SideSeat

Privacy

SideSeat helps classmates coordinate around real schedules. We keep contact details private until you choose to exchange them, and we do not sell personal data.

What we collect

  • Contact info — username; optional email and/or phone used for sign-in and account recovery.
  • Profile & academics — nickname, bio, avatar, life photos, and school-related fields you choose to share (for example major, semester, languages, city). School verification uses a school email first; if that is unavailable, you may voluntarily submit a redacted enrollment or graduation document.
  • User content — messages, plans, schedule shares, Discover posts and activities, calendar events you create or import, and reports you submit.
  • Identifiers — account ID; device push token when you allow notifications; session tokens to keep you signed in.
  • Location — only when you explicitly share a location in chat (approximate or precise, depending on what you send). We do not continuously track your location in the background.
  • Diagnostics — crash and performance diagnostics when Sentry is configured for a production build. Default PII transmission is disabled, and we do not use third-party advertising trackers.

How we use it

To operate SideSeat: authentication, classmate discovery within your school, chat, calendar coordination, optional push notifications, student verification, in-app feedback, and (if enabled) optional tips via Apple or Stripe. We use the data to provide the features you request and to keep the community safe (blocks, reports, abuse prevention).

Processors & subprocessors

Depending on which features are enabled on the server, we may use:

  • Hosting & database — application hosting, private object storage, and managed Postgres (for example Vercel and Neon) to run the service.
  • Email — Resend for verification and account-recovery codes.
  • SMS — Twilio (or an equivalent provider) when phone OTP is enabled.
  • AI schedule parsing — Alibaba DashScope / 通义千问 when you use natural-language calendar suggestions; prompt text you submit for that feature is sent to the provider to generate event drafts.
  • On-device recognition — calendar voice transcription runs only when on-device recognition is available, and timetable screenshot text recognition uses Apple Vision on device. Audio and recognition screenshots are not uploaded to our servers for those recognition steps.
  • Sentry — when enabled for production builds, processes crash and performance diagnostics that are not linked to an account.
  • Payments — Stripe for optional web tips; Apple for optional in-app StoreKit tips when that feature is enabled.
  • Push delivery — Apple Push Notification service (APNs) to deliver notifications you opt into on iOS.

These providers process data only to deliver the corresponding feature under our instructions.

Retention

Account and profile data are kept while your account is active. School verification documents are deleted after review, when replaced, or when you delete your account; unreviewed documents are deleted no later than 30 days after upload. We retain only the verification result, school, method, and timestamps. Chat realtime change events are pruned on a short rolling window after delivery; message history follows product retention for conversations you participate in. After you delete your account, we remove personal profile data from active systems, subject to limited legal, security, or backup retention where required.

Cookies & local storage

The web app uses session cookies (and similar storage) to keep you signed in and to remember preferences. The iOS app stores session credentials securely on device (for example Keychain) and may store local preferences such as Discover city. We do not use advertising cookies.

Children

SideSeat is intended for university classmates and is not directed at children under 13. We do not knowingly collect personal information from children under 13. If you believe a child has provided data, contact us and we will delete it.

Your controls

You can edit profile and privacy settings, block users, report content, manage notification permission in iOS Settings, and delete your account from Me → Settings (or the equivalent web account page). Deleting an account removes your personal profile data from active systems as described above.

App Store privacy labels

On the App Store product page we declare data linked to you that matches the categories above (contact info, user content, identifiers, and location when you share it). We do not track you across apps and websites owned by other companies for advertising.

Contact

Privacy questions: valeridium@gmail.com. Support page: /support.

Last updated: August 2026

Privacy · SideSeat