Privacy Policy
Version 1.1 · Last updated 2026-07-31Privacy at a glance
Outsidey places you in a small community and brings you to real-world events with them. This summary covers the points members most often ask about; the full policy follows.
- Your first name and your photo are shown only to the people attending an event you RSVP to, never to the wider community. Attendees are told where and when to meet.
- Nobody sees your surname, your email address, your date of birth, your postcode, or your quiz answers. Those never leave Outsidey.
- Other members can leave feedback about you after an event, and can flag that they connected with you. You never see either, and neither do they.
- Any member can report you. We keep reports, and we never reveal who reported you. If a report leads to action, you are told, with the reason.
- We do not sell your information – none of it, to anyone – we do not use it for advertising or pricing, and we do not use facial recognition on your photo.
- Being open to dating and preferring women-only groups are optional settings you can change at any time, and the monthly loneliness question is optional – you can skip any month. Outsidey works normally without any of them.
The rest of this policy sets out the detail. If you only read one more section, read What other members can see about you.
1. Who we are
Outsidey is run by Outsidey Ltd, a company registered in England and Wales (company number 17148298), with its registered office at 71–75 Shelton Street, London, Greater London, WC2H 9JQ, United Kingdom.
We are the data controller for the information described in this policy. That means we decide what is collected and why, and we are responsible for looking after it.
- Privacy contact: privacy@outsidey.co.uk
- ICO registration: applied for (application reference C1995384). We will update this policy with our registration number once it is issued.
We are not required to appoint a Data Protection Officer. Responsibility for privacy at Outsidey sits with the company’s director, who can be reached at the address above.
2. What this policy covers
This policy covers the Outsidey website and service. It sits alongside three other documents:
- our Terms of Service, which is the contract between us;
- our Community Guidelines, which set out how members are expected to behave; and
- our Moderation and Enforcement Policy, which explains how we handle reports, what action we can take, and how to appeal.
What this policy does not cover. It does not cover the venues you visit. Pubs, cafés, bookshops and other venues are independent businesses with their own privacy policies, and when you are on their premises you are their customer. It also does not cover what other members do with what they learn about you when you meet them. We explain the limits of our control in section 6.
Where we operate. Outsidey is offered to people in the United Kingdom. We do not market or target the service at people in the European Union or the United States.
3. The information we hold
What you give us.
- When you sign up: your name, email address and password.
- When you complete onboarding: your date of birth, gender, city and postcode, how far you are willing to travel, and a photo of yourself. A photo is required – it is how members recognise each other when they arrive at an event.
- Optionally: your nationality, occupation, the languages you speak, and a short bio. You can leave all of these blank.
- Your preferences: the age range, budget, days, timings and group size you prefer; whether you are open to dating; whether you want women-only groups; any accessibility needs or dietary requirements; and your email preferences.
- Your quiz answers: your answers to the onboarding questionnaire, and the personality and values profile we build from them.
- The monthly question: your answer to the single monthly question about how often you feel lonely. Answering is optional and you can skip any month.
- When you pay: your payment is handled by Stripe. We receive your subscription status and a customer reference, not your card number. If you cancel, we record the reason if you give one.
- When you contact us: whatever you write to us, and our reply.
What we collect automatically. Your login sessions and device and browser information; the pages you visit and the actions you take on the site; your event and RSVP activity; and information from the cookies described in section 14.
What other people tell us about you.Other members can leave feedback after an event (a thumbs up or down, a rating of the venue, and a short comment); flag that they connected with you, which helps us suggest events where you will see people you got on with; mark that you did not attend an event you had RSVP’d to; and report you, giving a category and a written description. We hold all four as information about you. Section 8 explains what happens to each.
If you do not provide something. Your name, date of birth, gender, location and photo are needed to run the service – we cannot place you in a community or get you to an event without them. Everything else is optional, and leaving it blank only makes your matches less well tuned.
4. How we use your information, our lawful basis, and how long we keep it
Under UK data protection law we need a lawful basis for everything we do with your information. This section sets out every purpose, one at a time, including who, other than us, sees it.
Creating and running your account
What we use: Name, email, password, date of birth, gender, location, photo, optional profile fields. Where we get it: You.
Basis, and how long we keep it: Contract – we cannot provide the service without it. Kept while your account is open.
Who else sees it: Your first name and photo are shown to the other attendees of events you RSVP to. Nothing else.
Placing you in a community
What we use: Quiz answers, personality and values profile, interests, life stage, location, preferences. Where we get it: You.
Basis, and how long we keep it: Contract. Kept while your account is open.
Who else sees it: Nobody. Your answers and your profile are not shown to other members.
Matching you for dating, and for women-only groups
What we use: Your dating preference, your women-only preference, your gender. Where we get it: You.
Basis, and how long we keep it: Consent – both are optional settings you choose, and you can change them at any time. Kept while set.
Who else sees it: Nobody. They only affect which communities and events you are shown.
Suggesting events you are likely to enjoy
What we use: Your profile and preferences, the events you have attended, connection flags, distance from the venue. Where we get it: You, and other members.
Basis, and how long we keep it: Legitimate interests in making suggestions relevant. Kept while it remains useful for recommendations.
Who else sees it: Nobody.
Running events and RSVPs
What we use: Your first name, photo, RSVP status, and any accessibility needs or dietary requirements you have told us about. Where we get it: You.
Basis, and how long we keep it: Contract. Accessibility needs and dietary requirements: explicit consent, given by providing them. Kept while your account is open.
Who else sees it: Your first name and photo are shown to other attendees. Accessibility needs go to our team, and to the venue only where that is the only way to arrange access, and only with your agreement.
Taking payment and managing your membership
What we use: Name, email, subscription status, customer reference, cancellation reason. Where we get it: You, and Stripe.
Basis, and how long we keep it: Contract, and legal obligation for the accounting records. Kept for as long as tax and accounting law requires.
Who else sees it: Stripe.
Post-event feedback and connection signals
What we use: Thumbs up or down, venue rating, written comment, connection flags. Where we get it: Other members about you, and you about them.
Basis, and how long we keep it: Legitimate interests – improving matching, and knowing which venues work. Kept while the signal remains useful to matching.
Who else sees it: Nobody. It is never shown to the person it is about.
Safety, reports and moderation
What we use: Report category and description, your account and attendance history, our decisions. Where we get it: Other members, and our team.
Basis, and how long we keep it: Recognised legitimate interest in preventing and detecting crime, and legitimate interests in keeping members safe. Where a report alleges a criminal offence, we rely on the substantial public interest condition for preventing unlawful acts. Kept after either account closes, for as long as needed to keep members safe and to defend legal claims.
Who else sees it: Our moderation team. The police, where we are required to disclose or where it is necessary to protect someone. Not the member who was reported.
Emails about your membership and your events
What we use: Name, email, event and payment details. Where we get it: You.
Basis, and how long we keep it: Contract. Kept while your account is open.
Who else sees it: Amazon Web Services, which sends our email.
Understanding how Outsidey is used, and improving it
What we use: Pages visited, actions taken, device and browser, an account identifier. Where we get it: Automatically.
Basis, and how long we keep it: Consent, given through our cookie banner. Kept for as long as set in our analytics configuration.
Who else sees it: PostHog.
Measuring our advertising
What we use: An advertising click identifier, and the fact that a sign-up or subscription happened. Where we get it: Automatically.
Basis, and how long we keep it: Consent, given through our cookie banner.
Who else sees it: Google.
Keeping Outsidey secure, and preventing fraud and duplicate accounts
What we use: Login and session records, IP address, device information, records of administrator actions. Where we get it: Automatically.
Basis, and how long we keep it: Legitimate interests – protecting members from people who should not be here, and protecting the service from abuse. Kept for as long as needed for security and accountability.
Who else sees it: Nobody outside Outsidey.
Meeting our legal obligations
What we use: Whatever the obligation requires. Where we get it: Various.
Basis, and how long we keep it: Legal obligation. Kept for as long as the law requires.
Who else sees it: Courts, regulators and law enforcement, where required.
Measuring whether Outsidey reduces loneliness
What we use: Your answers to the monthly question, together with attendance and membership length. Where we get it: You.
Basis, and how long we keep it: Explicit consent – answering is optional, every month. Kept for as long as needed to measure the effect of the service.
Who else sees it: Nobody. Your answers are never sent to our analytics provider.
A note on our legitimate interests. Where we rely on legitimate interests, we have weighed our interest against your rights. You can object – see section 12.
A note on how long we keep things. We keep your information for as long as we need it for the purpose it was collected for, and the entries above say what determines that in each case. When we no longer need it, we delete it or strip out everything that identifies you.
5. Sensitive information
Some of what we hold is treated as special category data under UK law, which means it gets extra protection. Some of it is not obviously sensitive on its own, but becomes sensitive in combination.
- Your dating preference. On its own it says you are open to meeting someone. Combined with your gender and the gender of the people you are matched with, it can reveal your sexual orientation.
- Your answers to the monthly question about loneliness. These are information about your mental wellbeing.
- Anything you write in the accessibility needs or dietary requirements fields. If you tell us about a condition or a requirement, that may be health information; a dietary requirement may also reflect a religion or belief.
- One question in the onboarding quiz asks how important religious belief is to you. It is part of the values profile we use for matching.
We process these only with your consent. Your consent for the quiz – including the religion question – is given at signup, when you agree to your answers being used to match you with communities and events. The rest you choose to provide or switch on, and you can change or remove them in your settings at any time.
Outsidey works without the optional ones. With the dating preference off, women-only groups off, every monthly question skipped, and the accessibility and dietary fields blank, you will still be placed in a community, you will still see events, and you will still be able to RSVP.
Four commitments:
- We do not sell your information.
- We do not use any of it for advertising targeting.
- We do not use any of it to set your price.
- We do not use your information to train artificial intelligence models, and we do not give it to anyone else for that purpose.
Your answers to the monthly loneliness question are never sent to our analytics provider and are never written to our logs.
6. What other members can see about you
Outsidey is built around meeting in person, so this section sets out exactly what other members see.
On an event roster: your first name and your photo. That is all. An event roster is the only place other members see you – there is no community-wide member list. Your surname, your email address, your date of birth, your postcode, your quiz answers, your personality profile and your account identifier never appear on a roster and never leave our service.
The roster for an event becomes visible to the people who have RSVP’d in the 24 hours before it starts. If you RSVP, your first name and photo appear to the other attendees from that point. Members who RSVP and then cancel will already have seen the roster – cancelling does not undo that.
Your profile is not public. It is not visible to people who are not members, and it is not indexed by search engines.
About the event itself.Attendees with an active membership are shown the venue’s name, its address and its what3words square. We do not share your location with anyone, and we do not track where you are.
What is never shown to you, or about you. Feedback other members leave about you is never shown to you, and yours about them is never shown to them. Connection flags work the same way: if you flag that you connected with someone, they are not told, and if they flag you, you are not told – we only use it to suggest events. Reports are not shown to the member who was reported, and the identity of the person who made a report is never shared.
What we cannot control. We can control what our service shows. We cannot control what happens in the room. The people you meet will see your face and hear what you choose to tell them. They can take photographs, and they can repeat what you said to other people. Our Community Guidelines ask members not to share photographs of other attendees without asking, and we act on reports when they do not – but we cannot prevent it. Only share what you are comfortable sharing, in person as well as online.
7. How we match you, and the decisions we make automatically
How matching works.We use your quiz answers to build a profile of your personality, your values and what you are looking for. We compare that profile with other members’ profiles, alongside your interests, your life stage, where you live and how far you will travel, your budget, the days and times you are free, and the group size you prefer. Members who come out as compatible on those measures, and who share at least one interest and live close enough to each other, are placed in a community together.
Event suggestions work the same way, with the addition of who has already said they are going, how far away the venue is, and whether you have connected with anyone attending.
Decisions we make without a person involved. The following are made automatically by our system:
- which community you are placed in, and whether you are put on a waiting list;
- which events you are eligible for and which you are shown;
- which other members you appear to, and which appear to you;
- removing you from a community after a long period of inactivity, and whether you can be placed there again; and
- recording that you did not attend an event, where other attendees say so.
Suspending an account and closing an account are never automatic. Every one of those is a decision made by a person on our team.
If you think one of these decisions has gone wrong for you, email privacy@outsidey.co.uk and a person will look into it.
8. Feedback, reports and safety
Three different things happen after an event, and they work differently.
Feedback and connection flags.You are emailed after an event and asked whether it was any good, how the venue was, and who you connected with. Everything you submit is used to improve matching and to decide which venues to keep using. It is not shown to the people it is about, in either direction, and it does not appear in a member’s profile.
Reports. Any member can report another member. A report has a category and a written description, and it goes to our moderation team.
- We never reveal who reported you.
- We do not usually tell you that a report exists. In a small community, doing so would often make it easy to work out who made it.
- If a report leads to action – a recorded warning, or a suspension – we tell you, with a case number and the reason, and you can appeal. Our Moderation and Enforcement Policy explains how reports are handled, what we may do, and how appeals work.
- Reports are kept after either account is closed. If we deleted a report when someone deleted their account, closing and reopening an account would erase a safety history. Reports are kept for as long as we need them to keep members safe and to defend legal claims.
- Where a report describes something that may be a criminal offence, we can pass it to the police, and we will where we are required to or where someone is at risk.
Attendance. If you RSVP and do not turn up, other attendees can record that. It affects how we treat inactive members and, over time, which events we suggest. If your attendance record is wrong, email us and we will look into it and correct it.
9. Who we share your information with
We share information with the companies below because we need them to run the service. They act on our instructions and cannot use your information for their own purposes, except where noted.
- Supabase (processor – our database, sign-in and file storage): everything held in our database, including your photo.
- Amazon Web Services, Amplify (processor – hosting and running the website): website requests and server logs.
- Amazon Web Services, SES (processor – sending our emails): your email address, your name, and the contents of the emails we send you.
- Stripe (a controller in its own right for parts of this – taking payment and managing your membership): your name, email address and payment details, and your subscription.
- PostHog (processor – understanding how the product is used): an account identifier, the pages you visit and the actions you take.
- Google Ads (a controller in its own right – measuring whether our advertising works): an advertising click identifier, and the fact that a sign-up or subscription happened.
- Google Places (processor – venue details and ratings): venue information only, no member information.
- what3words (processor – giving attendees a precise meeting point): venue locations only, no member information.
- postcodes.io (processor – working out how far you are from a venue): your postcode.
We do not currently verify members’ identity documents. If we start to, we will tell you before we do and update this policy.
We also disclose information:where the law requires it, or a court or regulator orders it; to the police or emergency services, where someone’s safety is at risk; to our professional advisers – lawyers, accountants, insurers – where they need it; and to a buyer or investor, if Outsidey is ever sold or merged. We would tell you first, and the buyer would be bound by this policy.
We do not sell your personal information, and we do not share it with advertising networks for them to build profiles of you.
10. Where your information is held
Your information is held in the United Kingdom and the European Economic Area: our database, file storage, website and email are hosted in Ireland, and our product analytics in Germany. The EEA is covered by the UK’s adequacy regulations, which means information can move there from the UK without any additional safeguard.
Some of the companies in section 9 – for example Stripe and Google – process some information in the United States. Where that happens, we rely on the UK International Data Transfer Agreement, or the UK Addendum to the European Commission’s standard contractual clauses. You can ask us for a copy of the safeguards that apply to a particular transfer by emailing privacy@outsidey.co.uk.
11. What happens if you delete your account
You can close your account at any time by emailing privacy@outsidey.co.uk. Deletion is carried out by our team and is irreversible – once it is done, we cannot restore your account.
When we delete your account, we permanently remove the values that identify you – your name, email address, date of birth, postcode and photo – from your account record. Your preferences (including your dating preference, women-only preference, accessibility needs and dietary requirements), your quiz answers and personality profile, your connections with other members, your answers to the monthly loneliness question, and your photo files are deleted outright.
Some records are kept, and it is worth being clear about which and why.
- Safety records – reports, warnings and other moderation records, and attendance marks – are kept, so that a safety history cannot be erased by closing an account and opening a new one.
- Payment and subscription records are kept for as long as tax and accounting law requires.
- Records of the emails we sent you, our administrator audit log, and attendance and venue records are kept for accountability and for understanding how the service performs.
- Events you proposed that other members joined remain available to them, without your name attached.
- Your venue reviews and comments are kept with your name and anything else that identifies you removed, so that what members have said about venues continues to inform how we choose them. The Terms of Service (clause 15.3) explain this.
These records are kept in pseudonymous form: they are no longer linked to your name or contact details. The exception is our administrator audit log, where a record of an action our team took can include the email address it concerned; we keep that for accountability.
12. Your rights
You have the following rights over your information. All of them are free, and using one will never lead to worse treatment.
- Access: ask what information we hold about you and get a copy – a subject access request.
- Correction: have anything inaccurate put right. Most of it you can edit yourself in settings.
- Deletion: ask us to delete your information. Section 11 explains what we keep and why.
- Restriction: ask us to pause using your information while a question about it is resolved.
- Portability: ask for the information you gave us in a machine-readable file.
- Objection: object to us using your information where we rely on legitimate interests, including for matching and recommendations.
- Withdrawing consent: change any setting you have turned on – the dating preference, women-only groups, or cookies – at any time. Withdrawing is as easy as giving, and it does not affect anything we did beforehand.
- Complain to us: complain to us about how we have handled your information. See section 13.
Your right to object. You have the right to object at any time to our using your information where we rely on legitimate interests, including profiling for matching and event recommendations. Email privacy@outsidey.co.uk and tell us about your situation; we will stop unless we have compelling grounds that override your rights, and if we believe we do, we will explain them.
What an access request includes. A copy of your data covers your profile, preferences, membership history, RSVP and attendance history, the feedback you submitted, and your billing records. It excludes our internal derived scores (your personality and compatibility scores), reports made about you or by you, and connection flags – the scores because they are our working calculations, the reports and flags because they are also about other people. These exclusions are stated here so they are never a surprise.
How to use any of these rights. Email privacy@outsidey.co.uk. We will ask enough to be sure it is really you, and no more than that. These requests are handled by our team rather than a self-service tool.
How long we take. One month. If your request is complicated, or you have made several, we can take up to two months longer, and we will tell you within the first month if that happens and why. If we need something from you to find what you are asking about, the clock pauses until you send it.
13. Complaints
Complain to us first. If you are unhappy with how we have handled your information, email privacy@outsidey.co.ukwith “Complaint” in the subject line. You have a legal right to complain to us directly, and we will acknowledge your complaint within 30 days and tell you what we are doing about it.
Then, if you are still unhappy, you can complain to the Information Commissioner’s Office, which regulates data protection in the UK. You can do that at any time – you do not have to come to us first.
Information Commissioner’s Office · Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF · 0303 123 1113 · ico.org.uk/make-a-complaint
15. Emails
Emails about your membership – your RSVP confirmations, event reminders, payment receipts, renewal notices and community updates – are part of the service, and we send them for as long as you are a member. They do not carry an unsubscribe link, because unsubscribing from them would mean not being told where your event is.
We do not currently send marketing emails. If we ever start, every one will include an unsubscribe link, and you will be able to opt out in your settings.
16. Keeping your information safe
- Every table in our database enforces access rules at the database level, so a member’s information can only be reached by that member and by the parts of our system that need it.
- Your photo is held in private storage. The links used to display it expire after a day and cannot be shared.
- Your personality profile can only be written by controlled server processes, not by anyone signed in as a member.
- There is no member-to-member messaging in Outsidey – a deliberate design choice that removes a major source of harassment and data leakage on comparable platforms.
- Every action taken by an administrator is recorded in an audit log.
- A suspended account loses access immediately, across every part of the service.
No service can promise that information will never be at risk. If something does go wrong, we investigate, and we tell you and the Information Commissioner’s Office where the law requires it.
17. Age
Outsidey is for adults aged 18 and over. We ask for your date of birth when you sign up, and by signing up you confirm that you are 18 or over.
If we find out that someone under 18 has an account, we close it and delete their information.
If you are a parent or guardian and you think your child has signed up, email privacy@outsidey.co.uk and we will deal with it promptly.
18. Changes to this policy
We update this policy when what we do with your information changes. The version number and the last-updated date are at the top of the page. If we make a change that materially affects you, we will tell you before it takes effect – by email, or in the product.
For any question about this policy, or to use any of the rights in section 12, email privacy@outsidey.co.uk and we will respond within one month.
