Privacy
Version 2026-09-20 · last updated 20 September 2026
This is a small, invite-only service. The short version: it keeps what it needs to show you events near you, it does not sell anything to anyone, and you can delete all of it yourself at any time.
What is kept
- Your account — email address, username, display name, and a scrypt hash of your password. The password itself is never stored and cannot be recovered, only replaced.
- A home area, if you set one — the place you typed and its coordinates. Optional, and you can clear it.
- Your current location, if you tap “Use my location” — stored in a cookie in your browser and sent with searches so results can be sorted by distance. Clearing the cookie removes it.
- What you post — events, RSVPs, friendships and circles.
- Coarse usage records — that a search happened, roughly where (rounded to about a kilometre), the radius and date range, and how many results came back. Search text is not stored. This exists to find out where coverage is missing.
- A security log — sign-ins, failed sign-ins, password resets, account deletions and administrator actions, with IP addresses truncated to the first three octets.
What is not kept
No advertising identifiers, no third-party analytics, no tracking pixels, no cross-site cookies, no profile sold or shared with anybody. There is no payment processing, so there are no card details to lose.
Who else sees anything
- Resend delivers confirmation and password-reset email, so it processes your address and the contents of those messages.
- OpenStreetMap receives the place names you search in order to turn them into coordinates. Separately, when a map is on screen your browser loads map tiles directly from OpenStreetMap, so they can see your IP address and roughly what area you are looking at. That is true of most maps on the web and is worth knowing.
- The host runs the server and stores the database.
Email you will get
- Confirming your address, and resetting your password. These are how the account works, so they are sent whether or not you want them. You will also be told if your password changes, which is how you would find out if it was not you who changed it.
- Occasional news about tohode — only if you asked for it. A few times a year at most, every one with an unsubscribe link, and you can change your mind on your account page at any time.
Your address is never sold, shared or passed to anyone for their own marketing. There is no mailing list beyond the one described here.
How long
Account data lasts until you delete your account. Usage records are deleted after 180 days and security-log entries after 2 years. Past events from feeds are removed a week after they happen.
Deleting everything
Your account page has a delete button. It removes your account, the events you posted, your RSVPs, friendships and circles, immediately and permanently. The security log keeps a record that an account was deleted, with your name replaced by a number.
Children
tohode is not intended for anyone under 13, and accounts are not knowingly created for them.
If something goes wrong
If account data is ever exposed, affected people will be told directly and promptly, at the address on their account.
Questions
Ask whoever invited you — this is a beta run by one person, not a company.