Privacy

Draft — pending legal review.

Last updated September 1, 2026. This is a plain-language description of what Lately actually does during this test, written by the person building it, not a lawyer. Where something genuinely needs a lawyer's judgment rather than mine, I've marked it "needs counsel" instead of guessing. This page will be replaced with a reviewed version before this goes beyond a closed friend test.

What this is

Lately is a small, invite-only prototype being tested for six weeks with a closed group of friends. This page explains what data it collects, why, where it lives, who else can see it, and what happens to it — including if you leave.

Who's behind this

Lately is operated by an individual based in Canada. Every Phase 0 participant is based in the US, and the data itself is stored in the US (see "Where your data lives," below) — so this isn't a case of your data crossing a border to get here. Needs counsel: whether a Canadian operator running a US-only test creates any obligation under Canadian privacy law even when no data or participant is in Canada. Not resolved here.

The waitlist on latelylist.com

The public website has a form where anyone can ask to be told when Lately opens. This is the one part of this page that applies to people who aren't participants.

If you submit your email address there, we store that address and the date you submitted it. It is used for one thing: to tell you if and when Lately opens to new people. It is never sold, never shared with anyone outside the services listed under "Who else sees your data," below, and never used for anything else.

It's stored in the same Supabase database as the rest of the app, in AWS's us-east-1 region, in a table separate from any participant account. Submitting it does not create an account, does not put you in the test, and does not connect you to anyone.

You can have it removed at any time by emailing privacy@latelylist.com. If Lately never opens, or the project stops, the list is deleted rather than kept.

The website sets no cookies and carries no advertising tool of any kind. It does use Vercel Web Analytics, which counts pageviews so we can see how many people are finding the site. It's cookieless and doesn't build a profile of you, but it is an analytics tool and we're not going to pretend otherwise. The app itself — everything behind the sign-in — has no analytics tool at all.

Beyond that, the site loads nothing from any third party — no fonts, no scripts, no embedded content from anywhere else. Vercel's analytics is the only outside code running on this page, and the fonts are served from our own domain.

Separately, and not something we opted into: because the site is hosted by Vercel, Vercel's own infrastructure logs each request, including your IP address and the city and country it implies. That happens for every site they host. We don't use those logs to analyse visitors, and their retention is short. Vercel's privacy notice covers what they do with it.

What we collect, and why

Your profile

  • Name — shown to friends you're connected with, so they know whose routine or reply they're looking at.
  • Cluster (a rough group like "uni," "work," or "hometown") — used only to compare patterns across groups of participants, never shown on your profile.
  • City or metro area, if you choose to enter one — entirely optional and self-reported. We never derive your location from your IP address, GPS, or any browser location permission — Lately never asks for that permission at all, and nothing in your profile or on your list comes from an IP address. (Our host does log one at the infrastructure layer; see "Who else sees your data," below.) Never shown to other people in the test; it only ever feeds grouped, aggregate views, and only once enough people share it that no individual can be picked out.
  • Age cohort (a range like "26–30") — collected once, right after you sign up, and never editable afterward. It is never displayed to anyone, including you — not on your profile, not in your own account settings. It exists purely to let us compare patterns across age ranges in aggregate, subject to the same can't-pick-out-an-individual threshold as everything else described here.
  • Birthday, if you choose to add one — day and month only, never a year. Shown to your friends (so we can tell you when a friend's birthday is coming up), editable any time, unlike age cohort.
  • A scattered/local research classification — a flag recording whether you live near the majority of the friend group you were invited alongside, set by hand by the person running the test at the moment you were invited, based on where you told us you live and when you last saw that group in person. It is never displayed to anyone, including you, and is never changed afterward regardless of whether you move. It exists to let us compare how a geographically close-knit friend group behaves against a spread-out one — that comparison is a core part of what this test is trying to learn.

There is no email field on your profile. Your email address is held by our login system (Supabase, which also handles authentication for us) and passed to Resend, which sends the actual sign-in email — see "Who else sees your data," below, for both. It is never used to market anything to you, never shared or sold, never copied onto your visible profile, and never connected to the website waitlist described above. One thing worth knowing: when you sign up, your name, the invite code you entered, and your discoverability choice (below) are temporarily attached to that same login record before being copied into your profile. That copy is never actively cleared afterward — it sits there, unused, for as long as your account exists, and is deleted along with everything else if you delete your account.

What you add

  • Products, prices, and notes you enter — whatever you add to your routine, wishlist, or note field, including any price you choose to log and which category (skincare, food, gear, etc.) you file it under.
  • Your check-in answers — how often you use something, whether you'd buy it again, and whether you still recommend it, at the points the app asks. Also whether and why you retired something, if you choose to say.
  • Whether an item came from a friend's list — if you add something because you saw a friend has it, we record that fact and whose list it came from. We do not record whether you actually paid for it, or how — a gift, something you already meant to buy, or something you never bought at all all look the same to us. This is a deliberate choice, not an oversight: see the exit interviews for how the difference actually gets checked during this test.
  • Routine names, if you create any — a routine is an optional way to group your own items together, and any name you give one (like "Race Day Kit") is free text you choose, not a fixed category label the way slots are. Any friend who can already see your routine sees that name too, the same as everything else in it.
  • A photo you attach to an item, if you choose to add one — entirely optional, prompted once right after you add something you already own. It's stored in a private Supabase Storage bucket in the same us-east-1 region as the rest of your data (see "Where your data lives," below), and it is never public: the app itself is the only thing that can request it, generating a short-lived, expiring link on our own server each time a photo is shown, rather than a permanent public address. Whoever can already see the item — you, and any accepted friend who could see it anyway under the same rules as the rest of your list — can see its photo, through the app, the same way. Deleting the item, or your account, deletes the underlying photo file along with it, not just the reference to it.
    One limitation, stated plainly rather than implied away: the permission that lets the app generate that link is bucket-wide for anyone signed in, not scoped friend-by-friend the way visibility inside the app is. In practice that means any other signed-in participant who somehow already knew or guessed the exact, randomly-assigned file path for a specific photo could independently request a link to it, even if they aren't your friend — the app never hands that path to anyone who isn't already allowed to see the item, but the storage system itself doesn't independently re-check friendship the way the rest of the app does. A tighter, friend-scoped version of this permission is planned for a later phase, not this one.
  • A daily photo, if you choose to post one — at most one per day, meant to be taken in the moment with your device's camera through the app itself, not chosen from your photo library. (If your browser doesn't support opening the camera directly, the app falls back to letting you pick a photo instead — and tells you plainly when that's happening, rather than quietly treating it the same as a real camera shot.) It's stored in its own private Supabase Storage bucket in the same us-east-1 region as everything else. A friend can see it, through the app, only for the calendar day you posted it, measured in your own local time — once that day ends, it disappears from the Feed for everyone but you. You keep every daily photo you've ever posted, indefinitely, in your own archive on your own profile. Nobody else can ever see that archive — only today's photo, and only in the Feed. Deleting your account deletes every daily photo you've posted, the same way it deletes an item photo.
    You can also delete any single daily photo yourself, any time, from your own archive, including the one you posted today — this removes the photo file and its database record completely, not just from what's displayed. Deleting today's own photo does free you to post another one the same day; "at most one per day" describes how many can be visible at once, not a limit on how many times you can capture and delete. Deleting a photo does not remove the plain fact, logged automatically (see "Activity Lately logs automatically," above), that you posted something that day — only the photo itself and the record of what it was. That log entry is aggregated and deleted on its own schedule (see "How long we keep things," below), the same distinction our takedown process draws when a photo is removed following someone else's report.
    Unlike the item-photo limitation above, this one is enforced at the database level, not only by what the app chooses to display: a friend's ability to request a link to one of your daily photos is checked, and denied once that day has passed, by the storage system itself — not just left out of what the app happens to show them. This is a stronger guarantee than item photos currently have.
    One limitation, stated plainly rather than implied away: before a daily photo ever uploads, your own browser strips hidden technical data a camera normally embeds in a photo file — including, notably, exact GPS location — by re-processing the image before it leaves your device, the same way item photos already do. That stripping happens in your browser, though, not on our server, so it depends on going through the app normally rather than being independently re-checked once a file reaches us.

Activity Lately logs automatically

The app keeps a log of certain things you do, timestamped, so the Feed and various counts can work and so we can measure whether the test is doing what it's meant to. This is the most easily overlooked category, so here it is in full — every kind of event Lately can log about you:

  • You added an item, and to which product.
  • You retired an item, and which product.
  • You posted a daily photo, and when.
  • You viewed a specific friend's list — which friend, and when (this is grouped so it's only recorded once per 30 minutes, not on every glance).
  • You clicked a specific product link, on a specific item, on a specific friend's list — which product and whose list, recorded at the moment you click, before you leave the app.
  • You submitted a week-4 "would you buy it again" answer.
  • You submitted an ongoing "do you still recommend this" answer.
  • You dismissed a weekly prompt without adding anything that week (only logged if nothing was added — adding something already counts on its own).

One more category exists in our system's design but isn't currently used by anything — copying a routine wholesale. Nothing in the app writes it today; it's listed here for completeness, not because it's happening.

The social and request features

Friend connections (who requested whom, and when it was accepted), group memberships (which named groups you're in and who invited you), notifications about the above plus replies to things you've asked for, and the asks themselves — a request for a recommendation, sent to one friend or your whole circle, along with any reply someone gives (which always points at a real item on their own list, never free text).

If you block someone: your friendship with them is removed in both directions, and you're both removed from any group you currently share, immediately. A block cannot currently be reversed from within the app. If you want to undo one, contact us (below) and we'll do it by hand.

Separately, a table called nudges records when the person running this test contacts a participant directly about it — which participant, the channel used (a text, in person, a group chat), and a note describing what was said, timestamped. This is the one record in this system that is about you rather than generated by your own activity — written by the person running the test, not by anything you do, and not visible to you. It exists so that engagement measured shortly after a personal nudge can be told apart from engagement nobody prompted. This record is not removed if you delete your account. The row stays; only its link to your profile is cleared.

A few things exist in our database that nothing currently uses

In the interest of not omitting anything: a free-text "bio" field exists on every profile, but no part of the app reads it or lets you write to it today. Three columns that look like they'd store a usage streak also exist, but the streak actually shown to you (see the Feed and your own page) is calculated fresh from your recent activity every time it's displayed — it is not read from or written to those columns, which sit unused. An older check-in table from an earlier version of this feature still exists but nothing reads or writes it anymore. None of this affects what's collected about you in practice; it's listed so this page stays accurate rather than convenient.

Where your data lives

The database is hosted by Supabase in AWS's us-east-1 region (N. Virginia, USA) — this is a fact about our hosting configuration, not an estimate. Every Phase 0 participant is US-based, so your data is stored in the same country you're in; this isn't a cross-border transfer, and we're not describing it as one. The app and the public website are both hosted by Vercel, also a US company. Sign-in emails are sent through Resend, also a US company — the same reasoning applies: no cross-border transfer there either.

Email addresses submitted to the website waitlist are stored in that same US region, regardless of where the person submitting one lives — unlike the test itself, the website is public and anyone can reach it. Needs counsel: whether storing a bare email address from a non-US visitor in the US carries any obligation we haven't accounted for. We're not asserting an answer.

Who else sees your data

  • Supabase — our database and login system.
  • Resend — sends the sign-in link email you receive when you log in. Supabase Auth is configured to route those emails through Resend, from a verified latelylist.com address, rather than through Supabase's own built-in sender; Resend sees your email address for that purpose and nothing else about you. Resend runs entirely server-side — nothing about it loads in your browser, so it doesn't change the "loads nothing from any third party" claim above.
  • Vercel — hosts both the app and the public website. Vercel's own infrastructure logs every request to either, including IP address and the city and country derived from it; that's inherent to their hosting and not something we configure. Vercel also provides the pageview analytics used on the public website, described above. It is not used anywhere inside the app.
  • Open Library, Google Books, and the Apple Podcasts/iTunes directory — when you search for a book or podcast to add, your search text is sent to whichever of these services is relevant. That request is made by our own server on your behalf, not directly from your phone or browser — so these services see our server making the request, not your device or IP address, but they do see the exact text you typed.
  • The merchant, if you tap a "Link" button on a product — you're redirected there through a link of ours first, so we can log that a click happened (see above). Our site sends a minimal referrer to the merchant when you land there — enough for them to tell the click came from Lately generally, not which product, which item, or who you are.

The app itself uses no analytics or advertising tool of any kind — there is no such tool anywhere behind the sign-in. (The public website does use one; see "The waitlist on latelylist.com," above.) The only cookies this app sets are the ones needed to keep you signed in; there is nothing else to consent to, so there's no cookie banner.

Who can see what, inside the app

The core feature of Lately is that friends in your test group can see your routine, your feed activity, and your check-in verdicts — that is the point of the app, and it's how it works for everyone in the group. There is no public profile and no audience: nothing you add is visible to anyone outside the friends you've accepted, and there is no setting that makes any of it public.

A drop (retiring an item) is never shown attributed to you; it only ever shows up as part of an aggregate count, and only once at least 3 people are behind that count. The same floor of at least 2 other people applies to the small "N others/friends have this" line shown on an item — below that, the line simply doesn't appear, so a count is never shown that would point at one specific, identifiable person. Group-level stats work the same way, withheld entirely until a group has at least 5 people who've accepted membership. Your age cohort and your scattered/local classification are never shown to anyone, including you, under any circumstance.

Because this is a test, the person operating it can see all data in the system — every table, every row, including things not shown in the product itself. That access exists to build and debug the prototype, not to monitor anyone individually, but you should know it exists.

How long we keep things

Two different kinds of record exist here, and we treat them differently.

Content you create yourself — your items, notes, prices, check-in answers, asks and replies, and notifications — is something you chose to enter and can see in the app. That stays for as long as your account exists, same as everywhere else on this page. Deleting your account (above) removes your personal records; anything already folded into an anonymous aggregate stat by that point stays in that aggregate form, since it no longer exists as a record about you specifically.

The events log is different. It records things you did that you never chose to generate and never see: that you viewed a specific friend's list, that you clicked a specific product link, that you added an item, that you retired an item, that you posted a daily photo, and the fact that a checkpoint was answered (not what you answered — that's a check-in answer, covered in the paragraph above, not this one). That asymmetry — content you made and can see, versus a log made about you that you never see — is why this record gets a fixed end date instead of an open one.

On December 27, 2026 — 90 days after September 28, 2026, the last day of the six-week Phase 0 test window (August 18 – September 28, 2026) — the row-level detail in the events log (who viewed whose list and when, who clicked what and when, and that a daily photo was posted and when) will be aggregated into per-person and per-cluster summary counts, and the row-level detail itself permanently deleted. This applies to the events log only, not to your check-in answers, asks and replies, or notifications — and, for daily photos specifically, not to the photo itself. The fact that you posted, and when, is a log entry and is included in this purge; the photo file and the record of which day it belongs to are content you created, described above, and this purge never touches them. December 27 is well past the point where the exit interviews and the resulting write-up are expected to be finished, so this doesn't interfere with that work.

Deleting your account, and getting your data

You can delete your account at any time from the You tab. Doing so permanently removes: everything on your routine, wishlist, and dropped list; your check-in and endorsement history; your activity log (views, clicks, adds) and notifications; any asks you've made and replies you've given; your friendships and any pending requests, either direction; anyone you've blocked or been blocked by; and groups you created or belonged to — then your sign-in itself is deleted. Products you added to the shared catalog stay, since a friend's item may still reference them, but nothing about that catalog entry identifies you afterward.

There is currently no built-in way to export a copy of your data before deleting it. If you'd like a copy, or want us to delete your account for you instead of doing it yourself, email us (below) and we'll handle it directly.

If something goes wrong

If we discover a security incident that materially affects your data, we will notify affected users directly. Needs counsel: whether a specific regulator must also be notified depends on which US state each affected participant lives in, and we're not asserting an answer to that here.

US state privacy laws

Roughly twenty US states now have their own comprehensive privacy laws, each with its own thresholds for which businesses they apply to (usually based on number of residents' data processed, or revenue). Needs counsel: whether any of them apply to a thirty-person invite-only prototype. Our own read is that a test this small most likely falls under most states' thresholds — several set a floor in the tens of thousands of residents — but that's a reasoned guess, not a legal conclusion, and we're not asserting it as one.

Product links

Lately earns nothing from any purchase during this test. Outbound product links exist only so we can log that a click happened (see above) and so you can reach the merchant — no affiliate program is connected today. If that ever changes, it will be disclosed on the item itself, before it happens, not only on this page.

Separately, and regardless of whether commission ever exists: nothing in Lately is ranked by what it might earn. Items surface because more of your friends have them and kept them. No brand can pay to appear anywhere in the app, and nobody — participant or otherwise — is paid to be on Lately or to recommend anything on it.

Contact

For deletion requests, a copy of your data, removal from the website waitlist, questions about anything on this page, or to ask us to reverse a block, email privacy@latelylist.com. For anything else — general questions about Lately, or about the project — email hello@latelylist.com. Both addresses are monitored by the person operating the test.

TermsSupport