Vibz — Privacy Policy

Version: 1.0.0 Effective date: 2026-08-27 Last updated: 2026-09-03 Operator: Midwest Technical Training & Consulting INC, a Missouri corporation ("Vibz", "we", "us").

This Privacy Policy explains how Vibz ("we", "us") collects, uses, and shares information when you use the Vibz mobile apps, website, and related services (the "Service").


1. Information we collect

1.1 Information you give us

1.2 Information collected automatically

1.3 Information from third parties

We do not sell your personal information.

2. How we use your information

We rely on the following legal bases under GDPR / UK-GDPR: contract performance (operating your account), legitimate interests (security, abuse prevention, product improvement), legal obligation, and your consent (for tracking, marketing, optional integrations).

3. Sharing

We share information with:

We do not share your contact list or message contents with third parties for advertising. Section 1.1 explains what happens to address-book numbers when you turn contacts permission on, and section 5 explains how long the resulting match records are kept.

4. Encryption

5. Retention

We keep your information only for as long as we need it. The periods below are the retention targets our systems apply. Deletion is carried out by scheduled clean-up jobs, so a record can persist past its stated period until the next sweep removes it. A legal hold, a safety investigation, or a security incident can extend any of them. Indicative retention:

CategoryRetention
Active accountUntil you delete the account
Deleted accountDeletion runs immediately when you confirm it. Hard-deleted: your messages, posts, comments, follows, blocks, channel relationships, settings and interests, sessions, devices, encryption keys (including any optional key-recovery backup), and the media files you uploaded, which are removed from our storage and not only unlinked. Your phone number is erased from your account record, not replaced with a placeholder. What remains is a tombstone row carrying no phone number and the name "Deleted user", kept so that safety reports and other people's conversations referencing the account remain actionable. Moderation and safety records about the account — enforcement history, reports, and anything we are required by law to preserve — are retained as described in the rows below
Delivered direct messages and private-group messages (E2EE ciphertext)We do not retain message contents in the ordinary course: message bodies are purged from active servers about 24 hours after delivery, unless reported or preserved for legal, safety, or security reasons
Undelivered messagesIf a message cannot be delivered immediately (for example, the recipient is offline), we keep it in encrypted form on our servers for up to 30 days while we try to deliver it, then delete it
Call records (participants, start/end time, status — never call audio or video)Up to 30 days
Teen social access records, where enabledPairing codes expire after 10 minutes. Link requests, approvals/declines/revocations, adult attestations, teen safety acknowledgement, and capability settings are kept as needed to operate and audit the relationship and are handled by the account-deletion process, subject to legal, safety, and security retention requirements. No companion-review message copies, call content, or decryption keys are created.
Message metadata and tombstones (message ID, timestamps, delivery/read state, reaction/edit/delete state — never message contents)Up to 12 months where needed for delivery, abuse prevention, edits, reactions, deletions, safety, and legal compliance
Contact-match records (which two accounts are connected — never a phone number, and never a copy of your address book)Kept while your account exists, and deleted when you delete your account. We only act on a record your device has refreshed within the last 35 days, so a contact you remove from your address book stops affecting your suggestions within that window even while the record itself is still on file
Sign-in, security, message-delivery state, and time-limited technical diagnostic recordsUp to 7 days, unless preserved longer for legal, safety, or security reasons
Push notification delivery records (device token, message and conversation identifiers, delivery result)Kept while your account exists, and removed when you delete your account
Stale device recordsDeleted after 90 days of inactivity
Encrypted message key-delivery records for private groupsKept with message metadata/tombstones where needed to deliver, sync, recover, or troubleshoot encrypted group messages; these records are wrapped to recipient devices and do not contain plaintext message content
Signal device public keys and one-time prekeysKept while the device/account is active; claimed one-time prekeys are pruned after about 90 days by default; old signed prekeys may be kept in limited history so delayed messages can still decrypt
Optional encrypted key-recovery backupKept until you replace it or delete your account; the backup is encrypted before upload and is used to restore access to encrypted messages still available to your account
Public postsUntil you delete or your account is deleted
Public-group messagesUntil deleted by the sender, removed by moderation, or the account/group is deleted
Moderation reports + decisionsKept while needed to enforce our rules, handle appeals, and detect repeat abuse. Reports tied to a child-safety determination are kept as required by law
Server access logs30 days
Backups35 days rolling

Important encryption-retention note: deleting an encrypted message body from active servers does not immediately delete every supporting key or device record. Vibz keeps some encrypted key-delivery records, device public keys, prekey history, and optional encrypted key-recovery backups longer than 24 hours so the Service can deliver delayed messages, support multi-device sync, recover encrypted messages that are still available to an account, prevent abuse, and troubleshoot encryption failures. These records are not plaintext message content and are not made available to linked adults for review.

Your device may keep decrypted message bodies, media files, and media decryption keys in local app storage after the server copy is purged. You can remove that local copy by deleting the message, deleting the conversation, deleting your account, or clearing/removing the app data from your device.

6. Your rights

Depending on where you live (GDPR/UK-GDPR, CCPA/CPRA, Jamaica's Data Protection Act, etc.), you may have the right to:

To exercise any right not directly available in the app, email privacy@marketvibz.com.

7. Children

The Service is not directed to children under 13. We do not knowingly collect personal information from children under 13. If we learn we have collected such information without verifiable parental consent, we will delete it. Some jurisdictions set a higher minimum age (e.g. 14, 15, or 16) — those minimums are enforced where they apply.

For users between 13 and 17, we apply additional safety defaults: private profile by default, restricted DM and calling, limited discoverability, no private-group access, public-group access only where allowed by our safety rules, and no view-once or time-expiring secure media. Teen accounts do not receive adult-oriented recommendations.

Where teen social access controls are enabled, an eligible minor and adult account must both approve a link before the adult can allow specific social capabilities. The adult account's declared date of birth must indicate age 18 or older, and the adult attests that they are authorized to supervise the minor; Vibz does not verify identity or legal relationship through this flow. The link controls access only and provides no message, call, or activity monitoring. Age-restricted content, adult-oriented recommendations, view-once media, disappearing media, private groups, and other age-restricted features remain blocked.

Adults may enable Filter messages from strangers so direct messages from people they do not follow land in a separate Message Requests inbox without a notification or badge. From there, the adult can accept the conversation into the main inbox or decline it and delete the request.

8. International transfers

We are based in the United States. If you use the Service from outside the US, your information will be transferred to and processed in the US (and possibly other countries where our service providers operate). If you use the Service from Jamaica, your information is processed in the United States. Where required, we use approved transfer mechanisms such as Standard Contractual Clauses.

9. Security

We use industry-standard administrative, technical, and physical safeguards. No system is 100% secure. Vibz has no passwords: you sign in with your phone number and a one-time code, so the security of your account depends on the security of your phone and your phone number. We encourage you to lock your device with a passcode or biometric, keep control of your phone number (and contact your carrier immediately if you suspect a SIM-swap), and never share a Vibz verification code with anyone — we will never ask you for one.

If we discover a security incident affecting your information, we will notify you and the appropriate regulators as required by law.

10. Service providers (categories)

The current categories of third parties that process data on our behalf include:

Vibz does not claim proactive image or video scanning at upload. Reports involving possible child sexual exploitation receive priority moderator review. After a moderator records a reportable determination, the backend queues the required CyberTipline submission and applies the appropriate preservation and takedown workflow. End-to-end encrypted content cannot be inspected by Vibz; recipient reports may identify a message or attachment for targeted action.

The automated screening Vibz performs before publication is on text, not media: a keyword filter runs when you change your display name or profile status, when you upload a post with a caption, and when you write or edit a comment. The list is tiered, and a match does not always mean the same thing. A small set of child-sexual-abuse solicitation phrases is refused outright — the post, comment, or profile change is not saved. A separate list of severe slurs and explicit violent threats is not refused: that content is published, and an automatic report is filed at the same time so a person reviews it. Anyone who sees it can also report it. It is a keyword filter, not a general-purpose content classifier, and it does not read your end-to-end encrypted messages.

11. Changes

We may update this Policy. When we do, we will bump the version, post the updated version at this URL, and notify you in-app. For material changes affecting your rights, we will require you to accept the new policy before continuing to use the Service.

12. Contact