Clubhouse

Legal

Clubhouse Privacy Policy

Version 1.0
Effective date: September 2026

Clubhouse is a university community platform that helps students and clubs discover events and opportunities, share content, connect with others, and participate in campus life.

This Privacy Policy explains what information Clubhouse collects, how we use it, when it may be processed by service providers, how long we keep it, and the choices available to you.

Clubhouse is operated by RightToGo, based in British Columbia, Canada.

For privacy questions or requests, contact:

Clubhouse Privacy Contact
Clubhouse.community2026@gmail.com

1. Information We Collect

The information Clubhouse collects depends on how you use the service and whether you use a Student or Club account.

Account and authentication information

When you create or access a Clubhouse account, we may receive or store information such as:

  • your name;
  • email address;
  • profile image provided by your sign-in provider;
  • authentication provider;
  • provider account identifier;
  • authentication and account-linking information;
  • account type;
  • username;
  • account status;
  • session information;
  • IP address and user-agent information associated with authentication sessions; and
  • authentication tokens and related expiry information where required to maintain or revoke your sign-in connection.

Clubhouse currently supports authentication through Google and Sign in with Apple.

Authentication credentials and provider tokens are used to operate sign-in, account linking, session management, and account deletion.

Student profile information

Student accounts may provide information including:

  • display name;
  • username;
  • faculty;
  • year level;
  • biography;
  • profile image;
  • phone number, if provided;
  • profile and activity visibility preferences;
  • interests;
  • content-category preferences; and
  • personalization preferences.

Some profile fields are optional.

Club profile information

Club accounts may provide information including:

  • Club name;
  • description;
  • logo;
  • website;
  • contact email;
  • categories;
  • profile visibility information; and
  • information associated with the account responsible for the Club.

Content you create

Clubhouse stores content you create or submit through the service.

This may include:

  • Events;
  • Opportunities;
  • Club Posts;
  • comments;
  • replies;
  • images;
  • Event venue names and addresses;
  • external registration, application, or payment links;
  • prices or cost information;
  • Event capacity and scheduling information; and
  • other information included in content you choose to submit.

Content you submit may itself contain personal information. Please avoid including sensitive personal information that is not necessary for the purpose of your content.

Social and activity information

Clubhouse records activity needed to provide social, discovery, recommendation, and participation features.

This may include:

  • friendships and friend requests;
  • Club follows;
  • blocks;
  • Event attendance or registration;
  • likes and dislikes;
  • saves;
  • Opportunity submission or application-progress status;
  • content impressions;
  • listing views;
  • account activity dates; and
  • other interactions with Events, Opportunities, Clubs, or content.

Reports and moderation information

When you submit a report, Clubhouse may store:

  • your account identity;
  • information identifying the reported account or content;
  • report category;
  • your written explanation;
  • a limited snapshot of relevant reported content;
  • report status;
  • timestamps; and
  • moderation or enforcement information associated with the report.

Reports may concern Students, Clubs, Events, Opportunities, Posts, Comments, or Media.

Clubhouse also maintains records related to automated moderation and moderator actions. These may include moderation results, relevant content or account identifiers, action type, timestamps, moderator notes, previous and resulting account or content state, provider information, and limited technical information about moderation attempts.

Device and notification information

If you enable push notifications, Clubhouse may collect or store:

  • a Firebase Cloud Messaging token;
  • a randomly generated installation identifier;
  • device platform, such as iOS or Android;
  • token registration and last-seen timestamps;
  • notification type;
  • delivery state; and
  • limited error information relating to notification delivery.

Clubhouse does not require you to enable push notifications to use the core service.

Personalization and derived information

Clubhouse uses preferences and interactions to personalize discovery and recommendations.

You may optionally provide a short natural-language personalization prompt describing what you are interested in.

The raw personalization prompt is processed to generate suggested preferences but is not stored in Clubhouse’s database after the request is completed.

Clubhouse may store derived information such as:

  • preferred categories;
  • semantic tags;
  • preference rankings;
  • recommendation-related signals; and
  • numerical vector representations, sometimes called embeddings, representing preferences or content.

These derived representations are associated with the relevant Student account or content and are deleted when the corresponding account or content is deleted.

Logs and security information

Clubhouse and its hosting providers may process technical information needed to operate, diagnose, and protect the service.

This may include:

  • request paths;
  • timestamps;
  • IP addresses;
  • user-agent information;
  • response status;
  • performance information;
  • resource or account identifiers;
  • security flags;
  • moderation errors;
  • notification errors; and
  • storage or application errors.

Clubhouse does not intentionally log passwords, raw request bodies containing user content, or authentication tokens as ordinary application logs.

2. Information We Do Not Currently Collect

Based on the current Clubhouse service, we do not collect:

  • GPS location;
  • precise device location;
  • coarse device location;
  • date of birth;
  • government identification for age verification;
  • payment card information;
  • banking information;
  • Clubhouse subscription or in-app-purchase information;
  • direct-message content, because Clubhouse does not currently provide direct messaging; or
  • advertising identifiers for behavioral advertising.

Clubhouse also does not currently use an advertising network or cross-app tracking system.

Event venue information is not the same as device location. A Club may enter or select an address for an Event without Clubhouse accessing the device’s GPS location.

3. How We Collect Information

We receive information when you:

  • authenticate using Google or Apple;
  • create a Student or Club account;
  • complete onboarding;
  • update your profile;
  • upload an image;
  • create or edit an Event, Opportunity, or Post;
  • comment or reply;
  • follow, friend, like, save, attend, apply, or otherwise interact with content;
  • configure your preferences;
  • request personalized recommendations;
  • enable push notifications;
  • report content or an account;
  • contact Clubhouse; or
  • use the application or public website.

We also generate limited derived information while operating recommendation, moderation, security, and analytics features.

4. How We Use Information

Clubhouse uses information for purposes including:

Providing the service

We use information to:

  • create and maintain accounts;
  • authenticate users;
  • display profiles;
  • publish and display content;
  • provide Events and Opportunities;
  • support comments and social features;
  • manage friendships, follows, blocks, likes, saves, and attendance;
  • provide Club management functionality; and
  • maintain application state.

Personalization and discovery

We use preferences, interactions, tags, and derived representations to:

  • personalize recommendations;
  • rank or organize relevant content;
  • understand a Student’s stated interests; and
  • improve content discovery within Clubhouse.

Notifications

We use device tokens and relevant activity information to deliver notifications such as:

  • friend activity;
  • friend requests;
  • new content from followed Clubs;
  • Event registration milestones;
  • Opportunity milestones; and
  • Club follower or engagement milestones.

Clubhouse does not currently operate a general marketing-email or SMS campaign system.

Safety and moderation

We process content and reports to:

  • detect potentially prohibited content;
  • enforce the Community Guidelines;
  • investigate reports;
  • prevent harassment, scams, harmful conduct, and abuse;
  • restrict or remove content;
  • suspend or disable accounts where appropriate; and
  • maintain records needed for safety and enforcement.

Security and abuse prevention

We use technical information to:

  • authenticate requests;
  • protect accounts;
  • enforce rate limits;
  • detect abuse;
  • diagnose failures;
  • investigate security problems; and
  • maintain the reliability of Clubhouse.

Service operation and analytics

We use limited interaction and operational information to understand how Clubhouse is being used and maintain the service.

For example, Clubhouse may record content impressions, listing views, and active usage days.

Clubhouse does not currently use third-party behavioral advertising analytics.

5. Automated Safety Moderation and OpenAI

Clubhouse uses automated systems to assist with content safety.

Certain user-submitted text and images may be sent to OpenAI for automated safety classification.

This currently includes selected content associated with:

  • Events;
  • Opportunities;
  • Club Posts;
  • Student avatars; and
  • Club logos.

For Events, moderation may include information such as the Event name, description, venue name, and address.

Other text, including certain profile information, usernames, bios, comments, and replies, is checked using moderation systems operated within Clubhouse’s infrastructure rather than being sent to OpenAI.

Before Clubhouse sends applicable user content to OpenAI for this purpose, Clubhouse asks for explicit permission for this third-party AI safety processing.

Clubhouse does not intentionally add your Clubhouse account ID, email address, IP address, user-agent information, or authentication/session credentials to OpenAI moderation requests.

However, text or images you submit may themselves contain information that identifies you or another person.

Images sent for moderation are processed versions of the uploaded image rather than the original unprocessed upload.

Clubhouse stores the result and limited technical metadata needed to operate and audit moderation, but does not store OpenAI’s full category-score response as a separate copy of your submitted content.

OpenAI is a separate service provider and processes information under its applicable service terms and data-handling practices.

6. Local Automated Moderation

Clubhouse also uses automated moderation systems running within Clubhouse’s infrastructure.

These may evaluate content such as:

  • names;
  • usernames;
  • biographies;
  • Club descriptions;
  • comments; and
  • replies.

This moderation is performed using locally operated machine-learning models.

User text processed through this local moderation path is not sent to a remote Hugging Face inference service.

7. Personalization and Machine Learning

Clubhouse uses an internally operated embedding service to help understand interests and content.

When you submit an optional personalization prompt, the prompt is sent to Clubhouse’s own embedding service and used to generate suggested preferences.

The raw prompt is not retained in the Clubhouse database after processing.

Derived preferences, tags, and numerical embeddings may be stored and associated with your Student account.

Similar numerical representations may be stored for Events and Opportunities to help with discovery and recommendations.

The underlying embedding model is operated within Clubhouse’s infrastructure. Clubhouse does not send user personalization text to a Hugging Face remote inference API.

8. Google Maps and Places

When a Club enters an Event location, Clubhouse may use Google Maps or Google Places to provide address autocomplete.

Information typed into the address search may therefore be processed by Google in order to return location suggestions.

When a place is selected, Clubhouse may store the venue name and formatted address with the Event.

Clubhouse does not currently store GPS coordinates or the selected Google Place ID as part of an Event.

If an Event is publicly available, its venue name and address may also be publicly available.

9. Public Content

Some information on Clubhouse is intended to be public.

Eligible Events and Opportunities may be available without signing into Clubhouse at: clubhouse.community

Public Event information may include:

  • title;
  • description;
  • image;
  • category;
  • dates and times;
  • venue name;
  • address;
  • capacity;
  • price information;
  • organizer name; and
  • organizer logo.

Public Opportunity information may include similar listing and organizer information.

Public pages may be processed and cached by Clubhouse’s website hosting provider and may be indexed, cached, or otherwise processed by search engines and other third parties that access public webpages.

Publicly displayed images may also be accessible to anyone who has their public image URL.

Changing or deleting content from Clubhouse does not guarantee that copies independently created by search engines, users, archives, or other third parties will immediately disappear.

Student profiles are not currently exposed as anonymous public webpages through clubhouse.community, although profile information may be visible to authenticated Clubhouse users according to applicable visibility and blocking settings.

10. Service Providers

Clubhouse uses third-party service providers to operate parts of the service.

Current providers may include:

Google

Google services are used for purposes including:

  • Google authentication;
  • Google Cloud infrastructure;
  • database and application hosting;
  • Cloud Storage for media;
  • Firebase Cloud Messaging for push notifications; and
  • Google Maps/Places for location autocomplete.

Apple

Apple processes information when you choose Sign in with Apple and as part of relevant iOS platform services.

OpenAI

OpenAI processes selected text and images for automated safety moderation as described above.

Vercel

Vercel hosts the public Clubhouse website and may process public-web requests, associated network information, server logs, and publicly available Event or Opportunity information needed to render webpages.

Other websites

Events, Opportunities, or Club profiles may contain links to services operated by third parties.

When you follow one of those links, you leave Clubhouse and interact directly with that service.

Those services control their own privacy practices.

Clubhouse does not process payment credentials merely because an Event or Opportunity displays a price or links to an external payment provider.

11. Push Notifications

If you enable push notifications, Clubhouse uses Firebase Cloud Messaging to deliver them.

Information sent for notification delivery may include:

  • your FCM token;
  • notification title and text;
  • notification type;
  • relevant Event, Opportunity, or Club identifier;
  • limited actor or milestone information where necessary to construct the notification.

Clubhouse does not intentionally include your email address in Firebase notification payloads.

You can control notification permission through your device settings.

12. How Long We Keep Information

We retain information only for as long as reasonably necessary for the purposes described in this Policy, including service operation, safety, security, legal obligations, and resolving disputes.

Our current retention policy includes the following general periods:

Account and content data

Account information, profile information, preferences, and user-generated content are generally retained while the relevant account or content remains active.

When the associated account or content is deleted, corresponding database records and derived embeddings are generally deleted, subject to the exceptions described below.

Sessions and authentication

Authentication sessions generally expire after approximately 7 days, unless ended earlier.

Provider authentication information is retained while needed for the linked account and is removed when the provider is unlinked or the account is successfully deleted.

Notifications

Notification delivery records are generally retained for up to 90 days.

Push-device tokens are retained until they become invalid, are unregistered, or the associated account is deleted.

Usage information

Detailed content impressions, listing views, and account-activity records are generally retained for up to 90 days.

Aggregated or de-identified information that no longer reasonably identifies an individual may be retained for longer.

Reports and safety records

Open reports and associated evidence may be retained while a moderation or safety matter remains active.

Following final resolution or enforcement, relevant report, evidence, and moderation records may generally be retained for approximately one year.

They may be retained for longer where reasonably necessary for an active safety investigation, legal obligation, dispute, or similar legitimate purpose.

Automated moderation records

Limited metadata relating to automated moderation attempts may generally be retained for up to one year.

Application and security logs

General application logs are generally targeted for retention for approximately 30 days.

Security-specific records may be retained for approximately 90 days where such records are maintained.

Infrastructure providers may maintain their own operational logs according to configured service settings.

Moderation staging media

Images held temporarily in private storage for moderation are intended to be removed or promoted promptly and are subject to a maximum operational retention target of approximately 24 hours, unless an upload is still actively being processed.

Media-cleanup records

Completed media-cleanup records may be retained for approximately 90 days.

Failed cleanup records may be retained until the issue has been resolved and for approximately 90 days afterward.

Local drafts

Unsaved Event drafts stored on a device expire after approximately 30 days.

They are also cleared from Clubhouse’s local application storage following successful account deletion.

Backups

Deletion from Clubhouse’s active database does not rewrite historical backups immediately.

Our operational target is a backup and point-in-time recovery window of approximately 7 days. Information deleted from the active service therefore ages out of those backups through the normal backup-retention cycle.

Restored backups would remain subject to Clubhouse’s deletion and retention obligations.

13. Account Deletion

Students and Clubs can permanently delete their Clubhouse account from within the application.

You can find account deletion in Clubhouse Settings.

If you cannot access the app, you may request account deletion by contacting: Clubhouse.community2026@gmail.com

We may need to verify that you control the account before processing an off-app deletion request.

When an account is successfully deleted:

  • the primary Clubhouse account is hard-deleted;
  • authentication sessions are invalidated;
  • stored provider-account information is deleted;
  • applicable Google or Apple authorization credentials are revoked where available;
  • Student or Club profile information is deleted;
  • associated social and activity relationships are deleted;
  • push-device records are deleted;
  • associated preferences and embeddings are deleted;
  • owned content is deleted according to the account type and content model;
  • managed media is scheduled for deletion; and
  • local account state managed by the Clubhouse application is cleared.

Deletion of media from external object storage may complete shortly after the primary account deletion transaction rather than at the exact same moment.

Some information may be retained temporarily or in limited form where reasonably necessary for:

  • safety and moderation;
  • investigation of abuse;
  • enforcing previous account actions;
  • security;
  • resolving disputes;
  • complying with legal obligations; or
  • backup recovery.

For example, moderation or enforcement records may remain for the retention periods described in this Policy even after identifying account references have been removed or limited.

Backups expire through their normal retention cycle.

More information and deletion instructions are available at: clubhouse.community/delete-account

14. Your Privacy Choices

Depending on the information and feature involved, you may be able to:

  • edit profile information;
  • change profile visibility settings;
  • manage social relationships;
  • block supported accounts or Clubs;
  • delete content;
  • disable push notifications through your device;
  • discard personalization selections;
  • revoke or unlink authentication providers where supported; or
  • delete your Clubhouse account.

Some information is required to provide the service. If required information is removed, Clubhouse may no longer be able to provide the corresponding account or feature.

15. Access and Correction Requests

You may request access to personal information Clubhouse holds about you or ask us to correct inaccurate personal information.

Send a written request to:

Clubhouse Privacy Contact
Clubhouse.community2026@gmail.com

Please provide enough information for us to identify you and understand the information or correction you are requesting.

We may need to verify your identity before disclosing personal information.

Where British Columbia’s Personal Information Protection Act applies, Clubhouse will respond to qualifying access or correction requests within the time required by law, generally within 30 days unless a permitted extension applies.

Certain information may not be available for access where withholding it is required or permitted by law, including where disclosure could reveal another person’s protected information or interfere with an investigation.

Where Clubhouse relies on your consent to collect, use, or disclose personal information, you may withdraw that consent subject to reasonable notice and any legal or contractual limitations.

Some processing is necessary to provide Clubhouse.

For example, we cannot maintain an authenticated account without processing the information required to authenticate and associate that account.

For third-party AI safety moderation, Clubhouse obtains a separate acknowledgement or permission before applicable content is transmitted to OpenAI.

If a required permission is withdrawn, certain content-creation or upload functionality that depends on that processing may become unavailable.

You can contact the Clubhouse Privacy Contact if you have questions about withdrawing consent.

17. Information About Other People

Clubhouse allows users to create content that may refer to other people.

You are responsible for respecting other people’s privacy and ensuring you have an appropriate basis to share personal information about them.

Do not use Clubhouse to publish private or sensitive information about another person in violation of our Community Guidelines.

If you believe your personal information has been posted without permission, use Clubhouse’s reporting features or contact us.

18. International Processing

Clubhouse is operated from British Columbia, Canada, but some service providers operate infrastructure in Canada, the United States, or other jurisdictions.

As a result, information processed through providers such as Google, Apple, OpenAI, Firebase, or Vercel may be processed or stored outside your province or country.

Information processed in another jurisdiction may be subject to the laws applicable in that jurisdiction.

We select service providers for legitimate operational purposes and limit the information we send to what is reasonably needed for the relevant service.

19. Security

Clubhouse uses reasonable administrative and technical safeguards intended to protect personal information.

Depending on the system, these safeguards include:

  • encrypted network connections;
  • authentication and authorization controls;
  • secure authentication cookies and native credential storage;
  • restricted moderator access;
  • hashed moderator API credentials;
  • rate limiting;
  • server-side validation;
  • private moderation staging;
  • controlled public-data allowlists;
  • image validation and normalization;
  • removal of image metadata during processing; and
  • account and content access controls.

No online service can guarantee absolute security.

If you believe your Clubhouse account or information has been compromised, contact us at: Clubhouse.community2026@gmail.com

20. Children and Child Safety

Clubhouse is designed for university communities.

Clubhouse does not currently collect date of birth or use technical age verification to determine whether every user is an adult.

Regardless of a user’s age, Clubhouse prohibits child sexual abuse and exploitation and maintains child-safety standards.

For more information, see: clubhouse.community/safety

If you believe a child is in immediate danger, contact local emergency services or law enforcement.

21. External Services and Links

Clubhouse may link to websites and services operated by Clubs, Event organizers, Opportunity providers, payment providers, application platforms, or other third parties.

Clubhouse does not control the privacy practices of those external services.

Before submitting information or making a payment to an external service, review that service’s privacy and security practices.

22. Changes to This Privacy Policy

We may update this Privacy Policy as Clubhouse evolves, our data practices change, or legal and operational requirements change.

The current version will always be available at: clubhouse.community/privacy

We may provide additional notice where a change materially affects how we collect, use, or disclose personal information.

A routine clarification, formatting change, or correction may not require renewed acknowledgement.

Where new consent is required for a materially different use or disclosure of personal information, Clubhouse will request it as appropriate.

23. Contact and Privacy Responsibility

Clubhouse has designated the following position as responsible for privacy matters:

Clubhouse Privacy Contact

Questions, privacy requests, access or correction requests, and concerns about this Privacy Policy may be sent to: Clubhouse.community2026@gmail.com

For Community standards: clubhouse.community/community-guidelines

For safety matters: clubhouse.community/safety

For account deletion: clubhouse.community/delete-account

For copyright concerns: clubhouse.community/copyright