Effective date: July 25, 2026
This Privacy Policy explains what information we collect, why we collect it, and what choices you have when you use the IHNYC RC web properties and the calendar subscription system (the “Service”).
Quick Summary
- Calendar subscriptions: if you subscribe, you give us your name and email so we can send a magic link and issue a calendar access token.
- Token safety matters: calendar links are sensitive—anyone with your tokenized link may be able to access your calendar feed.
- Security logs: like most services, we keep access/security logs and may use anti-abuse tools.
- Analytics: we keep first-party product and security event logs in our own database to understand usage and operate the Service. We do not send your raw email address to analytics. The former Mixpanel integration has been removed (see Section 4.4).
- AI processing on Cloudflare: event and message parsing runs on Cloudflare Workers AI (Llama models) on Cloudflare’s platform. We do not send your data to OpenAI or other external AI providers.
- WhatsApp assistant: the assistant redacts personal information before text is stored and does not keep raw chat, phone numbers, image bytes, or audio bytes. It can route events, official updates, sanitized resident observations, and private casework (see Section 4.7).
- Cookies: Cloudflare, including Turnstile and Access where enabled, may set cookies.
- We don’t sell personal information.
- Questions? Email admin@ihnyc-rc.org.
This summary is here to help. The full policy below is what controls.
Important relationship notice. Affective Technologies operates the website and technical backend supporting the Resident Council and is not affiliated with the Council, with International House NYC, or with AVI Foodsystems.
1. Who we are
The Service is operated by Affective Technologies LLC (“Affective Technologies,” “we,” “us,” or “our”).
2. What the Service includes
The Service includes IHNYC RC web properties such as ihnyc-rc.org (informational pages and public updates) and calendar.ihnyc-rc.org (the calendar subscription system and token-gated access to an .ics feed).
The Service also includes the operational tooling used to create and publish calendar events and updates, including automations and databases described below.
3. How the calendar subscription works (high level)
We designed the calendar subscription to be easy to use and reasonably private. At a high level, the system works like this:
- Event creation. Weekly “Happenings” newsletter emails are forwarded to a Cloudflare Email Worker, which uses Cloudflare Workers AI (Meta Llama models) to extract structured events and house updates into Notion databases (the Resident Council’s primary knowledge base). Where an event is shared as a poster image, Cloudflare Browser Rendering plus a vision model read it. The raw forwarded email is archived in Cloudflare R2. All AI runs on Cloudflare’s platform — we do not send this content to OpenAI or other external AI providers.
- Calendar generation. Events are periodically fetched from Notion and written into an
.icscalendar feed stored in Cloudflare R2. - Token-gated delivery.
calendar.ihnyc-rc.orgserves token-gated access to the.icsfile using Cloudflare Pages/Workers plus a Cloudflare D1 database. - Email verification. Subscribing uses email-based magic link verification (transactional email via Resend), token minting, token expiry, token revocation, and
last_seen/last_seen_attimestamps. - Anti-abuse. We may use Cloudflare Turnstile (where enabled), Cloudflare Access (admin panels where enabled), and rate limiting/cooldowns for repeated requests.
Important: calendar subscription links can be sensitive. If someone gets your tokenized calendar URL, they may be able to fetch your feed until the token expires or is revoked.
4. Information we collect
4.1 Information you provide
The informational website does not offer user accounts/logins. If you subscribe to the calendar, you may provide:
- Name (optional/if requested by the subscription form)
- Email address (required to send a magic link and manage your subscription)
If you use third-party services linked from the site (for example, external forms, documents, or resources hosted on other domains), those services may collect information under their own policies.
4.2 Subscription records and identifiers
To operate the calendar subscription system, we store certain records in our database (Cloudflare D1). These may include:
- Subscriber records (name and email address, and subscription status)
- Verification requests (for example, magic link request records; we store a hash of the one-time code, not the code itself)
- Calendar access token hashes. The token is shown in your private feed URL, but the current service stores only its SHA-256 hash. Renewal uses a separate signed, expiring credential that cannot fetch the feed.
- Token lifecycle metadata (for example, expiry, revocation status, renewal counts, the inferred calendar client, and
last_seen/last_seen_attimestamps)
4.3 Technical, security, and access data
When you use the Service (including when your calendar app fetches the .ics feed), we and our infrastructure providers automatically receive technical and security information:
- Hashed IP address — we store a SHA-256 hash of your IP address (not the raw IP), used for security logging and abuse prevention
- User agent — the browser/device/calendar-client string sent by your software, which often identifies the calendar client (Apple, Google, Outlook)
- Approximate country — the two-letter country code Cloudflare derives from your connection (e.g.
US), stored with calendar-feed requests - Request path, status, and timestamps (for example, what endpoint was requested, the response code, and when, including
last_seen_at) - Request latency — how long a calendar-feed request took to serve, for performance monitoring
- Infrastructure/security metadata (for example, Cloudflare identifiers like
CF-RAY) - Email-provider message IDs — the identifier Resend assigns to a magic-link or renewal email, so we can match delivery events back to your request (see Section 4.5)
- Theme preference stored in your browser via
localStorage(key:ihnyc-rc-theme)
4.4 Product and security event logging
To understand usage, operate the signup flow, and secure the Service, we keep a first-party event log in our own database (Cloudflare D1). These events are recorded by us and not shared with a third-party analytics vendor.
Example events we record include: a magic link being requested, sent, clicked, or consumed; Turnstile passing or failing; a token being minted, seen, renewed, or expired; a calendar feed being fetched; invalid/expired/revoked token attempts; and email delivery outcomes (see Section 4.5). Each event may carry context such as the calendar id, a hashed identifier, the inferred calendar client, the response status, country, and request latency. We do not store your raw email address in these events.
Mixpanel (retired). The service previously sent a copy of these events to Mixpanel’s EU endpoint. That integration has been removed and no current event path writes to Mixpanel. Where it was active, Mixpanel received a distinct_id derived from a SHA-256 hash of the normalized email plus a server-side pepper, not the raw email.
4.5 Email delivery events
We send magic-link and renewal emails through Resend. Resend notifies us, via a signed webhook, when one of those emails is delivered, bounced, or marked as spam/complaint. We verify the signature on these webhooks and record the outcome (and the related provider message id) in our event log so we can tell whether your verification email reached you and troubleshoot delivery problems. We do not use this to track your activity outside of email delivery.
4.6 Event content stored in Notion
The Resident Council’s primary knowledge base is stored in Notion. As described in Section 3, a Cloudflare Email Worker parses the weekly “Happenings” newsletter using Cloudflare Workers AI (and Cloudflare Browser Rendering with a vision model for poster images) and writes structured event and house-update content into Notion databases. A person reviews this content before it is published to the calendar or site.
This content may include event titles, dates/times, locations, descriptions, sign-up links, and House Updates. Public council-member data comes from RC Console D1 rather than Notion. The Council supplies that profile content; RC Console produces the public member artifact used by the site.
4.7 WhatsApp group assistant
An automated assistant operated by Affective Technologies reads selected Resident Council WhatsApp groups for community events, official update candidates, resident observations, and private casework. It is limited to approved groups and does not send messages, reply, or participate in conversations.
What it does:
- Redaction at the door. Before any message text is stored or processed, the assistant automatically strips personal information from it, including email addresses, phone numbers, and @ mentions of group members.
- No raw chat is kept. The assistant does not store raw messages, contact names, profile photos, message history, or your phone number. Redacted candidate text may remain in a temporary Cloudflare KV buffer for up to 14 days before processing or expiry.
- Images and voice notes. Event-flyer images may be read with a vision model, and voice notes may be transcribed with Whisper. Image and audio bytes are used only for the inference call and are not written to KV, R2, logs, or the processing ledger.
- Classification. Redacted candidates are classified after a short debounce or by a six-hour batch. Most ordinary chat and obvious spam are ignored.
- Review boundaries. Events and official House Update candidates remain unpublished until a person approves them. Resident observations are rewritten to remove or generalize identifying details before they enter the Resident Notes feed; an editor can revoke them. Casework goes to a private database and is never a public-content route.
The assistant does not retain raw message contents, your phone number, your WhatsApp display name or profile photo, read receipts, message history, or raw media.
The assistant connects to WhatsApp through a self-hosted connector (Evolution API) operated by Affective Technologies. WhatsApp is provided by Meta under its own terms and policies, which govern the messaging platform itself.
4.8 Resident observations and casework
A resident observation may be published only after an automated sanitation step removes or generalizes personal details. The stored record may include a category, summary, generalized body, source group, received time, confidence, and evidence text. An editor can set it to Revoked to remove it from the public feed.
Private casework can arrive through WhatsApp, email, or a contact-form relay. A case may include the issue text, source, timestamps, department, urgency, status, routing owner, reply-thread identifiers, and attachments or contact details the resident supplied. Related reports or replies may be consolidated into one open case. Email is archived before processing so a failed parse can be recovered.
Casework is stored in a private Notion database with a stricter operator access boundary than RC Console. Current role owners are read from RC Console. Casework is not published as an event, House Update, or Resident Note.
5. How we use information
We use the information we collect to:
- Operate the informational site and the calendar subscription system
- Verify subscriptions (magic links), mint/rotate/revoke tokens, and deliver the token-gated
.icsfeed - Secure the Service (fraud prevention, abuse prevention, debugging, auditing, and incident response)
- Measure usage and improve the Service (analytics and performance monitoring)
6. Cookies and similar technologies
Depending on which parts of the Service you use, cookies and similar technologies may be set by us and/or by our providers. For example:
- Cloudflare may set cookies or use similar identifiers for security/performance features, and Cloudflare Turnstile and Cloudflare Access (where enabled) may set additional cookies to operate.
- Mixpanel may have set cookies while the retired analytics integration was active. The current service does not load that integration.
You can control cookies through your browser settings. Blocking cookies may impact some features.
7. Third-party services and processors
We use the following third-party services to operate the Service (these act as service providers/processors, depending on context):
| Service | Purpose |
|---|---|
| Cloudflare | Hosting and infrastructure: Pages, Workers, D1 (database), R2 (storage), KV, Turnstile, Access, Email Routing, and Browser Rendering |
| Cloudflare Workers AI | On-platform models that parse newsletters and classify, transcribe, sanitize, and route redacted WhatsApp or casework candidates. |
| Notion | Event and content databases (the curation/staging surface the Council edits before publishing) |
| Resend | Transactional email delivery, plus signed webhooks reporting delivery/bounce/complaint status |
| Evolution API (self-hosted) | WhatsApp group connector operated by Affective Technologies |
| GitHub | Stores public site code and generated public content artifacts |
| Short.io | Click statistics for short links used on the site |
| n8n | Legacy automation host; now used only as a proxy for the internal (members-only) calendar feed. It no longer parses newsletters — that moved to Cloudflare Workers AI. |
| Mixpanel | Retired analytics provider; no current event writes |
The Service may also link to third-party websites and resources (for example, Notion pages, Google Forms, Canva documents, and other external resources). If you follow those links, your interaction is governed by the third party’s policies.
Some pages may display embedded content or previews of third-party documents. When that happens, third parties may receive standard request data (such as IP address and user agent) as part of serving or rendering that embedded content.
8. How we share information
We may share information in the following circumstances:
- Service providers. We share information with the vendors listed above to operate the Service (hosting, storage, security, email delivery, automations, analytics, and document/content platforms).
- Legal and safety. We may disclose information if required by law, or if we believe disclosure is necessary to protect our rights, safety, users, or the integrity of the Service.
We do not sell personal information.
9. Data retention
We retain information for as long as reasonably necessary to operate the Service, maintain security, comply with legal obligations, resolve disputes, and enforce our policies. Retention periods may vary by data type, system configuration, and operational needs, and we may update them over time.
When information is no longer needed for these purposes, we take reasonable steps to delete it or de-identify it, unless we are required to keep it longer by law or for legitimate business and security needs.
| Data Type | Retention |
|---|---|
| Subscriber records (name/email) | Retained to provide the subscription and support requests |
| Verification requests and code hashes | Retained according to operational settings for verification and abuse prevention |
| Token hashes and lifecycle metadata | Retained to operate access control and for security/auditing |
| Calendar access logs (hashed IP, user agent, country, latency, path/status) | Retained for security, abuse prevention, and troubleshooting |
| Product/security event log (first-party) | Retained for operating the signup flow, security, and auditing |
| Email delivery events (from Resend webhooks) | Retained to confirm deliverability and troubleshoot email problems |
| Mixpanel analytics copy (legacy) | No current writes; any prior data follows the former account’s retention settings |
| Notion event content | Retained according to Resident Council’s operational practices |
| Redacted WhatsApp candidates | Held in a temporary buffer for up to 14 days; raw chat and raw media are not stored |
| Resident observations | Retained while active; an editor can revoke a note from the public feed |
| Private casework | Retained for routing, follow-up, audit, and recovery according to operational and legal needs |
10. Your choices and privacy requests
- Cookies. You can manage cookies through your browser settings.
- Theme preference. You can clear the theme preference by clearing site data in your browser (local storage).
- Token safety. If you believe your tokenized calendar link has been shared or compromised, contact us so we can revoke it and issue a new one.
- Privacy requests. You may request access, correction, deletion, or other help with your information by contacting us (see Section 14). We’ll respond consistent with applicable law and the needs of operating and securing the Service.
11. Data security
We use reasonable administrative, technical, and organizational measures to help protect the Service and the information we process. This includes measures like access controls (for example, Cloudflare Access where enabled), bot mitigation (for example, Cloudflare Turnstile where enabled), and rate limiting/cooldowns for repeated requests. No method of transmission or storage is perfectly secure.
12. International users
If you access the site from outside the United States, your information may be processed in the United States or other jurisdictions where our service providers operate. For users in the European Economic Area (EEA) and other jurisdictions with data protection laws, we comply with applicable requirements, including GDPR. We try to use GDPR-compliant service providers when possible, including running model inference on Cloudflare’s platform, and maintain appropriate data processing agreements where required.
13. Changes to this Privacy Policy
We may update this Privacy Policy from time to time. If changes are significant, we will update the Effective date above. If you keep using the Service after the update takes effect, you’re agreeing to the updated policy.
14. Contact
For privacy questions or requests, contact: admin@ihnyc-rc.org
15. Intellectual property and platform notice
The technical backend and implementation details that operate the Service are intellectual property of Affective Technologies LLC. This Privacy Policy describes how data is handled by the Service; it does not grant any rights to the underlying technology.