What we know, and what we refuse to.
Last updated August 12, 2026 · Applies to the Crowded iOS app and crowded.nyc
Crowded is a real-time crowd map for New York City. This policy describes exactly what data we handle and why. The short version: we collect the minimum needed to run a crowd map, we never sell personal data, there are no ads, there are no third-party analytics or tracking SDKs in the app, and you can delete everything in one tap.
Where we process data. Crowded is operated from New York, NY, in the United States, and can be reached at info@crowdednyc.com. If you use the app from outside the U.S., your information is transferred to, stored, and processed in the United States, where data-protection laws may differ from those in your country.
What we collect and why
Account
The app works without any sign-up: on first launch we create an anonymous account so your Cred and reports have somewhere to live. If you use social features (finding friends), you verify a phone number, which attaches to that same account. Your phone number is used for verification and friend matching — it is never shown to other users. Verification works by SMS one-time passcode: by providing your phone number, you consent to receiving these verification messages, and standard messaging rates from your carrier apply.
Location
While using the app: location centers the map, sorts nearby venues and bounties, and — most importantly — verifies you're physically at a venue when you report its crowd level. A report stores the venue, your crowd rating, any vibes you selected, a timestamp, and the coordinates you reported from.
Arrival Asks (optional — off until you turn it on): if you enable Arrival Asks and grant "Always" location access, iOS's built-in visit detection tells the app when you've arrived and stayed somewhere during evening hours. The app then asks our server which venues are near that spot, purely so the notification can name the place — and shows you a local notification asking how crowded it is. The visit itself is never stored: prompts are capped at two per night, the decision happens on your device, and nothing is reported unless you open the app and choose to report. You can turn Arrival Asks off anytime in Settings. There is no continuous location tracking, with or without it.
Contacts (optional, processed on your device)
If you use "Sync Contacts," your contacts are read on your device only. Phone numbers are converted to a one-way cryptographic hash (SHA-256) on your device; only those hashes are sent to our server, compared against registered users to find your friends, and not stored. Your address book — names, numbers, anything else — is never uploaded to us.
Camera and photos (optional)
The camera is used for two things: scanning a friend's QR code, which photographs nothing, and taking a crowd photo.
A crowd photo is a picture of a place you are standing in, attached to a report you just made there. You can use the app fully without ever taking one. Photos can only be taken with the camera in the moment — Crowded has no access to your photo library, and cannot open it.
Before a photo leaves your phone, your device blurs faces in it and strips the embedded metadata, including the GPS coordinates and the timestamp your camera wrote into the file. What we receive is the image, the venue, the crowd level you reported, and the time you took it.
Crowd photos are public. Anyone using Crowded can see them in the Feed and on the venue, alongside the venue name, the crowd level, and how long ago it was taken. They are not linked to your display name.
Crowd photos expire on their own, in two stages. A photo stops appearing on the map when the venue closes — at least 90 minutes, at most 8 hours after you take it — because on the map it stands for how busy a place is right now. It stays in the Feed for 7 days, labelled with how long ago it was taken, and is then deleted. It stays visible to you under Your photos until you delete it.
Every photo is checked automatically before it appears (see Service providers). You can report any photo, or block an account, from the photo itself; blocked accounts are listed in Settings → Blocked Accounts.
Venue owners who have verified their venue can post photos of their own business. Those are permanent, labelled, and kept separate from crowd photos — an owner can never post a crowd photo.
Profile
A display name you choose. It's visible to your friends and — if you earn your way onto it — the Cred leaderboard, which other users can see. Accounts without a display name never appear on leaderboards. An optional Instagram handle, if you add one, stays on your device and is never sent to our servers.
Activity
Your crowd reports, vibes (picked from a fixed vocabulary — reports carry no free-text), Cred history, achievements, friendships, and bounty activity — the product itself.
What we don't do
- No ads, no ad networks, no data brokers, no sale of personal data — ever. We may share or sell aggregated, deidentified insights (as "deidentified" is defined under the California Consumer Privacy Act) — for example, "interest in nightlife venues by neighborhood and hour" — that cannot be linked to any person or device.
- No third-party analytics or behavioral tracking SDKs in the app.
- No continuous location tracking. Arrival Asks, if you opt in, uses Apple's battery-friendly visit detection — arrival events, not a trail.
- No reading of message content, no access to your photo library, nothing beyond what's listed above.
Service providers
We use a small number of infrastructure providers to run Crowded, each receiving only what's needed to do its job:
- Supabase — hosts our database, authentication, and photo storage (your account, reports, friendships, and the crowd photos you take).
- SMS delivery (Twilio) — your verification code is sent through Twilio, our authentication platform's SMS provider, which sees your phone number solely to deliver that code.
- Anthropic — every crowd photo is checked by an automated safety model before it is published, to keep explicit, unsafe, and off-topic images out of the feed. The image is sent for that check and is not used to train anyone's models.
- Mapbox — renders the map. Your device requests map imagery from Mapbox's servers, which involves your IP address and the area of the map on screen, subject to Mapbox's privacy policy. The Mapbox SDK may also collect device-level telemetry (such as device model, OS version, and usage metrics) to improve its services, as described in Mapbox's privacy policy.
- Wikimedia Commons — venue photos load from Wikimedia's servers (a standard image request from your device).
- Cloudflare — hosts this website.
These providers are used solely as needed to operate the app and are contractually prohibited from using your data for any other purpose.
This website
crowded.nyc is a static page. It sets no cookies and runs no tracking pixels. We use Cloudflare Web Analytics, which is cookieless and does not identify you. The "Live right now" line on the homepage asks our database which venues are busy; that request carries no account identity.
Sharing
We do not share personal data with anyone except the service providers listed above, in aggregated and deidentified form as described, or as described under "Law enforcement and legal process" below.
Law enforcement and legal process
We may disclose personal data if we reasonably believe disclosure is required by law, regulation, legal process (such as a subpoena, court order, or search warrant), or enforceable governmental request. Where legally permitted, we will attempt to notify affected users before disclosing their data in response to legal process. This notice does not apply to reports we are required to make under child-safety law, which we do not disclose to the account holder. We may also disclose information if we believe in good faith that it is necessary to protect the rights, property, or safety of Crowded, our users, or the public.
Deleting your data
Settings → Delete Account & Data permanently deletes your account, reports, photos, Cred history, profile, achievements, friendships, blocks, and any venue content you posted as an owner, and releases your phone number. It works in-app, immediately, with no email required. Open bounty requests you placed lose their connection to you and expire on their own.
Your photos are removed from the app the moment you delete your account. The image files themselves are erased on the next scheduled sweep, which runs several times a day.
One exception. If a photo has been preserved under U.S. federal child-safety law (see Age requirement and children), we are legally required to keep it and cannot delete it on request. Everything else goes.
Retention
Data lives as long as your account does. Delete the account and server-side personal data is removed immediately.
Photos work differently, and in two ways. A crowd photo stops appearing on the map when the venue closes and leaves the public feed 7 days after it was taken, but the file is kept after that so it can appear in your own photo history and so we can keep the automated safety check accurate. Photos that were never approved are erased outright. Delete a photo, or your account, and the file is erased on the next sweep.
Photos preserved under U.S. federal child-safety law are retained for one year, as that law requires, regardless of any deletion request.
Routine database backups that may contain residual personal data are overwritten within 30 days of account deletion. Aggregated, deidentified insights derived from your data before deletion may persist indefinitely, as described above.
Security
Data travels over TLS and is stored with our database provider with server-side access controls. No system is perfect — our main defense is collecting very little in the first place.
Age requirement and children
Crowded is intended for users aged 17 and older. The app displays nightlife venues — including bars and clubs — and is not designed for minors. We do not knowingly collect personal data from anyone under 17. If we learn that we have collected data from a user under 17, we will delete it promptly.
Crowded has zero tolerance for child sexual abuse material. Photos are checked automatically before publication, and anyone can report a photo from the app. Where we become aware of apparent child sexual abuse material, we report it to the National Center for Missing & Exploited Children as U.S. federal law requires (18 U.S.C. § 2258A), and we preserve the material and related account information for one year as that law requires. We do not notify the account holder in these cases.
If you are a California resident under 18, you may request removal of content you posted on Crowded by contacting us at info@crowdednyc.com. Removal does not ensure complete erasure — for example, insights that have been aggregated and deidentified may persist.
Your choices
Every permission — location, contacts, camera, notifications — is optional and can be revoked anytime in iOS Settings. Arrival Asks has its own switch inside the app. You can also email us to request a copy of the data we hold about you — or for anything else, and we'll help.
Your privacy rights
California residents. If you are a California resident, the California Consumer Privacy Act ("CCPA"), as amended by the California Privacy Rights Act ("CPRA"), provides you with specific rights regarding your personal information.
Categories of personal information we collect:
- Identifiers (your anonymous account ID; your phone number, if you verified one)
- Geolocation data (the coordinates you reported from, collected only at report time; approximate location while the app is open)
- Internet or other electronic network activity (your IP address, seen by our infrastructure and map provider when the app requests data)
- User content (crowd reports, vibes, display name, and any crowd photos you take)
- Visual information (crowd photos, with faces blurred on your device before upload)
Your rights under the CCPA/CPRA:
- Right to know: you may request that we disclose the categories and specific pieces of personal information we have collected about you, the categories of sources, our business purpose for collecting it, and the categories of third parties with whom we share it.
- Right to delete: you may request deletion of personal information we have collected from you, subject to certain exceptions (or just use Settings → Delete Account & Data).
- Right to correct: you may request that we correct inaccurate personal information we maintain about you.
- Right to opt out of sale or sharing: we do not sell personal information as defined by the CCPA, and we do not share personal information for cross-context behavioral advertising.
- Right to limit use of sensitive personal information: we do not use or disclose sensitive personal information for purposes beyond those permitted without a right to limit.
- Right to non-discrimination: we will not discriminate against you for exercising your CCPA rights.
To exercise any of these rights, contact us at info@crowdednyc.com or use the in-app account settings. We will verify your identity before processing your request — normally by confirming the phone number on your account via SMS, or your access to the account in-app. We do not knowingly sell or share the personal information of consumers under 16.
Other states. Residents of Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, and other states with comprehensive privacy legislation may have similar rights under their respective laws, including rights to access, delete, correct, and opt out of certain processing. To exercise these rights, contact us at info@crowdednyc.com. We will respond within the timeframe required by applicable law.
Changes
If this policy changes materially, we will provide at least 30 days' advance notice by updating the date above and noting the change prominently in the app. Continuing to use Crowded after the updated policy takes effect means you accept it. If you disagree with a change, you can delete your account before the effective date.
Contact
Questions or requests: info@crowdednyc.com
← Back to the map