coetio

Legal

Privacy Policy

Last updated: August 29, 2026

This Privacy Policy describes what personal information Coetio™ collects, why it is collected, on what basis, who can access it, and how long it is kept. It applies to the service operated at coetio.com and, under the Coevio™ mark, at coevio.com. Both addresses reach the same underlying service; “Coetio” is used in this document as the defined name for that service regardless of which mark a given page displays. This policy is incorporated into and forms part of the Terms of Service.

Most people who use Coetio are minors. Collection is limited to what is required to operate a club or volunteer program, records are kept inside the club they belong to, and this document states plainly what is retained. Where the product keeps a record that may not be obvious from the interface, that record is disclosed here.

Summary

  • Personal information is not sold, and no advertising is served.
  • A phone number is optional at every point of collection. If provided, it is visible only to the club owner and to accounts with platform administrative access.
  • Most information entered into the product is visible only inside the club it belongs to.
  • Clubs retain a record of task and work activity: who created a task, who assigned it, each reminder sent, and who completed each step. Where a leader marks a task complete on behalf of every assignee, the record identifies that leader. This record is available to the club's leaders and to the other members assigned to the same task. Task and work records below has the full detail.
  • Account holders can turn off email from their clubs, export their data, correct it, or delete their account, from their own account settings.
  • Analytics are anonymous and cookieless. No cookie consent banner is shown because no non-essential cookie is set.
  • An account may be held only by a person who is 13 years of age or older. Coetio does not knowingly collect personal information from anyone under 13.

Information collected

Account information

  • Name, email address, and graduation year. Creating a password-based account requires these three fields. An account created through Google sign-in begins with only the name and email address Google provides; the remaining fields can be completed afterward on the Profile page.
  • Date of birth, collected at account creation to confirm the account holder is 13 years of age or older, as described in Children's privacy below. This requirement took effect August 24, 2026 and applies to a new account created directly on Coetio, whether by password or by completing a Google sign-in, from that date forward. An account created before that date was not asked and has no date of birth on file. A roster entry a leader creates for a person with no account, and a guest event check-in, are not accounts and are not subject to this requirement. Date of birth is visible to nobody but the account holder and accounts with platform administrative access, not a club owner, not an officer, not in any roster export or club backup, and is retained for as long as the account exists, deleted with the rest of the account profile on account deletion.
  • Phone number, which is optional. It may be left blank at account creation and when joining a club; joining does not require it. A club leader may request it to reach members about meetings. If entered, it is validated for format and stored. If left blank, nothing is stored.
  • Optional profile fields: grade level (derived from graduation year, and editable), pronouns, and a profile picture.
  • Password. Authentication is handled by Coetio's authentication provider, which stores passwords only in hashed form. Coetio's own database does not hold account passwords, and passwords are therefore not included in a data export.
  • Google sign-in: Google authenticates the account holder's identity and provides a name and email address. Coetio does not receive the Google account password and does not access any other Google account data.
  • Account settings: notification preferences, the default landing page, whether club email is enabled, whether the account has opted into a club's member directory, and whether the account holder has asked leaders not to include them in photos.

Club membership

  • Roster record: club memberships, status, role and title, join date, dues-paid status, the answer given to a club's join question, a private note a leader may keep about the member, and a buddy pairing where the club uses one. Title grants and removals are timestamped.
  • Club-defined roster fields: a club owner may create custom roster columns and populate them for members. Because these fields are defined by the club, their content is not limited or reviewed by Coetio and may include sensitive information such as allergies, a birthdate, a guardian contact, or an address. What a given club collects in these fields is a matter for that club, not Coetio.
  • Kiosk PIN, if a short code is set for tap-in attendance.

Participation

  • Attendance: check-in date, exact time, and the answer to a club's optional check-in question. Check-in occurs by scanning a QR code a leader displays, by tapping a name in kiosk mode, or by a leader recording attendance manually. Coetio does not access device location; no field in the product records it. An event may carry a street address, and checking in to that event does record that the account holder was present at that address at that time.
  • Guest check-in: attendance at a public event does not require an account. The guest option stores the first name and last initial entered, the event, and the time. No email address or phone number is requested from a guest, no account is created, and no location is recorded. The club owner and its officers can view that list on the event page. Guest check-ins are stored separately from member attendance and are not counted toward any member's attendance record.
  • Attendance change requests submitted to a leader, and the leader's decision.
  • Events: RSVP and waitlist status, check-ins, a rating and comment on a past event, a live-meeting rating, and any note written about contribution to an event.
  • Event acknowledgements: where an event requires a sign-off, the acknowledgement is recorded, together with a parent or guardian's name if the form requests one.
  • Work and duties: committee membership, sign-up claims and any accompanying note, rotating duty assignments, and event checklist items. Task records are described in Task and work records below.
  • Service hours: date, duration in minutes, and description as logged, plus approval status and the identity of the approving leader.
  • Votes: election and poll votes are stored together with the voting account's email address, so that each account votes once. Ballots are not disclosed to other members: the interface renders only aggregate totals and the viewer's own choice, so voter identity cannot be determined from the page. A club data export omits voter identity. Underlying database rows remain accessible to accounts with platform administrative access, as with every record described in this policy.

Content and uploads

  • Posts and messages: announcements, meeting minutes and agendas, replies to announcements (subject to leader approval before other members can see them), reactions, mentions of other members, handoff notes, and ledger entries where a club tracks money.
  • System-generated notices: when a leader cancels an upcoming event and elects to notify the club, the product posts an announcement containing the cancelled date and the reason entered, and sends a push notification to active members who have not muted the club or its announcement alerts. Rescheduling an event offers the same option. The club's activity log records which leader issued the notice.
  • Audience targeting: a leader may direct an announcement to the whole club, to a committee, or to named individuals. Where an announcement targets a member by name, that targeting is stored with the post.
  • Read receipts: opening an announcement is recorded, with a timestamp. The club owner and its officers see a view count and can expand it to the identities of members who opened it.
  • Files: profile pictures, club banners and gallery photos, event photos (subject to leader approval before publication), images embedded in announcements, files attached to an announcement or to meeting minutes, and files in a club's Documents area. Access is described in Photos and files.
  • Suggestions: the suggestion box is anonymous. The submitted text is stored with no name, email address, or account link, so a club leader cannot identify the submitter. A separate rate-limit counter records that an account used the box, without recording its content; that counter is deleted after approximately two days, and until then only an account with platform administrative access could correlate it with a submission.
  • Financial records: where a club tracks dues or a budget, its ledger entries and any budget request submitted to a leader, together with the stated reason and the leader's decision. These are club bookkeeping records, not payment data. Coetio does not process payments and does not store payment card numbers.

Messages and notifications

  • Push notifications: if enabled, the browser subscription for that device (an endpoint address and two cryptographic keys) is stored to deliver the notifications requested. Disabling notifications removes the stored subscription.
  • Account email: sign-in links, confirmations, and reminders, plus a weekly summary of club activity. For accounts created on or after August 6, 2026, the weekly summary is enabled by default and can be disabled on the Profile page. Accounts created before that date retain their existing setting.
  • Club email: a leader may elect to send an announcement by email to every active member; the message contains the announcement text and a link to any attached image. Leaders may also send a dues reminder and an automatic welcome message on approval, both in Coetio's standard wording. Each recipient is sent a separate message, so members do not see one another's email addresses.
  • Unsubscribe records: every club email carries a one-click unsubscribe link, compliant with the unsubscribe mechanism supported by major email clients, in addition to a link in the message body. Unsubscribing is recorded against the email address, independent of whether that address has an associated account, because a leader may add a roster entry by email address alone. The unsubscribe link is cryptographically signed and affects only the address it was issued for.
  • Platform messages: an account with platform administrative access may send a message to an individual account or to a club; it appears in the recipient's notification feed. A record of the message sent is retained.

Reports, appeals, and support

  • Bug reports and feedback: the message submitted, the page it was submitted from, and the submitter's email address if signed in or voluntarily provided.
  • Abuse reports: the content of the report and the reporter's email address if signed in or voluntarily provided. Reports are routed to accounts with platform administrative access.
  • Suspension appeals: where a club is suspended, its owner may appeal. The appeal text, the owner's email address, and the outcome are retained.
  • Moderation notes: a private note may be kept about an account or a club for support and moderation purposes. These notes are not shown to users.
  • School outreach records: where Coetio contacts a school, the school's name, the staff contact's name and email address, the status of the conversation, and an internal note are retained. These records contain staff information only, never student information, and are not shown to users.

School verification (school staff only)

A school staff member may claim their school at no cost. The claim form collects a name, job title, work email address, the school's name, address, and website, and a link to a staff directory page listing that person. Coetio compares the work email domain to the school website domain and records whether they match, for administrative review. No request is sent to the school's website in the course of that comparison. This form does not collect student information.

Technical and security records

  • IP address: processed during a session for security, rate limiting, and abuse prevention, and stored inside short-lived rate-limit records. It is not used to build a profile of an individual or to determine their location.
  • Bot detection: public forms such as sign-up and club-join pages may present a Cloudflare Turnstile challenge. Cloudflare receives the request, including the IP address, to distinguish a human from an automated request. Cloudflare states that Turnstile does not track individuals across websites.
  • Club activity log: each club retains a log of leader actions, including settings changes, posts, and roster edits, for accountability among leaders. This log is visible to the club owner. As a single exception, the entries recording that a leader marked a task complete for every assignee, or reopened it, are also shown in that task's history to the club's leaders and to a committee chair with access to that task. The activity log contains leader actions only; member activity records are described in Task and work records.
  • Crash reports: the error message, the affected page path, and the account's email address if signed in at the time, retained to diagnose and correct the underlying issue.
  • Operational counters: aggregate numeric counters, such as monthly email volume, used to remain within provider limits. These counters contain no personal information.
  • Usage analytics: anonymous, aggregate analytics through Vercel Web Analytics. Vercel states that it records page views, referring site, device, operating system, browser type, and a coarse geographic region such as a country. This data is not linked to an account and is not used for advertising.

Coetio does not collect precise geolocation, does not use advertising identifiers, does not serve advertising, and does not sell personal information.

Task and work records

When a club assigns work, Coetio records who did what and when. This is the most detailed activity record the product keeps about an individual, and it is documented in full here rather than in a single bullet point. Each task has a dedicated page, and the record below is what that page displays.

  • Who created the task, and when.
  • Who assigned each person, and when. Where an assignment is made after a task's creation, the record reflects the actual assignment date.
  • Every reminder sent about the task. Each reminder is a separate, dated entry identifying the leader who sent it; two reminders sent within one afternoon appear as two entries. Leaders may send a reminder no more than once per hour per task. Muting task notifications stops delivery to a device; it does not remove the record of the reminder. Automated overdue reminders are not attributed to a person and are recorded without a sender.
  • When an assignee's portion of a task was marked complete, and, if unmarked, that completion record is cleared. An assignee ordinarily marks their own portion; the one other mechanism is described next.
  • When an entire task was marked complete, or reopened, on behalf of every assignee. A leader with task-management access, or a committee chair granted that capability, may mark every unfinished portion of a task complete at once. That action is recorded with the acting leader's identity and the time, and the task's history states that each assignee's portion “was marked complete” under that leader's name, so the record does not represent that each assignee completed their own portion when they did not. Reopening a task clears every assignee's completion status, including portions an assignee completed themselves, and is recorded in the same way. No entry is written when a status does not change.
  • Who marked each step complete, and when. Steps are shared among assignees; whoever completes a step first is recorded as having completed it. Reversing a step clears that record.
  • Which sub-step is assigned to which person, where a task is divided.
  • Event checklist items record, as plain text at the moment of completion, the name of the person who completed the item.

Access to this record. A club leader with visibility into the task sees the complete record. Where a club owner has enabled chair task access, which is disabled by default, a committee chair sees this record for a task on which every assignee belongs to their committee. An active member assigned to a task can open its page once the task has been assigned, and sees who created the task, who is named on each shared step, and the full record concerning their own participation: when they were added, who added them, and every reminder sent to them. Where a task was marked complete on behalf of every assignee, an assignee's own view shows their portion as complete but does not show the identity of the leader who applied that mark, which is recorded only in the club's activity log and visible only to leaders. An assignee does not see other assignees' identities, reminders, or assignment dates on that task, only a count of how many people are assigned. Club members who are not assigned to a task cannot open its page.

These records are retained for as long as the task exists. If a leader deletes a task, the associated records are permanently deleted after the 30-day trash retention period described in Data retention. One category of record outlives the task itself: the log entry recording that a leader marked a task complete for every assignee is written to the club's activity log and remains with the club after the task is deleted. Account deletion does not remove all of these records; see Account deletion.

Use of information

Information collected is used only to operate the service, specifically to:

  • display club pages, rosters, events, and records to authorized viewers;
  • record attendance and participation for clubs using those features;
  • send account email and the notifications an account holder has enabled;
  • maintain security, prevent abuse, and enforce the Terms of Service;
  • diagnose and correct errors, and improve the product;
  • respond to support requests;
  • comply with a legal obligation, where one applies.

Personal information is not used for advertising, is not sold or rented, is not disclosed to any party outside the service providers identified below except where required by law or requested by the account holder, and is not used to train an artificial-intelligence model.

Access and disclosure

Coetio distinguishes several account types within a club. Their definitions govern the access described in this section:

  • Owner: the account that created the club, or to which it has been transferred. The owner has complete access to the club's records and settings and cannot be removed by another member.
  • Officer: an account granted the officer role by the owner. An officer's access is determined by the club's capability configuration, a per-club setting the owner controls; it may range from no management access to the same access as the owner, capability by capability.
  • Advisor: an account granted the advisor role by the owner. By default an advisor has read-only visibility into club information; the owner may grant an advisor any additional capability available to an officer.
  • Member: an account on a club's roster holding neither the officer nor the advisor role. By default a member has no club-management access; the owner may grant a member any capability available to an officer.
  • Leader, as used in this policy, means the owner together with any officer, advisor, or member who holds at least one management capability in that club. A given leader's specific access depends on which capabilities that account holds; holding one capability does not imply holding all of them.

Access to personal information is as follows:

  • Phone number: visible to the club owner and to accounts with platform administrative access. Not visible to officers, advisors, or members. A roster export or club backup produced by an officer omits the phone column; only an export produced by the owner includes it.
  • Club owner and officers holding the relevant capability can view membership details, attendance, participation, tasks and their full history, dues status, custom roster fields, and per-member announcement read status, for their own club only. A leader granted the export capability may download club records, including attendance and the service-hours log with member names and email addresses. The phone column is withheld from such exports as described above.
  • Members assigned to the same task can access that task's page, subject to the access described in Task and work records. A committee chair may access a task where every assignee belongs to their committee, if the owner has enabled that access.
  • Advisors holding no additional capability receive a read-only view limited to a club's announcements, meeting and event counts, dues completion rate, and semester and year reports. Those reports identify members with the highest meeting attendance, alongside their attendance counts, and summarize the club's finances. Elsewhere in the product, an advisor with no additional capability sees what any other member sees.
  • Other club members see an individual member's records only where the club owner has enabled that visibility, which is disabled by default. A club leaderboard is a separate setting, also disabled by default; when enabled, every member sees a ranked list of names and point totals derived from attendance, completed tasks, approved service hours, and sign-ups, and members cannot opt out of inclusion individually. Where an account has opted into a club's member directory, other members also see that account's name, grade level, and pronouns there.
  • The calendar view shows a leader every event and task deadline in the clubs they lead. It shows a member only their own clubs' events and their own deadlines.
  • Meeting minutes are visible only to leaders until a leader shares them with the club. A leader's document export of minutes includes the day's attendance list; a member's export of the same minutes does not, because members do not see who else checked in to any event.
  • Preview as a member. A club owner may view the product as one of their own members sees it, to answer questions about member-facing navigation without requesting account credentials. Only the owner of a club may initiate this view, and only for a member of that club. It never shows the owner information beyond what they already had access to, no write operation of any kind can occur while it is active (no check-in, vote, task completion, or post), and the previewed member is not notified.
  • An anonymous visitor reaches a club only at that club's own join address, which carries no roster, no events, no announcements, no leadership list, and no photos. It shows the club's name, school, and icon, and a way to request to join or sign in, and nothing else. The address is excluded from search indexing. Sharing it in a chat application shows Coetio's generic site preview, not anything specific to that club.
  • Club visibility may be set to public, school-only, or unlisted. Only the school-only setting has a present effect: it limits who may submit a join request to signed-in, active members of another club at the same school; everyone else is offered an invite code or a sign-in link instead. Public and unlisted behave identically today, since there is no directory, sitemap, or search listing of clubs for either setting to be included in or excluded from.
  • A verified school. A school staff member may verify their school at no cost, at /schools/verify. Verification adds nothing beyond a note that a club's own leaders can see on that club's Settings page, confirming the school is verified. It creates no login, dashboard, or console of any kind, and grants no visibility into any club's roster, records, or member data.
  • Accounts with platform administrative access can reach the full database, including phone numbers, ballots, and every record described in this policy, for the purpose of operating, moderating, backing up, and repairing the service. This access exists for service operation, not for routine browsing.
  • Service providers, identified below, process data under Coetio's instructions to perform their function in the service.
  • Law enforcement or a court, where legally compelled, or where disclosure is believed in good faith to be necessary to prevent serious harm.

Photos and files

A profile picture, club banner, gallery photo, event photo, image embedded in an announcement, a file attached to an announcement or to meeting minutes, and a file uploaded through the Documents page are private files. Each is served through a Coetio route that checks the requester before responding: a profile picture requires only being signed in to Coetio; a club banner, gallery photo, or announcement image requires the same visibility check the club's own join page runs; an event photo requires active membership in that event's club; a document or an attachment requires club membership, and, for a file attached to meeting minutes, the same sharing state that governs the minutes themselves. The route mints a temporary address behind the scenes, good for about one minute, and never discloses that address to the requester directly; it streams the file back itself, with an instruction that only the requester's own browser may keep a copy, for up to five minutes.

This replaced a permanent, unauthenticated public address for a profile picture, club banner, gallery photo, event photo, and announcement image on August 29, 2026, and for a file attached to an announcement or to meeting minutes on August 25, 2026. Files uploaded through the Documents page have been handled this way since that feature was introduced. A file of an affected kind uploaded before its respective date keeps its old permanent public address, reachable by anyone who has it, including a person outside the club; only a re-upload moves it behind the private route.

Deleting a photo or file removes it from the product and from the page that displayed it. The underlying stored file may persist beyond that point, and a person holding a still-valid address to a legacy public file may still be able to open it. To request permanent removal of a stored file, contact support@coetio.com with the file's link.

Calendar feeds and external links

Certain features of Coetio are designed to be used outside the product, which means information is transmitted to a party with which Coetio has no data-processing agreement. Those features are:

  • Personal calendar feed. The dashboard, Profile page, and calendar offer a web address that can be added to Google Calendar, Apple Calendar, or Outlook so club events appear there. The address is a single opaque, encrypted path segment that functions both as the subscriber's identity and as the authentication for the feed; it does not place the account's email address in plain text in the URL. Whichever calendar application receives that address retains it and queries the feed repeatedly. That application receives a live copy of every event in every club the account is an active member of, including private clubs. Revoking a compromised feed currently requires rotating the platform-wide signing key, which invalidates every outstanding calendar feed at once; no per-account revocation exists at this time. That link should not be shared or posted publicly.
  • Add to calendar. Selecting this option on an event's page opens Google Calendar with the event's title, description, times, and full address pre-filled, transmitting those details to Google. This option is available only to a signed-in member viewing the event; there is no anonymous or public version of it.
  • Directions. Where an event has a street address, a link opens that address in a mapping service. Selecting the link transmits the address to Google; nothing is transmitted unless the link is selected, and the referring Coetio page is not disclosed to Google.
  • Link previews. When a Coetio link is shared in a chat application, that application requests a preview image from Coetio. A club's join address has no preview image of its own; the generic Coetio site preview is shown instead, which carries no club name, event, member, or contact information.

A note for club leaders: an event's street address is visible only to that club's own signed-in members. It is never published outside the club, whatever the event's visibility setting.

Cookies and analytics

Coetio sets only essential cookies: a session cookie that maintains sign-in state, a cookie recording which club is being managed for an account that leads more than one club, a language-preference cookie, and a cookie that exists only while a club owner is using the preview-as-member view. None of these cookies are used for advertising or cross-site tracking. Vercel Web Analytics, which records page views, operates without cookies and does not identify individual visitors, so no consent mechanism or cookie banner is required. Analytics run on every page, including while signed in, and remain unlinked to any account. Signing out removes the session cookie. The club-selection cookie contains only a club identifier and may persist on a device for up to one year unless cleared.

The browser also stores certain data locally on the device: theme preference, reduced-motion preference, dashboard section order, and a cached copy of upcoming events and open tasks so the product remains usable without a network connection. On a mobile device, local storage also tracks recent visit counts and dates, used to time the home-screen installation prompt, and a record of each dismissal of that prompt. Where a club is suspended, the device retains a flag indicating the suspension notice has been shown, to avoid repeating it. None of this local data is transmitted to Coetio, with one exception: an offline check-in is queued on the device and transmitted once connectivity is restored. Clearing browser data removes all of it.

Service providers

Coetio relies on the following service providers to operate. Each processes data under Coetio's instructions, solely to perform its function in the service, and is not permitted to use that data for its own purposes. Each is a United States company, and Coetio is operated from the United States. Some providers operate infrastructure in other countries to deliver the service, so information may be processed outside the account holder's own country.

  • Supabase · database, authentication, and file storage. Every record Coetio stores resides there.
  • Vercel · hosting and anonymous usage analytics.
  • Resend · delivery of account and notification email. It receives the recipient's address and the message content.
  • Cloudflare · bot detection on public forms, which receives the requesting IP address.
  • Browser and device push services · where notifications are enabled, each message is handed to the push service built into the account holder's browser or operating system for delivery. The message payload is encrypted for the receiving device, so the push service can observe that a message was sent and when, but not its content.
  • Google, for sign-in only · where Google sign-in is used, Google authenticates the account holder's identity. Google is not otherwise a service provider to Coetio; fonts on this site are served from Coetio's own infrastructure, not Google's.

Third parties reached by an account holder's own action. These parties do not process data under Coetio's instructions, and their own privacy policies govern what they receive.

  • Google Maps and Google Calendar · selecting Directions or Add to calendar transmits that event's details to Google.
  • The calendar application used to subscribe to a personal feed · Google, Apple, Outlook, or another provider, which retains what Calendar feeds and external links describes.

Data retention

  • Account data: retained for the life of the account. Account deletion removes it as described in Account deletion.
  • Deleted club items: when a leader deletes an announcement, event, set of minutes, task, or committee, it is held in a 30-day trash for possible restoration, then permanently purged.
  • Task history: assignments, reminders, and step completions are retained with the task for as long as the task exists, with no separate expiry, and are deleted when the task is deleted and its 30-day trash period elapses. The exception is the log entry recording that a leader marked a task complete for every assignee, which is written into the club's activity log and persists with the club.
  • Attendance, service hours, votes, and read receipts: retained until the club, the specific record, or the associated account is deleted. None of these records expire on a fixed schedule.
  • Crash reports: automatically deleted after 14 days.
  • Rate-limit records (short-lived anti-abuse counters keyed by an identifier such as an IP address, email address, or account): automatically deleted after approximately two days.
  • Maintenance logs: logs of scheduled system jobs are retained for 90 days and contain no personal information.
  • Backups: a full database backup is created daily and stored in private storage to support service restoration after a failure. A backup is a copy of the entire database, including phone numbers and ballots, and is never published. The 14 most recent daily backups and the 8 most recent weekly backups are retained, and every backup, without exception, is deleted no later than 90 days after it was created. Information deleted from the live service can persist in an existing backup file until that file is deleted under this schedule.
  • Club records: a club's history is retained with the club, including through a leadership transfer, until a leader deletes the specific record or a club owner deletes the club.
  • Roster-only members: where a leader added a roster entry for a person who never created an account, that record is retained until removed by a leader of that club. Contact support@coetio.com for assistance.
  • Guest check-ins: retained with the associated event and removed when a leader deletes that event and its 30-day trash period elapses, or when the club is deleted. No account is associated with a guest check-in; contact support@coetio.com with the event and approximate time to request earlier removal.

Security

Connections are encrypted using HTTPS. Passwords are stored only in hashed form by Coetio's authentication provider. Database access is restricted to the application's own authorization checks, and file uploads are validated for type and size. Sign-in and other sensitive actions are rate-limited to slow automated attacks.

No online service can guarantee absolute security. If a security incident is identified that affects personal information, affected accounts will be notified without undue delay, with an explanation of what occurred.

Rights and choices

  • Access and correction: account information can be reviewed and edited at any time from the Profile page.
  • Data export: the Profile page provides a file containing account information and its associated records, including memberships, attendance, RSVPs, votes, service hours, assigned tasks, and authored notes. Certain newer task records are not yet included in that export, specifically reminders received, steps completed, and tasks created. Contact support@coetio.com to request those records, or any other record expected and not found in the export.
  • Account deletion: available at any time from the Profile page. See Account deletion for scope.
  • Leaving a club removes the associated membership at any time.
  • Notification controls: push notifications can be enabled or disabled per device, a club can be muted, and a notification category can be disabled from the Notifications page.
  • Email controls: a single Profile page setting governs club-related email, and disabling it stops announcement email, dues reminders, and the weekly summary. Every club email also carries a one-click unsubscribe mechanism. Muting a club also silences that club's announcement email, in addition to its push notifications, unless a leader has marked a specific post as important. Account email, such as sign-in links and password resets, cannot be disabled while an account exists, because it is required to access the account.
  • Correcting roster information held by a leader: contact a leader of the relevant club, or support@coetio.com if that does not resolve the issue.
  • Requests: submit a question or request to support@coetio.com. A response is provided within 30 days, typically sooner. Additional rights may apply depending on the account holder's jurisdiction of residence; contact support@coetio.com to invoke a right applicable to that jurisdiction.

Account deletion

Account deletion is initiated from Delete account on the Profile page. An account that owns a club must first transfer or delete that club in Settings, so a club is never left without an owner.

Account deletion performs all of the following at once:

  • the account profile is deleted, including name, email address, phone number, date of birth, graduation year, grade, pronouns, and profile picture, and the sign-in account is removed;
  • roster records are anonymized rather than deleted, so a club retains its history while the row is renamed “Former member” and no longer identifies the individual. Phone number, custom roster fields, kiosk PIN, join answer, and any leader note about the member are cleared;
  • personal rows are deleted, including RSVPs, votes, reactions, replies, read receipts, sign-up claims, event acknowledgements and any associated guardian name, event ratings, contribution notes, budget requests, event photos uploaded by the account, feedback submissions, reports, invites, and push subscriptions;
  • the account's email address is removed from accountability records retained for other purposes, such as club activity logs, approval stamps, and crash reports.

Limits of account deletion. The following categories of record are not removed by account deletion:

  • Attendance, service-hour, and task rows persist, attached to the anonymized “Former member” row. The club retains its history, with nothing in it pointing back to the deleted account's name or email address.
  • Task history rows are not cleared. Reminders received, reminders sent as a leader, steps completed, sub-steps assigned, and tasks created continue to reference the anonymized row, so a leader viewing that task later sees “Former member” where the account's name previously appeared. Name and email address are removed from these rows. To request removal of these rows outright, contact support@coetio.com.
  • Event checklist entries retain the name at the time of completion. When an item on an event checklist is completed, the product writes the completing account's name into the item as plain text, and account deletion does not clear that text. An event checklist can therefore continue to display a real name after the associated account is deleted. This is a known limitation of the deletion process rather than an intended retention; contact support@coetio.com to have a specific entry cleared.
  • Photos uploaded by other accounts persist. Account deletion removes the record of photos uploaded by the deleted account, but not a photo uploaded by another account in which the deleted account's member appears. A request to remove such a photo should be directed to a leader of that club. The stored image file can also persist beyond the record referencing it; contact support@coetio.com with the file link to request permanent removal.
  • Backups retain the prior copy for up to 90 days. A backup created before account deletion continues to contain the deleted information until that backup file is deleted under the retention schedule in Data retention. Daily backups age out within roughly two weeks; weekly backups take longer.

Children's privacy

Coetio is built for students, and its collection practices reflect that: the minimum information needed to operate a club is collected, a phone number is optional and visible only to the club owner and to accounts with platform administrative access, membership details are kept inside the club, ballots are not displayed to other members, personal information is not sold, and no advertising is served.

An account may be held only by a person 13 years of age or older. Since August 24, 2026, creating an account directly on Coetio, whether by password or by completing a Google sign-in, requires a real date of birth, checked against this minimum before the account is created. This requirement is not retroactive: an account created before that date was not asked for a date of birth and none is on file for it. It also does not apply to a roster entry a leader creates for a person with no account, or to a guest event check-in, neither of which creates an account; those remain covered only by the separate age checkbox on the club-join form described in the Terms of Service. Coetio is not directed to children under 13 and does not knowingly collect information from anyone under 13.

Takedown for accounts under 13. If Coetio determines that an account belongs to a person under the age of 13, the account and the personal information associated with it are deleted promptly, using the same process described in Account deletion. To report an account believed to belong to a person under 13, contact support@coetio.com with the account's email address or the relevant club and name. Coetio investigates and acts on each report received.

A parent or guardian may contact support@coetio.com to request the information held about their student, to request a correction, or to request account deletion. Verification that the requester is the student's parent or guardian may be required before the request is fulfilled.

Schools

Coetio is an independent product. It is not affiliated with, endorsed by, or operated by any school unless a school states otherwise. Coetio is not a student-records system, and a club's records on Coetio are not official school records. Compliance with any school-specific rule governing student data or parental consent is the responsibility of the club's leaders.

Changes to this policy

The date at the top of this policy is updated whenever it changes. Where a change is material, meaning it meaningfully affects the information collected or the choices available to an account holder, notice is given before the change takes effect, through the product or by email.

Contact

Questions, requests, and corrections concerning this policy: support@coetio.com. Coetio is operated from Coetio, 9 Townsend West, Nashua, NH 03063, United States. This policy is also available in reference to Terms of Service and Community Guidelines.

© 2026 Coetio™. All rights reserved. · Terms of Service · Community Guidelines