Privacy Policy
1. What this policy covers
This Privacy Policy describes how SVibond accesses, collects, uses, stores, shares, and deletes information when you use the SVibond Android application, its account services, realtime messaging infrastructure, support channels, and optional SVibond AI Bond.
2. Information SVibond handles
- Account information: email address, username, display name, authentication identifiers, and account status.
- Bond and messaging information: your Bond relationships, conversation identifiers, Vibe/message text, timestamps, replies, reactions, delivery status, and seen/read status.
- Music context: when you choose to attach or share the current song, SVibond may access and transmit metadata made available by Android's active media session, such as title, artist, album, media provider/package, media identifier or URI, and playback position. SVibond does not upload the song's audio and does not use microphone access to identify music.
- Notification information: a Firebase Cloud Messaging registration token and related device-registration information needed to deliver private Vibe notifications to your signed-in device.
- Support communications: information you voluntarily send to support@svibond.com.
- Optional SVibond AI information: only the text and song metadata you deliberately send directly to the SVibond AI Bond, plus limited backend reachability/latency diagnostics when you explicitly request diagnostics.
3. Why SVibond uses this information
SVibond uses this information to create and secure accounts, connect users through Bonds, deliver and synchronize Vibes, show conversation history, attach optional music context, provide replies/reactions/receipts, send private notifications, provide support, prevent abuse, troubleshoot service reliability, and provide the optional SVibond AI experience.
4. Who can receive or process information
SVibond does not sell personal information and does not use private Bond content for advertising. Information may be processed by service providers that are necessary to operate the app, including:
- Supabase for authentication, profiles, Bonds, persistent message data, receipts/reactions, and push-device registration.
- Google Firebase for Firebase Cloud Messaging, App Check / Play Integrity integration, and the optional Firebase AI / Gemini experience.
- Resend for transactional account emails such as signup confirmation and password recovery.
- Cloudflare for SVibond's website, DNS, and support-email routing.
- Realtime relay infrastructure and its hosting/routing providers for live delivery of Vibe events between connected devices. Durable human Bond message history is stored in Supabase rather than relying on the realtime relay as the source of truth.
When you send a Vibe to another person, the recipient naturally receives the message and any song metadata you chose to attach.
5. SVibond AI
The SVibond AI Bond is optional. Human Bond conversations are not provided to the AI Bond by SVibond. When you deliberately message SVibond AI, the text and attached song metadata for that AI conversation may be processed by Google's Firebase AI / Gemini services to generate a response. AI Bond history is also kept locally on the device for the signed-in SVibond account in the current beta.
6. Message privacy and administrator access
Human Bond messages are currently stored server-side so history can persist and synchronize. Because the current beta is not end-to-end encrypted, authorized SVibond backend administrators with database-level access could technically access stored message content when required for service operation, security, troubleshooting, or legal obligations. SVibond does not routinely use private Bond content for advertising, marketing profiling, or sale to data brokers.
SVibond plans to introduce end-to-end encryption for Bond messaging. This policy will be updated when that architecture is actually deployed.
7. Security
SVibond uses authenticated access, encrypted network connections, server-side secrets for privileged operations, and database access controls to reduce unauthorized access. Sensitive administrative credentials are not intentionally embedded in the Android client. No system can guarantee absolute security, and the beta should not be treated as end-to-end encrypted until SVibond explicitly states otherwise.
8. Data retention and deletion
Account and human Bond data are retained while the account exists so SVibond can provide persistent history and account functionality. You can permanently delete your account from Settings → Account → Delete account. The current deletion flow removes the SVibond authentication account and associated active account data, including shared Bond history that depends on that account, push-device registration, and account-scoped local AI history.
SVibond does not intentionally restore deleted accounts from application data. Limited infrastructure logs or provider backups may persist temporarily according to service-provider operational requirements or where retention is required for security, fraud prevention, or law.
For deletion instructions outside the app, visit svibond.com/delete-account.
9. Your choices
- Turn song attachment on or off before sending a Vibe.
- Enable or disable the optional SVibond AI Bond.
- Manage Android notification, overlay, and media-control access in system settings.
- Log out of a device without deleting the account.
- Permanently delete the account from SVibond Settings.
10. Changes to this policy
SVibond is currently in beta and its architecture will evolve. Material privacy changes, including the introduction of end-to-end encryption or new categories of data processing, will be reflected in an updated policy and effective date.
11. Contact
Privacy questions: support@svibond.com