numbers, anything else — is never uploaded to us.
Camera (optional)
Used only to scan a friend's QR code when adding friends. Nothing is photographed or saved.
Profile
A display name you choose. It's visible to your friends and — if you earn your way onto it — the Cred leaderboard, which other users can see. Accounts without a display name never appear on leaderboards. An optional Instagram handle, if you add one, stays on your device and is never sent to our servers.
Activity
Your crowd reports, vibes (picked from a fixed vocabulary — reports carry no free-text), Cred history, achievements, friendships, and bounty activity — the product itself.
What we don't do
- No ads, no ad networks, no data brokers, no sale of personal data — ever. We may share or sell aggregated, de-identified insights (for example, "interest in nightlife venues by neighborhood and hour") that cannot be linked to any person or device.
- No third-party analytics or behavioral tracking SDKs in the app.
- No continuous location tracking. Arrival Asks, if you opt in, uses Apple's battery-friendly visit detection — arrival events, not a trail.
- No reading of message content, photos, or anything beyond what's listed above.
Service providers
We use a small number of infrastructure providers to run Crowded, each receiving only what's needed to do its job:
- Supabase — hosts our database and authentication (your account, reports, friendships).
- SMS delivery — your verification code is sent through our authentication platform's SMS provider, which sees your phone number solely to deliver that code.
- Branch — powers invite links, so a friend's invite opens the right screen after install (processes standard device information for link attribution).
- Mapbox — renders the map. Your device requests map imagery from Mapbox's servers, which involves your IP address and the area of the map on screen, subject to Mapbox's privacy policy.
- Wikimedia Commons — venue photos load from Wikimedia's servers (a standard image request from your device).
- Cloudflare — hosts this website.
This website
crowded.nyc is a static page. It sets no cookies and runs no tracking pixels. We use Cloudflare Web Analytics, which is cookieless and does not identify you. The "Live right now" line on the homepage asks our database which venues are busy; that request carries no account identity.
Sharing
We do not share personal data with anyone except the service providers listed above, in aggregated and de-identified form as described, or if we are legally required to.
Deleting your data
Settings → Delete Account & Data permanently deletes your account, reports, Cred history, profile, and friendships, and releases your phone number. It works in-app, immediately, with no email required. Open bounty requests you placed lose their connection to you and expire on their own.
Retention
Data lives as long as your account does. Delete the account and it's gone.
Security
Data travels over TLS and is stored with our database provider with server-side access controls. No system is perfect — our main defense is collecting very little in the first place.
Children
Crowded is not directed at children under 13, and we don't knowingly collect data from them.
Your choices
Every permission — location, contacts, camera, notifications — is optional and can be revoked anytime in iOS Settings. Arrival Asks has its own switch inside the app. For anything else, email us and we'll help.
Changes
If this policy changes materially, we'll update the date above and note the change in the app.
Contact
Questions or requests: info@crowdednyc.com
← Back to the map