Legal
Last updated October 1, 2026
This policy tells you what Thrown holds, who else touches it, how long we keep it, and where the sharp edges are. We have tried to write it the way we would want it written for us: specific, and honest about the parts that are not finished.
Thrown is a party-planning tool and a local vendor marketplace. To do that job we hold real information: your account, the parties you plan (including their street addresses), the guest lists you build, and the listings and reviews you publish.
Three things worth knowing before anything else:
Thrown is operated by Thrown LLC, based in New Jersey, USA. You can reach us about anything in this policy at hello@thrown.party, and you can reach a person through our About page.
This policy covers thrown.party and everything served under it, including the Thrown app. It describes what the product does today. A couple of features exist in the code but are switched off (for example, a party photo album); this policy does not describe them, and we will update it before turning any of them on.
Signing in. Thrown is passwordless: there is no password anywhere in the product, ever. You sign in with a one-time link or six-digit code we email you, with Google, or, in the Thrown app, with Apple. When you request a code we record the email you typed, the IP address the request came from, and, if a Google or Apple sign-in was waiting in your browser to be connected, which provider it was and a scrambled fingerprint of it that only tells us whether it is the same sign-in later; all of it is deleted automatically when the code expires, at most 15 minutes later. If you use Google sign-in, Google tells us your name, email address, whether that email is verified, your Google account ID and, for a Google Workspace account, the organization's domain (read only to decide whether that address can be trusted to match an existing account, and not stored). Nothing else, and not your profile picture. If you use Apple, Apple tells us your Apple account ID, your email (or a Hide My Email relay address, in which case mail we send you passes through Apple's relay), whether it is verified, and, the first time only, your name. When a Google or Apple sign-in matches no Thrown account, we ask whether you are new before making one; if you already have an account, you sign in to it another way (the emailed code, say) and can connect Google or Apple to it, and we then store that account ID on your Thrown account, noting that you connected it yourself. Creating an account asks you to tick a box agreeing to this policy and the Terms, and the date your account did so is recorded on it.
Your profile. Name, email, and optionally a phone number, location, bio, avatar, and social handles. You can also fill out an optional taste profile — vibes, palette, hosting energy, and a free-text note — which we use to personalize AI suggestions. You can delete your taste profile on its own, instantly, from your profile page, and you can delete the whole account from the same page (see “Deleting your data”).
Push notifications, in the Thrown app. If you allow notifications when the app asks (once, the first time you open the app signed in), Apple gives the app a device token, an identifier for that installation on that phone, and the app stores it with your account so we can notify you about things like a new RSVP. We keep the token, which phone platform it is, the app's version, and when that phone registered and last opened the app signed in; nothing else about the phone. Each kind of notification has its own switch on your profile page, and turning one off is honored before anything is sent. The app removes the phone's token when you sign out, and, if you were signed out while the app was closed, the next time it opens; deleting your account removes them all; and a token Apple reports as no longer valid is removed the first time we try it. A notification carries a title (the party's name), a short body and where in the app to open: for an answer, the guest's name and their answer; for a post on a party's wall, the author's name and the first line of the post; and never an address, a phone number or an email. Notifications about a party that is busy are grouped into one message with a count, and the bookkeeping for that (how many things you have not been told about yet, the newest one as a line, and who did it) is kept on your account until the notification goes out, then cleared; it is deleted with your account and with the party.
Your parties. Everything you type when planning: the party's name, description, date, street address, cover image, the planning intake (occasion, guest count, age mix, honoree, budget, free-text notes), planning notes, bring-board items, and the wall. Cover images on the manage page autosave — an upload can happen without you pressing Save.
Marketplace activity. Vendor listings (business name, contact details, street address, bio, gallery), rental listings and rental requests, reviews and comments (published under your real name), seller applications, purchases, and inquiries you send to vendors.
Your pack brainstorms. When you talk a party pack through with the planner, the conversation is saved with the pack — your messages, its replies, and which of its suggestions you applied — so the thread is still there when you come back. It is private to whoever owns the pack, and it travels with the pack if the pack ever changes hands.
Links you hand to vendor onboarding. If you build a business listing from a link, our servers fetch that page once and read it to fill in the draft. Before fetching anything we read the site's robots.txt, the file a site uses to say what automated visitors may look at, and if it says no then we do not fetch the page. We only ever request the address you typed, and what we extract is sent to OpenAI once to write the draft. Nothing is published until you have looked at it.
Instagram and Facebook are not read at all, here or anywhere else in Thrown. Both tell automated visitors to stay out, so we make no request to either: paste a profile and we keep the handle, which is sitting in the link itself, and nothing else. We built a reader for those profiles in September 2026 and removed it once we looked properly at what they ask for.
Feedback. The feedback box works even when you are signed out. It stores your message, an email address only if you choose to give one, a screenshot if you attach one, and the page you were on, your browser and your device — those last three go with every note, so that a report like “the button does not work” is something we can actually chase. It deliberately records the path only, never the address bar's query string, because query strings on Thrown can carry invite and sign-in links. A screenshot is readable only by an administrator, is not reachable by link the way a listing photo is, and is deleted outright if you delete your account.
This section exists because it is the biggest thing a policy like this usually buries. When you build a guest list, you are giving us names, phone numbers, and email addresses of people who have no Thrown account, got no notice, and may not know we hold anything about them. We think you should know exactly what happens to that information, and the people on those lists should have a way out.
Thrown can text party invitations. A host can invite their guests by text, and a guest who adds themselves on a party's RSVP page can check a box asking to be texted. Our SMS Terms, at thrown.party/sms, describe that program in full, including exactly how people opt in. This is what it means for your information.
Two different things happen with location on Thrown, and they are not the same.
City-level location. Most “use my location” buttons, and the marketplace, work at city scale. Coordinates are rounded to roughly a kilometer before we store or send them, and your chosen area is kept in a thrown_location cookie for up to a year so we can default your searches. That cookie is readable by scripts on the page. If you have previously granted location permission, parts of the app may read your (rounded) position without a fresh prompt; the location picker's Reset button turns that off.
The party address. When you use your device's location to fill in a party's street address, we ask the operating system for a real GPS fix — precise, not the cached city-level one — and send the unrounded coordinates to our mapping provider (Mapbox) to resolve them into an address. Under California law that momentary fix is “precise geolocation,” which is treated as sensitive information, so we want to be exact about it: the coordinates themselves are not stored — the resolved street address is, on the party, and it is printed on the invite. If you would rather not use a GPS fix at all, type the address instead.
Be careful with uploads. Here is exactly why.
The planner and the writing tools run on outside AI services, and it matters what reaches them.
There is no Google Analytics, no Meta pixel, no session recording, and no third-party tracker on Thrown. What exists is our own, and here is all of it.
Twelve outside services process data to make Thrown work. All are US companies. We do not sell or rent data to any of them or anyone else.
One thing that is not on this list, because none of it is a processor: three places in Thrown fetch a page or a file from whoever hosts it, on your behalf. Giving vendor onboarding a link fetches that page to draft your listing. Pinning a link to a pack fetches it for the picture that goes on the card. Adding a photo to a listing by pasting its address fetches that file so we can host our own copy rather than hotlinking yours. In all three the host sees a request coming from Thrown, and we tell them nothing about you beyond the request itself.
All three ask permission first. Before fetching we read the site's robots.txt, the file a site uses to say what automated visitors may look at, and if it says no then we do not fetch. That is why we never fetch an Instagram or Facebook page ourselves: both refuse automated visitors, including the servers that hold their images, so a link to either is kept as text and a picture on one of them cannot be imported. The only way Thrown ever reads either is the Meta connection described above, which happens through Meta's own API and only if you choose to connect the account.
We would rather tell you the real shape of this than a tidy fiction. A few things delete themselves; most things we keep until you or we delete them.
You can delete your account yourself, from the bottom of your profile page. It takes effect immediately, signs you out everywhere, and needs no email. Here is exactly what happens, because “delete” means different things for different kinds of record:
We do not sell personal information, and we do not share it for cross-context behavioral advertising — there is no advertising on Thrown at all. The disclosures that do happen (your details to a vendor when you inquire, to a coordinator when you ask for one, to a listing owner when you request a rental) happen because you pressed the button that does that thing, and the sections above describe each one.
Thrown is a small, new business, and some privacy statutes only kick in at thresholds we may not meet. We do not think your rights should depend on that. Whoever you are and wherever you live, you can ask us to tell you what we hold about you, correct it, or delete it, by emailing hello@thrown.party — and that includes people who never signed up. We will not treat you worse for asking. If California's rules on sensitive information apply to the party-address location path, the Location section describes exactly what that path does.
Thrown is built and hosted in the United States. If you use it from elsewhere, your information will be processed in the US.
Everything above describes information you chose to share by pressing a button. This section is about the one disclosure you do not choose: a government agency, police force, or court asking us for your information. We disclose personal information to a public authority only when we are legally required to, and only after someone at Thrown has reviewed the request and confirmed it is valid — that it really came from the authority it claims, that it is the kind of legal process that can compel us, and that it names the person and the information it is after. An email from an official asking nicely is not legal process, and we do not act on it.
When a request is overbroad, has no legal basis, or asks for more than the law requires, we push back: we ask for it to be narrowed, and where it is warranted we challenge it with our lawyers. When we do have to disclose, we disclose the minimum — the specific information the request compels, about the specific people it names, and nothing else. We never hand over a database, and we take particular care with guest lists, because most of the people on one never signed up for Thrown and a request about a host is not a request about their guests.
We keep a record of every request we receive: who asked, what they asked for, what we decided and why, and what, if anything, we disclosed. We will tell you before we disclose your information unless the law forbids it or someone is in immediate danger, and if we are forbidden from telling you at the time, we will tell you once we are allowed to. The one exception is an emergency: if we believe in good faith that disclosing information is necessary to prevent imminent death or serious injury, we may do so without waiting for legal process, and we record that decision like any other.
Thrown accounts are for adults 18 and up. Parties for children are welcome; accounts for children are not.
Because of what Thrown is, hosts do give us children's information — a kid's birthday party's guest list is mostly children's names, supplied by the adults hosting it — and we treat it accordingly: we use it only to run the party, we never put guest names into AI prompts, and when a party's intake says the audience is children we additionally use that fact to keep AI-generated party art age-appropriate (for example, no alcohol imagery).
A parent or guardian can have a child's information removed by emailing us, whether or not they have an account. We do not knowingly collect information directly from children under 13; if you believe a child has created an account or submitted their own information, tell us and we will delete it.
There are no passwords on Thrown, so there is no password of yours to breach — sign-in is by emailed link or code, by Google, or in the Thrown app by Apple, which means your Thrown account is as safe as the account you sign in with, so protect that. A sign-in link or code works once, expires after fifteen minutes, and we store only a hash of it. A session lasts 7 days in a browser and 30 days in the Thrown app, and is extended while you keep using Thrown, so you are signed out only after that long without a visit. The session cookie is signed and cannot be read by scripts in your browser.
Guest invite links are private capabilities: anyone holding one can open the invite it belongs to, so guests should treat their link like a ticket, and hosts should share the general party link rather than a specific guest's. We record the IP a sign-in code was requested from, for 15 minutes, to fight abuse, and briefly key our rate-limiting on IPs and emails for the same reason.
No system is perfect, and we would rather tell you where the edges are than imply there are none — that is what the photos section above is for.
When we change this policy in ways that matter — new data, new sharing, new AI flows, or turning on a feature this policy says is off — we will update the date at the top and say what changed, and for significant changes we will tell signed-in users in the app or by email before the change takes effect. The current version is always at thrown.party/privacy.
Questions, requests, or something in here that worries you: hello@thrown.party. You can also reach a person through our About page.