Back
Vibe Twin

Privacy Policy

Last updated: May 2026

1. Introduction

Vibe Twin ("we", "our", "us") is a music-based social networking application that connects people through their music taste. This Privacy Policy explains what information we collect, how we use it, how we share it, and the rights you have regarding your personal data. It applies to both the iOS and Android versions of the App and to our related websites and services. By using Vibe Twin, you consent to the practices described here.

2. Information We Collect

Account Information:
  • Display name, username, email address
  • Profile photo (optional)
  • Age, gender, country (optional)
  • Bio and Instagram handle (optional)
  • Encrypted authentication tokens for connected music services
Music Data (via Spotify / Last.fm):
  • Your top artists and tracks (typically the last 6 months)
  • Music genres you listen to
  • Audio features of your music (energy, danceability, valence, tempo)
  • Recently played tracks and playback history
  • Currently playing track (only while the App is active)
  • Listening habits (peak hours, daily listening minutes)
Social & Usage Data:
  • Swipe actions (like / pass)
  • Matches, friend requests, and blocks
  • Chat messages between matched users
  • Vibe-session participation and shared listening data
  • Reports you file against other users (used for moderation only)
  • In-app navigation events and feature usage metrics
  • App crash reports and performance data (via Sentry)
Subscription & Purchase Data:
  • Subscription status and entitlements (via RevenueCat)
  • Receipt validation tokens from the Apple App Store
  • We never see or store your full payment card details — payments are processed entirely by Apple
Device Information:
  • Device type, model, and operating system version
  • Push notification token
  • App version
  • IP address (used transiently for rate-limiting and abuse prevention; not stored long-term)
  • Approximate location inferred from IP at the country level (only if you grant the country field on your profile)

3. How We Use Your Information

  • Matching: We analyze your music data to find users with similar taste and calculate compatibility scores.
  • Social Features: Enable messaging, friend requests, the now-playing feed, vibe sessions, and Music DNA comparisons between matched users.
  • Personalization: Provide AI-powered song recommendations through Vibe Doctor based on your mood and music profile.
  • Notifications: Send push notifications for new matches, messages, and friend requests. You can disable these in Settings.
  • Subscription Management: Validate purchases, grant entitlements, and manage your Premium status.
  • Safety & Moderation: Review reports, enforce community guidelines, prevent abuse, and respond to legal requests.
  • Improvement: Analyze usage patterns and crash reports to fix bugs and improve the experience.

We do NOT sell your personal data to third parties and we do NOT use your data for advertising.

4. Legal Basis for Processing (GDPR)

If you are located in the European Economic Area, United Kingdom, or Switzerland, we process your personal data on the following legal bases:
  • Contractual necessity — to provide the App and its core features that you request.
  • Consent — for optional features such as push notifications and connecting third-party music services.
  • Legitimate interests — to improve the App, prevent abuse, and maintain security, balanced against your rights.
  • Legal obligations — to comply with applicable law.

5. Data Sharing

We share your data only as described below:
  • With Other Users: Your display name, profile photo, top artists, genres, audio profile, and (if active) currently playing track are visible to your matches. You can control visibility in Privacy settings.
  • Service Providers: Supabase (database & authentication, hosted on AWS), RevenueCat (subscription management), Sentry (crash reporting), Expo (push notifications), Google Gemini (AI recommendations).
  • Legal Requirements: When required by valid legal process, or to protect the rights, property, or safety of Vibe Twin, our users, or others.
  • Business Transfers: If we are involved in a merger, acquisition, or asset sale, your data may be transferred as part of that transaction; we will notify you and any successor will be bound by this Privacy Policy.

6. Third-Party Services

  • Spotify: We access your listening data through Spotify's Web API. We never post to or modify your Spotify account. You can revoke access at any time at spotify.com/account/apps.
  • Last.fm: Optional connection to enrich your music data from other platforms. You can unlink anytime at last.fm/settings/applications.
  • Supabase: Hosts our database and authentication infrastructure on AWS, with row-level security policies.
  • RevenueCat: Validates App Store purchases and manages subscription entitlements.
  • Google Gemini: Powers AI features such as Vibe Doctor recommendations and AI genre classification. Prompts may include limited music-profile information; no chat content is sent.
  • Sentry: Collects crash reports and performance data in production builds.
  • Apple: Processes In-App Purchases and delivers push notifications via APNS.

7. Data Storage & Security

Your data is stored securely on Supabase (hosted on AWS) with row-level security policies that prevent unauthorized access. Sensitive data such as third-party access tokens is stored locally on your device using the operating system's encrypted secure storage (iOS Keychain / Android Keystore). All data transmitted between your device and our servers is encrypted using TLS/HTTPS. We implement rate limiting, input sanitization, and SQL-injection prevention at every layer. No system is perfectly secure, and we cannot guarantee absolute security.

8. International Data Transfers

Your data may be processed in countries other than the one where you live, including the United States and the European Union. Where we transfer personal data outside the EEA, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses (SCCs) and equivalent mechanisms.

9. Data Retention

  • Active accounts: retained for as long as your account is active
  • Listening history: rolling window — older entries are automatically deleted after approximately 90 days
  • Chat messages: retained until you delete them or unmatch the other user
  • Crash reports: 90 days
  • Account deletion: when you delete your account, your personal data is removed within 30 days, except for limited records we are required to keep for legal, tax, or fraud-prevention purposes
  • Backups: may persist for up to 90 days after deletion before being overwritten

10. Your Rights

Depending on where you live, you may have the following rights:
  • Access — request a copy of the personal data we hold about you
  • Rectification — correct inaccurate or incomplete data
  • Erasure — delete your account and associated data from within the App, or by contacting us
  • Restriction — restrict certain processing
  • Portability — receive your data in a portable format
  • Objection — object to processing based on legitimate interests
  • Withdraw consent — at any time, where processing is based on consent
  • Complain — lodge a complaint with your local data protection authority

In the App you can already: view and edit your profile, control notification and privacy settings, disconnect Spotify or Last.fm, delete individual messages, block other users, and permanently delete your account.

11. California Privacy Rights (CCPA/CPRA)

If you are a California resident, you have the right to:
  • Know what personal information we collect, use, and disclose
  • Request deletion of your personal information
  • Opt out of any sale or sharing of personal information — we do not sell personal information, so there is nothing to opt out of
  • Non-discrimination for exercising your privacy rights

To exercise these rights, contact us using the email below.

12. Children's Privacy (COPPA)

Vibe Twin is not intended for, and we do not knowingly collect personal data from, children under 13 years of age. If we learn that we have collected data from a child under 13, we will delete it promptly. Parents or guardians who believe their child has provided us with personal data may contact us at the email below.

13. Cookies & Tracking

The Vibe Twin mobile app does not use advertising cookies, advertising identifiers, or cross-app tracking. We do not engage in tracking as defined under Apple's App Tracking Transparency framework. Our marketing website may use a minimal set of cookies for basic analytics; these are disclosed where applicable.

14. Changes to This Policy

We may update this Privacy Policy from time to time. We will post the updated version on this page with a new "Last updated" date. For material changes, we will provide additional notice through the App or by email. Your continued use of Vibe Twin after the effective date constitutes acceptance.

15. Contact Us

If you have questions about this Privacy Policy, want to exercise your rights, or want to file a complaint, contact us at:

rtimetasks@gmail.com