Vulti Privacy Policy
Last updated: Marzch 28, 2026
This Privacy Policy describes how Vulti ("we," "our," or "us") collects, uses, and discloses your information when you use our mobile application.
For the purposes of the General Data Protection Regulation (GDPR), Vulti acts as the Data Controller of your personal data. Vulti is designed to provide deep personality insights through facial expression analysis and connect you with compatible individuals. By using Vulti, you agree to the collection and use of information in accordance with this policy.
1. Information We Collect & How We Use It
A. Biometric Data & Profiling (Camera & Microphone)
• Purpose: To conduct the "Cognitive Interview," we request access to your Camera and Microphone. We capture video and audio to analyze facial landmarks, micro-expressions, and voice amplitude in real-time.
• Profiling & AI Analysis: The facial mapping and AI analysis are used to deduce your personality type. Under GDPR, this constitutes the processing of biometric data and profiling, which we perform strictly based on your explicit consent.
• Storage: Scans are processed on your device. If you choose to save a scan, it is securely backed up to our cloud servers so you can access it across devices. You may delete these at any time.
B. Account & Profile Data
• Purpose: We use Google Sign-In to create your account securely. We collect your email address, display name, and profile picture.
• Co-Vulti Profiles: For our social discovery feature, you may provide your age, gender, photos, and bio. This data maintains your account and connects you with matches.
C. Location Data
• Purpose: If you opt-in to Co-Vulti, we request your location to find nearby matches.
• Privacy Protection: We do not store exact GPS coordinates. Your location is "fuzzied" (randomized by a safe margin) on our servers to calculate distance without revealing your precise whereabouts.
D. Social & Communication Data
• Purpose: We securely process your likes, matches, and chat messages. Chat messages are encrypted in transit and at rest.
E. Usage & Log Data
• Purpose: We collect anonymous usage statistics and crash reports to fix bugs and improve the app (e.g., IP address, device name, OS version).
2. Legal Basis for Processing (GDPR)
If you are from the European Economic Area (EEA), our legal basis for collecting and using your personal information depends on the context:
• Explicit Consent (Art. 9 GDPR): For processing biometric data (facial scans) and location data. You can withdraw this consent at any time.
• Contractual Necessity (Art. 6(1)(b) GDPR): To provide you with the app's core functionalities, maintain your account, and deliver messages.
• Legitimate Interests (Art. 6(1)(f) GDPR): To analyze app usage, fix crashes, and ensure the security of our community (e.g., blocking/reporting users).
3. Your Data Protection Rights (GDPR)
If you are a resident of the EEA, you have the following data protection rights:
• The Right to Access, Update, or Delete: You can delete individual scans, photos, chats, or your entire account directly within the app's settings.
• The Right of Rectification: You have the right to have your information rectified if it is inaccurate or incomplete.
• The Right to Object & Restrict: You can object to our processing of your personal data or request that we restrict it.
• The Right to Data Portability: You have the right to be provided with a copy of the information we have on you in a structured, machine-readable format.
• The Right to Withdraw Consent: You have the right to withdraw your consent at any time where we relied on it to process your personal information.
If you wish to exercise any of these rights, please contact us. You also have the right to complain to a Data Protection Authority (DPA) about our collection and use of your personal data.
4. Data Retention
We retain your personal information only for as long as is necessary for the purposes set out in this Privacy Policy. If you delete your account, your profile, saved scans, chat history, and media are permanently and irreversibly deleted from our active servers.
5. International Data Transfers
Your information may be transferred to—and maintained on—computers located outside of your state, province, country, or other governmental jurisdiction where data protection laws may differ (e.g., the United States). We rely on Google Cloud/Firebase for data hosting, which uses Standard Contractual Clauses (SCCs) and the EU-US Data Privacy Framework to ensure your data is protected according to EU standards.
6. Third-Party Services
We use trusted services to host our infrastructure and process analytics:
• Google Play Services
• Google Firebase (Authentication, Firestore Database, Cloud Storage)
• Firebase Crashlytics & Google Analytics
7. Data Security
We use commercially acceptable security measures (such as secure HTTPS connections and Google Firebase's built-in encryption) to protect your personal and biometric information. However, no method of electronic storage or internet transmission is 100% secure.
8. Age Requirements (Children's Privacy)
Vulti is strictly not intended for use by anyone under the age of 18. We do not knowingly collect personal information from minors. If we discover a user under 18 has provided us with personal data, we will immediately delete their account and data.
9. Changes to This Privacy Policy
We may update our Privacy Policy periodically. We will notify you of any changes by posting the new Privacy Policy on this page.
10. Contact Us
If you have questions, wish to exercise your data rights, or need to contact the Data Controller, please reach out to:
vulti.contact@gmail.com