Privacy
Privacy Policy
Your data, with clear boundaries.
This policy explains what information Vapai processes, why it uses it, who may receive it, and what choices you have.
1. Controller and EU representative
Raftell S.A.S., with its address at Gaviotas M48 S11, Parque Solymar, Canelones, Uruguay, is the controller for Vapai data. Privacy contact: privacy@vapai.me.
Its European Union representative under GDPR Article 27 is Alejandro Gelos Pomi, established in Spain. Contact: privacy@vapai.me.
2. Data we process
- Account and authentication: email, Apple, Google and Firebase identifiers, a phone number whose SMS confirmation is required for every account during registration, dates and security signals.
- Profile: chosen name, declared date of birth, calculated age, photos, bio, languages, interests and Host-since information.
- Sensitive matching preferences: one choice for how you identify—Men, Women or Beyond Binary—and one or more choices for whom you are looking for from the same categories. “Everyone” means all three are selected. These choices may reveal or allow inferences about sexual orientation, sex life or gender identity.
- Matching and Discovery filters: age range and maximum search distance. By default, the age range is 18 to 99 and the distance is 50 km. In Settings, you can choose another age range within those limits and a distance from 1 to 200 km.
- Approximate location: city, region, country and coordinates rounded to two decimal places, with the collection date.
- Social activity: profiles viewed, interests, passes, connections, chats, proposals and experiences created, saved, requested or hosted.
- Safety and support: reports, blocks, appeals, requests, technical logs, fraud signals and minimum necessary evidence.
- Device: APNs/FCM tokens, permissions, communication settings, failures and diagnostics.
- Optional analytics: permitted product-use events and parameters, only after consent and applicable technical controls.
How you identify is a single choice; whom you are looking for may include one or more categories. The age range and maximum distance limit the people you can explore or match with. These preferences and filters are not shown on your public profile.
Your phone, email, full date of birth, location, coordinates, technical identifiers and identity or connection preferences are not part of your public profile. Vapai does not perform documentary, biometric or independent identity or age verification. Apple, Google and phone confirmation do not prove identity. Mandatory SMS confirmation does not activate a tick, badge or public “verified user” status.
3. Purposes and legal bases
| Purpose | Main data | Basis |
|---|---|---|
| Create accounts, authenticate, display profiles, connect people and provide chat/Host/Guest functions | Account, profile, activity and content | Performance of the contract |
| Configure mutual compatibility and provide matching and Discovery | How you identify and whom you seek among Men, Women and Beyond Binary | Separate explicit consent; it can be withdrawn |
| Apply your private filters when showing compatible people | Calculated age, selected age range, approximate location and maximum distance | Performance of the contract and the service requested by you |
| Prioritise nearby experiences | User-selected approximate location | Consent/device permission and requested service |
| Prevent duplicate accounts, spam, fraud and abuse | Phone, authentication and technical signals | Legitimate safety interests; consent before sending a phone number to Firebase |
| Moderate, investigate reports, block and protect the community | Content, reports and evidence | Contract, legitimate interests and legal obligation where applicable |
| Send necessary communications | Account, email, push and operational context | Contract or legal obligation |
| Send optional promotions or updates | Email, push and preference | Separate consent |
| Measure the product and diagnose failures | Minimised analytics or diagnostics | Consent where required; legitimate interests only for documented, strictly necessary technical security |
Ranking and matching may use interests, preferences, calculated age, age range, approximate location, maximum distance and activity within the service. They are not used for decisions with legal or similarly significant effects.
4. Location
On iOS, location is requested when you choose to use it, with kilometre-oriented accuracy and a one-time reading. Vapai stores city, region, country and coordinates rounded to two decimal places to rank nearby experiences and apply your selected maximum distance. The default is 50 km and it can be changed in Settings to a value from 1 to 200 km. Other users do not see your location or selected distance on your profile.
You can revoke permission in device Settings and change location in Vapai. Revoking device permission does not automatically delete the last stored location; to delete it or object, contact privacy@vapai.me or delete your account. This repository contains no Android app, so this policy does not attribute the iOS behaviour to Android.
5. Providers and transfers
Depending on the environment and enabled function, Vapai uses Firebase Authentication and Phone Authentication, Cloud Firestore, Cloud Storage, Cloud Functions, Firebase App Check, Cloud Messaging, Crashlytics, Google Analytics for Firebase and Firebase Hosting; Google Sign-In; Sign in with Apple and Apple Push Notification Service; and BigQuery for the analytics pipeline when enabled.
The app also requests fixed decorative and Demo images from Unsplash. A compatibility fallback may request a generic avatar from DiceBear using the fixed seed VAPAI. Those requests are automatic when the relevant image appears and may disclose IP address and ordinary request/device metadata to the provider or its CDN, but the URL does not contain your account UID, name, email, phone, location, preferences or chat content. Raftell has not verified a provider-specific maximum retention period for these delivery logs and is evaluating self-hosting the assets.
“Add to Google Calendar” and “Open in Maps” are user-initiated handoffs: the external service opens only when you tap the relevant link. Calendar receives the pre-filled event fields shown to you; current Maps links refer only to Demo fixture addresses.
Google acts as processor for services covered by its data-processing terms and may act as an independent controller for expressly described purposes of its own, such as certain anti-abuse signals. Apple processes data for its services under its own terms. Processing locations vary: Firebase Authentication runs in the United States and other services use global infrastructure or configured regions.
Uruguay benefits from an EU adequacy decision. Onward transfers to the United States or elsewhere require the applicable mechanism, such as adequacy, the Data Privacy Framework or contractual clauses, as well as Uruguayan requirements. Raftell does not currently transfer data automatically to experience providers. If you leave Vapai for a third party, that party collects what you choose to provide under its own policy.
6. Analytics, advertising and terminal technologies
Web and app analytics are optional and off by default until there is a valid choice. You can reject or withdraw without losing the core service. We do not send names, emails, phones, messages, photos, coordinates, sensitive preferences or user-entered free text to analytics or Crashlytics.
Vapai does not use Meta Pixel, TikTok Pixel, Hotjar, ad networks or third-party behavioural ads. It does not sell personal data or share it for cross-context behavioural advertising. Featured or sponsored experiences, if introduced, will be labelled; commercial placement does not mean personal data is sold.
See the Cookie Policy and change your web choice through “Cookie settings” in the footer. On iOS, change analytics in Settings → Privacy.
7. Retention and deletion
- Account, profile, photos, preferences, location and social data: while active; confirmation of deletion removes access and starts authoritative erasure.
- Raftell-controlled operational data: target deletion within 30 days, except isolated minimum evidence or a legal obligation.
- Raftell-controlled backups: target overwrite or deletion within 90 days.
- Closed reports and minimum safety, fraud or abuse evidence: up to 12 months after closure, unless a documented legal hold applies.
- Exports: links expire and artefacts follow their operational deletion cycle.
- Provider data: follows provider cycles after Raftell sends the request; Firebase Authentication states up to 180 days for live and backup systems.
The current version does not offer a 30-day recovery window after deletion is confirmed: confirmation starts an irreversible process. Other people's messages and necessary evidence may be retained in a limited form where needed for their rights, safety or a valid obligation.
8. Your rights and choices
Request access, a copy/portability, correction, deletion, restriction, objection or consent withdrawal at privacy@vapai.me. You can also manage profile, location, age range, maximum distance, marketing, analytics, sensitive preferences, download and deletion in the app where available.
In the EU we normally respond within one month, extendable where legally allowed. You may complain to the AEPD. In Uruguay you may contact the URCDP. We voluntarily offer reasonable access, correction and deletion routes to people in the United States even when a specific state law does not apply because its thresholds are not met.
Vapai does not discriminate for exercising rights. We may request proportionate information to verify that a request relates to the account without collecting more than necessary.
9. Regional information
Spain and the European Union
The GDPR and relevant national rules apply. Explicit consent supports sensitive preference processing; withdrawing it keeps the account open but disables matching and Discovery until new consent.
United States
Vapai does not claim that CCPA/CPRA or another state law applies without checking its thresholds. Applicable statutory rights will be honoured. In all cases, Vapai does not sell personal data, share it for cross-context behavioural advertising or perform profiling with legal effects.
Uruguay
Raftell applies Law 18,331 and supports access, correction, updating, deletion and objection. Database registration and international-transfer mechanisms are internal compliance obligations; this policy does not claim an unverified registration is complete.
10. Changes and contact
For material changes we will show a new version and request renewed acceptance or consent where appropriate. Contacts: privacy privacy@vapai.me; legal legal@vapai.me; security security@vapai.me; general contact@vapai.me.