Skip to content
Vibecheck
← Back

1. Data controller

The data controller under the GDPR for processing within the Vibecheck app is:

TODO: Name / Company
TODO: Street, ZIP, City
E-mail: [email protected]

2. Scope

This policy describes the processing of personal data within the Vibecheck application (Android, Desktop, iOS planned). The website is covered by the separate privacy policy.

3. What data we process

CategorySpecific dataSource
Account datae-mail address, internal identifier (UUID)Google sign-in
Real profiledisplay name, age, profile photosprovided by you
Anonymous identitynickname, gender, age, “vibes” (interests), photosprovided by you
Location dataapproximate or precise position (latitude/longitude)your device, only after consent
Device informationmodel, manufacturer, operating system, app version, cryptographic keysyour device
Communication contentchat messages, voice messages, reactionscreated by you; plaintext and automatically moderated before a match, end-to-end encrypted after a match (see section 6)
Relationship datamatches, likes, blocked usersfrom your usage
Subscription datatier (FREE / VIBE+ / VIBE PRO), statusApp Store / Play Store
Push datapush token (FCM or desktop)your device
Security dataIP address, device identifier, login/session timestampyour device / connection, automatically on sign-in
ProcessingPurposeLegal basis
Account, sign-in, device managementproviding the serviceArt. 6 (1) (b) GDPR (contract)
Profile, identity, matchingcore app functionalityArt. 6 (1) (b) GDPR
Gender & gender preference in matchingpersonalized matchingArt. 9 (2) (a) GDPR (explicit consent)
Location-based discoverynearby searchArt. 6 (1) (a) GDPR (consent)
Chat & voice messagescommunication between usersArt. 6 (1) (b) GDPR
Push notificationsalerting you to new activityArt. 6 (1) (a) GDPR (consent)
Subscription billingcontract performanceArt. 6 (1) (b) GDPR
Security, abuse prevention, blockingsecure operationArt. 6 (1) (f) GDPR (legitimate interest)

5. Special categories of personal data

When you select a particular gender you are looking for during matching, this may allow conclusions about your sexual orientation. This information is a special category of personal data under Art. 9 GDPR. We process it solely on the basis of your explicit consent, which you give separately during use and which you can withdraw at any time with effect for the future.

6. Message encryption and safety moderation

Vibecheck uses two message modes, depending on whether you have matched with the other person:

  • Before a match (roulette chat and pre-match private chat): messages, including any images you send, are stored on our servers in plaintext. This lets us run automated safety checks — a filter for prohibited content and, for images, automated NSFW detection — and, where needed, human review by our moderation team. We only access this content for safety, moderation, and abuse-prevention purposes.
  • After a match (private chat and Safespace): messages are end-to-end encrypted using a Signal-style scheme (X3DH + Double Ratchet). Content is stored on our servers only in encrypted form; we cannot decrypt or read it.

Push notifications never contain message content in either mode, only a generic notice.

7. Recipients and processors

We use carefully selected service providers with whom data processing agreements (Art. 28 GDPR) are in place:

  • Server hosting: self-hosted on our own infrastructure in Germany.
  • Media storage (photos, voice messages): currently stored on local disk on our own server in Germany; we plan to migrate this to AWS S3 (EU, Ireland) in the future.
  • Sign-in: Google (Google Sign-In)
  • Push notifications (Android): Firebase Cloud Messaging (Google)
  • Payment processing: Apple App Store and Google Play (independent controllers for payment data)

By design, other users are recipients of the content you share with them (profile, identity, messages).

8. International data transfers

When using Google Sign-In and Firebase Cloud Messaging, data may be transferred to Google in the USA. Google is certified under the EU-US Data Privacy Framework; Standard Contractual Clauses apply in addition. Server hosting and media storage currently take place in Germany, so no third-country transfer occurs for them; if we migrate media storage to AWS S3, this will remain within the EU (Ireland).

9. Retention and deletion

  • Account, profile, and identity data are stored for as long as your account exists.
  • Anonymous identities expire automatically (expires_at) and are then removed.
  • You can delete your account at any time in the app. On deletion we remove your account, profile, identity, messages and voice messages, reactions, likes, matches, blocked users, push tokens, and the associated media files.
  • Login/session data (IP address, device identifier) used for account-security and ban-evasion detection is retained for 90 days and then automatically deleted. If this data results in a ban, the ban record itself (which may reference the IP address or device) is kept for as long as the ban is in effect, independent of the 90-day period above.

10. Location data

Users near you are shown only if you actively grant location access. This permission is disabled by default and can be turned off at any time in settings (including via Ghost Mode).

11. Push notifications

You can enable push notifications to be informed about new activity. Notifications contain no decrypted content. You can disable them at any time in your system or app settings.

12. Minimum age

Use of Vibecheck is restricted to persons 18 years and older. By using the app you confirm that you have reached this age. Accounts of minors are deleted upon discovery.

13. Your rights

You have the right at any time to:

  • Access (Art. 15 GDPR)
  • Rectification (Art. 16 GDPR)
  • Erasure (Art. 17 GDPR)
  • Restriction of processing (Art. 18 GDPR)
  • Data portability (Art. 20 GDPR)
  • Object (Art. 21 GDPR)
  • Withdraw consent with effect for the future (Art. 7 (3) GDPR)
  • Lodge a complaint with a supervisory authority (Art. 77 GDPR)

To exercise your rights, contact [email protected].

14. Supervisory authority

Competent supervisory authority:
Der Hamburgische Beauftragte für Datenschutz und Informationsfreiheit (HmbBfDI)
Ludwig-Erhard-Str. 22, 20459 Hamburg, Germany
https://datenschutz-hamburg.de

15. Changes

We update this policy when our processing or legal requirements change. You can find the current version on this page at any time.