Privacy Policy

Effective Date: March 16, 2026
Last Updated: March 16, 2026

YOUR PRIVACY MATTERS. This Privacy Policy describes how Sigma Pi Labs Inc. ("Company," "we," "us," or "our") collects, uses, stores, shares, and protects your personal information when you use the Vibe Connect mobile application ("App"). By downloading, installing, accessing, or using the App, you acknowledge that you have read, understood, and consent to the practices described in this Privacy Policy. If you do not agree with this Privacy Policy, please do not use the App.

1. INTRODUCTION AND SCOPE

1.1 Who We Are

Sigma Pi Labs Inc. is the data controller responsible for your personal information collected through the Vibe Connect mobile application. We are committed to protecting your privacy and handling your data in an open and transparent manner.

1.2 Scope of This Policy

This Privacy Policy applies to all personal information collected through:

This Policy does not apply to information collected by third-party websites or services linked to or from the App, which are governed by their own privacy policies.

1.3 Agreement to This Policy

By creating an account and using the App, you expressly consent to the collection, use, disclosure, and processing of your personal information as described in this Privacy Policy. If you are providing information on behalf of another person, you represent that you have their consent to do so.

2. INFORMATION WE COLLECT

We collect information in several ways: directly from you, automatically through your use of the App, and from third-party sources.

2.1 Information You Provide Directly

2.1.1 Account Registration Data

Data TypeDetailsPurpose
Email addressProvided at registration or via Apple/Google Sign-InAccount creation, authentication, communication
PasswordFor email/password registration (hashed, never stored in plaintext)Account security
Display nameUser-chosen name displayed to other UsersIdentification within the App
Date of birth / AgeProvided during onboardingAge verification (18+ requirement), matching
GenderMale, Female, or OtherMatching preferences
Authentication providerEmail, Apple, or GoogleLogin and session management

2.1.2 Profile Data

Data TypeDetailsPurpose
Bio / About meFree-text personal descriptionProfile display, AI profile review
InterestsSelected from 20+ categories (Gaming, Music, Sports, Travel, etc.)Matching algorithm compatibility scoring
Personality typeSoft, Fun, Harsh, or Sporty (determined via quiz)Personality-based matching
Tolerance levelMinimal, Moderate, or HighEmotional compatibility matching
Happiness indexSelf-reported "happy days" metricWell-being-based matching
Companion role preferenceBoyfriend, Girlfriend, Brother, Sister, Friend, Best Friend, Mentor, Confidant, Listener, Mother, FatherRole-based matching
AvatarSelected from predefined avatar optionsProfile display
Gender preference for matchingPreferred gender(s) of matchesFiltering match candidates

2.1.3 Communication Data

Data TypeDetailsPurpose
Chat messagesText messages sent to matched UsersMessage delivery, safety monitoring
ReportsUser reports including report reason and optional descriptionSafety, content moderation, enforcement
Unmatch reasonsOptional reason provided when unmatchingService improvement, safety
Support communicationsEmails or messages sent to our support teamCustomer support

2.1.4 Wellness and Journal Data

Data TypeDetailsPurpose
Mood scoresNumeric mood rating (0-10 scale)Mood tracking, visualization, wellness tips
Wellness diary entriesFree-text journal entries about daily wellnessPersonal journaling, self-reflection
Memory Book entriesPersonal journal entries (text or voice-dictated)Personal journaling
Mood historyHistorical mood data (7-day, monthly)Mood trends and visualization
Breathing exercise usageWhether breathing exercises were completedWellness feature engagement

2.1.5 Payment and Subscription Data

Data TypeDetailsPurpose
Subscription tierFree or PremiumFeature access management
Purchase historySubscription plan selected, start date, renewal dateSubscription management
Entitlement statusActive/expired/canceledFeature gating

Note: We do NOT directly collect, process, or store your payment card information, bank account details, or financial account numbers. All payment transactions are processed by Apple (App Store), Google (Play Store), and RevenueCat. These entities have their own privacy policies governing payment data.

2.2 Information Collected Automatically

2.2.1 Device and Technical Data

Data TypeDetailsPurpose
Device type and modeliPhone, Android device modelApp optimization, debugging
Operating system and versioniOS/Android versionCompatibility, debugging
App versionInstalled version of Vibe ConnectVersion management, updates
Push notification tokenFirebase Cloud Messaging (FCM) device tokenPush notification delivery
Unique device identifiersGenerated internally for session managementSecurity, fraud prevention
Network informationOnline/offline status, connection typeService delivery, offline queueing
TimezoneDevice timezone settingTimestamp localization

2.2.2 Usage and Behavioral Data

Data TypeDetailsPurpose
Online/offline statusWhether you are currently active in the AppMatching availability, display to connections
Last seen timestampWhen you were last activeDisplay to connections
Match historyUsers you matched with, match duration, outcomeMatching algorithm improvement, safety
Connection historySaved connections, save requests, accepted/declinedConnection management
Skip/block historyUsers you skipped or blockedPrevent re-matching, safety
Chat countNumber of completed chatsMatching algorithm (new user identification)
Message read receiptsWhether messages were read and whenChat feature functionality
Feature usage patternsWhich features you use and how oftenService improvement, analytics
Notification interactionsWhether push notifications were opened, accepted, or declinedNotification optimization
Session dataLogin times, session durationSecurity, analytics

2.2.3 Location and Proximity Data

Data TypeDetailsPurpose
Geolocation coordinatesGPS latitude/longitude (when location permission granted)Vibe Zone map display, proximity-based matching
BLE proximity tokensBluetooth Low Energy proximity identifiersProximity detection between nearby Users
Location accuracyPrecision of location dataMap display accuracy

Location Data: Location data is collected only when you explicitly grant location permission through your device's operating system. You may revoke location permission at any time through your device settings (iOS: Settings > Privacy > Location Services; Android: Settings > Location). Revoking location permission may limit Vibe Zone and proximity features.

2.2.4 Voice and Audio Data

Data TypeDetailsPurpose
Voice recordings (transient)Audio captured during voice dictationVoice-to-text transcription for Memory Book entries
Transcribed textText output from voice dictationStored as journal entry content
Language preferenceSelected dictation language (28+ supported)Transcription accuracy

Voice Data Processing: Voice recordings are processed on-device by your operating system's speech recognition service (Apple Speech Recognition on iOS, Google Speech Services on Android). We do not transmit raw audio recordings to our servers. Only the resulting transcribed text is stored when you save a journal entry. Voice recordings are transient and are not retained after transcription.

2.3 Information from Third-Party Sources

2.3.1 Authentication Providers

If you sign in using Apple or Google, we receive the following from the respective provider:

We do not receive your Apple or Google account password.

2.3.2 Payment Providers

RevenueCat, Apple, and Google may share with us: subscription status, purchase dates, renewal dates, cancellation dates, entitlement information, and transaction identifiers. They do not share payment card or bank details with us.

2.4 Sensitive Information

We recognize that certain information we collect may be considered sensitive, including:

We treat this data with heightened care and implement additional safeguards as described in Section 8 (Data Security).

3. HOW WE USE YOUR INFORMATION

3.1 Primary Purposes

We use your personal information for the following primary purposes:

3.1.1 Service Delivery and Core Functionality

3.1.2 AI-Powered Features

AI Data Usage: When you use AI features, relevant contextual data (such as conversation snippets, profile information, or mood data) may be sent to third-party AI service providers for processing. See Section 5 (Third-Party Service Providers) for details. AI-generated outputs are not human-reviewed before being presented to you. We encourage you to review our Terms and Conditions, Section 5 (AI-Powered Features) for important disclaimers.

3.1.3 Safety and Security

3.1.4 Service Improvement

3.1.5 Communications

3.2 Legal Bases for Processing (GDPR / International Users)

Where applicable (e.g., for users in the European Economic Area, United Kingdom, or other jurisdictions requiring a legal basis), we process your data based on:

4. HOW WE SHARE YOUR INFORMATION

4.1 With Other Users

Certain information is shared with other Users as part of the App's core functionality:

What is NOT shared with other Users: Your email address, date of birth, exact age, mood scores, wellness diary entries, Memory Book entries, subscription status, payment information, report history, strike count, or any wellness/mental health data.

4.2 With Third-Party Service Providers

We share information with third-party service providers who assist us in operating the App. These providers are contractually obligated to use your information only for the purposes for which it was shared and to maintain appropriate security measures. See Section 5 for a complete list of providers.

4.3 For Legal and Safety Reasons

We may disclose your information when we believe in good faith that disclosure is necessary to:

4.4 Business Transfers

In the event of a merger, acquisition, reorganization, bankruptcy, dissolution, sale of all or a portion of our assets, or similar corporate event, your personal information may be transferred to the acquiring entity. We will notify you of any such change in ownership or control of your personal information via the App or email.

4.5 Aggregated and De-Identified Data

We may share aggregated, anonymized, or de-identified data that cannot reasonably be used to identify you for any purpose, including research, analytics, business intelligence, and marketing. This data is not considered personal information under this Privacy Policy.

4.6 With Your Consent

We may share your information for purposes not described in this Privacy Policy with your explicit consent.

4.7 What We Do NOT Do

5. THIRD-PARTY SERVICE PROVIDERS

The following third-party service providers process your data on our behalf or in connection with the App's functionality:

5.1 Infrastructure and Backend

ProviderPurposeData ProcessedLocation
Supabase, Inc. Database hosting, user authentication, real-time messaging infrastructure, Edge Functions (serverless compute) All account data, profile data, messages, wellness data, journal entries, match history, authentication tokens United States (AWS infrastructure)
Google Cloud Platform (GCP) Cloud Run backend services (matchmaker, notification delivery, proximity services) Match queue data, notification routing, FCM tokens, proximity tokens, matching algorithm processing United States
Redis (via GCP) Session management, match queue, real-time pub/sub, temporary data caching Match queue entries, skip/block lists, session data (TTL-based, auto-expiring) United States

5.2 Authentication

ProviderPurposeData Processed
Apple Inc.Apple Sign-In authenticationApple user ID, email (or private relay email), name
Google LLCGoogle Sign-In authenticationGoogle user ID, email, name, profile photo URL

5.3 Push Notifications

ProviderPurposeData Processed
Firebase / Google (FCM)Push notification delivery to iOS and Android devicesFCM device tokens, notification content (titles, bodies, metadata), device platform
Apple Push Notification service (APNs)iOS push delivery (via FCM)Device tokens, notification payloads

5.4 Payments and Subscriptions

ProviderPurposeData Processed
RevenueCat, Inc.Subscription management, entitlement verification, purchase validationApp user ID, subscription tier, purchase dates, renewal status, entitlement data, platform (iOS/Android)
Apple (App Store)Payment processing for iOS purchasesPayment card information (held by Apple, not shared with us), transaction data
Google (Play Store)Payment processing for Android purchasesPayment card information (held by Google, not shared with us), transaction data

5.5 Mapping and Location

ProviderPurposeData Processed
Mapbox, Inc.Map display, location visualization in Vibe ZoneGeolocation coordinates, map interaction data, device type

5.6 AI and Machine Learning

ProviderPurposeData Processed
Third-Party LLM/AI Providers (accessed via API) AI chat assistance, message suggestions, profile review, bio improvement, tone analysis, wellness recommendations Contextual data necessary for AI processing: conversation snippets, profile text, mood data, message content. Data is sent via API calls and is subject to the provider's data processing terms.

AI Data Transparency: When you use AI-powered features, relevant portions of your data (such as message context, profile information, or mood scores) are transmitted to third-party AI providers via secure API calls. We minimize the data sent to what is necessary for the specific AI function. We do not send your full profile, private journal entries, or complete chat history to AI providers unless the specific feature requires it (e.g., conversation-based message suggestions require recent message context). Third-party AI providers may process this data according to their own privacy policies and data retention practices. We select providers with strong data protection commitments, but we cannot control how third-party providers process data once received.

5.7 Speech Recognition (On-Device)

ProviderPurposeData Processed
Apple Speech Recognition (iOS)On-device voice-to-text transcriptionAudio input processed locally on device (not sent to our servers)
Google Speech Services (Android)Voice-to-text transcriptionAudio input (may be processed on-device or via Google's servers depending on device settings)

6. DATA RETENTION

6.1 Retention Periods

Data CategoryRetention PeriodRationale
Account and profile dataDuration of account + 30 days after deletionService delivery, account recovery window
Chat messagesDuration of active connection; deleted when connection ends or account is deletedMessaging functionality
Wellness and mood dataDuration of account + 30 days after deletionWellness tracking continuity
Memory Book entriesDuration of account + 30 days after deletionJournal feature continuity
Match historyDuration of account + 90 days after deletionSafety, abuse prevention
User reportsMinimum 2 years, or as required by lawSafety, legal compliance, pattern detection
Subscription/payment recordsDuration of account + 7 yearsFinancial record-keeping, tax compliance
Push notification tokensDuration of account; refreshed automaticallyNotification delivery
Location dataNot persistently stored; used in real-time for Vibe Zone displayEphemeral use only
Redis queue/session dataAuto-expires (5-minute TTL for queue, 60-second heartbeat)Ephemeral use only
Server logs90 daysDebugging, security monitoring
Backup copiesUp to 30 days after primary deletionDisaster recovery

6.2 Extended Retention

We may retain certain data beyond the periods above when:

6.3 Deletion Process

When your account is deleted or data retention periods expire, we will delete or anonymize your data from our active systems. Data in backups will be overwritten through the normal backup rotation cycle (up to 30 days). Some residual data may persist in encrypted backup archives until overwritten.

7. YOUR RIGHTS AND CHOICES

7.1 Universal Rights

Regardless of your location, you have the following rights:

7.2 Rights for European Economic Area (EEA), United Kingdom (UK), and Switzerland Residents

If you are located in the EEA, UK, or Switzerland, you have additional rights under the General Data Protection Regulation (GDPR) or equivalent legislation:

7.3 Rights for California Residents (CCPA/CPRA)

If you are a California resident, you have the following rights under the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA):

California "Shine the Light" Law

California Civil Code Section 1798.83 permits California residents to request information regarding the disclosure of personal information to third parties for their direct marketing purposes. We do not disclose personal information to third parties for their direct marketing purposes.

CCPA Categories of Personal Information Collected

CCPA CategoryExamples CollectedSold?Shared for Advertising?
IdentifiersEmail, display name, device IDs, FCM tokensNoNo
Personal information (Cal. Civ. Code § 1798.80)Name, age/DOB, genderNoNo
Protected classificationsGender, ageNoNo
Commercial informationSubscription history, purchase recordsNoNo
Internet/electronic activityApp usage data, feature interactions, session dataNoNo
Geolocation dataGPS coordinates (when permitted)NoNo
Audio/electronic informationVoice dictation (transient, on-device)NoNo
InferencesPersonality type, compatibility scores, mood trendsNoNo
Sensitive personal informationPrecise geolocation, health-related data (mood/wellness), account credentialsNoNo

7.4 Rights for Other Jurisdictions

If you reside in a jurisdiction with applicable data protection laws (including but not limited to Brazil's LGPD, Canada's PIPEDA, Australia's Privacy Act, India's DPDP Act, or other national or regional privacy laws), you may have similar rights to access, correct, delete, or restrict processing of your personal data. We will honor such rights in accordance with applicable law.

7.5 How to Exercise Your Rights

To exercise any of your rights, you may:

We will respond to verifiable requests within 30 days (or as required by applicable law, e.g., 45 days under CCPA with possible extension). We may request verification of your identity before fulfilling requests to protect your data from unauthorized access.

7.6 Authorized Agents

You may designate an authorized agent to submit requests on your behalf. We may require proof of authorization and identity verification before processing such requests.

8. DATA SECURITY

8.1 Security Measures

We implement commercially reasonable administrative, technical, and physical security measures to protect your personal information, including:

8.2 No Absolute Guarantee

Despite our efforts, no method of electronic transmission or storage is completely secure. We cannot guarantee absolute security of your data. You acknowledge and accept the inherent risks of providing information electronically. In the event of a data breach affecting your personal information, we will notify you and applicable authorities as required by law.

8.3 Your Security Responsibilities

You are responsible for:

9. INTERNATIONAL DATA TRANSFERS

9.1 Transfer of Data

Your personal information may be transferred to, processed in, and stored in the United States and other countries where our service providers operate. These countries may have data protection laws that differ from those in your country of residence.

9.2 Safeguards for International Transfers

When we transfer personal data internationally, we implement appropriate safeguards, which may include:

9.3 EU-U.S. Data Privacy Framework

Where applicable, we rely on the EU-U.S. Data Privacy Framework, the UK Extension to the EU-U.S. Data Privacy Framework, and the Swiss-U.S. Data Privacy Framework for transfers of personal data from the EEA, UK, and Switzerland to the United States.

10. CHILDREN'S PRIVACY

10.1 Age Restriction

The App is intended for Users who are at least eighteen (18) years of age. We do not knowingly collect, solicit, or maintain personal information from anyone under the age of 18. We do not knowingly allow individuals under 18 to create accounts or use the App.

10.2 COPPA Compliance

In compliance with the Children's Online Privacy Protection Act (COPPA), we do not knowingly collect personal information from children under the age of 13. If we learn that we have collected personal information from a child under 13, we will take steps to delete that information as quickly as possible.

10.3 Parental Notice

If you are a parent or guardian and believe that your child under 18 has provided personal information to us or created an account, please contact us immediately at privacy@sigmapilabs.com. We will investigate and delete the account and associated data promptly.

10.4 Reporting Underage Users

Users can report suspected underage users through the App's reporting system. Reports of underage users are investigated and addressed as a priority.

11. COOKIES AND TRACKING TECHNOLOGIES

11.1 Mobile App Context

As a mobile application, Vibe Connect does not use traditional web browser cookies. However, we may use similar technologies including:

11.2 Do Not Track

We currently do not respond to "Do Not Track" (DNT) signals, as there is no universally accepted standard for how DNT should be interpreted in mobile applications. However, you can control data collection through the privacy settings described in this Policy.

11.3 App Tracking Transparency (iOS)

For iOS users, we comply with Apple's App Tracking Transparency (ATT) framework. We will request your permission before tracking your activity across other companies' apps and websites. You may change your tracking preference at any time in your device's Privacy settings.

12. AUTOMATED DECISION-MAKING AND PROFILING

12.1 Matching Algorithm

The App uses automated algorithms to match Users based on profile data, preferences, and behavioral signals. This constitutes automated decision-making and profiling. You acknowledge that:

12.2 Content Moderation

We may use automated systems to scan content for potential violations of our Terms, including but not limited to detection of harassment, spam, and inappropriate content. Content flagged by automated systems may be reviewed by human moderators.

12.3 Strike System

Our strike system uses automated counting of verified reports to determine enforcement actions (e.g., 3 strikes results in account ban). This automated process may significantly affect your ability to use the App.

12.4 Your Rights Regarding Automated Decisions

Where required by applicable law (e.g., GDPR Article 22), you have the right to:

To exercise these rights, contact us at privacy@sigmapilabs.com.

13. WELLNESS AND HEALTH DATA — SPECIAL PROTECTIONS

We treat your wellness and mood data with heightened sensitivity.

13.1 Categories of Wellness Data

The App collects the following wellness-related data:

13.2 How Wellness Data Is Used

13.3 How Wellness Data Is Protected

13.4 Not HIPAA-Covered

Sigma Pi Labs Inc. is not a covered entity or business associate under the Health Insurance Portability and Accountability Act (HIPAA). The App is not a medical device and is not subject to HIPAA regulations. However, we voluntarily apply heightened privacy and security standards to your wellness data.

14. PUSH NOTIFICATION DATA

14.1 Notification Infrastructure

Push notifications are delivered through Firebase Cloud Messaging (FCM) for both iOS and Android. To deliver notifications, we collect and store:

14.2 Notification Audit Trail

All push notifications sent to you are recorded in an audit log (the user_notifications table) for service quality, debugging, and abuse prevention purposes. This log includes the notification type, title, body, delivery timestamp, and associated metadata.

14.3 Notification Content

Push notification content may include:

Be aware that push notifications are visible on your device's lock screen and notification center, which may be viewable by others with physical access to your device.

14.4 Managing Notifications

You can manage notifications by:

15. PROXIMITY AND BLUETOOTH DATA

15.1 BLE Proximity Features

The App may use Bluetooth Low Energy (BLE) technology to detect proximity between Users and facilitate nearby connections. This feature:

15.2 Proximity Data Minimization

Proximity tokens are ephemeral identifiers designed to facilitate specific connection interactions. They are not used for tracking, advertising, or any purpose beyond the intended proximity feature. Tokens are distributed via silent push notifications and are revoked when connections end or users block each other.

16. DATA BREACH NOTIFICATION

16.1 Our Commitment

In the event of a data breach that affects your personal information, we will:

16.2 Notification Methods

Breach notifications may be sent via email, push notification, in-app notice, or posted on our website, depending on the nature and severity of the breach.

17. CHANGES TO THIS PRIVACY POLICY

17.1 Updates

We may update this Privacy Policy from time to time to reflect changes in our practices, technologies, legal requirements, or other factors. When we make material changes, we will:

17.2 Your Continued Use

Your continued use of the App after any changes to this Privacy Policy constitutes your acceptance of the updated Policy. If you do not agree with the changes, you should stop using the App and delete your account.

17.3 Prior Versions

Prior versions of this Privacy Policy may be available upon request by contacting us at privacy@sigmapilabs.com.

18. CALIFORNIA PRIVACY RIGHTS — ADDITIONAL DISCLOSURES

18.1 Financial Incentives

We do not offer financial incentives (e.g., price or service differences) in exchange for the retention or sale of personal information.

18.2 Metrics (Annual Disclosure)

As required by the CCPA, we will publish annual metrics regarding consumer requests received, including the number of requests to know, delete, and opt-out, and our median response time. These metrics will be available upon request.

18.3 Verification Process

When you submit a CCPA request, we will verify your identity by matching information you provide with the information we have on file. For account holders, we will verify through your authenticated account. For non-account holders, we may require additional proof of identity.

19. VIRGINIA, COLORADO, CONNECTICUT, UTAH, AND OTHER STATE PRIVACY RIGHTS

If you are a resident of Virginia (VCDPA), Colorado (CPA), Connecticut (CTDPA), Utah (UCPA), Texas (TDPSA), Oregon (OCPA), Montana (MCDPA), or other states with comprehensive privacy laws, you may have rights including:

To exercise these rights or appeal a decision, contact us at privacy@sigmapilabs.com.

20. CONTACT INFORMATION

20.1 Data Controller

Sigma Pi Labs Inc.
Role: Data Controller

20.2 Privacy Inquiries

For any questions, concerns, complaints, or requests regarding this Privacy Policy or our data practices, please contact us at:

Privacy: privacy@sigmapilabs.com
General: support@sigmapilabs.com
Legal: legal@sigmapilabs.com

20.3 EU Representative

If you are located in the EEA and wish to contact a representative regarding data protection matters, please email privacy@sigmapilabs.com and we will direct your inquiry appropriately.

20.4 Supervisory Authority

If you are located in the EEA or UK and believe we have not adequately addressed your data protection concerns, you have the right to lodge a complaint with your local supervisory authority. A list of EEA supervisory authorities is available at: https://edpb.europa.eu/about-edpb/about-edpb/members_en

By using the Vibe Connect App, you acknowledge that you have read, understood, and agree to be bound by this Privacy Policy in its entirety.