Privacy Policy

Last updated: November 27, 2025

1. Introduction

Vengl ("we," "our," or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our dating and social platform. Please read this policy carefully to understand our views and practices regarding your personal data.

2. Information We Collect

2.1 Information You Provide

  • Account Information: Email address, password, age, location (city)
  • Profile Information: Photos, bio, preferences
  • Communication Data: Messages between users, support tickets
  • Payment Information: Processed securely through Stripe (we don't store card details)

2.2 Information from Connected Platforms

With your explicit consent, we access data from platforms you connect:

  • Spotify: Songs and artists from your library
  • Last.fm: Songs and artists from your library
  • Apple Music: Songs and artists from your library
  • Reddit: Subreddit community names you participate in
  • Steam: Game library and playtime statistics
  • Discord: Server names you're a member of
  • Twitch: Streamer/channel names you follow
  • Goodreads: Book titles and authors
  • Letterboxd: Films you've watched
  • Other platforms: Similar interest-based data as authorized

2.3 Automatically Collected Information

  • Usage Data: Features used, time spent, interactions
  • Device Information: Browser type, operating system, device identifiers
  • Log Data: IP address, access times, pages viewed
  • Cookies: Session management and preferences

2.4 Location Information

We collect and use location data to provide our services:

  • City-Level Location: Required during registration for city-based matching
  • Approximate Location: Used to show matches in your area (never precise location)
  • IP-Based Location: For security and fraud prevention
  • Travel Mode: Optional feature to find matches when visiting other cities

We NEVER share your exact location with other users. Only your city is visible on your profile.

3. How We Use Your Information

3.1 Primary Uses

  • Matching Algorithm: Analyze your interests to find compatible matches
  • Service Delivery: Provide core features like messaging and discovery
  • Account Management: Authentication, settings, subscriptions
  • Safety & Security: Content moderation, fraud prevention, user protection

3.2 Additional Uses

  • Communicate important updates and notifications
  • Respond to support requests and inquiries
  • Improve our matching algorithm and user experience
  • Comply with legal obligations and enforce our Terms
  • Aggregate anonymous data for analytics

4. Information Sharing & Disclosure

4.1 With Other Users

  • Your match compatibility score and shared interests
  • Profile information you choose to display
  • Messages you send to matches (Premium feature)

4.2 With Third Parties

We may share your information with:

  • Service Providers: Hosting (Vercel), database (Supabase), payments (Stripe), moderation (OpenAI)
  • Legal Requirements: When required by law or to protect rights and safety
  • Business Transfers: In connection with mergers or acquisitions
  • Consent: With your explicit permission

We NEVER sell your personal data to third parties.

5. Data Security

We implement industry-standard security measures including:

  • Encryption of data in transit and at rest
  • Secure authentication with Supabase Auth
  • Regular security audits and monitoring
  • Access controls and employee training
  • Automated content moderation for safety

However, no method of transmission over the Internet is 100% secure. We cannot guarantee absolute security.

Data Breach Notification

In the event of a data breach that may impact your personal information:

  • We will notify affected users within 72 hours of discovery
  • Notification will be sent via email and in-app message
  • We will provide details about what information was affected
  • We will offer guidance on protective steps you can take
  • We will notify relevant authorities as required by law

6. Data Retention

We retain your information for as long as necessary to:

  • Provide our services to you
  • Comply with legal obligations
  • Resolve disputes and enforce agreements
  • Maintain safety and security records

When you delete your account, you have a 24-hour grace period to cancel the deletion. After this period, we permanently remove your personal data, except where retention is required by law or for legitimate business purposes (e.g., fraud prevention).

7. Your Privacy Rights

Depending on your location, you may have the following rights:

  • Access: Request a copy of your personal data
  • Correction: Update or correct inaccurate information
  • Deletion: Request deletion of your account and data
  • Portability: Receive your data in a portable format
  • Restriction: Limit how we process your data
  • Objection: Object to certain uses of your information
  • Withdrawal: Revoke consent for data processing

To exercise these rights, please use our Help Center.

Data Export & Portability

You can request a copy of your data in a portable format:

  • Export via your Profile Page
  • Instant download available
  • Format: JSON file
  • Includes: Profile info, traits, connected platforms, activity counts
  • Does NOT include: Messages, photos, other users' data, or internal algorithms

8. California Privacy Rights (CCPA)

California residents have additional rights under the California Consumer Privacy Act (CCPA):

  • Right to know what personal information we collect, use, and share
  • Right to delete personal information (with exceptions)
  • Right to opt-out of the sale of personal information (we don't sell data)
  • Right to non-discrimination for exercising privacy rights

9. European Privacy Rights (GDPR)

If you are in the European Economic Area (EEA), you have rights under the General Data Protection Regulation:

  • Legal Basis: We process data based on consent, contract, and legitimate interests
  • Data Protection: Contact us via our Help Center
  • Supervisory Authority: You may lodge complaints with your local authority
  • International Transfers: We use standard contractual clauses for transfers outside the EEA

10. Children's Privacy

Vengl is not intended for users under 18 years of age. We do not knowingly collect personal information from children. If we learn we have collected information from a child under 18, we will delete that information immediately. If you believe we have information from a child, please contact us.

11. Cookies and Tracking Technologies

We use cookies and similar technologies to:

  • Keep you logged in to your account
  • Remember your preferences and settings
  • Analyze usage patterns and improve our service
  • Ensure security and prevent fraud

You can control cookies through your browser settings, but disabling them may limit functionality.

12. Law Enforcement & Legal Requests

We may disclose your information to law enforcement or government authorities when:

  • Required by law, subpoena, or court order
  • Necessary to investigate potential violations of our Terms
  • To protect the safety of users or the public
  • To prevent fraud or security threats

Our Process

  • We review all requests for legal validity
  • We notify users when legally permitted
  • We only provide the minimum data required
  • We document all law enforcement requests
  • Emergency requests are handled within 24 hours

13. Third-Party Links

Our service may contain links to third-party websites and services. We are not responsible for their privacy practices. We encourage you to read their privacy policies before providing any information.

14. International Data Transfers

Your information may be transferred to and processed in countries other than your own. We ensure appropriate safeguards are in place to protect your information in accordance with this Privacy Policy.

15. Data Retention Schedule

We retain different types of data for different periods:

  • Account Data: Immediately deleted when account is deleted
  • Photos: Kept while account active, immediately deleted with account
  • Messages: Kept indefinitely unless deleted by user (deleted messages removed after 14 days)
  • Platform Traits: Until manually refreshed or account deleted
  • Moderation Logs: 90 days
  • OAuth Audit Logs: 90 days
  • Payment Records: 7 years (legal requirement)
  • Legal Compliance Data: As required by law

16. Advertising & Analytics

We currently do NOT:

  • Display third-party advertisements
  • Share data with advertising networks
  • Use tracking pixels or advertising cookies
  • Sell or rent your data to marketers

We may use analytics tools (with your consent) to improve our service, but these are configured to respect your privacy.

17. Communications & Notifications

Types of Communications

  • Service Messages: Account security, important updates (cannot opt out)
  • Match Notifications: New matches, messages (customizable in settings)
  • Marketing Emails: Features, tips, promotions (opt-in only)
  • Push Notifications: Real-time alerts (manage in device settings)

Managing Preferences

You can control communications through:

  • Account settings for email preferences
  • Device settings for push notifications
  • Unsubscribe links in marketing emails
  • Use our Help Center to opt out

18. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by:

  • Posting the new policy on this page
  • Updating the "Last updated" date
  • Sending an email notification for significant changes

19. Contact Us

If you have questions about this Privacy Policy or our privacy practices, please contact us:

Help Center: vengl.app/help

Data Export: Export My Data

This Privacy Policy is part of our Terms of Service. By using Vengl, you acknowledge that you have read and understood this Privacy Policy.