Privacy Policy
This policy explains what personal data Vibe collects, why, who processes it on our behalf, and what you can ask us to do with it. It covers the Vibe mobile app and the Vibe admin and organisation portal, both operated by AOTC.
1. Data we collect
Account details. Your first and last name and email address are required to create an account. If you sign up with a password we store only a one-way hash of it, never the password itself. If you sign in with Google we store the Google account identifier and the email address Google returns, so we can recognise you next time.
Optional profile details. You may add a phone number, profile photo, gender, date of birth and address, city, state and country. These are optional — the app works without them, and you can clear them at any time.
Organisation membership. If you join through an employer or organisation, we record which organisation you belong to and your role within it, so the right people can administer your account and the right causes are visible to you.
What you create and do. Causes you submit (title, description, category, beneficiary name and any images), and your vibes — which cause you supported and how many seconds of attention you gave it. Vibes are how impact is measured in Vibe.
Device and diagnostic data. To deliver notifications we store a push token for each of your devices, its platform, an optional device description, and when it was last seen. The mobile app also sends usage analytics and, in released builds, crash diagnostics. Our servers keep ordinary request logs.
Security records. Session refresh tokens and one-time passcodes, both stored only as hashes, with their expiry and use timestamps.
2. What we do not collect
- No payment or financial data. Vibe has no donations, payments or payouts. Impact is measured in vibes and seconds of attention, never money, so there is no card, bank or transaction data to collect.
- No precise location. The apps do not request or track device location.
- No advertising profiles. We do not sell personal data and do not share it with advertising networks.
3. Why we use it
- To create and secure your account, sign you in and keep you signed in.
- To show you causes, record your vibes and display your impact.
- To let an organisation administrator manage members, invitations and their own causes.
- To send transactional email you asked for: email verification, one-time sign-in codes, password resets and invitations.
- To send notifications about activity relevant to you, where you have allowed them.
- To review and moderate submitted causes before they are published.
- To keep the service working — diagnosing crashes, understanding which features are used, and preventing abuse.
4. Who processes data for us
We do not sell personal data. We share it only with service providers who process it on our instructions, and only as far as their function requires:
- Google — Google Sign-In verifies your identity when you choose that option; Firebase Cloud Messaging delivers notifications; Firebase Analytics and Crashlytics provide usage and crash diagnostics.
- Brevo — sends our transactional email, and therefore processes your email address and the contents of those messages.
- Amazon Web Services — hosts the service and stores uploaded images in a private, encrypted bucket in the Mumbai (ap-south-1) region.
5. Notifications
Notifications are opt-in and controlled by your device. Declining the permission prompt, or turning notifications off later in your device or browser settings, stops them — nothing else about the service changes. When you sign out we remove the push token registered by that device.
6. How long we keep it
Account and profile data is kept while your account exists. Causes and vibes are kept as part of the record of activity on the platform. Deleted records are first marked as deleted and retained for a limited period so that accidental deletions can be reversed and so we can meet legal and audit obligations, then removed.
Security records are short-lived by design: one-time passcodes expire within minutes and cannot be reused, and refresh tokens expire or are revoked when you sign out.
7. How we protect it
Traffic between the apps and our servers is encrypted in transit. Passwords, session tokens and one-time codes are stored only as hashes, so they cannot be read back out of our database. Uploaded files are held in a private bucket with public access blocked and encryption at rest. Access to administrative functions is restricted by role.
No system is perfectly secure. If a breach affects your personal data we will notify you and the relevant authority as required by law.
8. Your rights
Subject to local law, you may ask us to:
- Give you a copy of the personal data we hold about you.
- Correct data that is wrong or out of date — most profile fields you can edit yourself in the app.
- Delete your account and the personal data associated with it.
- Withdraw a consent you previously gave, such as notifications.
- Explain a decision or restrict a particular use of your data.
Write to vibeplatform.app@gmail.com and we will respond within the period required by applicable law. If you are not satisfied with our response you may complain to your local data protection authority.
9. Children
Vibe is not intended for anyone under 18. We do not knowingly collect personal data from children. If you believe a child has given us their data, contact us and we will delete it.
10. Changes to this policy
We may update this policy as the service changes. The effective date at the top always reflects the current version, and we will give notice in the app or by email before a change that materially affects your rights takes effect.
11. Contact us
For any privacy question, request or complaint, including grievance redressal under India’s Digital Personal Data Protection Act, 2023, write to vibeplatform.app@gmail.com.