Strapped Ventures LLC operates the wyddd mobile application and its supporting services (together, “wyddd,” “we,” “us,” or the “Service”). This Policy explains what information the Service handles, how it is used and shared, and the choices available to you.
1. The account is anonymous, not data-free
You do not need to give us an email address or create a visible login. Supabase creates a random account identifier, and the app stores a session on your device. We use that identifier to keep your profile, chats, gems, purchases, and service-provider records connected. “Anonymous account” therefore describes the sign-up experience; it does not mean that no data is collected or that all data is deidentified.
Because the account is device-bound, account recovery and cross-device continuity are not guaranteed.
2. Information we handle
Profile information
Display name, birth date, gender selection, attraction preference, short bio, optional profile photo, onboarding state, and anonymous user ID.
Chats and activity
Character passes and likes, matches, conversations, messages you send, AI replies, read state, message timing, and photo offers or unlocks.
AI consent
The version of the AI-fiction and third-party-AI disclosure you accepted and the server-recorded acceptance time.
Gems and purchases
Gem balance and ledger entries, product and offer identifiers, gem costs, Apple transaction identifiers, purchase time and environment, and RevenueCat event identifiers. We do not receive your full payment-card number.
Usage and diagnostics
App version, platform and device information, anonymous user and provider identifiers, feature events, onboarding gender and attraction selections, profile-completion indicators, campaign or install attribution, request time and route, IP-derived network information, errors, model name, response timing, message length, and safety or quality results. Analytics events do not include the text of your messages.
Support
Your email address and anything you choose to include when you contact support.
Device permissions and local data
The app stores its session, an onboarding/profile cache, gem display state, analytics delivery state, and permission choices on the device. If you choose a photo, iOS grants access through its photo picker. Tracking access is controlled by Apple App Tracking Transparency.
3. How we use information
- create and maintain your anonymous account;
- save onboarding choices, show relevant fictional characters, create matches, and maintain conversations;
- generate, evaluate, and deliver AI character replies;
- maintain authoritative gem balances, unlock curated character photos, process purchase events, and prevent duplicate credits or charges;
- measure onboarding, engagement, retention, attribution, and purchase performance;
- detect errors, rate-limit abuse, secure the Service, investigate reports, and enforce our Terms; and
- comply with law and protect users, the Service, and others.
4. AI processing and your permission
After you accept the in-app AI disclosure, an AI request may send your display name, bio, recent conversation text, current conversation state, and the selected fictional character’s instructions to Google Cloud Vertex AI. Google processes those inputs to classify the turn, draft a reply, and evaluate reply quality. The current prompt does not send your birth date, gender selection, attraction preference, or profile photo.
Before AI generation, a limited automated rule checks the message for high-confidence suicide or self-harm language. If that rule intercepts a turn, wyddd stores and displays the message and a neutral safety response, but excludes both from that and later Vertex AI requests.
Google states that it does not use Vertex AI customer data to train or fine-tune AI models without the customer’s permission or instruction, although prompts may be logged in some circumstances for abuse monitoring. See Google’s Vertex AI data-governance information.
AI chat is a core part of wyddd. If you do not grant this permission, or later withdraw it, AI matching and chat features will not be available. You can withdraw by deleting your account and stopping use of the Service. Contact us if you need help.
5. Profile-photo visibility
Profile photos are stored in a private Supabase bucket. The backend gives the app a signed bearer link that expires after one hour so it can display your selected photo. Anyone who obtains an unexpired link can view the image until that link expires, so do not share the link or upload an image you consider sensitive or confidential.
6. Service providers and disclosures
We disclose information only as needed to operate, secure, measure, and sell digital goods in the Service, or where law requires it. Current providers include:
Supabase
Authentication, database, realtime delivery, and image storage. It receives the account, profile, conversation, gem, purchase, consent, and storage data described above.
Google Cloud Vertex AI
Third-party AI generation and evaluation. It receives the limited profile and conversation context described in Section 4.
Vercel
API hosting and operational logs. It may process request, network, device, route, timing, and error information.
RevenueCat
In-app purchase orchestration. It receives the anonymous user ID, product and transaction data, device identifiers, Mixpanel ID, and AppsFlyer attribution data.
Apple
App distribution and payment processing. Apple handles your Apple ID, payment method, purchase, refund, and StoreKit records under its own terms.
Mixpanel
Product analytics. It receives the anonymous user ID, app/device/network data, attribution properties, onboarding gender and attraction selections, profile-completion indicators, and feature-event properties—but not message text or profile photos.
AppsFlyer
Install attribution, campaign measurement, and fraud prevention. It receives the anonymous user ID, provider/device identifiers, install or campaign data, and selected product milestones. Access to Apple’s advertising identifier requires your App Tracking Transparency permission.
These providers handle information under their own service, privacy, and data-protection terms.
We may also disclose information in response to valid legal process, to protect rights or safety, or as part of a merger, financing, acquisition, or transfer of the Service, subject to applicable law.
We do not send conversation text or profile photos to AppsFlyer or Mixpanel. Mixpanel receives your selected gender and attraction preference when you complete those onboarding steps, as well as profile-completion indicators such as name length, bio length, and whether you added a photo. These are used for product analytics; the app does not send the selections or indicators to AppsFlyer. We do not sell personal information for money. Some privacy laws may treat advertising measurement disclosures to AppsFlyer as “sharing”; you can deny or revoke iOS tracking permission and contact us to exercise an applicable opt-out right.
7. Retention and deletion
Core account information is kept while your account exists so the Service can preserve your conversations and gem balance. Short-lived operational events may be removed sooner. Service providers may retain logs and records under their agreements and legal obligations. Support communications may be kept while needed to answer the request, document the resolution, or comply with law.
You can delete the anonymous account from You → Account & data → Delete account and data. The backend first records a durable erasure request for RevenueCat, Mixpanel, and AppsFlyer, blocks new profile-media uploads, removes and verifies the account’s stored profile media, deletes the Supabase authentication user and account-linked profile, matches, conversations, messages, AI run records, wallet, gem ledger, and purchase-credit records from the active application database, and then performs a second media cleanup and verification. Processor requests are delivered and retried in the background because those providers process deletion asynchronously. The delivery record holds only the server-bound anonymous account ID needed to submit those requests and is purged after all three providers accept them. Provider completion can take additional time; for example, Mixpanel states that a deletion task can take up to 30 days. Apple and other providers may retain transaction, security, legal, or backup records under their own policies.
Deletion is permanent. Because there is no visible sign-in or recovery flow, we may be unable to locate or restore an account once its device session is gone.
8. Your choices and rights
- Edit supported profile fields in the app.
- Delete your account and primary app data in the app.
- Allow, deny, or later change tracking permission in iOS Settings. Basic, non-IDFA measurement may continue where permitted.
- Choose whether to add a profile photo, replace it in the app, or remove it by deleting the account.
- Contact us to request access, correction, deletion, or another privacy right available where you live. We may need information from the active app session to verify the request.
We will not discriminate against you for exercising a privacy right. Some processing is required to provide the Service; if it cannot continue, account deletion may be the available choice.
9. Security, transfers, and age
We use access controls, encrypted network connections, row-level database restrictions, private delivery for paid character photos, and server-side purchase accounting. No security method is perfect, so do not place highly sensitive information in a profile or chat.
Providers may process information in the United States and other countries, which may have different data-protection laws from where you live.
wyddd is only for people aged 18 or older. We use the birth date you provide to enforce that restriction. If you believe someone under 18 is using the Service, contact us.
10. Changes and contact
We may update this Policy when the product, providers, or law changes. The “Last updated” date identifies the current version. A material change to AI data use may require a new in-app acknowledgement.
For privacy questions or requests, email contact@wyddd.app. Please do not include payment-card details or more chat content than is needed to explain the request.