HostnToast

Privacy Policy

Effective date: September 9, 2026

HostnToast ("we," "us," or "the app") is a party-planning app for iPhone and iPad. This policy explains what information the app handles and how. Most planner data stays on your device. Account, invitation and RSVP, Memories, recipe, Cookbook, and purchase features use the server and providers described below.

Information stored on your device

Your parties, guest lists, menus, seating charts, to-dos, grocery lists, journal entries, private notes, budgets, receipt references, and party photos are stored locally on your device. This planner information is not synced to our server as a general backup. Only the information needed for the account, invitation and RSVP, Memories, recipe, Cookbook, and purchase features described below leaves your device.

Device-local planner information remains until you delete it, remove the app or its data, or complete the in-app account-deletion flow for that signed-in account on that device. Account deletion removes that account's scoped planner record and attempts to delete its referenced local party photos and receipt files from the device where deletion is performed. A local file may remain if the device cannot delete it. Account deletion does not remove frozen legacy unscoped planner data or another account's local data.

Contacts

If you grant permission, HostnToast reads the name, email address, and phone number from a contact you select to help fill in a guest entry. The app does not bulk upload your address book. Selected contact information is copied into your device-local guest record. Email addresses and phone numbers used by your device to send an invitation are not sent to the HostnToast server. The invitation and RSVP information listed below is sent when an RSVP link is created.

Camera and photos

If you grant permission, the app uses your camera and photo library so you can capture or select party and Cookbook images. Party photos remain on your device unless you intentionally share them in a Memories keepsake. Cookbook images leave your device when you upload them to a saved recipe or choose one for recipe-image scanning, as described below.

Information that leaves your device

1. Your account

HostnToast offers sign-in with Apple or email through our authentication provider, Clerk. Clerk processes account and authentication information needed to create, verify, and maintain your sign-in. The HostnToast database stores your Clerk account identifier and the status of your one-free-party eligibility. It does not store your Clerk profile name, email address, phone number, or sign-in credential.

2. RSVP invitations

When you create an RSVP link, the HostnToast server stores the guest name as you entered it, internal party and guest identifiers, the party name, date, location or address, notes you chose to share with guests, and the allowed number of additional guests. It does not receive that guest's email address or phone number. When a guest replies, the server stores the response, response time, optional note, party size, dietary restrictions, and any additional guest names they enter so the response can appear in your app. Anyone with an invitation link can open and respond through that link.

3. Shared Memories keepsakes

Photos and party memories are uploaded only when you intentionally share a keepsake. A shared keepsake can include the party name, date, location, theme, notes to guests, selected journal highlights and rating, moments, food and drink names, attended guest names, photo captions, and the photos you selected as re-compressed copies. Host-private notes, expenses, and the "do differently" journal field are not included. Photos are stored in private object storage and delivered through the HostnToast service. Anyone with the keepsake link can view and download the content you chose to share. Guests can submit a name and comment through a Memories or keepsake page; those entries are stored and shown to the host and, when included in a shared keepsake, to people with its link.

4. Recipe search

Spoonacular searches send your search words, optional meal type, and requested result count through the authenticated HostnToast API to Spoonacular. The HostnToast server uses your account identifier to authenticate and rate-limit the request, and keeps a shared response cache keyed by the query rather than by your identity. Searches and category browsing using TheMealDB are sent through the HostnToast API to TheMealDB and can include search words, a category, a first letter, or a recipe identifier, depending on what you request.

5. My Cookbook and AI recipe-image scanning

My Cookbook recipes, including ingredients, instructions, notes, source details, and other recipe fields you enter or save, are stored on the HostnToast server and associated with your Clerk account identifier. Cookbook photos are uploaded to private object storage and are available through HostnToast's owner-scoped API to the authenticated owner.

When you choose to scan a recipe image, the selected image is transmitted to OpenAI through Replit AI so recipe information can be extracted. HostnToast does not use recipe images for advertising or profiling. If you save the result, the recipe data and any photo you choose to save are stored as described above. We do not state or control separate vendor retention periods; those providers handle data under their own terms and policies.

Deleting a Cookbook recipe or photo removes its associated server record and private stored photo. Deleting your HostnToast account removes Cookbook recipes and Cookbook photos associated with that authenticated account. If a storage deletion cannot be completed, account deletion stops with a retryable error rather than discarding the stored reference needed to try again.

6. Subscriptions

In-app purchases are billed by Apple and subscription status is managed through RevenueCat. Apple handles your payment details. HostnToast and RevenueCat process subscription product, entitlement, transaction, customer or app-user identifier, and status information needed to provide and restore access. The RevenueCat SDK also sends operational purchase and SDK-event data, including app, device, or browser context, to operate and diagnose the purchase service. HostnToast does not receive your full payment-card details from Apple. You can read RevenueCat's privacy policy at revenuecat.com/privacy.

7. HostnToast infrastructure

The HostnToast API is hosted on Replit. Server records described in this policy are stored in the app's Replit-hosted database, and shared keepsake and Cookbook images are stored in private object storage used by that API. Information may also pass to Clerk, Apple, RevenueCat, OpenAI through Replit AI, Spoonacular, or TheMealDB when you use the corresponding feature.

What we don't do

How long information is kept

HostnToast does not apply a fixed automatic deletion period to account-linked RSVP invitations, responses, shared keepsakes, guest comments, or saved Cookbook content. They remain until you delete or replace applicable content, delete your account as described below, or ask us to address information that cannot be removed in the app. A short-lived pending upload record may be reclaimed after an incomplete Cookbook photo upload. Spoonacular response-cache entries expire no later than one hour after retrieval. Device-local retention is described above. We do not promise or invent retention periods for third-party providers.

Deleting your account

You can delete your account any time in the app: Settings → Account → Delete Account. The process removes account-linked RSVP invitations and responses, shared keepsakes, keepsake photos, guest comments stamped with your account ownership, Cookbook recipes and photos, your HostnToast account record, and your Clerk sign-in account. Those invitation and keepsake links then stop working. It also removes that account's scoped planner data and referenced local party-photo and receipt files from the device where you complete deletion.

For an account linked to Sign in with Apple, deletion requires a fresh Apple confirmation. HostnToast temporarily processes Apple’s identity token and authorization code to verify the Apple identity and revoke HostnToast’s Apple authorization. These credentials are not retained. Confirmed Apple revocation is required before final deletion of the HostnToast account and Clerk user.

If an object-storage or account-provider deletion fails, the process returns a retryable error and preserves the information needed to try the unfinished step again. Server records created before account ownership was attached, including legacy records whose owner is null, are not linked to your account and survive ordinary account deletion; contact us to request review and removal. Frozen legacy unscoped data on the device and another account's device-local data are also outside the account-deletion scope. Deleting an account or the app does not cancel an Apple subscription, which survives until you cancel it in your Apple ID subscription settings.

Children

HostnToast is not directed at children under 13, and we do not knowingly collect personal information from children.

Your privacy choices and rights

You can edit or delete much of your information in the app and can delete your account as described above. Depending on where you live, you may also have rights to request access to, correction of, or deletion of personal information, or to object to or restrict certain processing. To make a privacy request, including a request concerning a guest response, comment, invitation, keepsake, or legacy owner-null record, email support@hostntoast.app. We may need information sufficient to identify the relevant account or link and verify that you are authorized to make the request.

Changes to this policy

If we make material changes, we will update this page and the effective date above.

Contact

Questions about privacy? Email us at support@hostntoast.app.