Vibeswap Privacy Policy
This Privacy Policy explains how Vibeswap collects, uses, and shares information when you use the Vibeswap mobile application and related services (collectively, the “Services”).
Vibeswap is intended for users aged 18+. We do not knowingly collect personal data from anyone under 18.
1) Who this is for (18+ only)
Vibeswap is intended for adults only. You must be 18+ to use the Services. If we learn we’ve collected personal data from someone under 18, we will delete it and may terminate the account.
2) Information we collect
A) Information you provide
- Account details (e.g., username, date of birth, profile photo, and profile info).
- If you sign in with Google, we receive your Google display name and profile photo from Google as part of the authentication flow.
- Content you create (e.g., videos, images, captions, vibe tags, venue tags, multi-stop vibe trails, reposts of other users' posts, and — where you have permission — curated playlists).
- Reactions, check-ins, likes, saves, and comments you make.
- Personal notes you add to venues saved in your library. These notes are private to your account and not shown to other users.
- Reports, feedback, and support requests you submit (including reports about misleading tags, venue information, or safety signals).
- Suggestions you submit (for example, new vibe suggestions).
B) Information collected automatically
- Device info (model, OS version).
- App activity (views, taps, interactions), including aggregated usage and performance analytics collected through tools such as Google Analytics for Firebase.
- A record, kept in our own database and linked to your account, of which posts you have viewed, when you first and last viewed each one, and where in the app you were viewing from (for example the main feed or a playlist). We also keep a daily count of how many posts you have swiped through. These power features such as the daily scrolling limit, and let our own team see which videos are landing. View counts are never shown to anyone in the app — not to you, not to other people, and not to venues. There is no view counter on a post, a profile or a venue page, and this record is not readable by the app at all. They are not sold and are not used for advertising.
- Location information (if you enable location permissions). This may include precise device coordinates when needed for features like venue distance, or an approximate location (for example, derived from general device signals) if precise location is not available. While you are using the app, we may also use your location to detect when you appear to have arrived at, or are close to, a venue — so we can offer location-relevant features (for example, a prompt to use an in-venue photo booth). We do not track your location in the background for advertising purposes.
- Crash/diagnostic logs.
- Certain app preferences and session data stored locally on your device (for example, to remember your settings between sessions).
C) Direct Chat (private messages)
When you use the Direct Chat feature we collect and store:
- The content of messages you send (text, reactions, media URLs, coin/venue/song shares).
- Sender and recipient user IDs, timestamps, and read-state indicators (e.g., whether a message has been viewed).
- Typing indicators (temporarily stored while you are typing; cleared when you stop or send).
- Which conversation you currently have open ("active chat" presence signal), used to suppress duplicate push notifications. This is cleared when you leave the conversation.
Direct Chat messages are not end-to-end encrypted. They are stored in our database and are accessible to Vibeswap staff where necessary for safety, abuse prevention, or legal compliance.
D) Push notifications
If you enable notifications, we collect and store a push token (e.g., an FCM/APNs token) to deliver notifications.
E) AI-powered features ("Pinkie")
Vibeswap includes AI-powered features collectively referred to as Pinkie. When you use Pinkie — for venue search, group planning, or personalised venue and user insights — we process and send certain information to OpenAI (the company behind ChatGPT) via their API in order to generate Pinkie's responses. The information we may send includes:
- Messages and queries you address to Pinkie (in the AI search feature or a group planning session).
- Your vibe preferences and profile context (e.g., the vibe tags associated with your account).
- Venue information relevant to your query (e.g., venue name, type, vibe tags).
- General location context (city or area — not your precise GPS coordinates).
- Conversation history within an active planning session, so Pinkie can follow the thread.
We do not send your full name, date of birth, contact details, payment information, or private direct chat messages to OpenAI.
Image processing: When you capture a video in the app, we may send one or more still frames from that capture to OpenAI in order to (a) suggest relevant vibe tags automatically and (b) screen for obviously unsafe or prohibited content before the post goes live. These frames are processed to generate those suggestions and safety signals; OpenAI handles them under the data processing terms referenced below.
OpenAI processes this data as a data sub-processor under a data processing agreement. OpenAI's privacy policy governs their handling of the data: openai.com/policies/privacy-policy.
AI-generated responses (venue suggestions, plans, insights) are stored in our systems as part of your session or conversation record, in the same way as other messages.
In group planning sessions: If you are a participant in a group plan and the session host has Pinkie enabled, messages sent in that session may be processed by Pinkie (and therefore by OpenAI) to generate group recommendations. This applies to all participants in the session, not just the host.
Pinkie's responses are generated automatically by a large language model. They may be inaccurate, incomplete, or not suitable for your specific situation. Do not rely on them for safety, medical, legal, or financial decisions.
2A) Community Pinboard flyers
When you submit a flyer to the Community Pinboard, we collect and store the flyer image you upload and the details you provide (such as the event title, date, time, venue, address, area, description, and any contact email or link you choose to add). Flyer images are stored with our hosting provider (Cloudflare R2) and the details are stored in our database.
If your flyer is approved, the image and details are shown to other users in the relevant area. If you turn on the optional "show my profile" setting, your username and profile photo are also shown on the flyer and link to your profile — this is off by default. Approved flyers are automatically removed after the event (or after a set period), and we may remove any flyer at any time during moderation.
2B) Claiming and managing a venue
If you claim a venue page, we collect the details you enter on the claim form: your name, your role at the venue, a contact email, and optionally a phone number, a website or social link, and any notes you add. We use these solely to check the claim is genuine and to contact you about it. Claims are reviewed by a person on our team.
If your claim is approved, your account is recorded as the manager of that venue page. We store which venue you manage and which plan it is on, including the date any free trial or paid plan started. Anything you then add through the venue tools — opening hours, venue type, links, event flyers — is published on that venue's page and, for events, on the Community Pinboard.
Venue managers can see information about their own venue, including how many different people have posted there, or used particular words to describe them. Venue managers are never shown who those individual people are, and are never given contact details for them.
3) How we use your information
We use information to:
- Provide and operate the Services.
- Show content and social interactions.
- Personalize or improve feeds and discovery.
- Power AI-powered features — such as Pinkie's venue recommendations, group planning, and personalized venue and user insights — by sending relevant context to OpenAI (see Section 2E above).
- Send notifications you request/enable.
- Prevent abuse, spam, fraud, and safety issues.
- Moderate content and enforce our Terms (including reducing distribution of content that appears misleading or incorrectly tagged).
- Display venue information sourced from third-party providers (such as Google Places) alongside community-sourced signals such as vibe tags, check-ins, and safety badges.
- Comply with legal obligations.
We may use automated systems to rank and recommend content, and to detect spam, fraud, and policy violations. Where appropriate, you can contact us to ask questions or contest a moderation decision.
4) Legal bases (UK/EU style)
Where applicable, we process personal data based on:
- Contract (to provide the Services).
- Legitimate interests (security, abuse prevention, product improvement).
- Consent (e.g., location permissions, push notifications).
- Legal obligation (compliance, law enforcement requests).
5) Sharing your information
We may share information with:
-
Service providers that help us run the Services, including:
- Firebase/Google — authentication, database, and notifications.
- Cloudflare — storage and delivery of uploaded photos and videos.
- Apple/Google (APNs/FCM) — push notification delivery.
- Google Places API — venue information (addresses, opening hours, contact details).
- OpenAI — large language model and vision processing to power Pinkie AI features (venue recommendations, group planning, personalized insights) and to suggest vibe tags and screen captured content for safety. We share relevant query context, vibe preferences, and venue data as described in Section 2E, and still image frames from captured videos for automatic vibe-tag suggestions and content-safety screening. OpenAI processes this data under their privacy policy: openai.com/policies/privacy-policy.
- Other users (your profile and public content visible inside the app, and — where you use the share feature — anyone with a share link).
- Authorities when legally required, or to protect users/platform safety.
- Rights-holders in copyright investigations where appropriate.
We do not sell your personal information, and we do not share it with advertisers. We do not run advertising in Vibeswap and we do not use third-party advertising or ad-tracking software.
5A) Venues using your clips outside Vibeswap
A venue you have tagged can ask you for permission to use one of your clips on their own channels. You are shown the request and you decide — we never pass a clip to a venue on your behalf, and a venue cannot download anything while a request is pending or after you decline.
If you approve, the venue can download that clip and publish it outside Vibeswap. Where a clip shows you, your voice, or anyone else, approving means that content may be published on channels we do not control. Once it is published elsewhere, deleting your post or your Vibeswap account will not remove those copies — you would need to contact the venue directly, and we will help you do so.
We keep a record of the request and your decision so that both sides can see what was agreed. See section 5A of our Terms for what approving actually grants.
6) Music uploads
Vibeswap allows users to upload original music tracks ("Uploaded Music") to the platform. By uploading music you confirm that:
- You own or hold all necessary rights, licences, and permissions for the content you upload (including any underlying compositions, recordings, samples, and artwork).
- Your upload does not infringe the intellectual property rights, privacy rights, or any other rights of any third party.
- You are not uploading content that is subject to a record-label exclusive or any agreement that would prohibit you from licensing it to us.
By uploading music you grant Vibeswap a non-exclusive, worldwide, royalty-free licence to store, host, display, stream, and associate your music with posts and profiles within the app. You retain ownership of your music. We do not claim any ownership rights in your Uploaded Music.
Uploaded Music may be played by other users within the app. If another user's video post is shared via a link, the music associated with that post may also be audible to recipients of that link.
We reserve the right to remove Uploaded Music that we reasonably believe infringes third-party rights or violates our Terms of Service, without prior notice. Repeated infringement may result in account suspension.
Data collected: When you upload music we collect and store the audio file, any artwork, your title and artist name, your user ID, and an upload timestamp. This information is used to operate the music feature and associate your track with your profile.
7) Content visibility
User content (posts, venue profiles, user profiles) is primarily designed to be viewed inside the app by signed-in users. However, if you or another user shares a link to a post, venue, or profile using the in-app share feature, a preview of that content may be accessible to anyone with the link, including people who are not signed in to Vibeswap.
Personal venue notes you add in your library are private to your account and are not visible to other users.
Please remember that other users can take screenshots or screen-record content, and may share it outside of Vibeswap. We can't control what other users do with content once they've viewed it.
8) Data retention
We keep data as long as needed to:
- Provide the Services.
- Meet legal/compliance needs.
- Resolve disputes and enforce terms.
If you delete content, we remove it from active systems, and it may remain in backups for a limited period (typically up to 30 days).
Direct Chat messages: Messages are stored as long as the conversation exists. If you delete your account (see below), your messages are removed from active systems. Your messages may remain visible to the other participant until that conversation is also cleaned up. We may retain limited metadata (such as timestamps and sender IDs) for safety, enforcement, and legal purposes.
We may retain records of reports, moderation actions, and related metadata for safety, enforcement, and audit purposes.
9) Security
We use reasonable administrative, technical, and organizational measures to protect data. No system is 100% secure, so we can’t guarantee absolute security.
10) Your choices and rights
Depending on your location, you may have rights to access, correct, delete your data, request portability of your data, object to or restrict processing (including processing based on legitimate interests), and withdraw consent (e.g., location, notifications).
To request access, correction, or deletion, or to raise a privacy concern: privacy@vibeswap.app (or support@vibeswap.app for general help). You can also disable notifications and location permissions in your device settings.
If you are in the UK, you also have the right to lodge a complaint with the Information Commissioner’s Office (ICO). You can find details at ico.org.uk.
10A) Deleting your account
You can delete your account directly inside the Vibeswap app (Settings → Account → Delete Account).
Before we begin, we ask what you would like to happen to the clips you have posted. You choose one of two things:
- Delete them. Your clips are removed, along with the video files and thumbnails behind them. This is what happens if you do not choose.
- Keep them on the venue. The clips stay, but your name comes off them — your username is replaced, the clips are unlinked from your account, and any tags or recommendations attached to them are stripped. They are no longer connected to you or to any other account.
Whichever you choose, when you delete your account:
- Your profile and account are removed, and your username is released for reuse.
- Your reactions, saves, check-ins, follows, notifications and other activity records are deleted.
- Your Direct Chat messages and private threads are removed. Group conversations you shared with other people continue without you; copies of messages already delivered may remain in other people’s conversation views.
- Venues and events you created remain on Vibeswap with your name removed from them. Deleting them outright would remove content other people have added, or tickets they have bought.
- Content and data may remain in encrypted backup systems for a limited period (typically up to 30 days) before being fully purged.
- We may retain certain records where required by law, for safety purposes, or to resolve disputes — for example, records of reported content, moderation actions, or legal hold obligations.
Account deletion is permanent and irreversible. If you need help or want to confirm deletion, contact privacy@vibeswap.app.
11) International transfers
Vibeswap is based in the UK, but our Services are designed to be usable globally. Depending on where you live and where our service providers operate, your information may be processed in countries outside your country of residence, including outside the UK or European Economic Area.
When we transfer personal data internationally, we use safeguards intended to protect your information, such as contractual protections (for example, UK International Data Transfer Addendum and/or EU Standard Contractual Clauses where relevant), and we assess the transfer risks where appropriate.
This applies to third-party service providers used for core features — including hosting, analytics, push notifications, and AI processing. In particular, OpenAI, which powers Pinkie, is based in the United States. When we send data to OpenAI, that data is transferred to the US and processed there. We rely on OpenAI's Data Processing Addendum and Standard Contractual Clauses (where applicable) as the transfer mechanism.
12) Changes to this policy
We may update this Privacy Policy. If changes are material, we’ll provide notice in-app or by other reasonable means.
13) Contact
General enquiries: hello@vibeswap.app.
Support: support@vibeswap.app.
Privacy questions or requests: privacy@vibeswap.app.
Legal notices: legal@vibeswap.app.
Security reports (vulnerabilities): security@vibeswap.app.
Copyright notices: dmca@vibeswap.app.