Privacy policy
Last updated: 3 October 2026
The short version: we keep what the service needs to work (your email, your events, what you search for and what you write), we use it only to run Social Agenda, and you can delete all of it from Settings. No advertising, no analytics, no tracking, and we never sell data. AI models see event information and your searches, never your email.
1. Who is responsible
- Controller: Biglobster LLC, a limited liability company organised under the laws of the State of New Mexico (United States)
- Registration number: 3279115 (Entity ID 0008120949, New Mexico Secretary of State)
- Address: 1209 Mountain Road Pl NE Ste N, Albuquerque, NM 87110, United States
- Privacy contact: hola@biglobster.top
The owner is established outside the European Union. Because Social Agenda is open to people in the EU, it handles personal data to the standard of the EU General Data Protection Regulation (Regulation (EU) 2016/679, "GDPR"). Because it is used by people in Thailand, it also follows Thailand's Personal Data Protection Act B.E. 2562 ("PDPA"). Everyone can exercise the rights in section 9, wherever they live.
No data protection officer has been appointed. Privacy questions are answered at the contact address above.
2. What data we process
When you visit. Your IP address and the technical details every browser sends, such as its type and the time of the request. Our hosting provider processes them to deliver the page and protect the site, and may keep them for a time in its own logs.
When you sign up or sign in. Your email address; your password, if you set one, stored only as an irreversible hash; when you joined and last signed in. A sign-in link is valid for 15 minutes and works once. Sign-in attempts are limited per IP address, and sign-ins, failed sign-ins (including the email typed) and other security-relevant actions are written to a security log with the IP address and browser type. The sign-in page runs Cloudflare Turnstile, an anti-bot check. When you sign up we record that you accepted the Terms and this policy, with the version and the date.
Your profile. The name, short bio and picture link you choose to add, and whether your profile is public or for followers only.
When you use the service. The events you create, import or join; the reminders you set; your interests, city and other preferences; your searches, the events found for you and what you accept or reject; feeds you add; who you follow and who follows you; invitation links you create and who joined through them; your chat messages and questions to the event assistant; your notifications; and the secret link of your calendar subscription.
When you search from the front page. Your email address and what, where and when you are looking for. If you never open the link we email you, the request is deleted after 7 days.
Places. When you type a city, your browser asks Photon (a place-search service run by Komoot) for suggestions. If you press "use my location", your browser asks your permission first and then sends your coordinates to Nominatim (OpenStreetMap) to find the city's name. These requests go straight from your browser to those services; we only receive the city name you end up choosing, never your coordinates.
Events from the web. To find events, the service reads pages and feeds that organisers, venues and ticket sellers publish. These can name organisers or performers. We keep only what describes the event.
The animal game. Nothing leaves your browser: your best score is kept in your browser's own storage (see the Cookies policy).
When you write to us. Your email address and whatever you tell us.
There are no analytics, advertising or tracking tools on this site. We do not buy data. We do not sell or rent it, and we do not build profiles of you beyond the interests you give us to find events for you.
3. Why, and on what legal basis
| Purpose | Legal basis |
|---|---|
| Providing your account and the service: your calendar, joining events, chat, invitations, following, calendar subscription | Performance of our contract with you (GDPR art. 6(1)(b)) |
| Emailing you sign-in links and the reminders you set | Performance of the contract (GDPR art. 6(1)(b)) |
| Finding, reading and summarising events for you with AI and web search, and answering your questions about an event | Performance of the contract (GDPR art. 6(1)(b)) |
| Keeping the service secure: limits on sign-in attempts, the anti-bot check, the security log | Legitimate interest in protecting the service and its users (GDPR art. 6(1)(f)) |
| Showing events that organisers have published | Legitimate interest in pointing people to public events (GDPR art. 6(1)(f)) |
| Recording that you accepted the Terms and this policy | Legitimate interest in being able to show what was agreed (GDPR art. 6(1)(f)) |
| Handling reports of illegal content and requests from authorities | Legal obligation (GDPR art. 6(1)(c)), including the EU Digital Services Act |
| Handling a request to exercise your data-protection rights | Legal obligation (GDPR art. 6(1)(c)) |
| Answering your messages | Legitimate interest in replying to people who write to us (GDPR art. 6(1)(f)) |
We send no marketing. AI chooses and describes events for you, but no decision with legal or similarly significant effects on you is taken by automated means (GDPR art. 22). You need an email address to have an account; everything else on your profile is optional.
4. Who can see what
- Your email address is never shown to other users.
- Your name and picture appear where you take part: on the page of an event you join, in its chat, and to people you follow or who follow you. On a public event the list of people going is visible to anyone who can open the event, including people who are not signed in.
- Your profile (name, bio, picture) can be opened by anyone with its link. If it is public, the events you are going to are listed on it; if it is for followers only, just the people you accept see them. You can change this in Settings.
- Events are seen according to the visibility chosen for them: public (anyone with the link), followers, or private (only the creator and the people going).
- Chat messages on an event are seen by the people going to it.
- The administrator can see all content, private events included, where needed to run the service, keep it safe and act on reports.
5. How long it is kept
- Your account and everything in it: until you delete your account. Deleting it removes your profile, preferences, attendance, chat messages, reminders, searches, feeds, follows, invitations and notifications.
- Events you created: they stay, so the other people going keep them, but are no longer linked to you. Delete an event first if you want it gone. Events the AI found for you are likewise kept without a link to you.
- Events after they happen: deleted, with their chat, 24 hours after they end.
- Front-page searches never confirmed: 7 days.
- Sign-in links: 15 minutes, and gone once used.
- Sign-in attempt counters (by IP address): 48 hours.
- Security log (IP address, browser type, action): 90 days. After an account is deleted its entries no longer name it.
- Sign-in cookie: 72 hours, or until you sign out.
- Logs of our providers: for the period each provider keeps them. We do not copy or archive them.
- Messages you send us: until your question or request is resolved, and afterwards only for as long as a legal claim about it could arise.
6. Who receives it
We do not sell or share personal data. These providers process it on our behalf, only for the purposes above:
| Provider | What for | Which data | Where |
|---|---|---|---|
| Zeabur | Hosting of the application and its database | Everything the service stores; IP addresses in technical logs | Application server in Frankfurt (Germany); the database is managed by Zeabur |
| Cloudflare | The Turnstile anti-bot check on sign-in | IP address and browser signals on the sign-in page | Worldwide network; Cloudflare, Inc. is in the United States |
| Brevo | Sending sign-in links and event reminders by email | Your email address and the content of those emails | European Union (France) |
| OpenRouter | Access to the AI models that read event pages, answer questions in event chats and find events for your searches | Event text, your search terms and interests, and questions you ask the event assistant. Never your email or account details | United States; OpenRouter passes each request to the model provider that answers it, which may be elsewhere |
| Tavily | Web search for event discovery | Search queries built from what, where and when you are looking for. Never your email or account details | See Tavily's privacy policy |
Two kinds of request go straight from your browser to others, not through us: the place look-ups described in section 2 (Photon by Komoot, Nominatim by the OpenStreetMap Foundation), and event pictures, which load from the organiser's own website. Those services receive your IP address and handle it under their own privacy policies.
Data may also be disclosed to public authorities and courts where the law requires it.
7. International transfers
The application server is in the European Union. Some providers above are in, or reach their models through, the United States, and the owner is established in the United States and runs the service remotely, so personal data may be processed outside the European Economic Area and outside Thailand. Where it is, we rely on the safeguards the law allows, such as the European Commission's standard contractual clauses (GDPR art. 46(2)(c)) or an adequacy decision. You can ask us for details and a copy of the safeguards at the contact address.
8. Security
Connections are encrypted; passwords are stored only as irreversible hashes; sign-in links expire and work once; sign-in attempts are limited and checked against bots; the session cookie cannot be read by scripts or sent from another site; every form is protected against forgery; and every page carries security headers that limit where the browser may load scripts and fonts from. Access to the data is limited to the administrator. If a breach posed a risk to your rights, we would notify the competent authority and, where required, you, within the legal deadlines.
9. Your rights
You may ask at any time for access to your personal data, its rectification or erasure, the restriction of its processing or a copy in a portable format (portability), and you may object to processing based on legitimate interest. Where processing relies on your consent you may withdraw it at any time.
- Delete your account yourself in Settings › Delete My Account. It takes effect immediately.
- Edit your profile and preferences in Settings.
- For anything else, including a copy of your data, write to hola@biglobster.top from the email of your account, saying which right you wish to exercise.
We answer within one month. If you believe your request was not handled properly, you can complain to the data-protection authority of the country where you live: in Spain, the Agencia Española de Protección de Datos (www.aepd.es); in Thailand, the Personal Data Protection Committee (www.pdpc.or.th).
10. Age
Social Agenda is for people aged 18 or older, and you confirm your age when you sign up. We do not knowingly process data about anyone younger; if you believe a minor has an account, tell us and we will delete it.
11. Changes to this policy
The version in force is the one on this page, with its date at the top. If we change it in a way that matters to you, we will tell you on the site or by email before the change applies.