Legal

Privacy Policy

Effective date: September 30, 2026

1. Introduction

SignEmUp is operated by Harrow Studio LLC. This Privacy Policy explains how we collect, use, and protect your personal information when you use our web application at signemup.app, our mobile application, and related cloud services (collectively, the “Service”).

If you have questions about this policy, contact us at support@signemup.app.

2. Information We Collect

Account Information

When you create an account, we collect your email address and, if you sign in with Google or Apple, your display name as provided by the identity provider. Passwords are hashed by Firebase Authentication—we never see or store plaintext passwords.

Family & Children's Information

Parents and guardians enter their children's names, birth month and year (used to calculate age for camp filtering), sports, activities, and interests. This information is entered by adults, not by children.

Location Data

You may optionally provide a home address and coordinates for camp discovery. On mobile, we request foreground GPS access with your permission. On web, we use the browser Geolocation API with your permission. We also derive a metro area from your location for filtering camp results.

Schedule & Event Data

Events you create—practices, games, camps, and other activities—including dates, times, durations, recurrence settings, and transport or carpool details.

Google Calendar connection

Connecting Google Calendar is optional. If you connect it, SignEmUp requests read-only access to the calendars your Google account can access. The app reads calendar names and identifiers, event titles, descriptions, locations, start and end times, recurrence information, and busy intervals. It uses this information to help you choose and classify calendar sources, review and import relevant events, keep imported schedules up to date, identify open time, and coordinate family availability and rides. This Google Calendar connection does not create, edit, or delete events in Google Calendar.

Imported event titles, dates, times, durations, locations, source identifiers, calendar names, and import settings are stored in your SignEmUp family workspace using Firebase / Google Cloud and are available to family members with access to that workspace. Events you have not yet reviewed may also be held, with their descriptions, in your personal import inbox until you accept or dismiss them. When you enable availability sharing, busy intervals are shared to support coordination without sharing the underlying event titles. On supported iOS devices, optional calendar classification suggestions use Apple’s on-device model. If you separately authorize an AI assistant to access your SignEmUp family workspace, the event information exposed by that connection can include imported calendar events.

You can disconnect Google Calendar in SignEmUp’s Calendar Sync settings and revoke SignEmUp’s access through your Google Account permissions. Disconnecting stops future Google Calendar synchronization; it does not automatically erase information already imported into a shared family workspace. Use the app’s calendar-source removal controls where available, or contact support@signemup.app to request deletion of imported data. Account and shared-family deletion are subject to Section 7 of this policy.

Device & Notification Data

If you enable push notifications, we store a device token (via Firebase Cloud Messaging), your notification preferences (enabled or disabled, quiet hours), and your timezone.

Feedback

Feature requests and bug reports you submit through the app, including the title, description, and category. Feedback is visible to other authenticated users.

Waitlist

If you join the waitlist on our landing page, we collect the email address you provide.

3. How We Use Your Information

  • Provide the Service: scheduling, camp discovery, family coordination, and push notifications.
  • Communicate: push notifications (delivered outside your quiet hours), and service announcements.
  • Improve the Service: aggregate feedback analysis to prioritize features and fixes.
  • Security: rate limiting on public endpoints, input validation, and fraud prevention.

We do not use your information for advertising or profiling. Optional calendar classification suggestions run on supported devices and help you review how events are organized.

Google API Limited Use

SignEmUp’s use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. We use Google Calendar data only to provide and improve the user-facing scheduling and coordination features described above. We do not sell Google Calendar data, use it for advertising, or use it to train generalized artificial intelligence or machine-learning models.

4. How We Share Your Information

Within Your Family

Family members you invite to your workspace can see all children, events, and camp data in that workspace.

Service Providers

We use the following third-party services to operate SignEmUp:

  • Firebase / Google Cloud Platform: authentication, database, cloud functions, hosting, and push notifications.
  • Google Maps Platform: address autocomplete, geocoding, and map display.
  • Google Fonts: typography loaded client-side (Inter, Playfair Display, JetBrains Mono).

We Do Not

  • Sell personal data to third parties.
  • Share data with advertisers or data brokers.
  • Serve targeted advertisements.
  • Use third-party analytics or tracking services.

5. Children's Privacy

SignEmUp collects information about children from their parents and legal guardians. Children do not create accounts, do not log in, and do not interact with the app directly.

Information collected about children (name, birth month and year, sports, and interests) is used solely to provide scheduling and camp discovery features to their parents.

Parents can view, edit, or delete their children's information at any time through the app or by contacting support@signemup.app.

We do not knowingly collect personal information directly from children under 13. If we learn that a child has provided us with personal information directly, we will delete it promptly.

6. Data Security

  • All data is transmitted over HTTPS (TLS encryption in transit).
  • Firebase Security Rules enforce family-scoped data access.
  • Authentication is required for all non-public endpoints.
  • Rate limiting protects public-facing endpoints.
  • Server-side input validation on all Cloud Functions.

No method of electronic storage is 100% secure. We implement industry-standard measures but cannot guarantee absolute security.

7. Data Retention & Deletion

We retain your data while your account is active. You may delete your account at any time via in-app account deletion or by emailing support@signemup.app.

Upon deletion, we remove your account data, family data (if you are the sole owner), children's data, events, camp statuses, and notification tokens. Waitlist emails are retained unless you specifically request their deletion. Data may persist in system backups for a limited period.

8. Your Rights

  • Access: request a copy of your personal data.
  • Correction: update your information through the app or by contacting us.
  • Deletion: delete your account and associated data (see Section 7).
  • Notification preferences: opt out of push notifications via device settings or in-app preferences.

California Residents (CCPA)

We do not sell your personal information. You have the right to know what data we collect and how it is used, to request deletion, and to not be discriminated against for exercising these rights. Contact support@signemup.app to exercise any of these rights.

9. Third-Party Services

SignEmUp integrates with third-party services that have their own privacy policies:

We encourage you to review their policies. We are not responsible for the privacy practices of third-party services.

10. Cookies & Local Storage

SignEmUp does not use traditional tracking cookies or third-party analytics cookies.

We use browser storage for functional purposes: IndexedDB for Firebase Auth session persistence (managed by the Firebase SDK) and localStorage for UI preferences. On mobile, we use AsyncStorage for auth session persistence.

Google Maps may use cookies per Google's own policies when the Maps component loads.

11. Changes to This Policy

We may update this Privacy Policy from time to time. When we make material changes, we will update the effective date at the top and notify users via the app or email. Continued use of SignEmUp after changes constitutes acceptance of the updated policy.

12. Contact Us

For privacy questions, data requests, or concerns:

Email: support@signemup.app

Entity: Harrow Studio LLC