privacy
last updated August 19, 2026
what we collect
Your phone number, which is how you sign in, display name, and birthday are required for a basic account. Gender, typed five-digit ZIP code, industry, interests, recovery email, dietary needs and details, and Instagram are optional private Profile fields. A profile image is also optional.
We ask for your birthday to confirm you are 18 or older. The main staff grouping screen shows an age range rather than the date, but authorized staff systems can access the exact date in your record. If you choose to provide a ZIP code, it is Coarse Location: we do not request GPS or precise device location. Staff see the ZIP when they read your application.
Supplied industry and interests may give authorized staff private curation context, but they are optional and do not promise a personalized matcher. None of these Profile fields is public member data.
If you choose a profile image, the processed image is stored in a private bucket. It is shown to you through a short-lived signed read URL, not a public object URL. Authorized operational staff and service providers can access stored account data only when needed to operate, secure, support, or delete it.
We also keep your applications, attendance status, account and message choices, and the wording shown when you make a text-message choice. Our infrastructure processes basic request and security information needed to connect you to the service, protect accounts, and diagnose failures.
When you apply to a paid after, we keep the event, amount, currency, payment and refund states, dates, and opaque payment-provider references. Stripe's payment sheet collects payment-method and billing details directly. AfterFive does not store your card number, security code, wallet token, or billing contact details.
Photographs of afters. Our staff photograph some afters and choose which pictures go up, and an attendee who has answered that night's recap may submit a photograph for staff approval. Those pictures can show you. Approved pictures go in a private album for admitted viewers: registrants from that afters and up to ten guests per host admitted through a valid time-limited album link. Staff may separately select pictures for our public website, where anyone can see them. We keep the picture, when it was taken, and who uploaded it. Before a picture is stored for member viewing, the upload path removes camera metadata, including any location the camera recorded.
Your answers to the questions we send after an afters you came to: whether you would come to another, what the best part was, what you would change, what we should run next, and, if you want to give one, the name or description of somebody you would like to see again. We keep what you answered, when you answered, and the version of the questions you read, the same way we keep a text-message choice. If you ask us to take a photograph down, we keep who asked and which picture.
what we do with it
We use it to operate your account, decide who to invite or admit to which afters, curate event rosters, put groups together for grouped afters, and tell you about your own applications and events. Optional Profile answers are used only when supplied as private staff context; they are not a promise of personalized matching. Your answers are shown only to authorized staff and are not shown to other members, and that is as true of the questions we send after an afters as of the ones we ask before it. We read those answers to decide what to run next and who to tell about it.
Event photographs are the one thing we show to anybody but authorized staff. We put approved pictures from an afters in its private album for admitted viewers, including the bounded guests admitted by an album link. We also publish some staff-selected pictures on our public website. Nothing else you give us, including your owner profile image, is shown to another member.
We do not sell your data, we do not share it with advertisers, and we do not use it to train anything.
All the above categories exclude text messaging originator opt-in data and consent; this information won’t be shared with any third parties.
Mobile information, including phone numbers and SMS opt-in data and consent, will not be shared with third parties or affiliates for marketing or promotional purposes. We may provide this information to service providers solely to operate AfterFive messaging, as described below.
what other guests see
Approved photographs in a private album you were both admitted to, and nothing else. Other guests never see your name, your number, your profile image, your answers, or whether you applied to or are attending an after. Guest lists are not public in this app.
Some of those pictures also go on our public website, where anyone can see them with no account — including people who were not there, and search engines. The same limits hold there: no names, no tags, no counts of who is in a picture, no comments, and no way from a face to a profile.
After some afters we put up approved pictures from that afters. Admitted registrants open them after answering the questions we send, and a valid time-limited album link may admit up to ten guests per host. Faces are recognizable. There are no names under the pictures, no tags, no counts of who is in one, no comments, no reactions, and no way to get from a face to a profile or contact details. There is no way to message another guest through AfterFive.
Nobody sees who else is coming to an after before it happens. Photographs come afterwards, and they are the whole of what opens up.
The current album viewer has no member-facing report or removal control. To ask about an album or public photograph, email support@afterfive.club. A signed read URL already issued to a browser may remain usable until its expiry, for up to fifteen minutes, even after access changes or a stored object is removed; we cannot invalidate that already-issued URL immediately.
For a photograph on our public website there is no control beside it, because that page has no idea who you are. Email support@afterfive.club and our staff will take it down. It comes off the page, but we cannot reach copies of it: while it was up, anyone could see it and save it, and search engines may have copied it. Those copies are not ours to remove.
who else touches it
Google Cloud hosts our database and servers. Firebase handles sign-in. Prelude sends your verification code. Resend sends our email. Stripe processes paid event applications, payment authentication, and refunds. PostHog measures how our website is used. Each one only receives what it needs to do that job.
Stripe receives payment-method and billing details through its native payment sheet. Its SDK may also collect device characteristics and interaction data for payment functionality, analytics, and fraud prevention. Stripe says it does not use this data for advertising or tracking. If card scanning is available on iPhone and you choose it inside payment entry, the camera is used for that scan; there is no camera request at launch.
PostHog is a product analytics service we use on our public website and event funnel. It is first-party: measurement requests go to www.afterfive.club, and we do not run it inside the AfterFive native app. Every /account/* page is excluded from browser analytics and session replay and sends no new PostHog person properties. On ordinary marketing pages it records page views, page exits, interactions, and session recordings with every typed input masked. On invitation pages it records bounded funnel events and a recording with the account/apply subtree blocked out.
What PostHog stores about you as a person is written only by our server, and it is two things beside an internal account identifier: an age range rather than your date of birth, which is one of 18-24, 25-29, 30-34, 35-44, or 45+; and the week your account was created. It also records when an application is submitted, when a paid application is paid, and when one is cancelled, along with the event, whether the event was open or invite-only, the price, whether a comp code was used, and whether a cancelled seat had been paid. Your name, phone number, email address, date of birth, gender, and zip code are never sent to it, and neither is your sign-in identifier.
We do not sell analytics data, we do not share it for advertising, and we do not use an advertising identifier. Deleting your account deletes your analytics record and the events attached to it; a failure on PostHog's side never stops or undoes the rest of your deletion.
A messaging delivery service provider processes the phone number, message, delivery status, and replies needed to deliver and operate Event Alerts on our behalf. We use service providers for these limited functions, not to let them advertise to you or use your information for their own marketing.
Service providers may process information only to perform services for AfterFive or as required by law. We do not give them permission to sell it or use it for their own advertising.
how long we keep it
We keep account, profile, application, attendance, and communication information while your account is active and for as long as it is needed to operate the service and fulfill the purposes described here. We keep consent records and limited operational or security records for as long as reasonably needed to document your choices, protect the service, prevent abuse, or meet legal obligations.
When information is no longer needed for those purposes, we delete it or remove identifying details. Retention can differ by type of information and why it is being kept; we do not claim one fixed period for every record.
An unfinished profile-image upload under the private pending prefix is automatically eligible for deletion after it is more than 24 hours old. The active profile image is never age-deleted; it stays while selected and is deleted when replaced, removed, or the account is deleted. Storage-provider recovery can retain a deleted object temporarily under the bucket's configured soft-delete policy. A signed read URL already issued may still work until it expires, for up to 15 minutes.
Event photographs stay up until staff remove them; the current album has no member-facing report or removal control. Email support about a photograph. A private signed read URL already issued can remain usable until it expires, for up to fifteen minutes, and our storage can keep a deleted file recoverable for seven days. A public photograph has no expiring link, and copies saved by visitors or search engines are outside our control.
your choices
You may update your profile information in the app. You may also email support@afterfive.club to ask us to correct information, provide a copy of your information, or help with deletion.
Your recovery email is optional contact information. It is not a Firebase sign-in method or recovery provider, and there is no automated lost-phone or phone-number-change recovery. Support cannot guarantee restoration when you lose access to the verified number.
If you do not provide a recovery email, application, outcome, recap, and emailed receipt messages are not guaranteed. Your private profile, application and payment history is the authoritative in-product record. Editorial emails include an unsubscribe link. Event Alerts are separate from sign-in and off by default; when required, the current agreement is shown at first Apply after the event is known, never during standalone signup. You can stop those texts at any time by replying STOP.
deleting your account
You can delete your account at any time from your profile or at https://www.afterfive.club/account/delete. The authenticated flow removes your sign-in, active profile and profile image, answers, applications, attendance and consent records, and the local personal links from payment records, and it cannot be undone.
Event photographs are the one thing deleting your account does not remove: they belong to an event album or public event page rather than to your owner profile. For a photograph request, email support@afterfive.club. An avatar signed URL that was already issued can remain usable until its expiry, for up to fifteen minutes, even though deletion removes the active avatar object.
We may keep the minimum pseudonymized transaction and refund facts needed for accounting, support, fraud prevention, disputes, chargebacks, and legal obligations. Those records can include amounts, dates, event and status history, and restricted Stripe references. Authorized staff may use a Stripe reference for accounting or support, so we do not call those records irreversibly anonymous. Stripe retains its own records under its policies.
Some limited information may remain temporarily in service backups or be retained separately when reasonably necessary for security, fraud prevention, or a legal obligation. We do not use information retained for those limited reasons to advertise to you.
messages
When you ask to sign in, Prelude sends a one-time verification code to the phone number you provide. That user-requested authentication message is separate from AfterFive Event Alerts.
Event Alerts are a text program for application status, confirmations, reminders, location or schedule changes, cancellations, and safety updates for events you apply for or attend. The required, default-off agreement is shown at first Apply after the event context is known, not during standalone Sign in or Sign up. Marketing is not part of the Event Alerts program, and we will not add it to this program.
When you make a text-message choice, we keep what you answered, when you answered, and the version of the wording you read. A new answer is added rather than written over the old one so the record shows what you agreed to on the day. Deleting your account deletes that record too.
After an afters you came to, we send one text with a link to the questions and the pictures. It is about an after you attended, so it goes out as an Event Alert and not as marketing, and it is one message: there is no reminder and no second text if you do not answer. If the text does not reach you and we have your recovery email, we email it instead. Treat the link as yours. Anyone you forward it to could open your album, and it stops working ninety days after we send it.
Reply STOP to an Event Alert to stop Event Alerts and HELP for help. AfterFive records the STOP and checks the latest consent before a later Event Alert is sent. Those commands apply to Event Alerts; they will not stop a verification code you separately request from Prelude when signing in. You may also email support@afterfive.club.
The weekly email carries an unsubscribe link, and so will every editorial email we send. Unsubscribing never stops messages about an after you applied to.
Read the SMS Program page for messaging details and our general Terms of Service for use of AfterFive.
protecting information
We use administrative, technical, and organizational measures intended to protect information and limit access to people and providers who need it for their work. No online service can promise perfect security, so please tell us promptly if you believe your account or information has been compromised.
contact
Questions, or want a copy of your data? Email us at support@afterfive.club.