Privacy Policy
Salty Digital LLC ("Salty," "we," "our," or "us") values your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard information when you use the Salty mobile application, website, and related services (collectively, the "Service").
We operate in accordance with New Jersey law and applicable U.S. privacy regulations.
Effective Date: May 31, 2025 · Last Updated: September 27, 2026
1. Eligibility
Our services are not directed to children under the age of 13. We do not knowingly collect personal information from anyone under 13 years of age. If you are under 13, please do not use our services or provide any personal information. If we learn that we have collected personal information from a child under 13, we will delete it promptly.
2. Information We Collect
2.1 Information You Provide Directly
- Account registration: name, email address, zip code, phone number, and password
- Profile information: display name and profile photo
- Event and ticket information you enter manually
- Notes, reflections, and mood tags you attach to events
- Direct messages you send to friends you are connected with
- Email-provider credentials you supply to connect a non-Gmail mailbox (see Section 4.1)
- Feedback, support messages, and other communications with us
2.2 Information Collected Automatically
- Device and technical data: IP address, device identifiers, OS, browser type
- App usage data: screens viewed, features used, session duration, interaction patterns
- Location data (with your permission): GPS used to detect nearby events and match photos
- Photos and camera content (with your permission): used to scan physical ticket barcodes, and to group your own photos and video frames and match them to events
- Calendar (with your permission): the title, location, calendar name, date, and all-day flag of entries in your calendar, read to find concerts, games, and shows you are already attending. Those five fields — and no others — are processed by our AI provider, Anthropic (Claude API), solely to judge whether an entry is a live event. Entries are screened this way when Salty scans your calendar, before you choose which of the events it finds to keep. Anthropic does NOT use that content to train any AI model and does NOT retain it after classification; Salty itself saves the entries that pass as pending imports in your account and keeps the ones you add to your archive. We do not read notes, attendees, or invitees.
- Contacts (with your permission): phone numbers from your address book, sent to our servers only to tell you which of your contacts already use Salty. We do not store your contacts, we do not upload names or email addresses, and we never message anyone on your behalf. A contact who has turned off discovery, hidden their profile, or blocked you is never returned.
- Cookies and similar tracking technologies
2.3 Information from Third-Party Services
- Google Account (OAuth): name, email address, and profile photo
- Gmail (with explicit permission): email content accessed solely to detect ticket confirmations — we do not read, index, store, or share any other email content (see Section 4)
- Other email providers via IMAP (Yahoo, iCloud, AOL — with explicit permission): accessed solely to detect ticket confirmations (see Section 4.1)
- Ticketmaster Discovery API: publicly available event and venue metadata
- Setlist.fm: publicly available concert setlist data
- TheSportsDB: publicly available sports statistics
- Spotify and MusicBrainz: publicly available artist information used for search and autocomplete, and — if you choose — for exporting a setlist to your music library
- Songkick: your own past-concert history, only when you choose to import it
2.4 Subscription and Purchase Information
If you buy Salty Premium, we store a record of that subscription in our database, linked to your account: whether it is active, the plan tier, the store's product identifier, the store's identifier for the subscription, the start and end of the current billing period, whether it is set to renew, and the billing events the store sends us (purchase, renewal, cancellation, billing issue, refund, and the like).
For a Salty Premium purchase, Apple and Google process the payment: Salty never receives or stores your card number, and the stores do not tell us which payment method you used. We use RevenueCat as our subscription-management provider; RevenueCat identifies your subscription by an opaque billing identifier we generate for that purpose alone. It is a random value that is not your Salty account identifier and carries no information about you.
3. How We Use Your Information
We use collected information to:
- Create, maintain, and secure your Salty account
- Import and organize your live event tickets
- Enrich ticket records with setlists, sports stats, venue details, and media
- Sell and deliver Salty Premium, keep your subscription status in step with the App Store or Google Play, and give you the features your plan includes
- Enable social features including friend connections, tagging, shared event experiences, and direct messages between connected friends
- Send push notifications about upcoming events, new ticket detections, and friend activity (only if you opt in)
- Respond to your support requests and feedback
- Analyze aggregate, anonymized usage patterns to improve app features and performance
- Detect and prevent fraud, abuse, and security incidents
- Comply with legal obligations under applicable law
4. Gmail Integration & Google API Policy
Salty's use and transfer to any other app of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Specifically:
- We request Gmail read-only scope solely to scan for ticket confirmation emails
- We extract only the minimum data necessary: event name, date, venue, seat, and confirmation number
- To extract these details, the text of matching confirmation emails is processed by our AI provider, Anthropic (Claude API), solely to identify the event name, date, venue, and seat. When the text alone does not carry those details — typically because the ticket itself is a PDF attachment — that PDF is sent to Anthropic as well, and read only for the same details. This content is sent over an encrypted connection, is NOT used to train any AI model, and is NOT retained after extraction.
- We do not store the full text or attachments of any email
- We do not use Gmail data for advertising, profiling, or any purpose other than importing your tickets
- Gmail access and refresh tokens are encrypted at rest (AES-256-GCM) on our servers and protected by row-level security, and are additionally secured on your device using Expo Secure Store
- You can revoke Gmail access at any time from Settings → Connected accounts within the app, or directly from your Google Account settings at myaccount.google.com
4.1 Other Email Providers (IMAP)
If you connect a non-Gmail mailbox (Yahoo, iCloud, or AOL), you provide your email address and a password (or app-specific password). We use these credentials solely to scan for ticket-confirmation emails and extract the same minimum details described in Section 4, using the same AI processing by Anthropic.
Your email password is encrypted at rest (AES-256-GCM) on our servers, is never used for any other purpose, and is permanently deleted when you disconnect the mailbox.
4.2 Forwarded Emails (Forward-to-Scan)
Instead of connecting a mailbox, you can forward individual ticket confirmations to a personal Salty forwarding address that is unique to your account. We receive and process only the emails you choose to forward — we have no access to the rest of your inbox. Forwarded emails are processed to extract the same minimum event details described in Section 4, using the same AI processing by Anthropic (not used to train any model and not retained after extraction). We use a transactional email provider (Resend) to receive forwarded messages and to send Service emails such as verification codes.
5. How We Share Your Information
We do not sell your personal information. We may share limited information only in the following circumstances:
5.1 With Other Salty Users
When you tag friends in events or use social features, your display name and profile photo are visible to Salty users you are connected with. Direct messages you send are visible to the connected friend you send them to. You control your visibility through privacy settings (Settings → Privacy → Privacy settings), including whether you appear in search, whether your events are shared, and whether others can tag you.
5.2 With Service Providers
We use Supabase (database, authentication, and file storage) to operate the Service, Anthropic (Claude API) for the AI features described below, Resend to send and receive Service emails, PostHog to measure how the app is used, and RevenueCat to manage subscriptions bought through the App Store and Google Play.
What we send to Anthropic, each only for the purpose named:
- The text of ticket-confirmation emails — and an attached PDF ticket, when the text alone does not carry the details — to extract the event name, date, venue and seat (Sections 4, 4.1 and 4.2)
- Photographs and single frames from videos, as images: a ticket or playbill you scan, and photos being considered for one of your events — together with the date and, where you have allowed location access, the place they were taken
- Photos from your library that a scan has grouped as a possible night out or trip, so the AI can judge whether the group is a real event and which images to leave out. Spotting screenshots, bank or ID cards, passports and boarding passes is part of that step, which means images of that kind are sent in order to be kept out of your review queue
- Calendar entries found when Salty scans your calendar, before you choose which of them to keep — their title, location, calendar name, date and all-day flag, and nothing else (Section 2.2)
- When you use Ask Salty, a summary of your own archive, which can include notes you have written, the names of people tagged on your events, and artists you follow
- Event titles, venues and dates, to look up casts, line-ups and setlists
Anthropic does not use any of it to train its models and does not retain it after processing.
What we send to RevenueCat: the opaque billing identifier described in Section 2.4, and the store receipt for a purchase or restore you make. RevenueCat returns the subscription status we store against your account. We do not send it your name, your email address, or your Salty account identifier, and we do not let it collect device advertising identifiers.
These providers process data only as instructed by us and are contractually obligated to protect your information.
5.3 Legal Authorities
We may disclose information if required by law, regulation, court order, or governmental authority, or if we believe disclosure is necessary to protect our rights, your safety, or the safety of others.
5.4 Business Transfers
If Salty Digital LLC undergoes a merger, acquisition, or sale of substantially all of its assets, your information may be transferred as part of that transaction. We will notify you before your information becomes subject to a materially different privacy policy.
6. Data Retention
We retain your personal data for as long as your account is active or as needed to provide the Service. If you request account deletion, your personal data will be removed from our active systems within 30 days, except where retention is required by applicable law and except for the minimal billing record described below. Anonymized aggregate data may be retained indefinitely for analytics purposes.
Billing records kept after deletion. The subscription record described in Section 2.4 — its status, plan tier, store identifiers, billing period and renewal flag — is deleted along with your account. Two things are deliberately kept, and neither holds your name, your email address, or any other way of contacting you:
- The opaque billing identifier described in Section 2.4, with the identifier of the deleted account and the date it was deleted. Deleting your Salty account does not cancel a subscription bought from Apple or Google; only you can do that, in your store account. A subscription can therefore keep renewing after the account is gone, and this record is the only thing that lets our support team tell whose renewal it is, give the subscription back to you if you come back, or close it out. It is kept for as long as that can be needed, which is indefinitely.
- Our ledger of billing notifications from the stores. Deleting your account removes your Salty account identifier from every entry in it, but the entries themselves are kept — including the store's own identifier for the payer and the notification exactly as the store sent it — because they are our record of payments made and the evidence we would need in a refund or chargeback dispute. The ledger is never deleted.
This is a support and payment-record exception, not a route back to your account: the entries above are readable only by our own staff, and nothing in them restores deleted tickets, photos, notes, or messages.
7. Data Security
We implement industry-standard security measures including:
- Supabase Row Level Security (RLS) — each user can only access their own data
- OAuth 2.0 authentication, with all tokens encrypted in transit (TLS) and at rest
- Encryption at rest (AES-256-GCM) for stored email-provider credentials (Gmail tokens and IMAP passwords); the encryption key is held only in our server environment, never in the database
- On-device protection of session tokens using Expo Secure Store
- HTTPS/TLS encryption for all data in transit
- Service role keys are never bundled in the mobile app
No method of electronic transmission or storage is 100% secure. While we strive to use commercially acceptable means to protect your data, we cannot guarantee absolute security.
8. Cookies & Tracking
Our website and web-based components may use cookies and similar technologies to analyze traffic, remember your preferences, and improve your experience across sessions.
You can control or disable cookies through your browser settings. The mobile app uses Expo Secure Store rather than browser cookies for session management.
9. Your Rights & Choices
As a New Jersey resident and/or user of our Service, you may have the following rights:
- Access: request a copy of the personal information we hold about you
- Correction: request that we correct inaccurate or incomplete information
- Deletion: request that we delete your personal information
- Portability: request your data in a structured, machine-readable format
- Opt-out of marketing: unsubscribe from promotional emails at any time
- Withdraw consent: withdraw consent for Gmail access, calendar access, contacts access, or location tracking at any time through app settings
To exercise any of these rights, please contact us at privacy@saltydigital.ai. We will respond within 45 days.
Account Deletion: You may delete your Salty account at any time from Settings → Delete account, or from Profile → Edit → Delete Account. Your personal data will be removed from our active systems within 30 days, apart from the minimal billing record described in Section 6, which holds no name, email address, or other contact detail.
10. Third-Party Links & Services
The Service may contain links to third-party websites or integrate with third-party services (Ticketmaster, Setlist.fm, Spotify, and others). This Privacy Policy does not apply to those third parties. We encourage you to review the privacy policies of any third-party services you access through our app.
11. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be communicated by updating the "Last Updated" date and, where appropriate, by in-app notification or email. Your continued use of the Service after changes take effect constitutes your acceptance of the revised policy.
12. Google Play Data Safety
Data Collected:
- Name and email address (account registration)
- Phone number and postal code (account registration; your phone number is also what lets contacts who already have it find you on Salty)
- Contacts (phone numbers only, to tell you which of your contacts already use Salty, with permission)
- Calendar events (title, location, calendar name, date, and all-day flag, with permission)
- Photos and videos (ticket scanning and event galleries, with permission)
- Precise location (nearby event detection and venue matching, with permission)
- Email messages (email integration and forwarded emails only, ticket confirmation parsing, with your action)
- Messages (direct messages between connected friends)
- Purchase history (the Salty Premium subscription linked to your account: its status, plan tier, store product and subscription identifiers, billing period, and whether it renews). Apple and Google process the payment for a Premium purchase and we never receive your card number
- Device and app identifiers (crash reporting and analytics)
- App activity and interaction data
Data Sharing: We do not sell your personal data. Data is shared only with Supabase (our infrastructure provider), Anthropic (the AI processing described in Section 5.2), Resend (sending and receiving Service emails), PostHog (product analytics), and RevenueCat (subscription management, which receives an opaque billing identifier rather than your Salty account identifier), each under a data processing agreement. Email data is never used for advertising and is never shared beyond the processing described in this policy.
Security: All data is encrypted in transit using HTTPS/TLS. Email-provider credentials (Gmail tokens and IMAP passwords) are encrypted at rest using AES-256-GCM with Supabase Row Level Security; session tokens are protected on-device using Expo Secure Store.
13. Contact Us
Questions about how your data is handled? Contact us at privacy@saltydigital.ai.
Salty Digital LLC · Effective May 31, 2025 · Last Updated September 27, 2026