Safety & trust
Privacy Policy
This policy explains what OnTheFarm collects through its iOS app and website, why we use it, when it reaches a service provider, and the controls available to you.
First-release scope: paid ticket sales and Apple Pay checkout are not enabled in the current release. OnTheFarm may link to a separate event seller, whose own privacy policy applies when you leave OnTheFarm.
1. Scope and contact
OnTheFarm ("OnTheFarm," "we," or "us") operates the OnTheFarm iOS app and onthefarmapp.com. OnTheFarm is a Stanford-first campus events and social-planning service.
Privacy questions and requests can be sent to [email protected] or mailed to:
OnTheFarm#1331
700 El Camino Real, Suite 120
Menlo Park, CA 94025
United States
2. Information we collect
| Category | Examples | How it is provided |
|---|---|---|
| Account and identity | Name, email address, account identifier, sign-in provider, and a password-derived credential when email/password sign-in is used | From you or the Apple or Google sign-in method you choose |
| Profile and preferences | Avatar, cover photo, pronouns, bio, major, interests, school affiliation, feed choices, and privacy settings | From you |
| Content and communications | Events, RSVPs, saves, invitations, posts, comments, reactions, polls, reviews, reports, direct messages, group activity, photos, and videos | From you and people who interact with you |
| Location | Precise or approximate coordinates, selected search area, and a last-known location used for nearby results | From your device after permission or from a location you choose |
| Search and product activity | Searches, filters, event interactions, feature use, and recommendation feedback | From your use of the service |
| Device, network, and diagnostics | App and OS version, device model, IP/network metadata, push or pass registration tokens, screen context included with a bug report, and reliability or security events | Automatically or when you submit a report |
| Advertising data, when ads are enabled | Consent state, device or advertising identifiers made available by the platform, coarse location, ad impressions, and product interactions | From the app, device, and Google advertising components |
A bug-report screenshot is attached only when you choose to include it. The report screen lets you review and remove the screenshot before sending.
3. Permission-based features
OnTheFarm requests a system permission only when a feature needs it. You can decline or later revoke a permission in Settings.
- Location. When-in-use location centers maps, measures distance, and supports nearby recommendations. If you separately enable Always Location for ambient discovery, iOS may deliver low-power significant-location changes and visit events while the app is not open. OnTheFarm does not run continuous precise background GPS tracking.
- Photos and camera. Used for images you select or capture for flyers, profiles, event albums, messages, and bug reports, and for QR scanning. An image is saved to your library only when you choose that action.
- Calendar. Calendar events are read on your device to calculate whether a time is free. Event titles and calendar contents are not uploaded for that availability check. OnTheFarm writes an event only after you choose Add to Calendar.
- Apple Music. On your request, the app searches Apple's catalog and stores selected track metadata with an event. Subscription eligibility is checked on device; OnTheFarm does not store your Apple Music subscription status.
- Local network and Bluetooth. Nearby Friends uses peer-to-peer discovery only while that feature is active. Devices advertise an ephemeral peer name and short-lived server-issued discovery token, not a person's name, email, location, contacts, or profile. The server resolves a selected token after account and block checks.
- Motion. Device tilt can drive artwork depth effects. Motion readings stay on the device.
- Notifications and Live Activities. Used for event, message, safety, and time-sensitive updates you enable. Device tokens are associated with the account or activity needed to deliver them.
4. How we use information
- Provide accounts, events, maps, searches, RSVPs, saves, invitations, messages, groups, eligible passes, and support.
- Personalize event and place recommendations using the interests, searches, feedback, and location context you choose to provide.
- Send service messages, event updates, security notices, and notifications you request.
- Detect abuse, investigate reports, enforce our Terms, protect accounts, and maintain service integrity.
- Diagnose failures, measure feature performance, and improve accessibility and reliability.
- Comply with law and respond to valid legal process.
5. Sprout AI and automated moderation
When you choose a Sprout or AI-assisted feature, OnTheFarm may send your prompt, bounded event context, selected search area, public-source excerpts, or an image or event email you submit to configured AI providers. These features support event discovery, flyer extraction, search, summaries, and recommendations.
User content that is reported or otherwise screened for policy violations may be classified automatically. An authorized human reviewer controls final content-removal, restriction, and appeal decisions; automated classification is not the final enforcement decision.
Optional AI personalization and AI-data sharing are separate from accepting the general policies. See the AI and Sprout Disclosure for feature limits and the kinds of context that should not be included.
7. Advertising and tracking
The iOS app includes Google advertising and consent components. Production ad requests remain off unless a release has valid production configuration and any required consent choice has been resolved. When ads are enabled, OnTheFarm requests non-personalized ads and labels advertising as Ad, Advertisement, or Sponsored.
OnTheFarm does not ask for Apple's AppTrackingTransparency permission and does not use your activity to track you across other companies' apps or websites. Available advertising privacy choices can be reviewed in the app's privacy settings.
8. Public, group, and private content
Your visibility choices affect who can see content. Public events, public profiles, reviews, and Global posts may be visible broadly. Group content is visible according to group membership and role rules. Private invitations and direct messages are intended for their recipients, but recipients can copy or share what they receive. Do not post information you do not have permission to share.
9. Retention and account deletion
We keep account information while the account exists and retain content and service records for as long as needed to provide the feature, protect the service, resolve disputes, or comply with law. Retention varies by record and context; this policy does not promise one fixed period for every category.
You can delete your account from Profile โ Settings โ Delete Account. The authenticated deletion workflow removes account-owned profile, relationship, message, event, pass, notification, verification, report, and owned-media records covered by that workflow. Shared records may be removed, anonymized, or disconnected from your identity where needed for another user's conversation, aggregate attendance, fraud prevention, safety, dispute resolution, security, or legal obligations. See the Account Deletion page for the current workflow.
10. Your choices and rights
- Update profile, discovery, notification, AI, and advertising choices in the app.
- Use iOS Settings to revoke location, photos, camera, calendar, Bluetooth/local network, motion, or notification access.
- Delete content where the feature provides a delete action, block another account, or delete your account.
- Request access, correction, deletion, or export by emailing [email protected]. We may need to verify the request before acting.
Depending on where you live, additional rights may apply, including rights to object to or restrict certain processing. We will not discriminate against you for exercising an applicable privacy right.
11. Children
OnTheFarm is not directed to children under 13, and we do not knowingly collect personal information from a child under 13. Contact [email protected] if you believe a child under 13 provided information to OnTheFarm.
12. Security
OnTheFarm uses HTTPS/TLS, access controls, server-side authorization, and other administrative and technical safeguards intended to protect information. No system or transmission method is completely secure, so we cannot guarantee absolute security. Report a suspected vulnerability privately to [email protected]; do not include passwords, secrets, payment credentials, or another person's private data.
13. Changes to this policy
We will update the Last updated date and document version when this policy changes. For a material update, OnTheFarm may provide an in-app notice and ask signed-in users to review the current policy. Acceptance records include the policy type and version, acceptance state and time, locale, and client platform. Optional marketing, AI-sharing, and advertising choices remain separate.
Contact
- Privacy requests: [email protected]
- Safety reports and moderation appeals: [email protected]
- Security reports: [email protected]
- Copyright notices: Copyright and DMCA Policy