The fine print

Privacy policy

Last updated July 21, 2026

Lineup records where people go at night, which is exactly why it was built paranoid. This page says precisely what we collect, what we throw away, and what we will never do - with a plain-English summary on every section.

Looking for how-do-I answers instead? Support has them straight.

1. What we collect

Account basics. A phone number or Apple ID for sign-in, a handle you choose, an optional avatar and display name, your campus, and your date of birth (see section 9). Real names are never required. An optional .edu email, if you choose to verify, is used to confirm campus affiliation and nothing else.

Activity you create. Crowd reports, check-ins, “going” marks, rallies, friendships, followed venues, redeemed deals, and photos you post. Each of these has its own visibility rules, described below and in the terms.

Device basics. App version, device model, and crash logs, so we can fix what breaks.

2. Location: used, then discarded

Location is the sensitive one, so here is the exact lifecycle. When you check in or file a report, your precise location is used once, server-side, to verify you are within 150 meters of the venue. Then it is discarded. Precise location points are never stored as a trace, a trail, or a history of coordinates.

What persists is the derived record: you were at venue X between time A and time B. That record lives in your private night history (section 4), and deleting a night deletes it entirely.

Location is never collected when you are outside your campus district, and venue monitoring is suspended entirely between 5am and 4pm. If you opt into arrival detection (“Always” permission), it exists to check you in automatically and prompt you to report - the same use-then-discard rule applies. You can turn it off any time in Settings.

3. Reports are anonymous. Full stop.

Crowd reports are anonymous to everyone: other users, your friends, the venue being reported on, and venue staff. There is no setting that changes this, no premium tier that reveals it, and no venue dashboard view that hints at it. Report anonymity is absolute and non-configurable, because the moment reporters can be identified, honest reporting collapses.

Internally, reports are tied to your account only for integrity purposes - weighting by reliability, rate limiting, and abuse detection. If you delete your account, your reports survive only as anonymized aggregate data.

4. Your night history is yours

Lineup keeps a private history of your nights: venues visited with arrival and departure times, rallies joined, deals redeemed, photos taken. It is visible to exactly one person - you. Friends see, at most, your live check-in tonight and summary stats like streaks and badges, and you can restrict those too.

You can delete individual nights or your entire history in Settings. Deletion removes the derived records entirely; it is not an archive toggle.

5. Friends and contact matching

Friendship on Lineup is mutual and requires acceptance - there is no one-way follow, because an app that knows where people are must not make it easy to watch someone who hasn't agreed to be watched.

If you use contact matching, phone numbers from your address book are hashed on your device and compared server-side. Your raw contacts are never uploaded, stored, or seen by us, and only mutual matches - you have them, they have you - are ever surfaced. Ghost mode hides all your outbound presence with one toggle, and its state is never disclosed to anyone.

6. What we never do

We do not sell your personal data. Not to advertisers, not to data brokers, not to venues, not in aggregate disguises of any of the above.

We do not track drinking. There is no drink counting, drink logging, or consumption tracking of any kind in the product, and no notification will ever name an alcoholic product or encourage you to drink. Lineup is about places and people, never consumption.

We never broadcast any user's live location publicly. Presence is visible to accepted friends only, expires nightly, and can be shut off entirely with ghost mode. Venues see aggregate crowd data only - never individual identities, never who reported.

7. Analytics

We collect product analytics events: things like “Tonight view opened,” “report completed,” “rally link shared,” and install attribution for rally invites. These events tell us which parts of the product work and which don't, and they are analyzed in aggregate.

Analytics events are tied to your account so we can understand usage over time, but they are not sold, not shared with venues in identifiable form, and not used to build advertising profiles. The venue-facing dashboard shows venues aggregate numbers only: views, taps, arrivals attributed, redemptions, and crowd trends.

8. Your controls and your data

Export. Settings → Data → Download my data gives you a machine-readable copy of your account, history, and activity.

Granular deletion. Delete individual nights, your whole night history, or your search history, each independently, in Settings.

Account deletion. Deleting your account is an immediate soft delete with a 30-day recovery window (in case the decision was made at 2am), followed by permanent hard deletion of all personal data. The only survivor is anonymized aggregate report data, which cannot be traced back to you.

Presence controls. Ghost mode, per-audience visibility for check-ins, who can find you by contacts, who can send friend requests - all in Settings → Privacy.

9. Age and date of birth

Your date of birth is entered once at the age gate. It is stored, immutable, and never displayed - not on your profile, not to friends, not to venues, not in any export another user could see. It is used for exactly one thing: deciding whether you see 21+ content (drink specials, cover pricing, reporting) or the under-21 view (hours, addresses, and events only).

The full policy lives at lineup-app.org/age-policy.

10. Changes and contact

When this policy changes in a way that matters, we announce it in the app before it takes effect, and the date at the top of this page moves. We don't do silent edits.

Privacy questions, data requests, or anything this page didn't answer: hello@lineup-app.org.