Legal
Privacy Policy
Effective 3 September 2026 · Last updated 4 September 2026
This policy covers the SessionStack mobile app (iOS and Android) and this website. The short version: the app stores the schedule you build, the notes you write and the preferences you set, so they survive a reinstall and reach your other device. There are no analytics, no advertising, no tracking SDKs and no third-party profiling in the app, and nothing here is sold or shared for marketing. The app is an independent, unofficial planner. It is not affiliated with, endorsed by, or connected to Amazon Web Services; AWS and re:Invent are trademarks of Amazon.com, Inc. or its affiliates.
1. Who is responsible
The controller for the personal data described here is Jim van Eijk, reachable at jim@23g.nl. The app is an independent, unofficial planner. It is not affiliated with, endorsed by, or connected to Amazon Web Services; AWS and re:Invent are trademarks of Amazon.com, Inc. or its affiliates.
2. What the app stores about you
Everything below is data you enter yourself. The app asks for no permissions beyond notifications, and it does not access your location, contacts, camera, photo library, calendar or health data.
| Data | Why |
|---|---|
| Email address and password | To create and sign in to your account, and to send the confirmation and password-reset emails. The password is stored only as a salted hash; it is never visible to us. |
| Display name and share code | So a colleague who enters your six-character code sees who they are connecting to. A display name is optional and does not have to be your real name. |
| Preferences | Interests, role, session levels, walking speed, minimum buffer between blocks, whether you use the shuttle, and your sharing level. These order the catalogue for you and decide what counts as reachable. |
| Your schedule | The sessions, parties and personal blocks you add to your days. |
| Notes and evaluations | What you write during a session, and the rating, relevance, recommendation, takeaways, actions and tags you give it afterwards. Your trip report is built from these. |
| Colleague connections | Who you are connected to and whether a request is pending, accepted or blocked. |
| Questions you type into Ask | The question text, whether it was understood, which screen it came from, and when. This is kept to see where the AI fails people and improve the wording it is given. It is never shown to other users and never used for advertising. |
Kept on your device only
- Your sign-in token, in the iOS Keychain or the Android Keystore. It leaves the device only to talk to our own server.
- Note drafts, in a local database, so a note written without signal is not lost before it can sync.
- Reminders — when to leave, an arrival deadline, a nudge to write a note — are scheduled by your own device. The app registers no push token and no server can send you a notification.
3. What other people can see
Nothing, until you connect to someone. A connection starts with a six-character code that you hand out yourself, and both sides have to accept it. You then choose what an accepted connection sees, and you can change it or disconnect at any time:
- Nothing — the default. They see your name, and no part of your week.
- Busy — when you are occupied and roughly where, without which session it is.
- Full — the sessions in your schedule.
Your notes, your evaluations and your trip report are never shared by a connection at any level. The report leaves the app only when you export it yourself.
4. The AI, and what reaches it
When you type a question into Ask, that sentence is sent to OpenAI through our own server, together with the list of valid filter values from the catalogue. It comes back as filters, and your device does the searching. What is not sent: your identity, your email address, your schedule, your notes or your evaluations. OpenAI processes it as our processor under their API terms, which do not use API content to train their models.
5. Who processes data for us
- Supabase — database, accounts and the confirmation and reset emails. Hosted in us-east-1.
- OpenAI — reads the questions you type into Ask, as described above.
- Vercel — hosts this website and counts its page views, as described under This website below. The app itself does not talk to it.
- Apple and Google — distribute the app. If you have opted in to their crash and usage reporting at the OS level, they collect that under their own privacy policies; we receive it only in aggregate.
Transfers outside the EEA, where they occur, rely on the European Commission's Standard Contractual Clauses. Nothing is sold, and nothing is shared with data brokers or advertisers.
6. Why we are allowed to hold it (GDPR)
- Performance of a contract — your account, schedule, notes, evaluations, connections and preferences. Without them there is no app.
- Legitimate interest — the questions logged from Ask, to see where the feature fails and fix it. You can object; see below.
7. How long it is kept
For as long as your account exists. Delete your account and the database removes your profile, schedule, notes, evaluations, connections and logged questions in the same operation — it cascades, so nothing is left behind under a stale identifier. Backups roll off within 30 days.
Deleting your account, in the app: Me → Delete my account.
It is immediate and cannot be undone. If you can no longer sign in, email jim@23g.nl from the address you registered with and it will be done for you within 30 days.
8. Your rights
You have the right to access, correct, delete, restrict and object to the processing of your data, and to receive it in a portable form. Most of it needs no request: your profile and preferences are editable in the Me tab, your trip report exports as Markdown, and deletion is one button. For anything else, email jim@23g.nl — you will get an answer within 30 days. If you are not satisfied, you can complain to your national supervisory authority; in the Netherlands that is the Autoriteit Persoonsgegevens.
9. Security
Everything travels over TLS. Access to your rows is enforced in the database itself with row-level security, so a query can only ever return your own data or what a connection has explicitly agreed to share. Sign-in tokens live in the platform keystore, and API keys stay on the server and are never shipped inside the app.
10. Children
The app plans a professional conference and is not directed at children under 16. We do not knowingly collect their data; if you believe a child has an account, email us and it will be removed.
11. This website
This site sets no cookies and embeds no advertising or third-party trackers. It counts page views with Vercel Web Analytics, which stores nothing on your device: it records the page, the referrer, and a coarse device type and country derived from your IP address, which is not itself kept. The identifier used to count a repeat visit is a hash that is thrown away daily, so it cannot follow you between days or to any other site. It loads a font from Google Fonts, which means your IP address reaches Google to serve that file. The page that confirms your email reads the result out of the address bar and immediately clears it, so a token does not sit in your browser history.
12. Changes
If this policy changes materially you will be told in the app before the change applies. The date at the top always says when this version took effect.
13. Contact
Jim van Eijk · jim@23g.nl
Karperstraat 4 - 2421HT Nieuwkoop - The Netherlands