Privacy Policy

GatherList is built and maintained by Devdomdom. This page explains, in plain language, exactly what data GatherList collects, how it's stored, and what it's used for. We do not sell or share your information with anyone — there's no advertising, no analytics, and no third-party service connected to this app at all.

No accounts, ever

GatherList has no user accounts, for hosts or guests. There's no sign-up, no password, no profile. A party and its RSVPs exist as their own independent records, reachable only through a private link — never tied to "who you are" as a returning identity across parties.

What we collect

When you create a party (as host):

Just the party details you choose to enter — title, description, date/time, location, and any items you'd like guests to bring. No email address or any other contact detail is collected from hosts.

When you RSVP (as a guest):

• Your name, and whether you're attending — required, since that's the point of an RSVP.

• Adult/child counts, if you're attending.

• Optional dietary notes and an optional message to the host, if you choose to leave them.

• Which items you've claimed you'll bring, if the party has a requested-items list.

No email address or phone number is ever collected from guests. All of the above is visible only to that party's host — never to other guests, unless the host has chosen to show guest names or claim-owner names on the invitation page.

How it's stored

Private links (a party's administration link, a guest's invitation link, a guest's personal update link) are never stored in a form that could be read back out of the database. Only a SHA-256 hash of each link — combined with a server-side secret not stored in the database — is kept. That means even someone with direct database access could not reconstruct your actual link; the database can only check "does this link match one it already knows the hash of," never produce the link itself.

IP addresses and browser user-agent strings are hashed the same way before being stored, for a small number of security purposes: detecting abuse (rate limiting), and as part of the record of when and where a host session was created. Raw IP addresses and user-agent strings are never written to the database.

Cookies

GatherList sets a small number of cookies, all strictly functional — none for advertising, tracking, or analytics:

gatherlist_host — keeps you signed in to a party's host dashboard for that browser session.

gatherlist_rsvp — keeps a guest signed in to their own RSVP-management page.

gatherlist_admin — used only by the platform's internal administration login, not by hosts or guests.

Each cookie holds the same kind of private link described above — never your name, email, or any other personal detail — and is marked HttpOnly, meaning page scripts can't read it.

Third parties

None. No analytics service, no advertising network, and — at the moment — no outbound email provider is even connected to this app. Nothing collected here is sold, shared, or handed to any outside company.

Deleting a party

When a host deletes a party, it's immediately removed from both the host's and guests' view — the administration and guest links stop working right away. The underlying record is retained rather than instantly erased, so it can be recovered by platform administration if a deletion turns out to have been a mistake. If you'd like a party's data permanently and irreversibly erased rather than just deactivated, contact Devdomdom directly.

Questions about this policy? Reach out to Devdomdom.

An unhandled error has occurred. Reload 🗙

Rejoining the server...

Rejoin failed... trying again in seconds.

Failed to rejoin.
Please retry or reload the page.

The session has been paused by the server.

Failed to resume the session.
Please retry or reload the page.