Legal
Last updated August 14, 2026
This explains what Thrown collects, why, who else touches it, and what you can do about it. We have tried to write it as a description of what the software actually does rather than as a list of things we reserve the right to do.
If something here is unclear, or you want your data out, email us — a person reads it.
Most of what we hold is something you typed. Creating an account stores your name, email, and — if you signed up with a password rather than Google — a hash of that password, never the password itself.
Planning a party stores the party. That means the details you enter and, unavoidably, whatever you choose to put in them: guest names, an address, what things cost, notes to your co-hosts. Treat those fields as what they are — a record you are creating about other people as well as yourself.
We keep a deliberately thin activity log so vendors and listers can see how their pages are doing. Two kinds of row, and nothing else:
Page views are deduplicated per viewer per day using a one-way hash, so a row records that a page was seen — not a browsing trail. Search rows record the query text, the filters you applied and how many results came back. They record whether a location was in play as a single true/false flag and deliberately store no coordinates at all.
If you are signed out, you are a random identifier generated in your own browser and kept in local storage. It is not linked to a person and you can clear it by clearing site data. Raw activity rows expire automatically after about thirteen months. We exclude owners from their own view counts, because a dashboard that counts you refreshing your own page is not telling you anything.
The marketplace needs a rough idea of where you are so it can show you businesses you could actually book. That is a city-sized question, and we hold it at city size.
You can type a place, or press "Use my location" and let the browser answer. If you do, the coordinates are rounded to roughly a kilometre before they are stored or turned into a place name — a radius search has no use for your doorstep, and we would rather not be holding it. Mapbox performs the lookup that turns coordinates into a city name.
The result lives in a cookie on your own device, which you can overwrite by picking a different place or clear with the Reset control. We never ask the browser for your location unless you have already granted permission or pressed the button.
When you ask the planner for a party, the brief you wrote, the answers you picked and any inspiration photos you attached are sent to OpenAI to generate the plan and its cover image. Photos are read for a written description of their look; that description is what steers the cover image.
Plans are saved private to you. Generated plans are also excluded from the pool the planner searches when it builds the next person's plan, so your party does not become someone else's suggestion unless you publish it yourself.
You can switch your taste profile out of AI personalization entirely. Vendors are opt-in rather than opt-out: a business does not appear in a generated plan unless its owner has turned that on.
We use these companies to run the product. They handle data on our behalf, for the purpose described, and nothing here is sold to anyone.
This is the part worth reading twice, because the boundaries are not always where people assume.
When you publish a thrown party back as a Party Pack, the pack carries the plan and never carries the private half: not your guest list, not your name as host, not the address, and not what anything cost. That is enforced when the pack is built, not left to you to remember.
On a live party page, guests see how many people are coming and the activity feed — not a roster of names. Reviews are public and carry your name. A published pack, a vendor profile and a rental listing are public pages, and search engines can index them.
One thing to know about images: uploaded photos are stored privately but served through an image URL that is not itself password-protected, because the search engine has to be able to fetch them to index them. Anyone holding that URL can open the picture. Treat anything you upload as effectively public.
You can edit or delete almost everything you have made — parties, packs, listings, reviews, your profile — from inside the app. Turning your taste profile's AI opt-out on stops it being used for personalization. Vendors control AI recommendation from their own manage page. The location cookie has a Reset button on the marketplace.
Two honest limitations, both true as of the date above. There is no self-serve account deletion and no password reset link — email us and we will delete an account by hand, and help you back into one. We would rather say that than put a button on this page that does not exist.
If you are in a place with statutory data rights — access, correction, deletion, portability, objection — email us and we will honour them. We do not require you to prove standing before we will help.
Thrown is for adults. Plenty of parties on it are for children, but the account planning them belongs to a grown-up. We do not knowingly collect information from anyone under 13; if you believe a child has created an account, email us and we will remove it.
Passwords are hashed with scrypt and never stored in a readable form. Sign-in cookies are signed and cannot be read by scripts in your browser. Uploaded files go to a private store. Payments run through Stripe's own hosted checkout, so card numbers never touch our servers.
No system is perfect, and we would rather tell you where the edges are than imply there are none. See the note about image URLs above.
If we change this policy we will change the date at the top. For a change that meaningfully affects what we collect or who we send it to, we will say so in the product rather than quietly editing the page.
Questions, corrections, or a deletion request: email us at the address on our About page.