VibeCheck Privacy Policy
1. Controller and contact
The controller is the VibeCheck operator identified in the relevant checkout, receipt or service legal information. Contact Support or @VibeChecks_bot. Before EEA production launch this notice must contain the controller's full legal name, registered geographic address and dedicated privacy email.
2. Data categories
- account: email, Telegram ID, password hash, session tokens, language and terms acceptance;
- profile: name, age, gender, city, preference, photos, bio, interests and voluntary fields;
- interactions: likes, matches, visits, blocks, reports, messages, voice, photos, gifts, XP and badges;
- payments: item, ★ amount, currency, discount, status, transaction ID and limited provider data — never full card data;
- device/security: IP, browser, OS, time, error logs, login history and anti-fraud signals;
- attribution: ref code, UTM, campaign, segment and approximate origin;
- optional permissions: precise location, push endpoint and keys only after device permission;
- support: ticket content, attachments and resolution.
3. Purposes and lawful bases
- Contract: account, matching, chat, balance, purchases and support.
- Legitimate interests: security, fraud prevention, essential product measurement, legal defence and reliability, subject to balancing and applicable objection rights.
- Consent: optional precise location, browser push and promotional email/SMS where required. Consent can be withdrawn.
- Legal obligation: tax/accounting records and lawful authority requests.
- Vital interests: exceptional situations involving a credible threat to a person.
4. Real profiles and automated tools
Dating profiles are created and operated by the members who register them through Telegram. VibeCheck does not use team-managed, virtual or AI-operated dating personas. Automated systems may support matching, safety, moderation, translation or optional writing suggestions, but they do not send messages as another member. Decisions with significant legal effect are not based solely on automation without human review where the law requires it.
5. Recipients
Data may be shared on a need-to-know basis with hosting/database providers, Telegram, browser push and email services, card/crypto/app-store payment providers, fraud, analytics, translation or AI suppliers, moderators, support, professional advisers and competent authorities. Support and safety access is limited to necessary work and logged. We do not sell contact lists.
6. International transfers
For EEA transfers we use an adequacy decision, Standard Contractual Clauses or another valid mechanism and additional safeguards where needed. Details of a specific mechanism can be requested from Support.
7. Cookies and local storage
Necessary storage supports login, language, theme, security, checkout and preferences. Optional analytics/marketing technologies must not start before consent where consent is required. Settings can be changed in the consent control or browser. Rejecting optional storage does not block the core service.
8. Marketing and push
Transactional messages concern security, purchases and support. Promotional email, SMS or push use consent or another valid basis and provide an easy opt-out. Browser push can be disabled in VibeCheck and device settings. Marketing opt-out does not disable critical security messages.
9. Retention
Active account and conversation data is kept while needed to provide the service. Account deletion begins a 30-day recovery period: the profile is hidden and sessions/push are revoked. Afterwards data is deleted or anonymised unless payment, accounting, safety, dispute or legal records need lawful retention. Security and failed-session logs are kept only for a risk-justified period.
10. Your rights
Depending on law, you may request access, a copy, correction, erasure, restriction, portability, objection to legitimate interests or direct marketing, consent withdrawal, and human review of a significant automated decision. We may verify identity. GDPR requests are normally answered within one month. You may complain to the data protection authority in your residence, workplace or place of the alleged infringement.
11. Security and breaches
We use access controls, staff audit logs, secure cookies, password hashing, encryption of selected secrets, backups and rate limits. No system is absolutely secure. We notify users and regulators of a qualifying breach within the period required by law.
12. Age, sensitive data, changes
VibeCheck is for adults 18+. Report a suspected minor immediately. Avoid sharing documents, financial details, exact address or health information. We give notice of material privacy changes where required.
13. Requests and illegal content
Submit privacy, marketing, deletion or illegal-content requests through Support or @VibeChecks_bot. Include account ID and enough context, but never send a password or wallet seed phrase.