Joyn
Sign inJoin the waitlist
Join the waitlist
Privacy policyTerms of serviceCompany informationContact↗
Sign inJoin the waitlist

Privacy Policy

Last updated 25 September 2026 · What changed

Contents

  1. Privacy at a glance
  2. 1. Information we collect
  3. 2. How we use your information
  4. 3. AI features and moderation
  5. 4. How your information is shared
  6. 5. Cookies and data on your browser
  7. 6. How long we keep information
  8. 7. Your choices and rights
  9. 8. Security
  10. 9. Children
  11. 10. International data transfers
  12. 11. Changes to this policy
  13. 12. Contact us

Joyn helps people organize events and stay in touch. This Privacy Policy explains what personal data we use, why we use it, who receives it, how long we keep it, and the choices you have.

This policy covers the Joyn iOS app, its App Clip, and joynevents.com. Joyn is operated by Joyn Events AS. In this policy, Joyn, we, and us refer to that company.

Privacy at a glance

  • We use personal data to run the features described below: your account, your events, messaging, safety, the website, notifications, calendar, and AI.
  • We do not sell personal data, show ads, build marketing profiles, or use third-party analytics or tracking software. We do keep two small counts, of active days and invite joins, described in section 1.
  • Content is shared with the people you choose and with the service providers needed to run Joyn.
  • When you delete something, Joyn removes it and queues its private files for permanent deletion. We keep no copy for you to restore later, apart from the narrow legal and safety cases described below.
  • Joyn is not an end-to-end encrypted messenger. Messages are stored on our servers and on your device so they can sync and support the features you use, including AI features when those are triggered.
  • When you ask, an AI feature can reach outside Joyn on your behalf: it can read a page on the open web, or read a window of your Apple Calendar if you have turned that on. Section 3 describes both.

1. Information we collect

We collect information you provide, information created when you use Joyn, and limited technical information needed to operate and secure the service.

Account and profile

When you create an account, we process your email address and sign-in information. If you use Sign in with Apple, we may receive the name and email address Apple makes available. Your Joyn profile can include your full name, username, avatar, time zone, locale, notification settings, and the assistant you chose.

Joyn checks that you meet its 16+ requirement before you sign up, and once more for an existing account that has no current eligibility decision on file. On iOS, Apple can share only a coarse age range around that threshold, never your date of birth. If that range is unavailable, or you would rather not share it, you can enter a birth date instead and our server uses it once to work out the answer. We keep neither the birth date nor Apple's range. We keep only the minimum age applied, how the check was made, the policy version, and when it finished. Where Apple supplied a qualifying range, we also keep the opaque identifier Apple gives the app, so Apple can tell us if the consent behind your account is later withdrawn; a confirmed withdrawal restricts the account and clears its eligibility decision straight away. None of this appears in your profile, in analytics, or in operator reports.

If you subscribe to Joyn Plus, we store what Apple tells us about it: which product you bought, its original transaction identifier, its status, whether it came from Apple's test environment or the live App Store, and when it expires. We need that to give you Plus and to check it is still valid. Apple handles the payment itself, so Joyn never sees your card or bank-account number.

If you buy Joyn Plus on the website, we store what Stripe tells us about it: the identifiers Stripe gives the subscription, the customer, and the price, which plan it is, its status, the amount and currency, and when the paid period ends. We need that to give you Plus, to show and manage your subscription, and to keep the accounting records the law requires. On joynevents.com, Joyn Plus is sold through Link (Sold through Link, LLC, part of Stripe), which takes your payment, charges any tax on our behalf, and sends your receipts. For the payment itself, Link is an independent controller: it decides for itself how it handles your payment details, under its own privacy policy. You give your card or wallet details to Link, never to Joyn. If you use the public Cancel contracts here page, we use the email address you enter only to find your account and to send the confirmation.

Messages, events, and connections

We process what you create in Joyn: messages, photos, videos you choose to share, GIFs, stickers, reactions, mentions, replies, delivery and read status, event details, locations, dates and times, RSVPs, polls and votes, posts, comments, tasks, and event media.

We also process who you are connected to in Joyn: friends, friend requests, groups, and invites, along with blocks, reports, and moderation records. Other people can tell us something about you too, when they invite or mention you, include you in something shared, or report an interaction. Joyn does not read the contacts or address book stored on your device.

We process searches you run in Joyn, including GIF and sticker searches and searches you ask the assistant to run. A search can also stay in place as part of the message, assistant conversation, or other content you made it in.

When a message contains a web link, Joyn may fetch its title and image so the message can show a preview. That fetch always happens on our own servers, in every app and browser: the page, the preview image, and the site icon all come through Joyn. So a link someone sends you never reveals your IP address or your device to the site it points at, and opening a conversation contacts nobody on your behalf.

Location, photos, camera, microphone, and calendar

If you allow location access, Joyn can use where you are to suggest a nearby address through Apple Maps. A location you add to an event can include both its text and its coordinates. Joyn does not collect your location continuously, in the background, or live.

Joyn uses the camera, the microphone, photos or videos you pick, and your calendar only when you use a feature that needs them and you have granted the matching iOS permission. The microphone does one job: recording sound with a video you choose to record in Joyn. Joyn records audio at no other time, and never asks for access to your contacts, your health data, or tracking.

Calendar access works in both directions, and the two are not the same. Writing needs only the iOS permission: calendar sync can add, update, and remove Joyn events in Apple Calendar for events you host or answer Going or Maybe to.

Reading takes a second, separate yes. The iOS permission alone does not let your private assistant read your Apple Calendar: you also have to turn it on in Joyn, under Profile, and it stays off until you do. If you ask about your schedule while it is off, the assistant can offer to turn it on, and you choose Allow once, Always allow, or Never. Allow once reads your calendar for that one conversation and saves no permission at all. Never is final: the assistant will not ask again, though you can still turn it on yourself later. It only ever makes that offer once.

When it does read, it sees only a narrow window of your calendar: at most 96 entries, and about two weeks either side of today unless you named other dates. Each entry carries its title, its start and end, whether it runs all day, a location, and whether you are free or busy, and nothing else. Joyn does not receive your calendar notes, or the name of the calendar an entry sits on, and stores none of it; the window exists for that one answer. Turning Calendar off in iOS Settings, or turning off the setting in Profile, stops the reading.

Feedback you send us

If you send feedback from Profile, we store the category you chose, what you wrote, any screenshots you attached, and basic context about the app: app version and build, device model, iOS version, app language, and time zone. Feedback is linked to your account so we can reply, give your request a reference, and send you an acknowledgement by email. A screenshot captures whatever was on your screen at the time, including other people's messages, so attach one only when you are happy for us to see it. Feedback and its screenshots are deleted with your account.

Device, website, and waitlist data

We process a device identifier for push notifications, along with your time zone and locale. On signed-in devices, Joyn also sends us a small amount of reliability data, so we can find crashes, freezes, unexpected quits, launch problems, slowdowns, and errors the app showed you. That data can include when the problem happened and what kind it was, the app version and build, the iOS version, the device model, a random session identifier, a standardized error code, and a short trace of where in the code it happened.

These reports are built not to carry your Joyn account ID, email address, messages, events, profile content, location, advertising identifier, or any lasting device identifier. Joyn does keep a separate record tied to your account for up to two hours, used only to cap how much gets uploaded, and it is never joined to the reports themselves.

When you use the website, our hosting and backend providers receive the usual request details: your IP address, information about your browser or device, the page you asked for, and the date and time. If you join the waitlist, we store your email address, the date you agreed to hear from us, and the version of the wording you agreed to.

Joyn uses no advertising, no tracking identifiers, and no third-party analytics or crash-reporting software. The reliability data described above is our own, and we use it only to run, secure, and improve the app.

Measuring whether Joyn is working

To understand whether people actually use Joyn, and whether invites bring friends in, we record two deliberately small things. The first is that your account was active on a given day: one record per account per day, with no time of day, no screen, and no device details. The second is that an invite link worked, meaning someone used it to join an event or connect as friends, which records who invited whom.

That is the whole of it. We do not record which screens you visit, what you tap, how long you look at something, or which features you use. There is no third-party analytics service, no advertising, and no profile built about you. The two records are used only in aggregate, to answer questions such as how many people used Joyn last week, or how many joined through an invite.

Both are deleted when you delete your account. If you invited someone, the record that their join happened remains, but the reference to you is removed from it.

2. How we use your information

We use personal data to:

  • Create, secure, and support your account.
  • Deliver messages, events, media, notifications, and the other features you use.
  • Run AI features and content moderation as described in section 3.
  • Prepare and send a restaurant booking request after you have reviewed it, as described in section 4.
  • Answer the feedback and support requests you send us.
  • Keep Joyn reliable, prevent abuse, respond to reports, and enforce our terms.
  • Measure, in aggregate, whether Joyn is being used and whether invites work, as described in section 1.
  • Respond to you and comply with legal obligations.

We do not use personal data for advertising or marketing profiles.

Legal bases for EEA, UK, and Swiss users

Each purpose below names the data it uses and the legal basis we rely on.

  • Creating and running your account — email address, sign-in information, profile, and the content and events you create. Basis: performance of our contract with you.
  • Delivering messages, events, media, and notifications — content, connections, and your push device identifier. Basis: performance of our contract.
  • Joyn Plus — what Apple or Stripe tells us about your subscription, described in section 1. Basis: performance of our contract, and legal obligations for the accounting records of payments made on the website.
  • Optional device features — location, camera, microphone, photos, and calendar. Basis: your consent, given when you grant the iOS permission and withdrawable in iOS Settings.
  • AI features — your request and the Joyn context needed to answer it, as described in section 3. Basis: performance of our contract for the assistant you chose to use, and our legitimate interest in offering a planning assistant that works, for the parts that run as a built-in feature, such as the Home brief and event suggestions in chats.
  • Assistant memory — your assistant conversations and your own Joyn activity, used to build the summaries and profile in section 3. Basis: your consent, given by leaving Personal memory on and withdrawn by turning it off.
  • Restaurant bookings — the name, email, phone, party size, and notes you review before sending. Basis: taking steps at your request before a booking. Where your notes contain health information such as an allergy or an accessibility need, we rely on your explicit consent, given by typing it and confirming the request.
  • Safety, moderation, and abuse prevention — reported content, blocks, moderation records, and AI event logs. Basis: our legitimate interest in protecting members and in keeping Joyn usable, and legal obligations where they apply.
  • Keeping Joyn reliable — reliability diagnostics, rate-limit records, and error reports. Basis: our legitimate interest in a service that works and is not abused.
  • Measuring whether Joyn is used — the active-day and invite-join records in section 1. Basis: our legitimate interest in knowing whether the product works, which is why the measurement is deliberately this small.
  • Feedback and support — what you send us and the app context attached to it. Basis: taking steps at your request, and our legitimate interest in answering and in fixing what you report.
  • Waitlist updates — your email address. Basis: your consent, withdrawable by unsubscribing.
  • Legal claims and compliance — whatever a specific obligation or claim requires. Basis: legal obligations and our legitimate interest in establishing or defending legal claims.

Where we rely on a legitimate interest, we have weighed it against your rights and use the least data that achieves it. You can withdraw consent at any time without affecting earlier lawful processing, and you can object to anything we base on a legitimate interest; see section 7.

Two things are needed to have a Joyn account at all: an email address and a profile name. Everything else is optional. If you skip it, or decline a device permission, the feature that needed it may not work, but we keep the rest of Joyn available to you wherever we can.

3. AI features and moderation

When AI uses your content

Joyn uses OpenAI to power a private assistant, private help from inside a chat, assistants in group conversations, and the assistant-written brief on Home. They can help you organize an event, summarize what happened, search the Joyn information you already have access to, draft something, and propose actions for you to review. When you ask, they can also read pages on the open web.

When an AI feature runs, Joyn sends OpenAI the request and the context needed to answer it. Depending on the feature, this may include:

  • Your request, recent assistant history, and relevant messages from conversations the feature is allowed to read.
  • Participant names, time zone, locale, and relevant events, RSVPs, polls, friends, or messages.
  • For your private assistant, what it has worked out about you: saved memories, summaries of your earlier assistant conversations, and the profile described under "What the assistant remembers" below. A conversation assistant gets that conversation's shared notes instead, never your personal ones.
  • For the Home brief, short titles and snippets from recent event changes and relevant unread messages.
  • For a request about your schedule, and only if you have turned on Apple Calendar reading, the calendar window described in section 1.
  • When you ask for something Joyn has to look up, your search wording and the text of the pages Joyn reads for it.
  • When you ask about a restaurant booking, the details of the request you are reviewing.

OpenAI says that what goes through its API is not used to train its models by default. We also configure our requests so that nothing is stored for product use, though OpenAI may hold abuse-monitoring logs for up to 30 days unless a different retention setting applies. See OpenAI's API data controls for details.

For safety and abuse prevention, Joyn keeps its own log of AI activity. It records which assistant ran and where, but never your message or the assistant's reply. We delete it after 30 days.

Reading the open web

Some questions cannot be answered from inside Joyn: when a film is showing, or whether a restaurant has a table. When you ask one, Joyn first asks OpenAI which pages to look at. Your own wording goes into that search, so a request phrased around something personal is searched in those words; keep it general if you would rather. Joyn then opens the pages itself and reads them.

Joyn reads a page either by fetching it directly or, when the page only reveals its content after running its own code, by opening it in a browser Joyn runs at Cloudflare. Either way the request comes from Joyn's servers, not from your device: the site sees Joyn, not your IP address, and Joyn signs in to nothing and carries none of your accounts. The browser opens for that one page and closes afterwards. Joyn sends the address and, where it matters, the words on a button to press; what comes back is the page's text, which goes to the model so it can answer you and cite what it read.

This is ordinary reading of public pages. Joyn never uses it to reach anything behind a login, and if a page answers with a bot challenge, Joyn stops there rather than treating that as content.

Event suggestions in chats

In group chats and one-to-one chats, Joyn can notice an event taking shape ("beers tonight, anyone?") and pin it as a suggestion so everyone in the chat can see who's in. To do that, Joyn periodically sends a short run of recent messages from that chat to OpenAI, which looks for event-shaped messages and pulls out a title, a time, and a place. Since September 7, 2026 each scan also includes the titles of upcoming Joyn events that every member of the chat is already invited to, so you are not offered an event you already have. An event that even one member is not invited to is never included. The scan does not run in an event's own chat. Until August 3, 2026 it ran in group chats only.

  • No names are sent: senders are replaced with neutral placeholders first, and any result that would echo a placeholder back is discarded.
  • What comes back is limited to event fields: title, time, place, and who expressed interest. No AI-written text is added to your conversation.
  • Each chat is scanned only a limited number of times a day, and a suggestion expires on its own if the event doesn't happen.
  • Any member can turn event suggestions off for a chat in the chat's settings, which also removes its active suggestions for everyone. You can also hide an individual suggestion just for yourself.

What the assistant remembers

Your private assistant remembers in three ways, all of them private to you and all shown on the memory screen in the app.

  • Saved memories. Short facts the assistant keeps because they make future help more relevant. You can view, edit, or delete each one.
  • Conversation summaries. When one of your assistant conversations has been idle for a while, Joyn writes a short summary of it: a title, what it was about, the people and places named, what was decided or dropped, and what is still open. These are what the assistant searches when you ask it about something you discussed before, and what the history list shows.
  • A profile of how you plan. At most once a day, Joyn reworks those summaries together with your own Joyn activity into a short description of you, in six sections: about you, people, places, how you plan, preferences, and loose ends. The activity half is a pattern across what you have hosted, accepted, and declined, not a record of any single event, and lines drawn from activity are marked so the assistant never repeats one back to you as something you said. Each line is a sentence at most, and names the conversations or events it rests on.

All three are yours alone. They are never given to an assistant replying in a group chat, never shown to anyone else, and never used to advertise to you or to train anyone's model. You can remove a single profile line, which also stops it from being written again, or clear everything from the memory screen. Turning off Personal memory in settings stops all three: no new summaries, no new profile, and none of it added to a request. A conversation started as private help from a chat is summarized for your own history, but never feeds the profile, because its content came from a shared conversation.

Shared notes and AI controls

A conversation assistant can use shared notes belonging to that conversation. These are separate from your personal memories and visible to everyone in the conversation. You can manage the notes you create, and the conversation owner may have further controls.

Whether you use the private assistant, and whether you add or trigger a conversation assistant, is up to you. Messages you have shared can still be processed when someone else asks for private help about content they can already see, or when a conversation assistant replies. The Home brief is generated when you open or refresh Home, and it has no separate off switch today.

Anything that would change your Joyn data, such as sending a message or editing an event, is shown to you for review wherever the feature supports it. A conversation assistant does post its own reply when triggered.

Reports and automated moderation

When something is reported, we send the reported item and the report itself, not the wider conversation, to OpenAI's moderation tools, which help us judge whether it breaks our rules. A clear and serious violation can be hidden automatically. Anything unclear or higher-stakes goes to a person, and an automatic hide can be undone. Suspected illegal content is handled separately and is never sent to these AI tools.

We keep a protected record of moderation decisions and their reasons. If an automated decision hides your content or affects your account, you can ask for human review by replying to the notice or contacting us.

4. How your information is shared

With other people in Joyn

Messages, media, posts, RSVPs, votes, tasks, and event details are visible to the members of that conversation or event. Your name, username, and avatar can also appear in search, invites, friend lists, conversations, and events.

With service providers

We use a small number of providers to run Joyn:

  • **Supabase** handles sign-in, database hosting, private file storage, syncing, and server functions, and stores most of your Joyn account and content.
  • **OpenAI** provides the AI and moderation services described in section 3.
  • **Apple** provides Declared Age Range, Sign in with Apple, push notifications, App Store distribution, and place search in Maps. A notification preview can include a name, an excerpt of a message, or an event title.
  • **Cloudflare** runs the browser Joyn uses when a page only reveals its content after running its own code, serves Joyn's DNS, and keeps a backup copy of the photos, videos, and other files shared in Joyn. For a page it opens, it receives only the address. The backup copy is stored in the EU and is used only to restore files that are lost from Supabase.
  • **Klipy** provides GIF and sticker search and receives the search terms you submit.
  • **Resend** delivers some of our account and notification emails.
  • **Vercel** hosts Joyn's website and processes web requests.
  • **Stripe** runs the checkout on the website and tells Joyn the state of a Joyn Plus subscription bought there. For the payment itself, Link, Stripe's payment service, acts as an independent controller rather than on our instructions.

Where a provider handles personal data for us, we require it by contract to follow our instructions and protect that data.

When you ask Joyn to book a restaurant

Joyn never sends anything to a restaurant without first showing you exactly what it is about to send. What it can offer depends on how that restaurant takes bookings. In every case the restaurant, and any booking service it uses, becomes an independent controller of what you send: it decides what happens to it under its own privacy policy, which Joyn neither controls nor answers for.

  • Open the booking page. Joyn opens the restaurant's own page in the app and you complete the booking there. Joyn records that it handed you over, and nothing about what you filled in.
  • Call. If only a phone number is available, Joyn can start a call that you make yourself.
  • Email the request. If the restaurant takes requests by email, Joyn sends the request you reviewed, and the restaurant replies to you directly.
  • No channel found. Joyn says so plainly and offers you the restaurant's own page rather than guessing.

Joyn never fills in or submits a restaurant's booking form for you. Whichever channel you use, the booking is completed by you, by the restaurant, or not at all, and Joyn never enters payment details anywhere.

Notes you add can carry health or other sensitive information, such as an allergy, an accessibility need, or a dietary requirement, so include only what you want the restaurant to receive. When no channel can deliver them, the contact and notes fields are not shown at all. And a request that has been sent is not a table: Joyn treats it as confirmed only when the restaurant says so.

If Joyn is sold or reorganized

If Joyn Events AS is acquired, merges, or transfers part of its business, personal data can pass to the acquirer as part of that transaction. We would tell you before your data became subject to a different privacy policy, and the rights in section 7 would continue to apply until then.

For legal or safety reasons

We may disclose information where it is reasonably necessary to comply with the law, answer a lawful request, enforce our terms, or protect Joyn, the people who use it, or the public.

We do not sell personal data or share it with advertisers.

5. Cookies and data on your browser

The website uses necessary cookies and browser storage to keep you signed in, remember your privacy choices for up to 6 months, show event times in your own time zone for up to 1 year, hand an invite to your account for up to 7 days, and complete Sign in with Apple for up to 10 minutes. With your permission, Joyn also stores today's date in your browser and records one active day against your account, which is how we understand whether Joyn is used without recording which screens you visit or what you tap. The necessary storage is handled by Joyn and by Supabase on Joyn's behalf; the optional measurement storage is handled by Joyn alone. We use no advertising cookies, and no third-party analytics or tracking cookies.

When you are signed in, chat keeps conversation snapshots, drafts, unsent messages, and unsent images in your browser so messaging stays quick. Post drafts and link-preview details can be stored there too, and saved link previews expire after 7 days. All of it stays in that browser until Joyn replaces or clears it, you remove the content it belongs to, or you clear the browser's data.

To keep the waitlist from being abused, Joyn turns the incoming IP address into a one-way value that cannot be turned back, and uses it only to limit how often a request can be made. The address itself is never stored in Joyn's database, and the record is deleted after 24 hours.

6. How long we keep information

Most of your account and content stays while your account is active, unless you delete it sooner. Deletion is the default: there is no waiting period, and no copy kept for you to restore later. A shared event or conversation can carry on for the other people in it, but that is not a reason for Joyn to keep a deleted message, its media, or a departing account simply because they were shared.

  • Deleting a message takes its content out of Joyn and clears its text, media, GIF and mention data, search data, metadata, edit history, reactions, read receipts, polls, pending AI work, Home-brief source copy, and pending notification copy from the live database. What can remain is an empty marker holding just enough structure for replies and message order to still make sense. Deleting the account removes the departing member's messages outright instead.
  • Deleted message media, event photos, assistant images, and replaced covers and avatars go into a deletion queue on our servers. Joyn normally works through it within minutes, and retries anything that fails without needing your device. Finished queue entries are removed after 7 days, and hold file identifiers and status, never the deleted file itself.
  • AI event logs, Home briefs, and the recent-change records used to create those briefs are deleted after 30 days. Temporary AI queue records are cleared within a day.
  • Saved memories, assistant conversation summaries, and your assistant profile remain while your account is active, because remembering across time is the whole point of them. You can delete any of them in the app whenever you like, and all of them go with your account. Deleting an assistant conversation removes it from what is summarized and searched.
  • A booking record keeps which channel was used, what was sent, and how it ended, so you can see your own booking history and we can look into a request that went wrong. It is deleted with your account. What the restaurant received stays with the restaurant under its own policy, so deleting your Joyn account does not cancel a booking or remove it from their records; contact the restaurant to cancel.
  • Pages Joyn reads for you on the open web are not kept as a browsing record, and the browser is closed when the read ends. What remains is the assistant's answer in your conversation, which you can delete.
  • Feedback you send, with its screenshots and app context, remains while your account is active so we can keep answering it, and is deleted with your account.
  • Reliability reports are deleted after 90 days, and the separate account-linked upload limit record after two hours. Because the reports carry no account link, deleting your account removes that limit record but gives us no way to pick out your individual reports; they stay unlinked and expire on their own.
  • An age check completed before the account exists expires after 10 minutes and is deleted within a day, and its rate-limit record after two hours. The eligibility decision itself, and for an Apple-verified account the opaque Apple identifier beside it, stay while the Joyn account is active and are deleted with it. If Apple reports that consent was withdrawn, Joyn marks that identifier revoked and deletes the eligibility decision at once. The birth date you submitted, and Apple's age range, are never kept.
  • The active-day and invite-join records described in section 1 remain while your account is active, because measuring whether people come back requires knowing what happened before. They are deleted with your account. If you invited someone, the record that their join happened remains, with the reference to you removed.
  • After you delete your Joyn account, the only App Store purchase data Joyn keeps is a record with your identity stripped from it, needed to settle renewals, expirations, refunds, and a subscription you bought directly and later want back. On its own it cannot restore your profile or give anyone Plus. If you do recover the subscription onto a new Joyn account, Joyn checks the purchase with Apple before attaching it. A record nobody recovers is deleted once both the account deletion and the subscription's expiry are at least 180 days old. You can manage or cancel the subscription through Apple at any time.
  • A Joyn Plus subscription bought on the website is cancelled when you delete your Joyn account, and Joyn's record of it is deleted with the account. The accounting records of the payments stay for five years, because Norwegian bookkeeping law requires it. Stripe and Link keep their own payment records under their own policies.
  • Waitlist emails stay until you unsubscribe, or until we stop sending launch updates. After you unsubscribe we may keep a minimal record of that, for the sole purpose of not emailing you again.
  • Browser and waitlist rate-limit periods are described in section 5.

We keep limited information beyond all this only where the law, a live legal claim, or the investigation and prevention of serious abuse requires it. We hold it apart from ordinary product use, restrict who can reach it, and keep checking whether we still need it. We do not hold on to deleted content just because it might be useful later.

Content leaves Joyn the moment the deletion succeeds. The database records go in that same step, and private files are queued and retried until Supabase confirms they are gone. Encrypted backups can still hold an older copy until Supabase's backup window expires; that data is not reachable from Joyn and is held only for disaster recovery, and you can read about Supabase database backups. Photos, videos, and other files also have a backup copy at Cloudflare, which is used only to restore lost files. When a file is deleted in Joyn, or an account is deleted, its backup copy is removed within an hour. A file removed by Joyn's own cleanup keeps its backup copy for up to eight days, so a mistaken removal can be undone. Copies someone else saved outside Joyn, and data on their device or in their browser, are beyond our reach and are not deleted.

7. Your choices and rights

Delete your account

In the iOS app, go to Profile → Edit profile → Delete account. Joyn deletes every private file the account owns first, and checks that none are left, then deletes the account, your profile, your messages, your notification tokens, the private age-eligibility decision and its rate-limit record, your personal AI history, saved memories, conversation summaries and assistant profile, booking records, feedback and its screenshots, and everything else tied only to you. If you host an event with a co-host, Joyn hands the event to the longest-standing co-host so it can carry on; an event with no other host is deleted. Shared conversations stay available to the people still in them, with the creator role passed on, but your account and your messages are removed. Only a narrowly necessary legal or serious-safety record may be kept, as described in section 6. If you signed in with Apple, Joyn also asks Apple to revoke that sign-in; your deletion goes ahead whether or not Apple accepts, so if it does not, Joyn may stay listed under Settings → your name → Sign in with Apple until you remove it there.

Access, correction, deletion, and portability

Depending on where you live, you may have the right to see your personal data, correct it, delete it, or receive a machine-readable copy; to withdraw consent; and to object to or restrict certain processing, including anything we base on a legitimate interest. You can change much of it directly in Joyn, and delete your account yourself as described above. For anything else, email privacy@joynevents.com.

We answer within one month. If a request is complex or you have made several, we may extend that by up to two further months and will tell you why within the first month. We do not charge for a request or discriminate against you for making one.

You can also complain to a supervisory authority. In Norway or elsewhere in the EEA, that is your local authority or Datatilsynet, the Norwegian Data Protection Authority, which is ours. In the United Kingdom it is the Information Commissioner's Office, and in Switzerland the Federal Data Protection and Information Commissioner. We would rather you came to us first, but you do not have to.

Decisions made automatically

Automation decides two things in Joyn, and neither is left to run unchecked. Moderation: a clear and serious violation can hide content automatically, as described in section 3. Suspending or banning an account is never automatic; a person decides it. Age eligibility: if Apple tells us the age consent behind your account was withdrawn, Joyn restricts the account automatically, because continuing to serve it would be the greater wrong. In both cases you can ask for a person to look at it by replying to the notice or emailing privacy@joynevents.com, and both can be reversed. Apart from these, we make no decision about you by automated means alone that produces a legal effect or similarly significantly affects you. The assistant's profile described in section 3 shapes only how the assistant talks to you: it gates nothing and changes nothing you are charged.

If you live in the United States

Several US states give their residents privacy rights. Rather than work out which of them reaches a company of Joyn's size in any given year, we give everyone the same answers and honor the same requests wherever you live.

  • We do not sell your personal data, in the sense those laws give the word, and never have. No part of Joyn's income comes from passing your data to anyone.
  • We do not share it for cross-context behavioral advertising. Joyn has no advertising of any kind, so there is no opt-out to offer and nothing for a browser's opt-out signal to turn off.
  • Sensitive personal information — precise location, and the health or accessibility details you may put in a booking note — is used only to provide the feature you asked for, never to infer characteristics about you and never for advertising. There is no secondary use to limit.
  • We do not profile you to make decisions that produce legal or similarly significant effects; see the two exceptions under "Decisions made automatically" above.
  • Your rights to know, access, correct, delete, and obtain a portable copy are set out above and apply to you. We charge nothing, and using them changes nothing about your account or your price.

You can make a request yourself or through an authorized agent with written permission we can verify. We verify a request against the account it concerns; if we cannot confirm that it is yours, we will tell you why rather than act on it. If we refuse a request, you can ask us to reconsider by replying to our answer, and we will respond to that appeal in writing.

8. Security

We protect personal data with encryption in transit, access controls that keep each account to the data it is allowed, private file storage, and credentials held in the platform's own secure storage. No way of sending or storing data is perfectly secure, but we review and strengthen these protections as Joyn develops.

9. Children

Joyn is not intended for anyone under 16, and we do not offer a parental-consent route for account registration below that age. If the law where you live requires a higher minimum age, you must meet that requirement before using Joyn.

We do not knowingly collect personal data from anyone below the applicable minimum age. If you believe a child has given us personal data, contact privacy@joynevents.com and we will take appropriate steps to remove it.

10. International data transfers

Joyn is operated from Norway, and most of your data stays in Europe. Your account, messages, events, and private files are stored by Supabase in Ireland, a backup copy of those files is kept by Cloudflare in the EU, and the website runs from Vercel's Dublin region. Norway is covered by the EEA agreement, so this is not a transfer out of the EEA at all.

Four things do leave. AI requests go to OpenAI in the United States, as described in section 3. Some notification and account emails go through Resend, also in the United States. A page Joyn reads for you runs in a browser at Cloudflare, whose network is global, so that request is handled wherever Cloudflare places it. And a Joyn Plus purchase on the website is handled by Stripe, which can process the subscription details in the United States. Separately, Apple handles sign-in, the age range, push notifications, and place search under its own policy, and Link handles the payment under its own.

For transfers to countries without an EU adequacy decision, we rely on the European Commission's standard contractual clauses together with the provider's own safeguards. Those countries may give you fewer rights against public authorities than Norway does, and no contract fully removes that difference; we tell you so rather than implying otherwise. Email privacy@joynevents.com if you want the specific safeguard for a specific flow.

11. Changes to this policy

We may update this policy as Joyn changes. We will revise the date at the top and provide a more prominent notice when a change is significant. If a change requires new consent, we will ask for it.

12. Contact us

Joyn's data controller is Joyn Events AS. Organisation number: 938 238 294. Organisation form: Aksjeselskap (AS). Register: Foretaksregisteret. Registered business address: Fossen 20, 1530 Moss, Norway.

For privacy questions or requests, email Joyn Events AS at privacy@joynevents.com. Current company details are also available on the Company information page.

Joyn

The best moments are the ones you share.

Joyn

  • Sign in
  • Join the waitlist
  • Contact↗

Legal

  • Privacy policy
  • Terms of service
  • Company information
  • Cancel contracts here

© 2026 Joyn Events AS