1. The three roles, and what each one gives us
People use All In On It in one of three roles. What we collect depends on the role.
| Role | What we collect | Why |
|---|---|---|
| Main Conspirator | Your name, email address and — if you sign in with Google or Apple — the identifier and profile picture they share with us. The missions you create: the special person's name, the date, timezone and occasion, an optional way to reach them (email or phone), the message you write to your co-conspirators, and the look you choose for the page. Sign-in sessions record the IP address and browser they were started from. | To run your account, keep you signed in, build the page and reveal it at the right moment. |
| Co-conspirator | The name you enter, optionally your email address, and the greeting you send — text and, once available, one photo or short video. Without an account: a small token stored in your browser so we recognise you on the same device. With an account (optional, coming later): the same details as an organiser, and your greetings across missions are linked to that one account so you can find them in one place. | To show your greeting to the organiser and, once approved, to the special person; to let you edit or withdraw it; and, with an account, to show you all your missions together. |
| Special Person | No account and no name. When you enter the page passcode, a signed cookie remembers that you did. Your likes and replies to greetings are stored with the mission. | To let you into the page and let you respond to the people who wrote to you. |
Everyone: like every website, our hosting provider (Cloudflare) records basic request information — IP address, browser, page requested, time — in short-lived logs used for security and debugging.
2. What we do not do
- No advertising, no ad networks, no selling or renting of personal data — ever.
- No analytics or tracking scripts today. We don't use Google Analytics, pixels or fingerprinting. We may add privacy-friendly, cookieless usage statistics (such as Cloudflare Web Analytics) to see how the service is used as a whole; if we ever add analytics that uses cookies or identifies you, we will update this policy first and ask for consent where the law requires it.
- No reading of your contacts, photo library or location. You choose each file you upload.
- No indexing by search engines: mission, contribution and special-day pages carry a "noindex" instruction, and their addresses are long random tokens that cannot be guessed.
- We don't email your co-conspirators or the special person on your behalf unless you explicitly ask for a feature that does so.
3. Who can see a greeting
Greetings are private by default. Before the reveal, a greeting is visible to the person who wrote it and to the organiser of that mission. The organiser decides whether co-conspirators can see each other's greetings — never, immediately, or only after the reveal. After the reveal, approved greetings are visible to anyone who has the page link and the passcode the organiser set.
Nothing reaches the special person without the organiser approving it first.
The platform operator can see mission metadata (who created it, when, how many greetings, storage used) in order to run the service. Greeting content is not visible to the operator in normal operation; it can be opened only through a deliberate, time-limited "open for support" action that records who opened what, when and why in an audit log — for example to handle a complaint under this policy or the Terms.
5. Service providers we rely on
We don't run our own servers. Almost everything runs on Cloudflare, so the list is short. These companies process data on our behalf, only as needed to provide the service, under their own privacy commitments:
| Provider | What for | Data involved |
|---|---|---|
| Cloudflare, Inc. | Hosting, database, file and video storage, sending sign-in codes and service emails, receiving mail to our contact address, security | Everything stored by the service; your email address and the content of emails we send you; request logs |
| Google LLC | Sign in with Google (optional) | Your Google account identifier, name, email and profile picture, if you choose Google |
| Apple Inc. | Sign in with Apple (when available) | Your Apple identifier, name and the email Apple shares, if you choose Apple |
Cloudflare operates a global network, so data may be stored and processed in data centres outside the country you live in, including the United States and the European Union. A payment provider will be added to this list once paid missions exist, and this page will be updated first.
We share personal data with no one else, except when the law requires it or to protect someone's safety.
6. How long we keep things
- Missions and greetings: a revealed page stays live for one month after the reveal. It is then archived and, after a short grace period, its photos and videos are permanently deleted. The organiser can delete a mission — and everything in it — at any time before that.
- A withdrawn or declined greeting is hidden immediately and deleted with the mission.
- Accounts (organiser or, later, contributor) are kept until you ask us to delete them. Deleting an account deletes the missions it owns and any greetings of yours that are still pending. A greeting of yours that has already been approved on a live page stays there — the organiser and the special person have relied on it — unless you ask us to remove it too; it is deleted with the mission in any case.
- Sign-in codes expire within minutes. Sessions expire after inactivity.
- Request logs at our hosting provider are kept for a short period for security and debugging.
- The audit log of operator actions is kept for as long as the service runs, so that access to content stays accountable.
7. Your choices and rights
Whatever country you are in, you can ask us to tell you what we hold about you, correct it, or delete it, and we will answer within 30 days. Many of these you can do yourself:
- Organisers can edit or delete a mission from the app, and can ask us to delete their account by writing to us from the account's email address.
- Co-conspirators can edit or withdraw a greeting from the same device — or from another device using the personal link shown after sending — until the organiser approves it. After that, ask the organiser, or write to us.
- The Special Person did not sign up for any of this. If a page about you exists and you would like it — or a particular greeting on it — taken down, write to us and we will remove it and inform the organiser. You do not need an account.
- Anyone who believes a greeting contains their personal information, image or work without permission can ask for it to be removed (see the takedown process in the Terms).
We give these rights to everyone, wherever you live. The law where you are — the GDPR in the European Economic Area and the UK GDPR, India's Digital Personal Data Protection Act, the CCPA in California, Australia's Privacy Act, Vietnam's personal-data decree, among others — may give you more, such as the right to object to processing, to receive a copy of your data in a portable format, or to complain to a data-protection authority. Where it does, we honour it. privacy@allinonit.com is the contact for all requests and grievances.
8. Children
You must be at least 18 to create an account and organise a mission. Missions are often about a child — a daughter's birthday, say — and that is fine: the organiser must be the child's parent or guardian, or have their permission, and is responsible for what is collected and shown. We do not knowingly collect personal data from children directly; if you believe we have, tell us and we will delete it.
9. How we protect it
- Everything travels over HTTPS. Cookies are marked secure and cannot be read by scripts.
- Page passcodes are stored only as salted hashes; co-conspirator tokens are stored only as hashes.
- Page and mission addresses are long random tokens (128 bits or more) — not guessable, not listed anywhere.
- Photos and videos live in private storage and are served through the app, never from a public bucket.
- Secrets live in the hosting platform's secret store, never in code.
10. Changes to this policy
We will update this page when the service changes — for example when paid missions or store apps arrive — and change the date at the top. For material changes we will tell signed-in organisers by email or in the app before they take effect.
11. Contact
Privacy questions, deletion requests and complaints: privacy@allinonit.com. We reply to every message.