PRIVACY · WHAT'S THE VIBES
Privacy policy
This is the plain-English version of how we handle your data. We're a New York-based nightlife app and we keep what we collect to the minimum needed to run the service.
What we collect
- Account info: your email and password (or your Apple ID name and email — or Apple's relay address — if you use Sign in with Apple), a username, and an optional display name, photo and bio. Your username, display name, photo, bio, who you follow and the venues you mark as familiar make up your public profile, which other members can see.
- Date of birth: collected once at sign-up for the 21+ check. It is stored in a private record only you and we can read, is never shown on your profile, and is never shared.
- Location: your device's precise location (to roughly 100 metres), only while you're using the app and only after you grant permission. We use it to confirm you're in a coverage area, to show and sort nearby venues, and to let you file a crowd report from inside a room. We don't build a location history and we don't attach coordinates to your account, your posts or your reports. If you join the waitlist for a city we don't cover yet, we store your email together with the city and state we detected and the location fix we detected them from, so we know where demand is.
- Contacts (optional): if you choose "find friends," the app reads your address book on your phone, turns each email and phone number into a one-way hash (SHA-256), and sends only those hashes to our servers to match against members who opted in to being found. Unmatched hashes are kept so we can tell you when one of those contacts joins; they are deleted with your account. We never receive names, raw numbers or raw emails from your contacts.
- Your phone number (optional): if you add a number under "help friends find you," it is hashed on your phone before it is sent and stored only as that hash. This is the opt-in that lets people who have you in their contacts find you; until you do it, you can't be found this way. Remove the number in the same place to opt out.
- Content you post: clips (video, photos and their audio), captions, crowd and line reports (which venue, when, and what you reported), comments, and recaps. These are public by design — that's the product.
- Engagement: likes, saves, RSVPs, follows, blocks and reports, used to run the features they belong to.
- Usage & analytics: in-app activity such as screens you open and features you use, collected through Google Analytics for Firebase when it is enabled, so we can understand how the app is used and plan what to build next.
- Diagnostics & crash data: crash logs and basic performance diagnostics, collected through Firebase Crashlytics, so we can find and fix bugs.
- Device data: app version, OS version, a per-install device identifier (used to manage your signed-in devices), and a push token so we can deliver notifications you've opted into.
How the "vibe" is made
A venue's vibe word starts from a typical-for-this-hour estimate for rooms like it and moves with what comes in from the floor: clips, comments on those clips, and crowd reports from the last thirty minutes. When nothing has come in, the app says "typical for this hour" instead of "live." Short "what to expect" lines and weekly venue summaries are written by an AI model (OpenAI's API) from the venue's public description and from public comments — comments you post may be sent to OpenAI for that purpose and for automated safety screening, without your name or account details. AI-written text is labelled as such in the app.
What we don't do
- We don't sell your data. Period.
- We don't track you across other apps or websites, and we don't share your data with data brokers or advertising networks.
- We don't store your password — Firebase Authentication hashes it (scrypt) and we never see plaintext.
- We don't show ads, and we don't let third parties buy promoted slots inside the feed.
Where your data lives
Account auth and profile data live in Google Firebase (US-Central region). Video clips are hosted by Mux (mux.com/privacy). Verification and password-reset emails are sent through Brevo, which receives your email address for that purpose only. AI-written venue text is generated through OpenAI's API (openai.com/policies/privacy-policy) from public content, never from your account record. App analytics and crash diagnostics are processed by Google through Google Analytics for Firebase and Firebase Crashlytics. Push notifications route through Apple's APNs. We use these providers only to operate the app — never to advertise to you or to link your activity to other companies' data.
How long we keep it
We keep your account data for as long as your account is active. Crowd reports are used for thirty minutes and kept for moderation and venue history. When you delete your account (see below), your profile, clips, recaps, comments, reports, RSVPs, contact hashes, devices and notifications are removed, and your videos are deleted from Mux. Analytics and crash records are retained in aggregate/de-identified form for a limited period and are not used to re-identify you.
Your rights
- Delete your account: Settings → delete account. This permanently removes the data listed above; some traces (likes and votes on other people's posts) may take a little longer to sweep. You can also email support@whatsthevibes.app from your registered email if you'd prefer we do it for you.
- Export your data: email the same address and ask. We'll send a JSON dump of your account, posts, and engagement.
- Access, correct, or object: wherever you live, you can email us to ask what we hold about you, correct it, or ask us to stop a particular use. We honor these requests regardless of your region (including rights under laws like the GDPR and CCPA).
- Be found, or not: adding your number under "help friends find you" is the only way other members can find you through their contacts; remove it to opt out.
- Block someone: tap the ⋯ menu on any clip, or on their profile → block. You won't see their clips or comments.
- Report content or a profile: same menus, "report." Every report goes to our moderation queue; a clip reported by several people is hidden automatically while we look.
Children
What's The Vibes is for adults 21+ (it's a nightlife app — most content involves alcohol or 21+ venues). We gate sign-up behind a date-of-birth check and don't knowingly collect data from anyone under 21. If you believe an underage user has signed up, email support@whatsthevibes.app and we'll close the account.
Contact
Privacy questions: support@whatsthevibes.app
Mailing address available on request.
Last updated: 2026-08-22 (added date of birth, precise location, contacts and phone-number hashing, opt-in discoverability, AI-written text, and the Brevo and OpenAI processors). We'll notify users in-app before any material change.