Legal
Privacy Policy
The short version
- We store your email, and — if you sign in with Google — your name and profile photo.
- Passwords are hashed with Argon2. We never store or transmit them in readable form.
- When you use Ask, the text of your request is sent to OpenAI. Your email and account ID are not.
- We use Google Analytics to count visits. No advertising, no ad profiling, and nothing sold or shared for marketing — and you can switch it off below.
- You can delete your account and everything in it at any time, from the account menu.
1. Who we are
filter.events is a search tool for public events. It collects event listings that Luma and Partiful publish openly, stores them in one database, and lets you search that database — including by describing what you want in ordinary English. The service is operated by Zyno AI Inc.. You can reach us at support@zyka.ai.
2. What we collect
Only what the product needs to work. Specifically:
Account information
| Data | Why | When |
|---|---|---|
| Email address | Identifies your account and is how we would contact you | Always |
| Argon2 password hash | Lets you log back in without us knowing your password | Email sign-up only |
| Google account ID, name, profile photo URL | Identifies your account and shows your name and picture in the interface | Google sign-in only |
Session information
When you log in we generate a random token, send it to your browser as a cookie, and store only a SHA-256 hash of it alongside its creation, last-use and expiry times. The hash cannot be turned back into the cookie, so a copy of our database does not let anyone log in as you.
Things you create
Saved prompts store the words you typed and the filters they were understood as. Saved views store a name and a set of filters. Both are private to your account and are only ever returned to you.
Technical information
Your IP address is held briefly in server memory to enforce rate limits on sign-up, login, prompt search and manual syncs. It is not written to the database and is discarded when the window elapses. Our web server also writes ordinary access logs, which include IP addresses and requested paths.
Usage analytics
We use Google Analytics 4 to understand how the site is used in aggregate —
how many people visit, which pages they open, roughly where in the world
they are, and what kind of device they use. It is configured with
anonymize_ip, so your IP address is truncated before it is
stored, and with Google Signals and ad personalisation turned
off, so it cannot be used to build an advertising profile
of you or follow you across other sites.
Analytics never receives your email address, your account ID, your saved prompts, or the text of anything you type into Ask. You can turn it off for this browser in section 4.
What we do not collect
No advertising cookies, no cross-site tracking, no fingerprinting, no precise location, no contact lists, and no data from any source other than you, the sign-in provider you choose, and the aggregate analytics above.
3. Where your data goes
OpenAI
When you use the Ask feature, the text of your request is sent to OpenAI's API so it can be converted into search filters. Your email address, account ID and saved data are not included. OpenAI processes it as a data processor and, under its API terms, does not use API inputs to train its models by default. If you would rather nothing left our servers, use the manual filters on Discover instead — they never call OpenAI.
If you choose "Continue with Google", you authenticate directly with Google
and we receive your Google account ID, email address, name and profile photo
URL. We request only the openid, email and
profile scopes. We cannot read your Gmail, Drive, Calendar or
contacts, and we never receive your Google password. You can revoke our
access at any time at
myaccount.google.com/permissions.
Google Analytics
Separately from sign-in, Google acts as our analytics processor. It receives truncated IP addresses, page paths, referrers, and coarse device and country information. Google's own handling of that data is described in Google's privacy policy and how Google uses data from sites that use its services.
Content delivery networks
The interface loads fonts, stylesheets, scripts and map tiles from jsDelivr, unpkg, Google Fonts and OpenStreetMap. As with any resource loaded from another domain, those providers can see your IP address and the file requested. They receive nothing about your account.
Luma and Partiful
We read publicly available event listings from these platforms. We do not send them anything about you, and they do not know you use this service.
Who else
Nobody. We do not sell your data, rent it, share it with advertisers or brokers, or transfer it for anyone else's marketing. We would disclose data only where the law compels it, and only what is compelled.
4. Cookies and local storage
| Name | Purpose | Lifetime |
|---|---|---|
session | Keeps you logged in. HttpOnly, SameSite=Lax, Secure in production. | 30 days, sliding |
oauth_state | Prevents cross-site request forgery during Google sign-in. | 10 minutes |
filter-events-theme | Your light/dark preference. Stored in your browser only; never sent to us. | Until you clear it |
_ga, _ga_* | Google Analytics. Distinguishes one browser from another so visits can be counted without identifying you. | Up to 2 years |
ga-opt-out | Set only if you opt out below, so we remember not to load analytics. Local to your browser. | Until you clear it |
The first three are strictly necessary or purely local. The analytics cookies are not: you can decline them.
Turning analytics off
Use the switch below and this browser stops sending analytics immediately and on every future visit. We also honour your browser's Do Not Track setting automatically — if it is on, analytics never loads in the first place.
5. How long we keep it
- Account data — until you delete your account.
- Sessions — deleted when you log out, and expire after 30 days of inactivity. Expired rows are purged automatically.
- Saved prompts and views — until you delete them, or delete your account.
- Rate-limit counters — minutes; they live in memory and do not survive a restart.
6. Deleting your account
Open the account menu in the top-right and choose Delete account. This removes your user record immediately, and your sessions, saved prompts and saved views are deleted with it by the database itself. It cannot be undone and we do not keep a shadow copy. You can also email support@zyka.ai and we will do it for you.
Deleting your account here does not delete anything on Luma or Partiful — those are separate services with their own accounts.
7. Your rights
Depending on where you live you may have the right to access, correct, export or erase your personal data, to object to or restrict processing, and to complain to a data protection authority. The account menu covers access and erasure directly. For anything else, write to support@zyka.ai and we will respond within 30 days.
8. Security
Passwords are hashed with Argon2. Session tokens are 256 bits of cryptographically random data, stored only as a SHA-256 hash. Traffic is served over HTTPS. Cookies are HttpOnly and SameSite=Lax. Sign-up, login and prompt search are rate limited. Every saved prompt and view is scoped to its owner in the database query itself, not merely hidden in the interface.
No system is perfectly secure. If you find a vulnerability, please report it to support@zyka.ai before disclosing it publicly.
9. Children
This service is not directed at children under 16, and we do not knowingly collect their data. If you believe a child has created an account, contact us and we will remove it.
10. International transfers
Our servers and the third parties named above may process data outside your country, including in the United States. Where required, transfers rely on the standard contractual clauses those providers publish.
11. Changes
If we change this policy we will update the date at the top. Changes that materially affect how we handle your data will be announced in the application before they take effect.
12. Contact
Questions about this policy, or a request to access, export or erase your data, should go to the data controller:
Zyno AI Inc.495 Alice Ave, Mountain View, CA 94041, United States
support@zyka.ai
See also the Terms of Service.