SlidThru

Privacy Policy

Last updated: 9 September 2026

SlidThru is an app for telling your friends where you'll be and when. This policy explains what we do with your information. It is written to be read, not to be skimmed past.

The short version. We collect what we need to run the app and nothing else. Almost everything you post is visible only to friends you have accepted. There is no advertising and we never sell your data or share it for marketing. We do use one analytics service, PostHog, hosted in the EU, to see which actions people take in the app: sending an invitation, answering one, turning up. It records nothing about what you look at, nothing you type, and no information about your device, and it is off unless you turn it on in Settings. The app never asks for your location. You can delete your account from inside the app: you disappear straight away, and everything is erased for good 30 days later — time enough to change your mind.

1. Who is responsible for your data

SlidThru is run by an independent sole trader based in the United Kingdom. Under UK data protection law, we are the "data controller" for the information described here.

For anything to do with privacy, email help@slidthru.com. A real person reads it.

This policy is governed by the UK GDPR and the Data Protection Act 2018.

2. What we collect and why

Your account

To sign up you give us an email address and a password. We never see your password in readable form. It is stored as a cryptographic hash. We send a confirmation email and you have to click the link before the account works.

There is no social login.

Your contacts. SlidThru can show your contacts so you can pick who to invite, and only if you allow it. That happens entirely on your phone: the list is read on the device, shown to you, and used to open your own Messages or Mail app with an invite already written. We never upload your contacts, never store them, and never match them against anyone. Nothing about your address book reaches our servers, so there is nothing about it for us to keep, lose or hand over. You can refuse, and everything else in the app works exactly the same.

We could not match your contacts to other people here even if we wanted to: we do not hold anybody’s phone number. Signing up asks for an email, a handle, a password and a date of birth, and that is all there is on file.

Your profile

A username and display name are required. Optionally you can add a bio (up to 300 characters), an avatar photo, and up to 10 interests chosen from a list or typed in yourself. The optional parts are entirely up to you. The app works without them.

Your friends and circles

Friendships are mutual. Someone sends a request, the other person accepts, and only then are you connected. We store who is friends with whom, and the circles you create. A circle is a private named group of your own friends. Nobody else can see your circles.

Plans, events and nudges

Settling up between friends

If you split a bill or chip in for a booking, we store the amount, who owes what, and whether it has been settled. You can also save a payment handle, so friends know where to send your share. A handle can be a Monzo, Revolut or PayPal username, or a sort code and account number.

SlidThru never handles the money. We do not process, hold, transmit or refund payments, and we never see your card details. Paying happens in your own bank or payment app; all we record is that somebody says it happened.

A payment handle you save is not shown on your profile and not visible to your friends. It is disclosed to somebody who owes you on a specific split, at the moment they go to settle it, and it stops being shown once that share is settled. Where the person who owes you is not on Slidthru, that means a web link: the link carries your payment handle, and your sort code and account number if you saved them, so anybody the link is forwarded to can read them too. Send it to the person who owes you and nobody else. Who has and has not paid is visible only to the person owed and to each person for their own share; it is never shown to the group.

Deleting a split, a share, your payment handles or your account removes this data.

Photos and memories

Your avatar, a plan photo, an event cover image and a memory are all stored as files in our hosted storage. Memories can only be posted by people who actually attended the plan or event, and only people who could see that plan or event can find them inside the app.

The file itself sits behind a long, unguessable web address rather than one that requires you to be signed in — that is what lets the app show it quickly. Anybody who is given that exact address, including a messaging app's own link-preview service when a photo is shared as part of an invite, can load the file directly. Treat a photo the same way you would treat the link to it: nothing stops it travelling further than the people you meant to show it to, if the link itself is forwarded on.

We do not scan photos, we do not run face recognition on them, and we do not use them to train anything. If a photo carries a timestamp from the camera that took it (EXIF data), we read only that timestamp, to check it was taken during the plan you are adding it to — everything else in the file's metadata, including any location the camera recorded, is discarded when the photo is re-encoded for upload.

Venue highlights

You can post a photo and a short caption to a venue's own page, if you have actually been there. Unlike a memory, this is deliberately public: it is the one kind of content in SlidThru visible to every signed-in account, not only your friends, because it is about the venue rather than about a plan you shared with anyone in particular. Do not post anything here you would not want a stranger to see attached to your name.

Guests who RSVP through an event link

An event link can be shared with people who do not have SlidThru. If someone opens that link and RSVPs on the web page, the only thing they give us is a display name. No email, no password, no account, no profile. That name is shown on the guest list of that one event and is used for nothing else.

Push notifications

If you allow notifications, your device gives us a push token, an identifier for that device, which we store so we can deliver notifications. Turn notifications off in your phone's settings and we stop sending them.

Venues, and why we never ask for your location

Discover contains a directory of real Manchester venues, chosen and described by us. Venues are identified by name and by area ("Ancoats", "Northern Quarter"), which you pick from a list.

Those venues have map coordinates, which we looked up ourselves from an open dataset and store against the venue. That is how a plan with several stops can show you the places on a map. The coordinates belong to the building, not to you: they are the same for everybody, they are there whether or not anybody ever visits, and nothing joins them to a person.

The app never reads your location. There is no location permission request anywhere in SlidThru, and no location tracking of any kind. The map shows where the venues are; it does not show where you are, and it cannot, because we never ask.

When you are free, and when you are usually about

There are two separate things here, and both are things you type rather than things we observe.

A free window is you saying "I'm about tonight". It is a start time, an end time, and optionally a short note in your own words. Your accepted friends can see it. It disappears from the app the moment it has passed, and the row is deleted for good within seven days. It is a sentence you said once, not a record of your evenings.

A rhythm is you saying which days and which halves of the day you are usually free: "Thursday evenings", "Saturday daytimes". It is a standing statement, visible to your accepted friends, and it does not expire because it is not about any particular week. You set it on your own profile and you can change or clear it whenever you like.

Neither is inferred. We do not work out when you are free from how you use the app, where you have been, or when you are on your phone. The app never publishes a free window on your behalf: a rhythm can prompt you to confirm you are about, and confirming is always a tap you make yourself.

Your calendar, if you connect it

There is a switch in Settings called Share when I'm busy. It is off, and nothing below happens unless you turn it on.

If you do, SlidThru reads your phone's calendar for the next fortnight and works out the blocks of time you are already committed. Only those blocks leave your phone: a start and an end, and whether it covers a whole day. Never the title. Never the location, the notes, the other people invited, which calendar it came from, or anything that could be matched back to a particular appointment. Your friends see that Thursday evening is spoken for; they cannot see what for, and neither can we, because we were never sent it.

The narrowing happens on your phone, before anything is sent. Apple does not offer an app a way to see only whether you are busy: it is the whole calendar or nothing. So SlidThru asks for the whole calendar and immediately throws away everything except the times. That is a promise about our code rather than a limit Apple imposes, which is why it is written here.

It expires, like a free window does. A block disappears once it has passed, and we delete it. What is stored is only the part of the near future you chose to publish. Never a history of where your evenings went.

Turning the switch off deletes all of it, immediately, and nothing is read again until you turn it back on. Revoking calendar access in your phone's own settings has the same effect: there is nothing left to read, so nothing gets refreshed.

This is the one thing in SlidThru that starts from something you already keep rather than something you typed here. It is still yours: you connect it deliberately, you can see what your friends can see, and you can end it in one tap.

Messages

You can message a friend directly, and there is a conversation attached to every plan, event and circle you can see. We store what you send, who sent it, and when, because a message nobody stored is a message that does not arrive.

A direct message is visible to the two of you. A conversation on a plan, an event or a circle is visible to exactly the people who can see that plan, event or circle, and to nobody else. We do not read your messages, we do not scan them to target anything at you, and they are never sent to the analytics service.

We also keep a marker of when you last opened each conversation, which is the only way the app can show you that something is unread.

Deleting your account deletes your messages.

Reports and blocks

If you report something, we store who you are, what you reported, the reason you chose and any note you added, so the report can be acted on and so someone cannot flood the same complaint. If you block someone, we store that the block exists, in one direction only — the person you blocked is never told and cannot see that a block exists. A report or a block is visible to you and, for reports, to the person handling it. It is never shown to the person it is about.

Searching for a venue

When you search for a place that is not already in our directory, we may ask a third-party places provider on your behalf, through our own server rather than directly from your phone, so that provider never sees who you are. We keep a count of how many searches you make each day, to stay within that provider's usage limits. We do not keep what you searched for — only that a search happened.

A few smaller things

Times you said work for you. When somebody offers two or three possible times for a plan, the ones you tick are stored against your account and shown to everybody else who can see that plan. That is the whole point of asking.

Your birthday, if you add one. The day and the month only, never the year, so nobody learns your age. Like the rest of your profile (section 5), the day and month themselves are readable by any signed-in account — the "coming up soon" prompt friends actually get is narrowed to your accepted friends, as a design choice rather than as a limit on who could otherwise read the date. You can clear it whenever you like.

Whether you turned up. If you tap "I'm here" at a plan, we store that you did. It is what makes the app able to tell you who you actually see rather than who you agree to see.

Product analytics

We use PostHog, on their EU servers, to understand whether the app does the thing it exists to do. It receives a short, fixed list of actions: you sent an invitation, somebody answered one, a plan was posted, you said you had arrived. Each one is sent with your account's random identifier, so that a sequence of actions can be followed through.

What it never receives: anything you typed, including plan titles, notes, names and messages; which screens you opened or how long you spent on them; which venues or people you looked at; and any information about your phone. No model, no operating system, no language, no advertising identifier.

The list of actions is written into the app by hand rather than collected automatically. There is no session recording, no heatmaps and no autocapture.

It is off until you turn it on. Settings → Improving the app. Until you do, nothing at all is sent for you. Turning it back off stops it again immediately, and deleting your account also asks PostHog to delete everything held against your identifier.

Counting how the app is doing

Once a night we work out a handful of totals for the previous day: how many people did anything at all, how many plans were made, how many invitations were answered. We store those numbers on their own. They are totals, not lists: they say "six people did something", never who, and they are worked out from the plans and replies that already exist rather than by watching anybody.

We also record which of your friends you have actually been out with, taken from plans and events you both said yes to and that have already finished. That is what lets the app offer to arrange the same night again. It is built from things you had both already published to each other. Nothing here is sensed: the venue is whichever one the person making the plan chose, and the app never reads your location. It does add up over time into a record of where you go, which is what the places grid on your profile shows, so we describe it as one rather than claim otherwise.

Your notification settings

If you turn off a kind of notification, we store that choice so we can honour it. It is visible only to you, not to your friends, and not to whoever would otherwise have been notified.

Popularity counts

Discover shows aggregate counts of what is popular among your friends, and an app-wide popularity view. The app-wide view is anonymised and only ever shows something once at least three different people are involved, so it cannot point back at an individual.

Technical and security records

Our hosting providers keep limited server and authentication records, so we can keep accounts secure and investigate abuse. Those records hold things like the time of a sign-in attempt and an IP address. These are kept briefly and are not used to build any profile of you.

3. What we do not do

4. Our lawful basis for each use

UK GDPR requires a lawful basis for every use of personal data. Here is ours, in plain terms.

WhatWhyLawful basis
Email, password, confirmationTo create and secure your accountPerformance of a contract (our terms with you)
Username, display nameSo friends can find and recognise youPerformance of a contract
Bio, avatar, interestsOptional profile details you choose to addPerformance of a contract
Friend requests, friends, circlesTo run the friend-graph that controls who sees whatPerformance of a contract
Plans, events, nudges, replies, commentsThe core purpose of the appPerformance of a contract
Venues you have been to, and how oftenTo show on your profile where you go, so a friend can suggest somewhere you would actually wantPerformance of a contract
Settling up (amounts, who owes what, payment handles)To let you split a bill with friends and show them where to send itPerformance of a contract
Where you have been, the places gridNothing is stored for it. It is worked out from your plans and events each time it is opened, so it shrinks as they do and it is gone when they are
Photos and memoriesTo show them to the people you chosePerformance of a contract
Transactional email (confirmation, password reset, invite)To make the account usablePerformance of a contract
Push token and notificationsTo tell you about invites and repliesConsent: given through your device, withdrawable at any time
Free windows and rhythmsTo let your friends know when you are around, so plans can actually happenConsent: you publish each one yourself, and can remove it at any time
Busy times, if you connect your calendarTo let your friends see when you are already committed, without seeing what toConsent: the switch is off until you turn it on, and turning it off deletes everything already shared
Notification settingsTo send you only what you have asked forLegitimate interests: honouring a preference you set
Daily totals about the appTo know whether the app is doing the thing it exists to doLegitimate interests: totals only, never a profile of anyone
Which actions you take, sent to PostHogTo see where the app helps people meet up and where it gets in the wayConsent: off by default, and only ever sent once you turn it on in Settings
Who you have been out withTo offer to arrange the same night againLegitimate interests: derived from plans you both accepted
Guest display name on a web RSVPSo the host can see who is comingLegitimate interests: running an invite the host deliberately shared, using the minimum possible information
Aggregate popularity countsTo make Discover usefulLegitimate interests: the app-wide view is anonymised and suppressed below three people
Security and abuse-prevention recordsTo keep accounts safeLegitimate interests: protecting users and the service
Responding to legal requests, keeping required recordsBecause the law says soLegal obligation

Where we rely on legitimate interests, we have weighed our interest against your rights and kept the data to a minimum. You can object at any time. See section 10.

5. Who can see your content

This is the part most people care about, so it is set out plainly.

6. Who we share data with

We use a small number of companies to run the service. They are our "processors": they act on our instructions, under a written contract, and may not use your data for their own purposes.

CompanyWhat they do for usWhere
SupabaseDatabase, sign-in and authentication, and file storage for photosEuropean Union (eu-west-1)
Expo / EASBuilding the app and delivering push notificationsUnited States
ResendSending transactional email: confirmations, password resets, invitesUnited States
VercelHosting the public web page where guests RSVP, and these documentsUnited States, with global edge delivery
PostHogProduct analytics: which actions people take in the appEuropean Union
AppleDrawing the map on a plan with several stops. Your device asks Apple for the map of that area; we send Apple nothing about you, and no account identifier is attachedUnited States

That is the full list. There is nobody else.

We may also disclose data if we are legally required to (for example a valid court order), or where it is necessary to protect someone's safety. If that ever happens we will tell you unless we are legally forbidden from doing so.

If SlidThru is ever sold or transferred to another business, your data would move with it. We would tell you before that happened and this policy would continue to apply until you were given a new one.

7. Sending data outside the UK

Your account data, your content and your photos are stored on servers in the European Union. The UK Government recognises the EU as providing an adequate level of protection, so no extra safeguard is needed for that transfer.

Push notifications, transactional email, the public event page and the map involve providers in the United States. For those transfers we rely on the UK International Data Transfer Addendum to the EU Standard Contractual Clauses (or the UK IDTA), which are contracts approved for this purpose, together with the providers' own encryption and access controls.

You can ask us for a copy of the safeguards we use. Email help@slidthru.com.

8. How long we keep things

WhatHow long
Your account, profile, friends and circlesUntil you delete your account, plus the 30 days you have to undo it
Plans, events, nudges, replies and commentsUntil you delete them, or until you delete your account
Settling up records and payment handlesUntil you delete the split or your handles, or until you delete your account
Photos and memoriesUntil you delete them, or until you delete your account
Venue highlights (photo and caption)Until you delete the highlight, or until you delete your account
Reports and blocksReports are kept for as long as needed to act on them and to spot repeat behaviour; a block lasts until you undo it
Daily venue-search countsKept only as a per-day count, with nothing about what was searched
Push tokenUntil you turn notifications off, sign out, or delete your account
Free windowsHidden from everyone the moment the window passes, and deleted within 7 days
Busy times from your calendarOnly ever the next fortnight. Deleted as each block passes, and all of it deleted the moment you turn the switch off
Rhythms and notification settingsUntil you change them, or until you delete your account
Daily totals about the appKept indefinitely. They are counts and contain no personal data
Action records at PostHog12 months, and deleted sooner if you switch analytics off or delete your account
Who you have been out withUntil you delete your account, which removes your side of it
Guest display name from a web RSVPUntil the host deletes the event, and in any case no more than 12 months after the event has finished
Transactional email delivery recordsUp to 30 days at our email provider
Security and authentication recordsUp to 90 days, unless we need them longer for a specific abuse investigation
Encrypted backupsDeleted data disappears from backups within 30 days of the erasure, as backups roll over

9. Deleting your account

You can delete your account from inside the app, on your own, without emailing anyone. Deleting it removes your profile, your photos and avatar, your plans, your events, your nudges, your memories, your friendships, your circles, your replies and comments, and your push token.

You disappear straight away, and the data is erased 30 days later. The moment you confirm, you are signed out and your account is gone as far as everybody else is concerned: nobody can search for you, you are suggested to no one, you leave your friends' lists, nothing you posted is visible any more, and links to your plans stop working. Thirty days after that, everything above is permanently erased by an automatic nightly job — not by anyone reviewing it, and not on request.

Those 30 days are yours to change your mind in, and nothing else. Signing back in during the window reaches one screen, which offers to bring the account back or to sign out. There is no usable app behind it. If you bring it back, everything returns exactly as it was, because nothing had been erased yet. If you do nothing, it goes.

Encrypted backups roll over within 30 days of the erasure, after which the data is gone from those too.

Two honest caveats. If you commented on a friend's plan, that plan still belongs to your friend, and comments attached to it are removed with your account. And if someone else took a photo at an event you attended, that photo is theirs and stays with the event. Deleting your account does not delete other people's content.

If you would rather we did it for you, email help@slidthru.com from your account address and we will.

10. Your rights

Under UK GDPR you have the following rights. They are free to use, and we will respond within one month.

To use any of these, email help@slidthru.com. We may need to check you are who you say you are before we act, usually by asking you to write from the email address on the account.

If you RSVPed to an event as a web guest and want your display name removed from that guest list, email us with the event link and the name you used, and we will remove it.

11. Complaining to the ICO

If you think we have handled your data badly, please tell us first. It is usually the fastest way to fix it. But you have every right to go straight to the regulator.

The UK regulator is the Information Commissioner's Office (ICO).

Complaining to the ICO does not stop you from also taking your own legal action.

12. Keeping data safe

Data is encrypted in transit and at rest. Passwords are hashed, never stored in readable form. Access to the database is controlled by row-level security rules that enforce the friend-graph, so the visibility described in section 5 is applied by the database itself and not just by the app on your phone. Only the developer has administrative access, protected by multi-factor authentication.

No system is perfect. If a breach happens that is likely to put your rights at risk, we will report it to the ICO within 72 hours and tell you directly without delay.

13. Children

SlidThru is for people aged 16 and over. Signing up asks for a date of birth, checked once on your device to confirm you meet that floor — we do not keep it, and it never leaves your phone as a date, only as a pass or fail. If you believe a child has an account despite that, email help@slidthru.com and we will delete it.

14. If you are in the United States

SlidThru is a UK company and this policy is written under UK law, but the App Store makes the app available worldwide, so this section speaks to United States residents directly.

We do not sell your personal information, and we do not share it for cross-context behavioural advertising, as those terms are used in US state privacy laws (including the CCPA/CPRA). Section 2 above lists every category of personal information we collect and section 6 lists every company we share it with, none of whom uses what we give them for their own advertising.

You have the same practical rights described in section 10 regardless of where you live: you can ask us what we hold about you, ask us to correct or delete it, and object to how we use it. Email help@slidthru.com and we will act on it the same way for everyone, not only where a specific law requires it.

15. Changes to this policy

If we change something meaningful, we will update the date at the top and tell you in the app before the change takes effect. That includes a new processor, a new use of your data, or a change to who can see what. We will not make a quiet change and hope you miss it.

Contact

Email: help@slidthru.com
SlidThru is operated by a UK-based sole trader. A postal address is available on request.