VIERA - Privacy Policy

Working pre-launch draft • Separate public legal document • 16 September 2026

Status: Working draft. This document covers personal-data processing only; product-use rules are contained in the separate Terms of Service.

Ten dokument prawny jest dostępny w języku angielskim.

1. Introduction

  • Viera (“Viera”, “we”, “us”, or “our”) is a women-only social and personal safety service designed to help women connect, participate in Activities and use safety-related features.
  • This Privacy Policy explains what personal data we collect and process, why we process it, how it may be shared, how long it may be retained, and the rights and choices available to users.
  • Where consent is required by applicable law, Viera will request it separately.

2. Who We Are and Contact

  • Viera is the service responsible for operating the Viera application and website.
  • For privacy questions or requests, contact: support@vieraapp.com.

3. Scope

  • This Policy applies to the Viera mobile application, website and related services, features and communications.
  • It applies when a user creates or uses an account, manages a profile, uses social/safety/location features, participates in Activities, communicates with members, contacts support or otherwise interacts with Viera.

4. Age and Eligibility Data

  • Viera is intended only for users aged 18 or older.
  • Viera collects full date of birth privately to determine age eligibility and calculate age-related profile information.
  • Full date of birth is not displayed to other members. Calculated age is displayed only if the user enables Show My Age.
  • Certain social/community features require third-party identity and eligibility verification.

5. Account and Authentication Data

  • Viera may process identifiers and account data received from supported authentication providers such as Apple or Google, including provider identifier, email address and display name where made available.
  • Display name may be edited and is not treated as a verified legal name.
  • Viera processes a unique @username and account/status information required to operate the account.

6. Profile Data

  • Profile data may include one optional avatar, display name, unique @username, calculated age where the user chooses to show it, mandatory interests and Verified status.
  • Interests are currently designed as 3–10 hobby/activity interests. Custom interests may be moderated and should not be used to publish contact details, URLs or social handles.
  • About Me/free-text biography is not part of the current MVP data model.

7. Identity and Eligibility Verification

  • Where a user chooses to access features requiring verification, Viera initiates a verification process performed by a third-party provider.
  • The verification process may require a government identity document, selfie/liveness check and eligibility information.
  • The preferred technical architecture sends verification materials directly from the user's device to the provider rather than storing them in Viera's application database.
  • Viera intends not to retain copies of identity documents, verification selfies or biometric templates.
  • Viera intends to receive and retain only the minimum verification result needed to enforce access, such as provider reference, status, eligibility result and verification timestamp.
  • Other members may see the Verified status/badge but do not receive verification documents, verification selfie, full DOB or other verification materials through Viera.

8. Women Nearby and Visibility Location Data

  • Women Nearby and Become Visible are available only to Verified Members.
  • Location permission alone does not make a user visible; the user must explicitly activate Become Visible.
  • While visibility is active, Viera periodically processes current location to determine nearby members and generate an intentionally approximate map position.
  • Viera's backend may process a precise coordinate for this calculation, but other members receive only an obfuscated/approximate position and a distance bucket rather than the raw coordinate.
  • Working display design: approximate position roughly 100–300 m from real position; distance buckets within 500 m, within 1 km and within 3 km.
  • Viera uses only the latest location for this feature and does not create a GPS movement history for Women Nearby.
  • When visibility expires or is switched off, location processing for Women Nearby stops.

9. Safer Route Data

  • Viera processes the current location and destination needed to calculate a user-requested route.
  • Viera does not intend to create a personal history of routes or movements for this feature.
  • Anonymous or aggregated segment feedback may later be retained to improve route recommendations.

10. Activities Data

  • Before acceptance, Activity data may include type/description, date, time, district/neighborhood, participant count/capacity and host profile.
  • Exact meeting location is disclosed only to approved participants after host acceptance.
  • Host processes/receives requester identity within Viera; accepted participants may see each other and receive group-chat access.
  • Future Activity participation is not displayed publicly on a member's profile.
  • Exact meeting location is intended to be removed from active systems about 24 hours after the Activity ends.
  • Past Activity metadata may remain in the user's private history until deleted or according to applicable retention rules.

11. Friends, Connections and Trusted Contacts

  • Viera processes relationship status for Connect requests, Friends and Trusted Contacts.
  • Trusted Contacts are Viera users selected from Friends, not phone-book contacts; Viera does not need Contacts permission for this feature.
  • An Unverified user may use exact-@username lookup for a specific known person. The limited result should expose only the data necessary for that known-person flow and no location/discovery information.
  • A user may currently have up to three Trusted Contacts.

12. Safe Journey Data

  • Safe Journey may process start time, expected duration/end, status, selected Trusted Contact and an optional destination.
  • Viera does not intend to store the journey start point or a GPS track for Safe Journey.
  • Working retention: personal Journey record/history about 30 days.
  • Working retention: optional destination removed from active systems about 24 hours after Completed/Cancelled or after an Overdue Journey is closed.
  • After destination removal, limited history such as date/status may remain for the applicable history period.
  • Viera may send functional check-in reminders and an overdue push to the selected Trusted Contact.

13. Messages and Communications

  • Viera processes private 1:1 text messages and Activity group-chat messages needed to provide messaging functionality.
  • Chats generally persist rather than being automatically erased after a short fixed period.
  • A user may hide/delete a chat from her own interface without erasing another recipient's copy.
  • Messages already received by others may remain after account deletion and may be attributed to Deleted Member without a profile link.
  • Reported or moderation-relevant messages may be retained separately where necessary for trust & safety.

14. Reports, Moderation and Safety Data

  • Viera may process reports about profiles, messages, Activities or offline behavior, report reasons, related content, violation history and post-Activity safety feedback.
  • Reports are treated as confidential and the reported member is not ordinarily told the reporter's identity.
  • Viera may use these data to investigate abuse, enforce rules, prevent fraud and protect members and the service.
  • MVP does not intend to continuously AI-scan all private chats; private message content may be reviewed when reported or needed for a moderation case.

15. Notifications

  • Viera may process device/push identifiers and notification preferences to deliver functional notifications for chats, social requests, Activities and Safe Journey.
  • Safety notification delivery depends on platform/device/network settings and cannot be guaranteed.
  • No marketing/re-engagement push campaign is assumed for the current MVP.

16. Technical and Security Data

  • Operating the service may require processing IP address, timestamps, authentication/session information, app/device/OS information and security logs.
  • Viera should collect only technical data reasonably necessary for operation, security, troubleshooting and abuse prevention.
  • No advertising identifiers or cross-app advertising tracking are planned for MVP.

17. How We Use Personal Data

  • To create and operate accounts and profiles.
  • To provide requested social, messaging, Activity and safety functionality.
  • To provide verification-gated community access.
  • To calculate location-based functionality while requested/active.
  • To send functional notifications.
  • To investigate reports, enforce rules, prevent fraud/abuse and secure the service.
  • To comply with applicable legal obligations.
  • To improve the service using appropriately minimized analytics/feedback where implemented.

18. Legal Bases for Processing

  • Performance of a contract (GDPR Article 6(1)(b)) may apply where processing is objectively necessary to provide a feature requested by the user.
  • Legitimate interests (Article 6(1)(f)) may apply to proportionate security, fraud prevention, moderation and service protection, subject to necessity and balancing.
  • Legal obligation (Article 6(1)(c)) may apply where Viera must process or retain information under applicable law.
  • Consent (Article 6(1)(a)) may apply to genuinely optional processing where consent is the appropriate legal basis.
  • Verification/biometric legal bases must be finalized after the verification provider and exact data flow are selected.

19. Sharing and Service Providers

  • Viera may use service providers for infrastructure and functionality such as authentication, hosting/database, verification, mapping/routing, push delivery, payments and security/diagnostics.
  • Viera should share only the data reasonably necessary for the relevant service and should contractually and technically limit processing where applicable.

20. International Transfers

  • If personal data is transferred outside the EEA, Viera will use the transfer mechanism and safeguards required by applicable data-protection law.

21. Retention and Backups

  • Viera retains personal data only for as long as needed for the purpose for which it was processed, subject to feature-specific periods, safety needs and legal obligations.
  • Deleted/expired data should be removed from active systems according to the applicable retention rule.
  • Residual copies may remain temporarily in protected backups and be overwritten/deleted through the ordinary backup lifecycle.
  • Do not publish a specific backup retention period until the production backup configuration is fixed.

22. Account and Data Deletion

  • Users may request account deletion through Profile → Settings → Delete Account.
  • After confirmation, profile/access should become unavailable to other members promptly.
  • Deletion/anonymization from active systems may take up to approximately 30 days.
  • Messages already received by others may remain as messages from Deleted Member.
  • Limited reports, security, fraud-prevention, dispute or legally required records may be retained where justified.

23. Permissions

  • Location: Women Nearby and Safer Route.
  • Notifications: chats, Activities and Safe Journey.
  • Photos/media: only when the user explicitly selects or changes an avatar; prefer the platform photo picker over broad gallery access.
  • No Contacts permission is required for Trusted Contacts.

24. Security

  • Viera will use reasonable technical and organizational safeguards appropriate to the nature and risks of the data processed.
  • No online service can guarantee absolute security.

25. Your Privacy Rights

  • Users in the EEA may have rights under applicable data-protection law including access, correction, deletion, restriction, portability, objection and withdrawal of consent where processing relies on consent.
  • Users may also have the right to lodge a complaint with the competent data-protection supervisory authority.
  • Requests may be submitted through support@vieraapp.com.

26. Children

  • Viera is not intended for persons under 18. Accounts identified as belonging to persons under 18 may be restricted or removed.

27. Changes to This Privacy Policy

  • Viera may update this Privacy Policy as the service develops or legal/technical requirements change.
  • Where required, Viera will provide appropriate notice of material changes.

28. Contact Us

  • For privacy questions and rights requests: support@vieraapp.com.
  • [Controller legal identity and address - TODO before production launch.]