Back to Nostalgic

Privacy Policy

Last updated: February 2026

Draft Notice: This privacy policy is a draft pending attorney review. Content may change before launch.

1. Information We Collect

1.1 Planner-Provided Information

Event planners may provide factual information about classmates from publicly available yearbook records, including names, graduation year, clubs, athletics, and yearbook photos. This factual data is not subject to copyright protection under Feist v. Rural Telephone.

1.2 User-Provided Information

When you claim your profile and use the platform, you may voluntarily provide:

  • Current location (city, state)
  • Current photo
  • Social media links (Facebook, Instagram, LinkedIn)
  • Event RSVPs and life updates

1.3 OAuth-Derived Information

When you sign in with Google or Facebook, we receive your email address, display name, and profile photo as authorized by your OAuth consent. We request only basic scopes: openid, email, and profile.

1.4 AI-Generated Content

With your explicit opt-in consent, we may generate age-progressed photos using AI. No biometric data is stored during or after processing — facial analysis is transient only and immediately discarded.

2. How We Use Your Information

Your information is used exclusively for reunion planning and classmate reconnection:

  • Displaying your profile to verified classmates
  • Enabling event RSVPs and communication
  • Your class's owner and planners can see your email address so they can contact you about the class (as can those of a class you ask to join); other classmates cannot
  • Showing your location on the classmate map (with your consent)
  • Content moderation to maintain a safe environment

2.1 What We Never Do

Your data is never used for:

  • Advertising or marketing by third parties
  • Sale to data brokers or any third party
  • Background checks or employment screening
  • Law enforcement purposes (absent valid legal process)

3. Per-Field Visibility Controls

After claiming your profile, you control the visibility of each field individually. You can set each piece of information to be visible to "everyone" (all verified class members), "connections only," or "only me."

4. Data Retention

Data TypeRetention Period
Active account dataDuration of account + 30 days
Unclaimed profile stubs2 years post-event, then archived
AI-generated photosUntil user deletes or withdraws consent
AI facial embeddingsImmediately deleted after processing
Server logs90 days (auto rotation)
Backup data30 days after primary deletion

5. Data Deletion & Portability

You may request deletion of your data at any time. Our deletion process:

  1. 7-day cooling-off period (you may cancel during this time)
  2. Primary deletion within 30 days of confirmation
  3. Backup purge within 30 days after primary deletion
  4. Maximum total: 67 days from request to full purge

You may also request a data export (ZIP archive containing your data in JSON format plus original images), prepared within 72 hours with a download link valid for 7 days.

6. Third-Party Services

We use the following third-party services to operate the platform:

  • Supabase — Database, authentication, and file storage
  • Vercel — Web hosting and deployment
  • Google / Facebook — OAuth authentication
  • OpenAI — Nostalgia content generation
  • Sentry — Error monitoring

7. California Privacy Rights (CCPA/CPRA)

California residents have the right to know what personal information we collect, request deletion, and opt out of the sale or sharing of personal information. We do not sell or share personal information. To exercise your rights, contact us at the email below.

8. Illinois Biometric Information (BIPA)

If you opt in to AI photo aging, facial analysis is performed transiently. No biometric identifiers or biometric information is stored, sold, or shared. You may withdraw consent at any time, which will delete all AI-generated images within 24 hours.

9. Contact

For privacy inquiries, data requests, or concerns, contact us at: [privacy@20years.com]