Privacy Policy
Updated 20 September 2026. JoyKan is operated by Benjaphon Niramit, an individual in Thailand.
What JoyKan stores
Clerk handles identity and sessions. JoyKan stores a minimal identity mapping, account creation date, display profile, one optional profile photo, broad area, languages, interests, events and selected images, RSVP/waitlist/reconfirmation and check-in state, Event Room content, notification choices, referral campaign/redemption and Early Supporter reward state, one optional personal invite code, app-scoped inviter/invitee IDs, attribution and qualification state/timestamps, aggregate invite progress, positive post-event acknowledgements, and earned badges or profile frames derived from verified attendance and qualified hosting, moderation appeals, blocks, reports with evidence snapshots, developer feedback and optional screenshots, moderation actions, and in-app notifications, including deduplicated personal-invite progress milestones. If a member enables push notifications, JoyKan also stores an installation-scoped Expo push token, platform, app version, build, Store-update-routing capability, and bounded delivery receipts. If a member enables new-activity recommendations, JoyKan stores that preference and a bounded member/event delivery record with a Bangkok-day slot to prevent duplicates and enforce the limit. Personal-invite notices never include the invitee identity, activity or location. Store-update Push uses only platform/version/build and the non-personal routing-capability flag for active compatible installations on an older public build; it includes no arbitrary URL or member data. Push payloads use generic text and do not contain chat content, sender identity, event titles, or Host identity. Foreground location is used only after a member explicitly selects a current-area or Nearby action. Member coordinates stay in volatile on-device memory and are not sent to JoyKan, persisted, logged, or used in the background. JoyKan does not request contacts, payments, camera, or microphone access.
For first-party usage measurement, JoyKan stores only the random app-scoped user ID, opaque activity ID, bounded event name, broad category, broad area, bounded app or membership surface, membership outcome, allowlisted acquisition source, and timestamp for onboarding completion, activity views, Join/Waitlist creation, Event Room entry, activity creation, and aggregate check-in-linked outcomes. A First Circle link may carry a bounded random source token; the API verifies it against configured hashes and stores only first_circle, never the raw token. This excludes advertising/device identifiers, contact data, profile or message text, exact venue/address, raw coordinates, and cross-app data.
For Event Room read receipts, JoyKan stores only one latest-read cursor per member per room. JoyKan also records one deduplicated first-entry marker per member and room, including the member's app-scoped ID, activity ID, linked room-history item, and entry time. The room may show that member's display name with the first-entry item to authenticated people who can access the same room. Typing presence is sent only through the room's real-time channel, expires after approximately three seconds, and is not stored in the database.
Selected images
The system photo picker returns only the image a member selects. JoyKan creates a bounded JPEG copy, applies size and upload-rate limits, and stores it in Cloudflare R2. Selected profile, event, and Event Room images are sent to OpenAI for automated safety classification; images remain hidden until approved. Event Room text first uses bounded duplicate, link, and scam-pattern signals. Only text hidden by those signals is sent once to OpenAI for a second safety classification: clearly safe text is restored automatically, clearly risky text remains hidden, and ambiguous or failed checks go to human review. A sender can appeal for human review, and a risk score alone does not suspend an account.
Joy AI assistant
Joy runs only after a member explicitly chooses Create with Joy or invokes Joy in an Event Room. Create with Joy sends the member's current message, a bounded prior Joy transcript, and the current event-form draft. Room Joy sends the request, event facts, and at most 20 recent messages visible in that room, bounded to 6,000 characters. Images, hidden, removed or recalled messages, unrelated rooms, profile bio, contacts, and precise device location are excluded. Joy may fill a draft, answer event questions, summarize recent conversation, or draft a Host announcement, but it cannot publish an event, moderate content, remove a member, or act as a human account.
Messenger and Instagram support
When a person contacts JoyKan Support through Facebook Messenger or Instagram, Meta delivers the message to a dedicated Cloudflare support gateway. The gateway verifies the request, rate-limits and deduplicates it, removes contact-like data such as email addresses, phone numbers, links, and one-time codes, and replaces provider sender and message identifiers with pseudonymous hashes before any model request. For questions that cannot be answered from deterministic approved facts, JoyKan may send only the minimized, redacted support text to OpenAI to draft a reply with provider response storage disabled and no tools or access to JoyKan's internal systems. JoyKan may auto-send only low-risk, high-confidence general answers. Safety, privacy, billing or refund, account or deletion, moderation, complaint, technical, attachment, uncertain, and prompt-injection cases remain for human handling. JoyKan does not intentionally run overlapping native Meta auto-replies and the custom support responder for the same audience.
Why
We use this data to provide the event service, show consent-controlled social proof, enforce capacity, automate waitlist movement, reduce no-shows, enable mutual connection after shared checked-in attendance, measure aggregate Host quality, attribute member invitations and grant non-financial rewards, secure accounts, prevent abuse, and respond to safety reports. A personal inviter may receive one privacy-safe notice when a new account records the inviter's code and one when that referral first qualifies; a third-referral Badge unlock is combined with the qualification notice. These notices never identify the invited member or activity. A personal inviter unlocks the non-transferable “นักชวนจอย” badge after three attributed members complete verified participation; unresolved serious safety reports block qualification. A personal code accepts at most ten attributed accounts, cannot be self-used, and may be entered only during onboarding or within seven days of account creation before the first qualifying activity. JoyKan does not read contact lists or automatically message anyone; the device Share Sheet opens only after the member taps Share and does not create a progress notice by itself. If a member explicitly enables new-activity recommendations, JoyKan compares selected interests with a curated event category/tag mapping and uses the profile's broad area for in-person or hybrid activities. Online activities do not use area matching. This does not use raw coordinates, contacts, AI profiling, or cross-app tracking. Recommendation Push is limited to two per Bangkok day, deferred during 22:00–08:00, and can be disabled at any time. JoyKan does not sell personal data or use cross-app tracking ads.
This first-party usage measurement is used only to evaluate in aggregate whether onboarding and core activity flows are useful. Moderator reporting derives activation and days 6–8 meaningful return at query time, joins attendance only to authoritative append-only check-ins, and suppresses cohorts below five acquired users. JoyKan does not use an advertising SDK, mobile measurement partner, advertising/device identifier, fingerprinting, or cross-app tracking for this measurement.
Visibility and providers
Event details, approved event images, and Host names may be visible to members. Every published event has a public invitation link; anyone with that link may see the event details, approved images, public location, and the Host's display name and approved profile photo. Public event pages do not expose participant or Interested identities, private meeting links, internal instructions, or room content. Hosts can stop access by cancelling the event or contacting Support, although third-party messaging apps may temporarily retain a cached preview. An approved profile photo otherwise appears only alongside identity on surfaces where that identity is already visible; initials remain the fallback. New profiles start with event identity visibility enabled, the choice is shown during onboarding, and members can switch it off at any time; existing profile choices are not changed automatically. Profiles a viewer is allowed to open show only the account creation month and year, not the exact day. A system-controlled public allowlist marks official JoyKan team accounts; members cannot set this mark themselves. Before Join, members may see the Host and up to seven attendee identities plus up to eight Interested identities when those members allow visibility. Hosts and confirmed participants can see the full active participant list needed for the event. Entering an Event Room intentionally creates an Interested action without reserving a place; joining moves that member from Interested to Going. Interested totals include private actions while identity follows each member's visibility setting. Saves are private. A member may use one campaign code per account. Early Supporter activates only after onboarding plus a first Join or Event Room entry; official campaign accounts cannot redeem their own campaign. Separately, an eligible member may create one personal invite code and attribute one inviter. The inviter sees only pending and qualified totals, never invitee identities or activity details. Personal-code sharing contains the code and public Store links, not contacts or a recipient list. Connection requests require both people to have checked in to the same event and require acceptance; either person can remove the connection or block. Individual feedback stays private and an aggregate Host signal appears only after at least three records. Private meeting links are released only to eligible confirmed participants near start time.
Event Room messages, participant lists, mentions, reactions, room galleries, and bounded activity history are visible to authenticated users who enter that event's room, including people who have not confirmed attendance. Activity history can include the first time a member enters, joins, leaves, is promoted, removed or checked in, and material event updates or cancellation. Entering a room does not reserve a place or reveal private meeting links or confirmed-participant instructions. Room images remain private to the room and hidden until approved. Members can choose all notifications, important activity plus announcements/mentions/replies, or no notifications. Background push may use the device's standard sound; JoyKan suppresses duplicate system sound while the app is in the foreground. Authenticated real-time delivery may be enabled by the server with polling fallback without changing room access.
Read receipts show only the aggregate number of other room members who have read through the sender's latest message. JoyKan does not show reader names, read times, online status, Last seen, or typing history. Current typers may be named transiently only inside the same room.
Meta delivers messages sent to JoyKan through Messenger or Instagram. Clerk and Cloudflare process data needed for identity, application logic, notifications, support-message minimization, messaging, and storage. Expo Push Service routes generic payloads and installation tokens to Apple Push Notification service or Firebase Cloud Messaging. OpenAI receives selected profile, event, and Event Room image copies, plus only Event Room text already hidden by JoyKan's local safety signals, for safety classification. After a member explicitly invokes Joy, OpenAI also receives only the bounded assistant data described above. For support drafting, OpenAI receives only minimized and redacted support text after deterministic checks. Each path uses a separate credential with provider response storage disabled and no agent tools. JoyKan does not send every chat message to OpenAI. OpenAI's default API controls do not use API inputs for model training unless the operator opts in, which JoyKan does not, and abuse-monitoring data may be retained for up to 30 days.
Event titles and descriptions are checked for bounded spam, advertising, direct-selling, and scam signals. Suspicious events stay out of Discovery until human review. Reports preserve a snapshot of the reported event, profile, or message. AI may categorize and summarize reports for prioritization, but a human moderator makes enforcement decisions; report volume or AI output alone never suspends an account.
When a member uses meeting-place or broad-area autocomplete, JoyKan sends the query through its Cloudflare Worker to Google Maps Platform Places API (New). A newly selected event venue may trigger one additional Place Details request. Event selections store the place name, supporting address, Google place ID, and coordinates of that public venue while attached to the event; profile selections store only the chosen district or city label. JoyKan does not build a shared place directory or store the query, suggestion list, or member coordinates. A per-user usage counter containing only the JoyKan user ID, request kind, and timestamp is removed after approximately 25 hours; a monthly aggregate stores only the month, request kind, and count for approximately 400 days. Manual entry and named-area filters remain available, and Online activities remain visible in Nearby results. Google's processing is governed by the Google Maps Platform Terms and Google Privacy Policy.
Retention and deletion
Active account, profile, event, membership, social, acknowledgement, referral reward, personal invite-code ownership and attribution, selected place identity including public venue coordinates, and Event Room data is kept while in use; rooms close 24 hours after an event starts. Personal inviter/invitee relationships are removed when either linked account is deleted, and the inviter's aggregate progress and reward eligibility are recalculated. Replaced, removed, rejected, moderated-away, and account-deletion images are removed from active storage. Per-user autocomplete and Place Details counters are removed after approximately 25 hours; monthly aggregate counts after approximately 400 days. Queries, suggestion lists, and member coordinates are not stored. Notifications and disabled push tokens are kept for 90 days; new-activity recommendation delivery records are kept only to enforce one notification per member/event and the daily limit and are removed with the member or event; push delivery receipts and bounded error codes are kept for 30 days; bounded AI results, appeals, report evidence, before/after evidence for edited messages, and moderation history for up to 24 months unless a documented incident hold applies. Active push tokens remain while push is enabled and are removed on account deletion. Developer feedback and optional screenshots are kept until resolution and routine cleanup. Account deletion removes the identity, referral redemption, personal referral relationship, and active content boundary; only non-identifying integrity or necessary safety/legal records may remain.
The latest-read cursor and identifiable first-entry marker are removed with the linked room, event, or account. Room activity-history items are retained for up to 24 months with other bounded moderation and safety history; after account deletion, any retained item no longer links to that member's account. Typing presence expires after approximately three seconds and is never stored in D1.
Joy draft JSON, bounded transcript, and idempotency response content are cleared within 24 hours. Joy request telemetry containing status, provider/model, provider request ID, token counts, and bounded error code—but no raw prompt, copied room history, or input hash—is eligible for deletion after 30 days. Shared Joy room answers follow the Event Room retention boundary. Account deletion removes the member's Joy drafts and request records immediately.
Minimized support events and reply drafts in D1 are cleared within 7 days. The encrypted reply handle that can address the originating Messenger or Instagram conversation expires within 24 hours. Provider sender and message identifiers are stored only as bounded pseudonymous hashes for deduplication and audit.
Store-update campaign metadata is retained as a small per-release audit and deduplication record. Per-device Store-update delivery rows follow the 30-day Push-delivery window and are removed with the linked token.
Raw first-party usage-measurement rows are eligible for bounded deletion after 30 days and are deleted immediately when the linked account is deleted. Production collection must remain off until the bounded retention schedule is separately approved, enabled, and verified.
Contact
Privacy requests: support@joykan.app. Inbound and authenticated outbound delivery were tested on 23 August 2026.