Legal
App Privacy Policy
Last updated · 2026-09-26
1. Data controller
The data controller under the GDPR for processing within the Vibecheck app is:
Nikita Lemke
Maakenhofwinkel 5
21147 Hamburg
E-mail: [email protected]
We have not appointed a data protection officer, as we are not legally required to do so. For all data protection matters, contact the e-mail address above.
2. Scope and overview
This policy describes the processing of personal data within the Vibecheck application (Android, Windows desktop, iOS planned). The website is covered by the separate privacy policy.
Vibecheck is only for persons aged 18 and older. The most important points in brief:
- Chats before a match (roulette and pre-match private chat) are stored on our server in plaintext so that they can be moderated. They are checked automatically, and authorized moderators can open them.
- Chats after a match (Safespace) are end-to-end encrypted. We cannot read them.
- Photos are automatically scanned for nudity before other users can see them. Unclear cases are reviewed by a human.
- Parts of our moderation work automatically (see section 7). Every moderation decision can be appealed in the app.
- We only use your approximate location and only show others a rounded distance.
- Ads only appear in Vibi-TV and only when you start a clip yourself. Before the first clip, you decide whether Google may use your data for ads (see section 3.1).
3. What data we process
| Category | Specific data | Source |
|---|---|---|
| Account data | e-mail address of your Google account, internal user ID (UUID), role, creation date | Google Sign-In |
| Real profile | display name, age, profile photos (including blurred versions) | provided by you |
| Anonymous identity | nickname, gender, age, “vibes” (interests), photos, expiry date | provided by you |
| Matching settings | age range, maximum distance, gender you are looking for | provided by you |
| Photos | photos in your profile, identity and chats, including image size and a low-resolution placeholder (blurhash) | provided by you |
| Voice messages | audio recordings you send (the microphone is only used while you record) | provided by you |
| Communication content | chat messages, images, voice messages, reactions, replies, edits, read and typing status | created by you (see section 6 for the encryption mode) |
| Chat archive | copy of your chat history, encrypted on your device with your own key, so that you can restore it on your other devices. We cannot read it | your device |
| Relationship data | likes, matches, blocked users | from your usage |
| Sparks and Vibi items | your Sparks balance, a ledger of every credit and debit (amount, reason such as daily reward, conversation, match, bought Sparks, Vibi-TV, subscription bonus, purchase of an item or look, gift or refund, balance afterwards, time), your daily reward streak, your Vibi items and how you got them, your current outfit and gifts you sent or received (item, price, status, time and the sender’s nickname at the time of sending) | from your usage |
| Wishlist and saved looks | items on your wishlist (up to 50) and whether we have already notified you about a sale or return, your saved looks (name and the items they contain) | provided by you |
| Sparks purchases | purchased product (Sparks pack or starter pack), Google Play purchase token and order ID, Sparks and item granted, status (granted or refunded), time of purchase and of any refund | Google Play and your usage |
| Ad rewards (Vibi-TV) | transaction ID and time of each watched clip confirmed by Google, the Sparks credited for it | Google AdMob, only after you watch a clip |
| Ad data (Vibi-TV) | advertising ID (only with your consent), IP address, device and app information, interaction with the ad. Processed by Google, not by us (see section 3.1) | your device, only after you tap Vibi-TV |
| Location data | approximate location (coarse location permission only), stored rounded to approx. 500 m | your device, only after you allow it |
| Device data | device ID generated by the app, platform, device model and manufacturer, operating system and version, app version, push token (Firebase Cloud Messaging), public cryptographic keys | your device |
| Presence data | online status, last seen | from your usage |
| Purchase data (subscriptions) | purchased product, subscription tier (FREE / VIBE+ / VIBE PRO), expiry date, Google Play purchase token | Google Play |
| Diagnostic data | on app errors: error message and stack trace, the last up to 60 lines of the app log, technical context, platform and app version, linked to your account | your device, automatically on errors |
| Security data | IP address, device ID and time of each sign-in, plus session and refresh tokens | your device/connection, automatically on sign-in |
| Moderation data | reports you submit or that concern you (reason, comment, attached context), content filter hits with the affected text excerpt, photo review results (detector score and labels), strikes, restrictions, bans (including device or IP bans), appeals, ban-evasion alerts and, if an account is deleted while banned, a keyed hash of its e-mail address (see section 11) | from your usage and from our moderation |
| Key backup (optional) | backup of your chat encryption keys, encrypted with your PIN and only created once you set a PIN | stored in your own Google Drive (see section 6.4), not on our servers |
We do not use tracking or analytics SDKs. The only advertising SDK in the app is Google AdMob for Vibi-TV (section 3.1).
3.1 Ads in Vibi-TV (Google AdMob)
Vibecheck shows ads only in Vibi-TV. There you can voluntarily watch a short clip (rewarded ad) to receive Sparks. A clip only starts when you tap it yourself. The number of clips per day is limited (currently three). There are no ads in chats, and the app shows no banner or interstitial ads. The ad SDK of Google AdMob (Google Ireland Limited) is only started the first time you tap Vibi-TV. If you never use Vibi-TV, the app sends no data to Google AdMob. Vibi-TV is not available in the desktop app. Currently, only Google serves the clips.
Consent. Before the first clip, Google’s consent form (User Messaging Platform, based on the IAB Transparency & Consent Framework) asks whether Google and the ad partners listed in the form may store and read information on your device, use your advertising ID and personalise ads. Legal basis: Art. 6 (1) (a) GDPR and § 25 (1) TDDDG. Without your consent, Google only shows clips that do not use your advertising ID and are not personalised, or no clip is available. You can change or withdraw your consent at any time with effect for the future in the app settings (privacy options for ads). You can also reset or delete your advertising ID in your Android settings.
Data processed by Google. When a clip is loaded and shown, Google processes in particular your advertising ID (only with your consent), your IP address, information about your device and the app (for example model, operating system, language and app version) and your interaction with the ad (for example whether you watched it to the end or tapped it). Google processes this data as an independent controller to deliver and measure ads, to prevent ad fraud and, with your consent, to personalise ads. Details can be found in Google’s privacy policy and in how Google uses information from apps that use its services.
Your reward. So that you receive your Sparks, the app passes your internal user ID (UUID) to Google. After you have watched a clip to the end, Google sends our server a signed confirmation that contains this user ID, a transaction ID, the ad unit and the time. We check the signature, credit the Sparks and store the transaction ID in your Sparks ledger so that a clip is never rewarded twice and the daily limit is kept. We do not receive your advertising ID or any other ad data from Google.
4. Purposes and legal bases
| Processing | Purpose | Legal basis |
|---|---|---|
| Account, Google Sign-In, sessions, device management | providing the service, keeping you signed in on your devices | Art. 6 (1) (b) GDPR (contract) |
| Profile, identity, matching settings, likes, matches, presence | core app functionality | Art. 6 (1) (b) GDPR |
| Sparks, Vibi items, looks, outfit, gifts, wishlist and saved looks | providing the feature (earning and spending Sparks, items, looks, outfit, gifts, wishlist, saved looks, monthly subscription bonus) and preventing abuse, for example duplicate rewards or exploiting errors | Art. 6 (1) (b) GDPR, for abuse prevention Art. 6 (1) (f) GDPR |
| Buying Sparks packs and the starter pack, verification of the Google Play purchase token, handling refunds and chargebacks | contract performance, crediting bought Sparks and items, removing them again after a refund or chargeback | Art. 6 (1) (b) GDPR |
| Keeping purchase records where commercial or tax law requires it | fulfilling statutory retention obligations | Art. 6 (1) (c) GDPR |
| Ads in Vibi-TV: storing and reading information on your device, advertising ID, ad personalisation (section 3.1) | showing the clip you started, measuring ads | Art. 6 (1) (a) GDPR and § 25 (1) TDDDG (consent via Google’s consent form) |
| Confirming a watched clip and crediting the Sparks | contract performance, keeping the daily limit and preventing duplicate rewards | Art. 6 (1) (b) GDPR, for abuse prevention Art. 6 (1) (f) GDPR |
| Gender you are looking for | personalized matching | Art. 9 (2) (a) and Art. 6 (1) (a) GDPR (explicit consent, see section 5) |
| Approximate location | nearby search and distance display | Art. 6 (1) (a) GDPR and § 25 (1) TDDDG (consent via the system permission) |
| Chat, images, voice messages | communication between users | Art. 6 (1) (b) GDPR |
| Push notifications | alerting you to new activity, for example when an item on your wishlist is on sale or available again | Art. 6 (1) (a) GDPR and § 25 (1) TDDDG (consent via the system permission) |
| Subscriptions, verification of the Google Play purchase token | contract performance, unlocking paid features | Art. 6 (1) (b) GDPR |
| Automated content filter, photo scanning, reports, restrictions and bans (sections 7 and 8) | protecting users against illegal content, harassment and abuse, enforcing our Terms | Art. 6 (1) (b) GDPR, Art. 6 (1) (c) GDPR in conjunction with the Digital Services Act (DSA), Art. 6 (1) (f) GDPR (legitimate interest in a safe platform), for automated decisions Art. 22 (2) (a) GDPR |
| Moderator access to pre-match chats | reviewing reports and flagged content | Art. 6 (1) (f) GDPR |
| Security data, ban-evasion detection | protecting accounts, preventing banned users from returning | Art. 6 (1) (f) GDPR |
| Retaining moderation evidence, ban records and, for deleted accounts with an active ban, a keyed hash of the e-mail address | preventing banned users from returning, handling appeals, establishing, exercising or defending legal claims, cooperating with authorities | Art. 6 (1) (f) GDPR, Art. 17 (3) (b) and (e) GDPR |
| Reports of illegal content (in particular child sexual abuse material) to authorities | fulfilling legal obligations, protecting children | Art. 6 (1) (c) and (f) GDPR |
| Diagnostic data, server logs | fixing errors, stable and secure operation | Art. 6 (1) (f) GDPR |
| Key backup in Google Drive | restoring your encrypted chats on a new device, at your request | Art. 6 (1) (b) GDPR |
| Data export | fulfilling your rights of access and data portability | Art. 6 (1) (c) GDPR in conjunction with Art. 15 and 20 GDPR |
Where we rely on legitimate interest (Art. 6 (1) (f) GDPR), our interest lies in the purpose stated in the table. You can object to this processing (see section 13).
Providing your data is necessary to use Vibecheck: without a Google account you cannot sign in, and without a profile or identity, matching is not possible. Location, push notifications, purchases and Vibi-TV are optional.
5. Special categories of personal data
When you select a particular gender you are looking for during matching, this may allow conclusions about your sexual orientation. This information is a special category of personal data under Art. 9 GDPR. We process it solely on the basis of your explicit consent, which you give separately during use and which you can withdraw at any time with effect for the future. Without this consent, matching works without a gender preference.
6. Chat encryption, moderator access and your keys
6.1 Before a match: plaintext and moderated
Messages in the roulette chat and in the private chat before a match — including images and voice messages — are transmitted to our server and stored there in plaintext (protected in transit by TLS). This allows the automated checks described in section 7. Moderators and administrators with the corresponding permission can open these conversations to review reports and flagged content. Every such access is recorded in an audit log. We access this content only for safety, moderation and abuse-prevention purposes.
Media in pre-match chats is never publicly accessible: it can only be retrieved by the sender, the recipient, and authorized moderators.
Before a match, your chat partner only sees your anonymous identity. Your permanent account ID is not shared with them. It is only disclosed to the other person after a mutual match.
6.2 After a match: end-to-end encrypted
Once you have matched, you chat in the Safespace. These messages, including images and voice messages, are end-to-end encrypted using a Signal-style protocol (X3DH + Double Ratchet). They are stored on our server only in encrypted form. We cannot decrypt or read them, and our automated checks (including photo scanning) cannot analyze them. The switch between both modes is visible in the chat (“YOU MATCHED”).
6.3 Deleting messages and conversations
You can delete a message “for everyone”. The message is then hidden for both participants. However, the server keeps the content as moderation evidence so that abuse (for example, harassment that is deleted afterwards) can still be reviewed.
If you delete a whole conversation, it is only hidden for you. Your chat partner keeps it. Here, too, the content remains on the server as moderation evidence.
In both cases the content is deleted within the normal retention periods (see section 11), unless it is part of a moderation case. For end-to-end encrypted messages, the server only ever holds the encrypted form.
6.4 Key backup in Google Drive
Your private encryption keys stay on your device. The key backup is optional: only if you set a PIN does the app store a backup of these keys in the hidden app folder of your own Google Drive (appDataFolder). Nothing is uploaded before that. Before uploading, the backup is encrypted on your device with your PIN (key derivation with Argon2id, encryption with AES-GCM). Single-use keys (one-time prekeys) are never included. Unencrypted backups created by earlier app versions are converted into the PIN-encrypted format the next time you restore them, and the old file is deleted. Neither we nor Google can read the backup without your PIN. If you forget your PIN, the backup cannot be recovered and older end-to-end encrypted messages can no longer be decrypted on a new device. If you turn the backup off on one of your devices, the backup file is deleted and your other devices stop updating it instead of creating it again. The app then tells you and you can turn it on again with a new PIN. When you delete your account, the app deletes the backup. You can also remove it yourself at any time in your Google Drive settings under “Manage apps”.
Google user data. Vibecheck asks Google only for these permissions: your basic profile (name and e-mail address) to sign you in, and access to the app’s own hidden folder in your Google Drive for the key backup described above. The app cannot see any other files in your Google Drive. We use this data only to sign you in and to store and restore your backup. We never use it for advertising, and we do not sell it or share it with third parties. Vibecheck’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
6.5 Push notifications
Push notifications never contain message content in either mode, only a generic notice.
7. Automated moderation and automated decisions (Art. 22 GDPR)
To keep Vibecheck safe, we use automated procedures. Some of them lead to decisions that are made without prior human review. In accordance with Art. 13 (2) (f) GDPR we inform you about the logic involved and the consequences:
- Content filter (pre-match chats only): Every plaintext message is compared with a list of prohibited terms and patterns maintained by us (for example harassment, hate speech, sexual content, content endangering minors, scams). Depending on the rule, a hit leads to one of two results: Block — the message is not delivered and not stored as a message. You are notified, and the hit (with the text excerpt) goes to our moderation queue. Flag — the message is delivered, but the hit is recorded and reviewed by a moderator. Certain rules also record a strike (see below). Names and nicknames are checked against a similar list.
- Photo scanning: Every photo you upload to your profile or identity, and every photo you send in a pre-match chat, is analyzed by an automated nudity detector (an image-recognition model that we operate on our own server, without passing any data to third parties). A chat photo is only delivered to the recipient after the automated scan has approved it. You see your own photo immediately. Photos that the detector flags, that it cannot analyze, or that cannot be checked because the detector is unavailable are held for review by a human and are not delivered in the meantime. If a moderator rejects the photo, it is removed for both participants. Profile and identity photos are subject to the same check before others can see them. Images in end-to-end encrypted Safespace chats cannot be scanned.
- Automatic restrictions: When several trusted users report an account for serious reasons (for a report of child sexual abuse material, a single trusted report is enough), or when a content filter rule records a first strike, the account is automatically restricted. A restriction is temporary and reversible: you keep access to your account and your history, but you cannot start new matches, send messages, create identities or upload photos, and you are not shown to others in matching until the restriction expires or is lifted.
- Trusted-reporter logic: Reports from users whose previous reports have repeatedly (currently: twice) been dismissed as unfounded no longer trigger automatic measures. They are still reviewed by a human.
- Strikes and temporary bans: Recorded violations count as strikes. Strikes for minor violations expire after 180 days. If strikes accumulate, the system can automatically ban the account temporarily for 7 or 30 days. Permanent bans are only ever imposed by a human.
- Ban evasion: If a new account signs in from a device that belongs to a banned account, the new account is automatically banned for 7 days and the case is reviewed by a moderator. The ban only becomes permanent if a moderator confirms the evasion. A match based on the IP address alone does not lead to an automatic decision. It only creates a notice that a human reviews. If someone deletes an account while it is banned and then signs up again with the same Google account, the original ban is re-attached to the new account (see section 11). This ban can also be appealed.
Legal basis and safeguards: These automated decisions are necessary for the performance of our contract with you, i.e. providing a safe service in accordance with our Terms (Art. 22 (2) (a) GDPR). In the app you can see which measure applies to you, the recorded reason, whether the decision was made automatically or by a moderator and, where applicable, when it ends. You have the right to obtain human intervention, to express your point of view and to contest the decision: every restriction and every ban can be appealed directly in the app. A human reviews the appeal. If it is upheld, the measure is lifted immediately. You receive the result in the app and by push notification. Further information on moderation, reports and appeals under the Digital Services Act can be found in section 6 of our Terms.
8. Reports and child safety
You can report profiles, identities, messages and photos in the app. The report (reason, optional comment and the context you attach) is reviewed by our moderation team. The reported user is not told who submitted the report.
We have zero tolerance for child sexual abuse material. Where the law requires or permits it, we report such content, together with the associated account data, to the competent law-enforcement authorities and to the National Center for Missing & Exploited Children (NCMEC) in the USA. For this purpose, the affected content is preserved in a separate, access-restricted area. Details: Child Safety Standards.
9. Recipients and processors
- Other users receive, by design, the content you share with them (profile, identity, messages, online status, rounded distance, your Vibi’s outfit). Your Vibi’s outfit is visible to everyone who sees your Vibi, in particular the people you chat with, before and after a match. If you send a gift, the recipient sees the item and the nickname of your identity at the time of sending.
- Our moderation team: only authorized persons, bound to confidentiality, whose access to chats is audit-logged.
- Server and media storage: our application server, the database, the media storage and the nudity detector are operated by us on a server in Germany.
- Cloudflare, Inc. (101 Townsend St, San Francisco, CA 94107, USA): all connections between the app and our server (api.onedayvibes.com) run through Cloudflare’s network (Cloudflare Tunnel). Cloudflare terminates the TLS encryption in the process and therefore technically processes the transmitted data, including pre-match messages, as our processor. Cloudflare also hosts our website and the download server.
- Google (Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, and Google LLC, USA):
- Google Sign-In for signing in
- Firebase Cloud Messaging for push notifications (receives the push token and the generic notification)
- Google Drive for the optional, PIN-encrypted key backup in your own Drive
- Google Play for purchases (subscriptions, Sparks packs and the starter pack). Google processes your payment data as an independent controller. To unlock your subscription or credit your Sparks, we have the purchase token verified via the Google Play Developer API. Google also informs us when a purchase is refunded or charged back, so that we can remove the Sparks and items granted with it.
- Google AdMob for the ads in Vibi-TV, only after you tap Vibi-TV (see section 3.1). Google processes the ad data as an independent controller. For the reward, Google receives your internal user ID and sends it back to our server with the confirmation of the watched clip.
- Link previews (chats before a match only) and GIFs: Previews are only loaded for links to an exact list of supported platforms: YouTube (Google), Spotify (with noembed.com as fallback), TikTok, SoundCloud, Instagram, X/Twitter, Reddit, Twitch, Giphy and Tenor. For these links, your device retrieves the preview (title, thumbnail) from the platform itself or via the service Microlink (microlink.io). The respective provider receives the link and the IP address of your device. Links to any other website are never fetched by the app. In end-to-end encrypted Safespace chats, no link previews are retrieved. GIFs from Giphy or Tenor are loaded through our server in every chat, including Safespace chats: our server fetches the GIF and passes it on to your device, so Giphy and Tenor only see our server, not your IP address. Our server does not store the GIF and does not log the link. In Safespace chats it learns only which GIF link is loaded, never the rest of the message. We do not transmit any other data to these providers. They are independent controllers.
- Authorities: law-enforcement authorities and NCMEC (see section 8), and other public bodies where we are legally obliged to disclose data.
We have concluded data processing agreements under Art. 28 GDPR with our processors.
10. International data transfers
Some recipients are located in the USA or process data there:
- Google (including Google Play and Google AdMob) and Cloudflare are certified under the EU-US Data Privacy Framework (adequacy decision of the European Commission, Art. 45 GDPR). Standard Contractual Clauses (Art. 46 (2) (c) GDPR) apply in addition.
- Link preview providers (section 9) are contacted directly by your device when a pre-match message contains a link to one of the supported platforms. Their seat may be outside the EU. Giphy and Tenor are contacted only by our server.
- Reports to NCMEC (USA) are made on the basis of Art. 49 (1) (d) GDPR (important reasons of public interest in the protection of children).
Our own server and media storage are located in Germany.
11. Retention and deletion
- Account, profile, identity, matching settings: as long as your account exists. Anonymous identities expire automatically and are then removed. So that you can continue an expired identity, we keep its nickname, gender, age, vibes, languages, settings and approved photos for a comeback window (currently 7 days) and then delete them. Tap New me in the app to delete them right away. Creating a new identity also deletes them. Chats without a match and likes of the expired identity are not kept.
- Chat messages and chat media before a match: until the anonymous identity involved expires, and for conversations that led to a match, as long as the accounts exist. Messages “deleted for everyone” and conversations you have hidden follow the same periods (see section 6.3).
- Safespace messages: as long as the accounts of the participants exist.
- Sparks, ledger (including ad rewards), Vibi items, outfit, gifts, wishlist and saved looks: as long as your account exists.
- Records of Sparks purchases: as long as your account exists, unless commercial or tax law requires us to keep them longer. Google keeps its own records of your Google Play orders.
- Ad data at Google: according to Google’s retention rules, see how Google retains data.
- Sessions: refresh tokens expire after 7 days at the latest and are deleted when you sign out.
- Security data (IP address, device ID, sign-in time): 90 days, then deleted automatically.
- Last seen: 30 days after your last disconnect.
- Diagnostic data: 30 days.
- Server logs: 14 days.
- Strikes: strikes for minor violations expire after 180 days.
Account deletion. You can delete your account at any time in the app (Settings → Delete Account) or request deletion via our website. We then delete your account, your identities, your profile, your photos, your chat messages and chat media files, your encrypted chat archive, your likes, matches and blocks, your sessions, your devices and push tokens, your presence data, your subscription record, your Sparks balance and ledger, your records of Sparks purchases (unless a statutory retention obligation applies, see above), your Vibi items, outfit and gifts, your wishlist and saved looks, and the key backup in your Google Drive. Unspent Sparks, including bought Sparks, lapse without replacement (see section 8.6 of our Terms). Pending gifts you sent are cancelled, and the Sparks for pending gifts sent to you are refunded to the sender. Items you gave to others stay with them but no longer refer to you.
Retained after deletion: ban records (including device and IP bans) and moderation evidence (reports, flagged text excerpts, photo reviews, ban-evasion alerts) are kept for 365 days after deletion, detached from your deleted account, and then deleted. This prevents banned users from simply re-registering and allows us to handle appeals and legal claims. Reports you submitted yourself are kept without any reference to you. If your account had an active ban at the time of deletion, we additionally keep a keyed hash (HMAC-SHA256) of your Google e-mail address on that ban. We do not keep the e-mail address itself. If you sign up again with the same Google account, the original ban is re-attached (you can appeal it). The hash is deleted as soon as the ban expires or is lifted, and at the latest 365 days after deletion. Legal basis: Art. 6 (1) (f) GDPR (legitimate interest in platform safety and in preventing ban evasion). Diagnostic data (30 days) and server logs (14 days) are deleted when their normal period expires.
Kept for as long as legally required: content preserved for a report of illegal content to authorities (including the preserved copies) is kept for as long as our legal obligations and the authorities or criminal proceedings require. Records of moderator actions (audit logs) are kept for as long as necessary to account for our moderation decisions. There is currently no fixed deletion period for them.
An active subscription is not ended by deleting your account. Please cancel it in Google Play under Payments & subscriptions → Subscriptions.
12. Location data
Users near you are only shown if you actively allow location access. The app only requests your approximate location (coarse location). Your precise GPS position is not requested. The server stores your position rounded to approx. 500 m. Other users never see your position, only a distance rounded up to a coarse step (1, 5, 10, 25, 50 or 100 km, beyond that in steps of 50 km). The permission is disabled by default and can be revoked at any time in the system or app settings (including via Ghost Mode).
13. Your rights
You have the right at any time to:
- Access (Art. 15 GDPR) — you can download a copy of your data at any time in the app under Settings → Account → Export Archive
- Rectification (Art. 16 GDPR)
- Erasure (Art. 17 GDPR)
- Restriction of processing (Art. 18 GDPR)
- Data portability (Art. 20 GDPR)
- Withdraw consent with effect for the future (Art. 7 (3) GDPR), including your consent to ads in Vibi-TV, which you can change at any time in the app settings (privacy options for ads)
- Not be subject to a decision based solely on automated processing without human review — use the in-app appeal (section 7)
- Lodge a complaint with a supervisory authority (Art. 77 GDPR)
Right to object (Art. 21 GDPR): Where we process your data on the basis of legitimate interest (Art. 6 (1) (f) GDPR), you have the right to object at any time on grounds relating to your particular situation. We will then no longer process the data unless we can demonstrate compelling legitimate grounds that override your interests, or the processing serves the establishment, exercise or defence of legal claims.
To exercise your rights, contact [email protected]. To protect your data, we only reply to the e-mail address linked to your account.
14. Supervisory authority
Competent supervisory authority:
Der Hamburgische Beauftragte für Datenschutz und Informationsfreiheit (HmbBfDI)
Ludwig-Erhard-Str. 22, 20459 Hamburg, Germany
https://datenschutz-hamburg.de
You can also contact the supervisory authority of your place of residence.
15. Minimum age
Use of Vibecheck is restricted to persons 18 years and older. By using the app you confirm that you have reached this age. Accounts of minors are deleted as soon as we become aware of them.
16. Changes
We update this policy when our processing or legal requirements change. You can find the current version on this page at any time. We will inform you about significant changes in the app.