Privacy Policy
Effective: September 7, 2026. Previous version: August 22, 2026.
Dizko ("we", "our", "the app") helps you discover events through a live event map, recommendations, profiles, and conversational search. This policy explains what data we collect and how we use it.
What We Collect
- Identifiers - Device ID, user ID, session tokens, and related identifiers used to keep you signed in, secure your account, save preferences, and maintain app functionality.
- Phone, email, and Apple identity - Phone number, email address, Apple account identifier, verification status, and related authentication details when you choose to add or verify them.
- SMS concierge information - If you text the Dizko SMS Concierge, we collect your mobile number, message content, delivery status, timestamps, consent and opt-out records, event preference signals, and related conversation state needed to answer your request and operate the service. If you explicitly ask Dizko to remember something, we may also store an encrypted preference record linked to a hashed form of your mobile number. This may include event tastes or accessibility needs you choose to provide, including needs that apply when you are with a companion.
- Profile information and uploads - Display name, username, bio, social links, avatar images, event flyers, and other media or profile content you choose to provide.
- AI discovery chat - Prompts and related conversation context you send to the event-discovery assistant. These prompts may be processed by Groq to understand your request and find matching events.
- Private messages - Message text and event notes are end-to-end encrypted on your device. We store ciphertext plus the conversation members, timestamps, event references, votes, delivery state, and other metadata needed to deliver messages and coordinate plans. If you report a message, its text is shared with moderators only when you explicitly choose to attach it.
- Preferences and activity - Selected city, genres, vibes, saved events, RSVPs, hidden events, training responses, recommendation signals, ticket-link opens, profile interactions, and other product interactions used to operate and personalize the app.
- Agent connector preferences and feedback - If you use the Dizko Events connector in ChatGPT, Claude, or another MCP-compatible assistant and agree to save preferences, we may store a profile identifier, hashed profile secret used to protect access, event preferences, liked or disliked event feedback, ratings, notes you choose to provide, event IDs, timestamps, derived taste signals, learned avoid signals, and personalization summaries used to explain and improve future recommendations.
- Location - Approximate location such as your selected city or nearby event area, and precise location only when you allow iOS location access, used to show nearby events and map results.
- Analytics and diagnostics - App usage events, feature interactions, device/app environment, error reports, and performance signals used to understand and improve app reliability and discovery quality.
- Support and safety reports - Messages you send to support, abuse reports, blocked-user information, and related details needed to review, respond to, and protect the service.
- Artist accounts and pages - If you build an artist page, the email address and name your sign-in provider returns when you sign in with Google, Apple, or an emailed code, and everything you put on the page: your name, city, biography, portrait, links, dates, press clips, and products. We also read your public artist profile as Dizko already holds it, and what SoundCloud, Resident Advisor, Apple Music, Deezer, and Spotify publish about you, and offer it to you to confirm or reject before any of it is used.
- Artist verification - Whether you have proved the streaming account behind your page, so that somebody else cannot publish a page as you.
- Mailing list subscribers - If you join an artist's mailing list from their page, your email address, the artist and page you joined from, the time you joined, and your city when you ask to hear about dates near you.
- Press desk drafts - The source material you type into the press release writer, and the draft it produces.
How We Use Your Data
- To find and recommend events matching your preferences
- To remember event preferences and accessibility needs you ask us to save, apply short-lived outing context, learn from post-event feedback you choose to provide, steer away from disliked event traits, and improve personalized event recommendations
- To maintain your session, profile, saved events, RSVPs, messages, uploads, and app preferences
- To verify phone, email, or Apple identity when you choose to use those features
- To measure app performance, fix bugs, and improve the event discovery experience
- To provide support, safety review, and abuse prevention
Third-Party Services
- Groq - Processes limited prompt, conversation context, and active user-controlled preference context from the AI discovery chat and SMS Concierge using selected AI models, currently including Qwen. Dizko does not send mobile numbers to the AI model. Private person-to-person messages are not sent to Groq. Groq also completes press release drafts from the source material an artist types into the press desk. We do not use any of it to train a model and have not agreed to let anyone else do so. Groq Privacy Policy
- Twilio - Delivers SMS and MMS messages for the Dizko SMS Concierge and processes mobile numbers, message content, delivery records, and consent commands for that purpose. Twilio Privacy Notice
- Apple - Provides Sign in with Apple in the iOS app when you choose that login method.
- Hosting, storage, verification, and analytics providers - Help us run the backend, store uploaded media, deliver verification messages, analyze app usage, and respond to support requests. These currently include Vercel and Railway for hosting, Resend for sending sign-in codes, confirmations, and digests, and Sentry for error diagnostics. Sentry receives no IP addresses or request headers from the artist tools: that is switched off deliberately.
- Google - Provides Sign in with Google when you choose that login method for the artist tools.
- Resident Advisor, Dice, Eventbrite, and local sources - Sources of event data displayed in the app.
SMS Privacy
We use mobile information from the Dizko SMS Concierge to understand and answer the event requests you send, apply context for the current outing, remember preferences only when you ask us to save them, deliver and troubleshoot SMS or MMS replies, honor consent choices, prevent abuse, secure the service, and provide support. Dizko never initiates an SMS conversation. Every reply is triggered by a message you send, and we do not run SMS broadcasts or marketing campaigns.
We do not share mobile information, including phone numbers and SMS consent records, with third parties or affiliates for marketing or promotional purposes. Service providers may process mobile information only as needed to deliver and operate the concierge on our behalf. They may not use that information for their own marketing.
Message frequency varies based on the requests you send. Message and data rates may apply.
You can say REMEMBER with a preference to save it, ask WHAT DO YOU REMEMBER? to review active memory, or say FORGET with a topic to remove that memory. Reply STOP to opt out, START to opt back in, HELP for help, or DELETE to erase your Dizko SMS conversation history and saved memory. Carrier records may be retained according to the carrier's own policies.
Artist Mailing Lists
When you submit your address to an artist's signup form, it goes two places. It goes to the artist, who holds their own mailing list and can export it. It also goes to Dizko, who send the one confirmation email and, when you ask to hear about dates near you, a digest for your city led by that artist. Both are named under the field before you type, and you can leave either at any time from the link in the email or by writing to privacy@dizko.app.
Once your address is on an artist's own list, the artist decides what they send you and is the data controller for it, not us. Our Terms require them to send only what you signed up for, to honour an unsubscribe, and never to sell or pass on the list, and we will act on a complaint and can remove their signup block, but for what they send you they answer. Their contact details are on their page.
Dizko's own list is double opt-in: nothing is sent until you confirm from the email, and an address that never confirms is not mailed.
What We Don't Do
- We do not sell your data to third parties
- We do not track you across other apps or websites
- We do not require your name, email, phone number, profile photo, or precise location to browse events
- We do not use your data for advertising
- We do not use AI discovery prompts or private messages for AI model training by Dizko
- We do not include private message text in notifications
Your Choices
- You can browse events without granting precise location access. You can change location permission in iOS Settings.
- You can edit your selected city, preferences, saved events, RSVPs, profile fields, and uploaded avatar from the app where those controls are available.
- You can choose not to verify a phone number or email address unless a feature requires verified identity.
- You can avoid the AI discovery chat if you do not want prompts processed by our AI provider.
- You can control who may start a private conversation. Clearing browser storage or removing a device encryption key may make older encrypted messages unavailable on that device.
- You can decline preference saving in agent connectors. If you previously saved connector preferences, you can ask the assistant to delete your event preferences, or contact support for deletion help.
- In the SMS Concierge, you can inspect or remove saved memory by text. Dizko does not infer accessibility needs from a companion's age, relationship, or identity.
Data Retention
We keep account, device, profile, upload, encrypted message, message metadata, preference, saved-event, RSVP, recommendation, analytics, connector preference, feedback, and support data while your account or connector profile is active or as needed to operate, secure, improve, and support the service. SMS message bodies are normally deleted after 7 days, and SMS conversation state is normally deleted after 30 days. Encrypted SMS outing context expires after 36 hours. Encrypted SMS memory you explicitly ask us to save is normally deleted within 365 days after its last update, or earlier when you remove it with FORGET or DELETE. Encryption private keys for private person-to-person messages stay on your device. Support requests, safety reports, and message text you explicitly attach to a report may be retained as needed to resolve the issue and protect the service.
If You Are in the EU or the UK
Dizko is a United States company, and a large part of the people who use it are in Europe. That means the GDPR and the UK GDPR apply to us directly, and this section says what follows from that.
Why we are allowed to hold your data. For your account, your page, and anything you asked us to do, because we cannot provide what you asked for without it (Art. 6(1)(b)). For a mailing list, because you consented by submitting the form after reading the notice under it (Art. 6(1)(a)). For filling an artist page in from public profiles, for verification that stops impersonation, for diagnostics, and for abuse prevention, because we have a legitimate interest in the product working and not being abused, weighed against your interests (Art. 6(1)(f)). We do not use your data for advertising and we do not sell it.
Your rights. You can ask us for a copy of what we hold about you, ask us to correct it or delete it, ask us to restrict or stop what we do with it, and ask for it in a portable form. Where we rely on consent you can withdraw it at any time, and withdrawing it does not undo what we did before. Where we rely on legitimate interests you can object, and we stop unless we have grounds that override yours. Write to privacy@dizko.app and we answer within one month.
Where your data goes. We are in the United States, and so are our providers. For providers we rely on the European Commission's standard contractual clauses, or on the provider's certification under the EU-US Data Privacy Framework where it holds one.
Complaints. You can complain to the data protection authority where you live. In the United Kingdom that is the Information Commissioner's Office.
Our representative in the EU. [TO CONFIRM: name and address of the representative appointed under GDPR Art. 27. A company outside the EU that offers services to people in the EU must appoint one in writing and publish who it is.]
Access, Deletion, and Support
You can delete your account data at any time. On Android, open You and select Delete account. On iPhone, use the account deletion control in your profile. This removes the account tied to your device or verified profile from our active servers, including profile details, saved events, RSVPs, recommendations, and preferences. In agent connectors, you can ask the assistant to delete your event preferences, which removes saved connector preferences and feedback for that connector profile. If you cannot access the app or connector, email us from the address connected to your account, if any, and describe the device, profile, or connector profile you want deleted.
Children
Dizko is not for people under 16. We do not knowingly hold data about anyone younger, and we delete it when we find it.
Contact
Questions about this policy? Email us at privacy@dizko.app