Privacy Policy
Mixer is a consent-first networking service for events and person-to-person introductions. It helps people create an approved profile, selectively share a networking card, see possible common ground, mutually connect, and coordinate an optional conversation or meetup.
Information Mixer processes
- An opaque Mixer account identifier derived from the Apple or Google sign-in method you choose. Mixer does not receive your Apple or Google password.
- The events you join, membership and availability settings, and event profile fields you approve.
- A private modular peer profile you create, including only the work, interests, fitness, music, shows, games, projects, or other sections you choose to add. Each person-to-person share link stores an immutable snapshot of only the sections you selected for that networking card.
- On the peer web page, your browser may keep an editable copy of your complete peer-profile draft—including sections you have not selected to share—and card preferences in local device storage so you can continue later.
- For a no-sign-in App Clip or web guest, a random device credential generated on your device and the derived opaque Mixer identity used to restore that temporary profile. Mixer does not require an Apple or Google identity for this guest flow.
- Person-to-person comparison results generated from the two selective card snapshots, including shared topics, reasons, and a suggested conversation opener.
- Match results, connection requests, text messages, read and mute state, meetup plans, and private post-event feedback.
- Contact methods you choose to save. They are revealed to another attendee only after both people approve an exchange.
- If you choose to connect LinkedIn, the limited account claims LinkedIn provides and any public LinkedIn profile URL you add. Mixer does not receive your LinkedIn password, connections, posts, or messages.
- Safety reports and only the specific messages a reporter chooses to attach as evidence.
- In-app notification records and, when notifications are enabled, an Apple device token, app identifier, and delivery environment.
- If you choose “Allow analytics” on the website, mobile web experience, or Android app, privacy-safe product events such as visits, demo progress, invitation opens, sign-in completion, event joins, profile approval, match views, connection outcomes, and organizer actions. Random browser and session identifiers are hashed before storage. These records may include the Mixer surface, platform, app version, event identifier, campaign label, and a synthetic-test marker.
- Short-lived authentication, rate-limit, and operational records needed to secure and run the service.
Mixer does not request your Apple, Google, LinkedIn, ChatGPT, Gemini, or Claude password; provider access token; contact list; precise location; hidden model reasoning; or general chat history from another service. A personal-AI drafting button sends or copies a bounded prompt to the assistant you choose. Mixer receives only the profile fields you bring back, review, and submit.
How information is used
Mixer uses this information to operate event and peer profiles, produce comparisons from selective cards, present introductions, enable mutually approved communication, deliver notifications, prevent abuse, investigate reports, understand consented product funnels, and maintain the service. Product analytics do not use automatic event capture or session replay and never include profile answers or descriptions, messages, match explanations, contact information, feedback text, authentication tokens, full invitation URLs, or precise location. Mixer does not retain raw IP addresses in its product-analytics records. When model-assisted matching is enabled, approved event fields or the two selective peer-card snapshots—other than private boundary instructions—may be sent to OpenAI to generate a bounded result. Private Mixer messages, unselected master-profile sections, and contact details are not sent to the matching model. In the installed app, you can separately opt in to include bounded text from profiles you previously approved when drafting a future profile; this setting is off by default and does not include messages or contact details.
Who can see what
- Attendees see only the profile information and match explanation intended for their event experience.
- Anyone who has an active opaque person-to-person link can view that link’s selective card snapshot until the owner revokes it or it expires. The link does not expose unselected sections or the owner’s underlying private master profile.
- A completed peer comparison is stored for both participants so each can revisit the same result. Neither participant receives the other person’s unselected profile sections.
- Chat opens only after mutual connection. Contact details open only after a separate mutual exchange.
- Event organizers receive attendance and aggregate workflow information plus limited report summaries needed for event safety. Conversation ratings may appear as attendee averages only after an attendee has received at least two ratings; organizers do not receive who rated whom, individual ratings, private messages, exchanged contact details, or private feedback text.
- Push alerts use generic wording and do not contain private message text or contact details.
Service providers and disclosure
Mixer uses Amazon Web Services for hosting, storage, operational monitoring, and the first-party product analytics described above; Apple and Google for identity; Apple for notification delivery; LinkedIn only when you choose to connect it; OpenAI for the ChatGPT integration and optional bounded matching; Google when you choose Gemini; and Anthropic when you choose Claude. Mixer does not sell personal information or use it for advertising.
Retention and deletion
Event membership, event-history pointers, approved event profiles, private peer profiles, and reusable networking cards are retained while needed to provide the features you use. The peer web page removes its local editable draft after no more than 30 days; clearing that browser's site data removes it earlier. A peer share expires at the lifetime selected by its owner, from 8 to 24 hours; revoking it ends public access immediately even if physical database cleanup occurs later. Peer comparison records expire after no more than 90 days. Leaving an event ends active participation and matching eligibility. Deleting an event profile removes that profile from future profile-history and matching use, while limited event or safety records may remain. Social records such as messages, connection state, meetup plans, contact exchanges, notifications, and private feedback expire no later than 90 days after creation or earlier when the event has an earlier expiry. Consent-granted product analytics expire after no more than 400 days. Device registrations expire after 30 days unless refreshed. Safety records may be retained for a limited period where needed to investigate abuse, prevent fraud, or meet legal obligations.
You can pause discovery, leave an event, delete its profile, revoke a peer share, revoke contact sharing, or request account deletion. A no-sign-in guest can use Delete my temporary Mixer profile on the peer page; this deletes that Mixer identity’s peer profile, cards, comparisons, and active shares and clears its local device credential. After identity verification, Mixer will delete or irreversibly anonymize other account-linked personal information unless limited retention is required for security or law.
Security and changes
Mixer uses encrypted AWS services, audience-bound access tokens, PKCE, server-side authorization checks, bounded data access, and rate limits. No system is perfectly secure. Material policy changes will be posted here with a new effective date.
Contact
Questions or privacy requests can be sent to events@thinklavender.com.