Effective August 18, 2026 · Updated September 28, 2026 · Applies to the Poster iOS app and poster.fyi
Poster is built around one idea: you photograph event posters in the real world, and they become events other people nearby can find. That means some of what you capture is meant to be public. This page spells out exactly what is, what isn't, and what we do with your photo.
When you photograph a poster, we read and extract ("scrape") information from your photo: the event's title, date and time, venue, address, price, and category. The first read happens on your phone; after the poster is published, a second read on our side checks the details against the photo (see "How posters are read" below). Snapping a poster publishes it: there is no separate step in between. When it is published, these are uploaded:
The cropped photo and the event details become public: they are visible to anyone using Poster, alongside your display name. You can correct the details after publishing. The wider photo and the recognized text are not shown in the app. They are stored where only our server-side reader can open them, and kept so the details can be checked and so we can improve how posters are read. Don't capture things you don't want published. Poster photos should be of posters, not people. If a photo captures something it shouldn't, email us and we'll take it down, and any user can report an event in the app (events reported by several people are taken down automatically).
Adding one is optional. You can choose a photo from your library or take one with the camera, and you crop it yourself before anything is saved. It's saved as a single still image, even if you pick a Live Photo.
Only the picture is uploaded. The photo is cropped and re-encoded on your phone, and the original file's metadata is left behind, including where and when it was taken. iOS may warn you that the photo you're picking contains location information; that's about the file on your device, and Apple gives apps no way to decline it in advance. We don't receive it, and it isn't in what we store.
Your profile photo is public: it appears next to your name wherever you show up in the app. You can replace it at any time, or email us to have it removed.
The personal information Poster collects, in full:
If you choose to, Poster can look through your contacts to find people you know who already use it. That happens on your phone: names and numbers never leave it. For each number the app sends a scrambled version (a SHA-256 hash of the number), the server answers with any matching account, and what it was sent is discarded. Nothing from your address book is stored on our servers. A scrambled number is still your number in disguise, so it's matched and discarded, never kept. To make that work, we keep a scrambled form of your own verified number, made with a key only our server holds, so what's stored can't be turned back into a number without it. We still treat it as your number. Being findable also means people who have your number can invite you to events inside the app. You'll hear about it, at most three times a day; anything more waits quietly on your Plans. Anyone can stop being found this way in the app's Settings, under Privacy: "Let people who have your number find you." It's on unless you turn it off.
Poster is a public, browse-without-an-account app. Visible to anyone: published poster photos and their event details, your display name and profile photo, your capture history and awards (your wall), RSVP counts, and the leaderboard. Not public: your phone number, your precise capture locations (only the event's location is shown), your saved-events list, who you follow, who you've blocked or reported, and anything you typed into the invite request form.
The first read of a poster runs on your device: text recognition and a draft of the event details are made on your phone before anything is published. The cropping of your profile photo runs there too, and so does calendar sync: whichever calendar you sync to, the writing is done by your phone and none of it passes through us. Photos you don't publish never leave your phone.
Publishing is instant, and the details are double-checked afterwards. Once a poster is published, our server sends the poster photo (with the wider frame, when one was uploaded) plus the recognized text and your draft details to Anthropic's Claude API, which reads the poster and corrects the event. What travels with the photo is about the poster, not about you: no name, no phone number, and never where you were standing when you captured it. Anthropic's API terms bar it from training models on what we send, and requests are held only briefly on their side for abuse monitoring, not kept.
Optional, and off until you turn it on. When it's on, events you save are written to a calendar of Poster's own, a separate calendar named Poster rather than your personal one, and removed from it when you un-save them. What gets written is the event as the app already shows it: title, date and time, venue and address, and a line saying it was saved from Poster.
Apple Calendar goes through EventKit on your phone. It never reaches our servers, and we never see your calendar. One caveat about the separate calendar: an account can refuse to hold a new one, and if none of yours will take it, entries go to your default calendar instead, sync that still works being the better of the two failures. Poster still only touches the entries it wrote.
Google Calendar goes through the Google Calendar API, with an account you connect yourself. Your phone talks to Google directly. None of it passes through Poster's servers. We never receive your Google data, and we never see your calendar here either. Specifically:
You can disconnect Google in Settings at any time, which deletes the tokens from your phone. Entries already written stay where they are. They're on your calendar, not ours. Disconnecting doesn't withdraw the permission on Google's side, so if you want the grant gone as well, remove Poster on your Google Account's permissions page. One thing you may see there: an earlier version of Poster asked for a broader calendar permission, and a connection made back then keeps it until it is replaced. Removing Poster on that page and connecting again swaps it for the narrow one described here.
Limited Use. Poster's use and transfer of information received from Google APIs to any other app adheres to the Google API Services User Data Policy, including its Limited Use requirements.
No ads. No trackers, no advertising identifiers, nothing that follows you from here to another site. The app talks only to Poster's own servers and the services named under "Processors" below. This website loads one thing from outside: Cloudflare's visit counter, described under "Cookies and tracking" below. We don't sell your data. Anthropic, which reads published posters for us, is barred by its API terms from training models on what we send.
Three third-party service providers for the app, and one for this website. Our backend (database, photo storage, and phone verification) runs on Supabase. Verification codes are delivered by an SMS provider, which necessarily handles your phone number in transit. Published posters are read by Anthropic's Claude API, which receives the poster photo and its text, never your identity, and never your capture location. This website, poster.fyi, is served by Cloudflare, which handles your browser's request the way any host does and so sees your IP address for as long as it takes to answer it. Cloudflare also counts visits to this site for us, with a script it serves onto every page from static.cloudflareinsights.com (see "Cookies and tracking"). Its part is counting visits to these pages, not the app or anything you publish in it. That's the whole list. Google isn't on it: if you connect Google Calendar, that's your phone and your account talking to Google, not us handing anything over.
Our security measures, stated plainly rather than as a list of certifications. Everything travels over an encrypted connection: your phone to our backend, and this site to your browser. What's stored is encrypted at rest by Supabase, who host it.
Inside the database, access is enforced row by row rather than left to the app to remember to ask nicely: your saved events, who you follow, and who you've blocked are readable only by you. The precise spot where a poster was captured is readable only by the person who captured it. It was deliberately taken out of what any app can read, ours included, and only the event's own location is ever shown. Google Calendar tokens are held in your phone's keychain and never reach us at all.
One thing is unprotected on purpose: published poster photos and their event details are public. That's the app working as intended, not a gap, and it's why the section above tells you to photograph posters rather than people.
During the beta, administrative access to the database belongs to one person, and nobody else is on the inside.
Our retention periods are short enough to list outright:
Email hello@poster.fyi from any address and tell us your display name or phone number. We'll delete your account and everything tied to it, or individual captures if that's all you want. During the beta this is handled by a human (quickly).
Depending on where you live you may have a legal right to see the personal information we hold about you, correct it, take a copy of it, or have it deleted, and to withdraw consent you've given. We don't ask which country you're in before honoring any of that. Email us and we'll do it, whoever you are and wherever you are. The choices built into the app count too: you can browse without an account, decline location, skip a profile photo, leave calendar sync off, and disconnect Google whenever you like.
This site sets no cookies of its own. It has no tracking pixels, no advertising identifiers, and no cross-site tracking, and the fonts and images are served from poster.fyi itself. We count visits with Cloudflare's analytics, a script loaded onto every page here from Cloudflare's own servers, at static.cloudflareinsights.com. Cloudflare says it sets no cookies, takes no fingerprint of your browser, and doesn't follow you anywhere else; what reaches us is a count of pages, not of people. If you arrived from a link we shared somewhere, the link tells us which one. That's all it carries. Your browser keeps those tags and sends them along if you ask for an invite, so we can tell which post brought someone. Before September 2026 this page said the site loaded nothing from another company. That was true then. The visit count is what changed. One thing the homepage does count: it shows one of a handful of headlines, remembers which in your browser's own storage so you see the same one next time, and once per visit tells our backend which headline was shown. That is a number per headline per day, with nothing about you attached, and it goes to Supabase, which already runs the backend named below. A second script on every page is Cloudflare's too: a small bot check that looks at the browser asking for the page to tell people from automated traffic. It isn't analytics, it doesn't follow you anywhere else, and it isn't in the code we publish. Cloudflare may set a cookie for that check; we haven't seen it do so, and we set none. The app doesn't track you across other apps or websites, and there is no advertising network involved at any point.
Poster isn't for children. You need to be at least 13 to use it, and old enough where you live to agree to the terms. We don't knowingly collect personal information from anyone under 13; if you believe a child has given us some, email us and we'll delete it and the account with it.
One address, read by a person: hello@poster.fyi. Questions about this policy, requests about your data, and anything you think we've got wrong all go there. During the beta, Poster is run from San Francisco by its developer.
If this policy changes in a way that matters, we'll say so in the app before the change applies. This page always has the current version, with the date it was last updated at the top.