Privacy Policy

Effective Date: April 19, 2026  ·  Last Updated: April 19, 2026  ·  Version: 2.0

This Privacy Policy ("Policy") explains how Sigma Pi Labs Inc. ("Sigma Pi Labs," "we," "us," or "our") collects, uses, discloses, transfers, retains, and protects personal information in connection with the VibeConnect mobile application, related websites at vibeconnect.io, and associated services (collectively, the "Service"). This Policy is incorporated into, and forms part of, our Terms and Conditions. Capitalized terms not defined here have the meanings given in the Terms and Conditions.

At a glance. We collect information you provide (profile, photos, messages, mood entries, journal, interests), information your device generates (location, crash logs, device identifiers), and information from third parties that authenticate or bill you (Apple/Google/Firebase, RevenueCat, Twilio). We use it to operate the Service, match you, secure the app, comply with law, and respond to you. We do not sell your personal information. We do not serve advertising. We do not use your content to train AI models. Messages are encrypted in-transit and at-rest; they are not end-to-end encrypted. You can delete your account at any time; deletion purges your data after a 30-day grace period, with limited exceptions described below.

1. Who we are & how to reach us

The data controller responsible for the Service is Sigma Pi Labs Inc., a Delaware C-corporation. For any privacy-related request, to exercise any right described in this Policy, or to lodge a complaint:

2. Scope & acceptance

This Policy applies to personal information we process in connection with the Service. It does not apply to information processed by third parties (such as the Apple App Store, Google Play, a mobile-network operator, or an external website you visit from a link within the Service), except as expressly stated. By using the Service, you acknowledge this Policy. Where consent is required by Applicable Law, you will be asked for it separately at the appropriate point.

3. Information we collect

3.1 Information you provide directly

3.2 Information collected automatically

3.3 Information from third parties

4. Sensitive personal information

The following categories of personal information we process may be considered sensitive or "special category" under various laws (including GDPR Article 9, the UK GDPR, the California Consumer Privacy Act as amended, and equivalent regimes):

We process these categories only with your explicit consent where required, or where otherwise permitted under Applicable Law, and only for the limited purposes described in this Policy. We do not process biometric identifiers for unique identification, we do not collect or scan government-issued identity documents, and we do not infer or collect information about your race, ethnicity, political opinions, religious or philosophical beliefs, trade-union membership, or genetic data.

Wellness / mood data. The mood-tracking feature exists to help you reflect on your own state and to tailor your experience (e.g., conversation-tone suggestions). It is not a medical device or clinical tool. We do not share mood data with other Users. Mood entries are not used to train any AI model and are not analyzed to infer health conditions or diagnoses. If you withdraw consent or delete your account, mood entries are deleted in accordance with Section 11.

5. Sources of information

Sources of information summarized: (a) you; (b) your device and operating system; (c) other Users who interact with you (e.g., send you a message or report you); (d) our service providers, as listed in Section 9; (e) public sources (limited; primarily for fraud-prevention purposes).

6. How we use information

We use personal information for the following purposes:

7. Legal bases for processing (EEA / UK / Brazil)

If you are located in the European Economic Area, the United Kingdom, or a jurisdiction with equivalent legal-basis requirements, we process personal information on the following bases, as applicable to the purpose:

8. How we share information

8.1 With other Users

Information you choose to make visible in your profile (e.g., display name, age range, photographs, bio, interests, city or self-entered location, connection-type preferences, companion role) is visible to other Users through the Service's matching and discovery features. Messages you send to another User are delivered to that User. Activity RSVPs may be visible to co-participants in the activity. Do not post information in your profile that you would not want other Users to see.

8.2 With service providers (processors)

We share personal information with vendors who process it on our behalf, under written data-processing terms that restrict their use to the purposes we authorize. See Section 9 for a current list.

8.3 With authorities & to comply with law

We may disclose personal information when we believe in good faith that disclosure is necessary to: (a) comply with Applicable Law, legal process, subpoena, warrant, court order, or similar legal instrument; (b) protect the rights, property, or safety of Sigma Pi Labs, our Users, or the public; (c) enforce our Terms and Conditions and Community Guidelines; (d) detect, prevent, or address fraud, security, or technical issues; or (e) respond to a governmental or regulatory inquiry consistent with recognized data-protection principles.

8.4 Corporate transactions

If we are involved in a merger, acquisition, financing, reorganization, bankruptcy, receivership, sale of company assets, or transition of service to another provider, your information may be transferred as part of that transaction, subject to standard confidentiality protections and notice where required.

8.5 With your consent

We may share information for purposes not described in this Policy if we have your consent to do so.

8.6 We do not sell your personal information

We do not sell personal information, we do not share personal information for cross-context behavioral advertising, and we do not use personal information for targeted advertising. The Service contains no third-party advertising, no ad-network SDKs, no attribution SDKs (such as AppsFlyer, Adjust, Branch, or Singular), and no social-media pixels (such as Meta or TikTok pixels). We do not exchange personal information for monetary or other valuable consideration.

9. Sub-processors & service providers

We engage the following service providers, each of which processes personal information on our behalf and under written data-processing commitments.

ProviderPurposeCategories of personal informationProcessing location
Google LLC — Google Cloud Platform (incl. Cloud SQL, Cloud Run, Firebase Authentication, Firebase Cloud Messaging, Firebase Remote Config, Cloud Logging)Hosting, databases, authentication, push notifications, logging, feature flagsAccount identifiers, email, phone, profile data, messages, mood, journal, photos, device and diagnostic data, IP, push tokensUnited States (us-central1)
Google LLC — Firebase Crashlytics & Firebase AnalyticsCrash reporting, aggregate analyticsCrash stack traces, device identifiers, app version, event names, limited user identifiersUnited States
Google LLC — Vertex AI (Gemini models)AI conversational features, tone analysis, summarizationUser prompts and conversation context, User identifier (for rate-limiting). Not used to train models.United States (us-central1)
Google LLC — Google Places APIPlaces Discovery — search for public placesApproximate or precise location (as sent by app), search query, place identifierUnited States
Anthropic, PBC — Claude (accessed via Google Cloud and/or an intermediary routing service)Fallback / secondary AI conversational featuresUser prompts and conversation context, User identifier. Not used to train models.United States
Apple Inc. — Apple Push Notification Service, Sign in with Apple, StoreKitPush notifications, authentication, subscription billingDevice identifiers, push token, Apple identity token, transaction identifiersGlobal (Apple-determined)
RevenueCat, Inc.Subscription lifecycle management, receipt validation, entitlement resolutionUser identifier, device identifier, subscription state, transaction identifiersUnited States
Twilio, Inc.SMS verification (Twilio Verify)Telephone number, verification statusUnited States (with regional redundancy)
Resend (Resend.com Inc.)Transactional email delivery (e.g., password reset, moderation correspondence)Email address, email subject and bodyUnited States
Mapbox, Inc.Map rendering for Places DiscoveryApproximate device location (tile requests), map-interaction events, IP addressUnited States

Where a service provider sub-processes data further (e.g., Google's own infrastructure sub-processors), those further sub-processors are disclosed in the provider's own privacy and sub-processor documentation.

10. International transfers of personal information

Sigma Pi Labs is based in the United States, and our primary infrastructure (including Google Cloud Platform's us-central1 region) is located in the United States. If you access the Service from outside the United States, your personal information will be transferred to, stored in, and processed in the United States and other countries where our service providers operate.

10.1 Safeguards for EEA / UK / Switzerland transfers

For transfers of personal information from the European Economic Area, the United Kingdom, or Switzerland to the United States or other third countries that are not the subject of an adequacy decision, we rely on appropriate safeguards, principally the European Commission's Standard Contractual Clauses (Decision 2021/914), the UK International Data Transfer Addendum, and/or the Swiss-Approved SCCs, as applicable. You may request a copy of the transfer safeguards applicable to a specific processing activity by writing to privacy@vibeconnect.io.

10.2 Transfer-impact assessments

We conduct transfer-impact assessments where required and implement supplementary technical measures (encryption in-transit and at-rest, access controls, audit logging) to protect transferred data.

11. Data retention

We retain personal information only for so long as necessary for the purposes described in this Policy, unless a longer retention is required or permitted by Applicable Law.

CategoryRetention
Account profile (display name, photos, interests, personality, city, gender, connection types)Until account deletion; purged within 30 days after deletion
Messages (ephemeral match & saved connections)Deleted immediately upon account deletion. During active use, messages are retained as part of the account until deleted by you or by the expiration of a match.
Mood / wellness entriesUntil account deletion; purged within 30 days after deletion
Journal (Memory Book) entriesUntil you delete them or delete your account; purged within 30 days after deletion
Moderation reports (content, metadata)Up to 24 months, or longer where necessary for safety, investigations, legal defense, or legal obligation; pseudonymized where feasible
Authentication & security logsUp to 12 months for routine access; up to 24 months for incident-related logs
Crash, diagnostic, and API-metric logsUp to 90 days
Subscription / billing records, tax recordsUp to 7 years (as required by U.S. federal and state tax law and equivalent requirements in other jurisdictions)
Support correspondenceUp to 24 months
Records required to establish, exercise, or defend legal claimsFor the duration of the applicable statute of limitations plus a reasonable buffer

12. Security of personal information

We implement administrative, technical, and physical measures designed to protect personal information against unauthorized access, disclosure, alteration, loss, and destruction. These measures include:

No security measure is perfect. Transmission of personal information over the internet can never be guaranteed to be 100% secure. You are responsible for keeping your account credentials confidential and for notifying us promptly of any suspected unauthorized use of your account. See Section 28.

13. AI features & your data

13.1 Providers

Certain features use large-language-model AI technology provided by Google LLC (Vertex AI / Gemini, hosted within Google Cloud Platform) and Anthropic, PBC (Claude). These are our only AI providers at this time.

13.2 What we send

When you use an AI feature, the inputs you provide (for example, your message to "Ask Vibe," or a mood entry being analyzed for tone-matching), together with limited context drawn from your conversation, are transmitted to the applicable AI provider for the sole purpose of generating the requested output.

13.3 No training

Your content is not used to train AI models. Our contractual arrangements with Google Cloud (Vertex AI) and with Anthropic prohibit the use of our submitted data for model training or fine-tuning. We also do not use your content to train our own models.

13.4 Retention at the provider

Provider-side retention of AI inputs and outputs is governed by each provider's contractual terms with us and is limited to short-term retention for abuse-detection and operational purposes. Provider retention is disclosed in the provider's own documentation.

13.5 Consent & opt-out

Opt-in AI features display a consent prompt on first use. You may disable AI features in Settings at any time. Disabling a feature does not retract any output already delivered.

13.6 Not professional advice

AI outputs are not medical, mental-health, legal, financial, relationship, or safety advice, and you should not rely on them as such. See Sections 10.4 and 10.5 of the Terms and Conditions.

14. Messaging & encryption

Messages are encrypted in-transit (Transport Layer Security) and at-rest (AES-256 with server-managed keys). Messages are NOT end-to-end encrypted. This means that authorized Sigma Pi Labs personnel, and authorized service providers operating on our behalf under written data-processing obligations, may access message content where necessary to operate the Service, to moderate content, to respond to a report, to prevent fraud or abuse, to comply with Applicable Law, or to respond to valid legal process. Message content is never used to train AI models.

15. Location information

We collect location information only when and where you grant permission through your device's operating system. We use location information for:

We do not use location information for advertising. You can change location permissions at any time in your device settings; doing so may limit certain features.

16. Notifications & communications

We send transactional communications (account confirmations, password-reset emails, verification codes, safety/moderation correspondence, billing receipts where applicable, and service-operational messages). You cannot opt out of transactional communications while maintaining an active account. Marketing communications are not sent at this time; if we later introduce marketing communications, we will seek your separate, prior, opt-in consent where required, and we will provide an opt-out mechanism in every such message.

17. Cookies & similar technologies

The VibeConnect mobile application does not use browser cookies. Our website at vibeconnect.io may use strictly necessary and operational cookies or similar technologies for functionality, security, and basic traffic measurement. We do not use cookies or similar technologies for cross-site tracking, retargeting, or targeted advertising.

18. Children

The Service is intended solely for adults aged eighteen (18) or older. We do not knowingly collect personal information from children under 18. If we become aware that we have collected personal information from a person under 18, we will promptly delete the information and terminate the associated account. If you believe a child has provided personal information to the Service, please contact privacy@vibeconnect.io immediately.

19. Automated decision-making & profiling

We use automated systems (including matching algorithms, spam and abuse detection, content-moderation classifiers, and AI-based tone suggestions) that process your personal information. These systems do not produce legal effects or similarly significant effects concerning you within the meaning of GDPR Art. 22. Where we make a decision with significant consequences for you (for example, suspension or termination of your account for a safety reason), a human reviewer is involved, or you may request human review as described in Section 22.

20. Your privacy rights (summary)

Subject to Applicable Law and the specific rules of your jurisdiction (Sections 21–26), you may have some or all of the following rights:

To exercise a right, email privacy@vibeconnect.io. We will verify your identity by matching the request to the account, and we will respond within the time required by Applicable Law (generally 30–45 days, extendable as permitted).

21. United States state privacy rights

21.1 California (CCPA / CPRA)

If you are a California resident, you have the right to know, delete, correct, and limit the use of sensitive personal information; the right to opt out of the sale or sharing of personal information (we do not sell or share personal information for cross-context behavioral advertising, so there is nothing to opt out of in that respect); and the right not to be retaliated against for exercising your rights. You may submit a verifiable request to privacy@vibeconnect.io.

21.2 Categories disclosed under CCPA

We collect the following CCPA-enumerated categories: identifiers (e.g., email, telephone, Firebase identifiers); commercial information (subscription history); internet or network activity information (device data, IP, crash logs); geolocation data; audio-like content that is immediately converted to text on-device (not retained as audio); sensory data (photographs you upload); inferences drawn for matching; and sensitive personal information limited to precise geolocation, health-related mood data (with your consent), account-log-in credentials, and data concerning sexual orientation as inferred from your preferences.

21.3 Other U.S. state laws

If you reside in a state with a comprehensive consumer-privacy law (including Virginia — VCDPA, Colorado — CPA, Connecticut — CTDPA, Utah — UCPA, Texas — TDPSA, Oregon, Montana, Iowa, Delaware, New Jersey, Tennessee, Minnesota, Maryland, and other states with similar laws), you have substantially similar rights to access, correction, deletion, portability, and opt-out of targeted advertising and sale of personal data (which we do not engage in). Submit requests to privacy@vibeconnect.io.

21.4 "Shine the Light" (California)

California Civil Code § 1798.83 permits California residents to request information about disclosure of certain personal information to third parties for the third parties' direct marketing purposes. We do not engage in such disclosures.

22. European Economic Area & United Kingdom — GDPR / UK GDPR rights

If you are in the EEA, the UK, or Switzerland, you have the rights described in Section 20 as implemented under the General Data Protection Regulation, the UK GDPR, and the Swiss Federal Act on Data Protection. In addition:

23. India — Digital Personal Data Protection Act, 2023; IT Rules, 2021

If you are a Data Principal in India, we process your personal data as a Data Fiduciary. You may:

You also have the right to register a complaint with the Data Protection Board of India, when established.

24. Brazil — Lei Geral de Proteção de Dados (LGPD)

If you are a Data Subject in Brazil, you have the rights set out in Article 18 LGPD, including confirmation of processing, access, correction, anonymization, blocking or erasure, portability, information about entities with which we share your data, information about the possibility of refusing consent, and revocation of consent. Requests may be submitted to privacy@vibeconnect.io. You may also lodge a complaint with the Autoridade Nacional de Proteção de Dados (ANPD).

25. Canada — PIPEDA

If you are a resident of Canada, we comply with the Personal Information Protection and Electronic Documents Act (PIPEDA) and, where applicable, substantially similar provincial laws (including Quebec's Law 25). You may submit access and correction requests to privacy@vibeconnect.io. You may also lodge a complaint with the Office of the Privacy Commissioner of Canada (OPC).

26. Australia — Privacy Act 1988 (Cth) & Australian Privacy Principles

If you are in Australia, we handle your personal information in accordance with the Australian Privacy Principles. You may access and correct your personal information by contacting privacy@vibeconnect.io. If you are dissatisfied with our handling of a complaint, you may contact the Office of the Australian Information Commissioner (OAIC).

27. Account deletion & data purge

You may delete your account at any time through the in-app Settings → Delete Account flow. Upon confirmation:

28. Breach notification

In the event of a personal-data breach that is likely to result in a risk to your rights and freedoms, we will notify: (a) the relevant supervisory authority within 72 hours where required by GDPR Art. 33 or comparable law; (b) you, without undue delay, where the breach is likely to result in a high risk to your rights and freedoms, or where required by state breach-notification law. We will provide the nature of the breach, the likely consequences, the measures taken or proposed, and a contact point for further information.

29. Do Not Track & Global Privacy Control

The VibeConnect application is not served via web browsers and does not respond to browser-based Do Not Track signals. The application does not engage in cross-site tracking. Where required by Applicable Law (e.g., California), our website honors the Global Privacy Control signal as an opt-out of sale/sharing, although we do not sell or share personal information for cross-context behavioral advertising.

30. Changes to this Policy

We may update this Policy from time to time to reflect changes in our practices, technologies, legal requirements, or the Service. When we make a material change, we will notify you by in-app notice, push notification, or email before the change becomes effective, and we will update the "Last Updated" date at the top of this Policy. Your continued use of the Service following the effective date of a revised Policy constitutes your acknowledgment of the revised Policy.

31. Contact & grievance

Sigma Pi Labs Inc. — a Delaware Corporation (United States).


© 2026 Sigma Pi Labs Inc. All rights reserved. VibeConnect, Ask Vibe, and VibeZone are trademarks of Sigma Pi Labs Inc.