Privacy Policy
Last updated: April 19, 2026
Short version. We collect the minimum we need to make the App work: your phone number, what you post, who you talk to inside the App, and an approximate location. We don't sell your data. We don't track you across other apps or websites. You can delete your account and your data any time.
1. Who we are
The App is operated from Chișinău, Republic of Moldova. Contact: dev@vibex.team. For privacy questions specifically: dev@vibex.team.
2. What we collect
You give us directly
- Phone number — to create your account and sign you in via OTP.
- Profile information — display name, optional bio, optional avatar, optional Instagram handle.
- Plans you post — title, description, venue address, time, drink notes.
- Join requests and chat messages — content you exchange with other users in plan chats.
- Reports you submit — when you report another user or piece of content.
Collected automatically
- Approximate location — only when you grant permission. Used to show plans near you and to compute distance/ETA. Stored as the rounded coordinate you opted into; your exact GPS position is never sent to other users until a host approves you for their plan.
- Device info — model, OS version, app version, language, time zone. Used for diagnostics.
- Crash logs — stack traces and minimal context when the App crashes. Used to fix bugs.
What we do NOT collect
- We do not collect your contacts list.
- We do not collect your photos or media library.
- We do not use the iOS Advertising Identifier (IDFA).
- We do not track you across other apps or websites.
- We do not send your data to advertisers.
3. Why we use it
- To run the core features of the App (sign-in, posting plans, requesting to join, chat).
- To show plans relevant to where you are.
- To keep the App safe — detect spam, abuse, and breaches of our Terms.
- To respond to support requests.
- To comply with legal obligations.
Legal bases (GDPR, where it applies): performance of the contract you have with us when you accept these terms, your consent for location and notifications, our legitimate interest in keeping the service safe, and legal obligation where applicable.
4. Who sees what
- Other users see your display name, avatar, optional bio, and the plans you post or join.
- Hosts see who has requested to join their plans, including the approximate IG handle if you've added one.
- Joiners see the exact venue address only after the host approves.
- Phone numbers are never shown to other users.
5. Service providers
We use a small number of trusted vendors to run the App. They process data on our behalf, under contract:
- Supabase (database, authentication, real-time, storage) — EU region.
- Twilio or equivalent SMS gateway — to deliver one-time passcodes.
- Mapbox — to render maps. Receives anonymised tile requests, never your account identity.
- Apple App Store / Google Play — for distribution and crash reporting.
- Sentry (or similar) — for crash and error monitoring.
We do not share your personal data with any third party for advertising, tracking, or profiling.
6. International transfers
Some of our service providers operate in the European Union, the United Kingdom, and the United States. When data is transferred outside Moldova or the EU, we rely on Standard Contractual Clauses or equivalent safeguards.
7. How long we keep data
- Account data: as long as your account exists.
- Plans and messages: until you delete them or your account, whichever comes first.
- Crash logs: up to 90 days.
- Reports and moderation records: up to 2 years, to detect repeat abusers.
8. Your rights
You have the right to:
- access the personal data we hold about you;
- correct or update it;
- delete it (in-app: Profile → Settings → Delete Account; or email us);
- object to or restrict processing;
- export your data in a portable format;
- withdraw consent (e.g. revoke location or notification permissions) at any time;
- complain to your local data protection authority.
Email us at dev@vibex.team and we'll respond within 30 days.
9. Children
The App is for adults only. We do not knowingly collect data from anyone under 18. If you believe a minor has registered, contact us and we will delete the account.
10. Security
Data is transmitted over HTTPS. Database access is restricted by row-level security policies — every record is checked against the requesting user's identity. Phone-OTP authentication means we never store your password (we don't have one).
No system is perfectly secure. If you discover a vulnerability, please disclose it responsibly to dev@vibex.team.
11. Changes
If we change this policy in any material way, we'll post the new version here and notify you in-app before it takes effect.
12. Contact
Privacy questions: dev@vibex.team
General: dev@vibex.team