Effective March 16, 2026
foobos (“we,” “us,” “our”) operates the website foobos.net and the foobos mobile app (together, “the Service”). This policy describes what information we collect, how we use it, and your choices.
When you create an account, we collect your email address and a password (stored as a one-way hash — we never store your actual password). You may optionally provide a display name (username) and a zip code. If you sign in with Apple, we receive your name and a verified identity token from Apple; we do not receive your Apple ID password.
You may upload a profile photo. Before uploading, the photo is analyzed on your device using Apple’s content-moderation framework to block sensitive content — this analysis happens entirely on your device. The photo is then compressed and uploaded to our servers (Cloudflare R2 storage) and stored as a JPEG file associated with your user ID. Your profile photo is visible to other users (e.g., in friend lists and chat rooms). Your photo is permanently deleted when you delete your account.
We store the concerts you save (favorite), your app settings, and any show history you add — whether entered manually, imported from a file (CSV, spreadsheet), or imported from a third-party service such as SetlistFM. Imported files are processed and then discarded; we retain only the parsed show data (artist, date, venue, city, notes) and the import source.
If you use the friends feature, we store your friend list, pending friend requests, and the date each friendship was created. When you become friends with another user, that user can see your music taste profile (a breakdown of genres based on your saved shows), your total show count, and the number of shows you have in common. Your username is searchable by other authenticated users.
If you post in a concert’s chat room, your message and display name are stored and visible to all users who view that chat room. You may post anonymously using a self-chosen name; anonymous messages are still stored on our servers. Chat messages are retained for a limited time after the associated event.
We compute a taste profile from your saved shows (genre distribution, top venues, top neighborhoods) to generate personalized “For You” recommendations. This profile is stored on our servers and is visible to your friends (see “Friends and social data” above). It is not shared with any third party.
If you submit an event through our form, we store the artist, venue, date, and any notes you provide. Submissions are anonymous — we do not associate them with your account.
If you send us a message through the contact form, we receive your message text and, if you are signed in, your email and display name. Bug reports from the mobile app also include device diagnostics: device model, device name, OS version, app version, screen size, locale, timezone, free disk space, and app state information (loaded content counts, active filters, authentication state).
If you enable push notifications in the mobile app, we receive your device’s push notification token from Apple. We store this token on our servers solely to deliver the notification categories you have enabled (show reminders, chat replies, tonight’s digest, friend activity, etc.). You can disable push notifications at any time in the app or in your device settings.
Referral features are currently inactive. When referral features are active, each account has a unique referral code used to attribute signups. We do not share referral data with third parties.
If you enable calendar sync, we generate a unique, private URL for an iCalendar feed of your saved shows. This URL acts as a key — anyone who has it can see the events in your calendar feed. You can regenerate or revoke the URL at any time from your account settings.
On the website, we use Google Analytics to collect anonymous usage statistics such as pages visited, referral sources, and device type. No personally identifiable information is sent to Google Analytics. In the iOS app, we use TelemetryDeck, a privacy-first analytics service that collects anonymous usage patterns (such as which screens are viewed and which features are used) without collecting personal data, device identifiers, or IP addresses. TelemetryDeck does not require App Tracking Transparency consent.
We use a single session cookie (foobos_session) to keep you signed in. It is HttpOnly, Secure, and expires after 30 days. We do not use advertising or tracking cookies. The mobile app stores a cached copy of your account data and preferences on your device (in the app’s private storage) so the app works when you’re offline.
The iOS app may use Face ID or Touch ID to confirm sensitive actions such as account deletion. Biometric authentication is handled entirely by Apple’s on-device framework — no biometric data is collected, transmitted, or stored by foobos.
The iOS app uses Apple’s on-device machine learning (Foundation Models) for chat moderation, search suggestions, recommendation summaries, and stats insights. All AI processing happens entirely on your device. No data is sent to any external server for AI processing, and no AI-generated data leaves your device.
The “Near Me” filter in the iOS app uses your device’s coarse location to sort shows by proximity. Location is processed on-device only and is never sent to our servers. Location access requires your explicit permission and can be disabled at any time in your device’s Settings.
Certain information is visible to other users of the Service:
Your saved show list may be visible to friends depending on your favorites visibility setting (public, friends only, or private). When set to “friends only” or “public,” friends can see when you save or attend a concert in their activity feed. Email addresses, statistics, and account settings are never visible to other users.
We use the following third-party services to operate foobos:
We do not sell, rent, or share your personal information with third parties for their marketing purposes.
We retain your data for as long as your account is active. Chat messages are retained for a limited time after the associated event. You can delete your account at any time from the Settings tab in the app or on the website, which permanently removes your email, saved shows, show history, taste profile, friend relationships, notification preferences, and all associated data. You may also email [email protected] to request deletion. We aim to process deletion requests within 30 days.
We use industry-standard measures to protect your data, including encrypted connections (HTTPS), secure cookies, hashed passwords, and encrypted data at rest. However, no method of transmission over the internet is 100% secure.
foobos is not directed at children under 13. We do not knowingly collect personal information from children under 13. If you believe a child has provided us with personal information, please contact us and we will delete it.
You may access, correct, or delete your personal information at any time through your account settings or by contacting us. If you are in the EU, you have additional rights under the GDPR including data portability and the right to object to processing. If you are a California resident, you have rights under the CCPA to know what data we collect, request its deletion, and opt out of any sale of personal information (we do not sell personal information).
We may update this policy from time to time. We will note the new effective date at the top of this page. Continued use of foobos after changes constitutes acceptance of the updated policy.
Questions or concerns? Email [email protected].