Wevo — Legal documents
Privacy Policy
This policy explains which personal data are processed when you use Wevo, for what purposes, on which legal bases and for how long, pursuant to Articles 13 and 14 of Regulation (EU) 2016/679 ("GDPR"). It is written to be read: if anything is unclear, the contact details for asking are in section 12.
This is an English translation of the Italian original, provided for your convenience. If the two versions differ, the Italian version prevails.
1. Our principles
Wevo is a social app: to work, it necessarily processes some data about you and shows part of it to other users. Beyond that, the rule we follow is data minimisation.
- We do not sell your data and we do not hand it over to advertising intermediaries or data brokers.
- We only collect what is needed to run the features you use.
- Your email address is not stored in your public profile and cannot be read by other users: it lives only in the authentication system.
- You can delete your account, and your data with it, entirely from within the app, without having to contact us.
2. Data we process
Most data are provided by you. Some are generated automatically when you use the Service.
| Category | Data |
|---|---|
| Account data | Email address, password (stored exclusively in encrypted form by the authentication provider, never in clear text and never accessible to us), name, username, date of birth. |
| Profile data | Photos, personal description, city, gender, occupation, interests, any gaming platform identifiers you choose to link. All optional except where stated during sign-up. |
| Profile verification | If you choose to request the "Verified" badge: a selfie taken live with the pose shown by the app. Only moderators see it, to compare it with your profile photos; it is never visible to other users and it is deleted as soon as the request is approved or rejected. |
| Content | Messages in private conversations; text and voice messages in room chats, which are ephemeral; room furnishings and avatar appearance. |
| Usage data | Preferences expressed while discovering profiles, mutual connections, online presence status, avatar position inside a room, virtual currency balance and transactions, rewards earned. |
| Purchases | Product purchased, transaction identifier and date, coins credited and any refunds. Payment data (card, account, billing address) are processed exclusively by Apple or Google: we do not receive them. |
| Technical data | Installation identifier, push notification token (if you enable notifications), IP address and essential device information, recorded for security and abuse-prevention purposes. |
| Diagnostics and usage statistics | Crash and error reports (technical trace of the error, device model, operating system and app versions), linked to your account so that we can fix the problems you report to us. Usage statistics: screens visited and key events such as sign-up, swipes, matches and purchases, tied to the app installation and never to your account or to the advertising identifier; approximate location (country, region or city) is derived from the IP address, which is not stored. You can turn off both at any time (section 10). |
| Advertising data | The device's advertising identifier, processed by the ad provider only if you give your consent (section 7). To credit the coins of rewarded content, an internal identifier of your account is also sent to the ad provider, which returns it to us once viewing is complete. |
| Reports | Content of the reports you send or that concern you, the outcome of moderation, including automated moderation (section 3), and any measures taken. |
| Communications | Email address, message content and technical metadata of the messages you send to the Service's contact addresses or receive for account management. |
We do not process precise geolocation data and we do not access your device's location: your city is the one you choose from a list, and its approximate coordinates are used only to show you nearby profiles first. We do not collect your contacts and we do not ask for special categories of data under Article 9 GDPR. The verification selfie is not subject to facial recognition or any other biometric processing: the comparison with your profile photos is made by a person. If you choose to include information falling within those categories in your profile (for example references to sexual orientation or personal beliefs), you do so by your own free choice and with your consent, which you can withdraw by editing or removing that information.
3. Purposes and legal bases
| Purpose | Legal basis |
|---|---|
| Creating and managing your account; providing profile, discovery, connections, messaging, rooms and virtual economy features | Performance of a contract — Art. 6(1)(b) GDPR |
| Security of the Service, prevention of fraud and abuse, handling of blocks and reports, content moderation, including with automated tools | Legitimate interest in protecting users and the integrity of the Service — Art. 6(1)(f) GDPR |
| Profile verification and award of the "Verified" badge, at your request | Performance of a contract — Art. 6(1)(b) GDPR. Verification is optional. |
| Coin purchases; handling of refund requests submitted to the store | Performance of a contract — Art. 6(1)(b) GDPR; legitimate interest in preventing refund abuse — Art. 6(1)(f) GDPR |
| Crash and error reports, to detect and fix malfunctions | Legitimate interest in ensuring the operation and stability of the Service — Art. 6(1)(f) GDPR |
| Usage statistics, to understand how the Service is used and to improve it | Legitimate interest in improving the Service — Art. 6(1)(f) GDPR. Collection is kept to a minimum (section 2) and you can object at any time from Settings. |
| Email address verification and service communications | Performance of a contract — Art. 6(1)(b) GDPR |
| Replying to requests sent to the Service's contact addresses | Performance of a contract or pre-contractual steps — Art. 6(1)(b) GDPR; legitimate interest in handling communications — Art. 6(1)(f) GDPR; legal obligation for requests concerning your rights — Art. 6(1)(c) GDPR |
| Push notifications about messages and activity | Consent given through your device's operating system — Art. 6(1)(a) GDPR |
| Personalised advertising | Consent — Art. 6(1)(a) GDPR, which you can withdraw at any time |
| Compliance with legal obligations and responding to requests from authorities | Legal obligation — Art. 6(1)(c) GDPR |
Where processing is based on legitimate interest, we have assessed that this interest does not override your rights and freedoms; you can nonetheless object as described in section 10.
The Service does not use automated decision-making that produces legal effects concerning you or similarly significantly affects you. The order in which profiles are shown is a content presentation feature and is not of that nature.
The photos you upload to your profile are analysed automatically to detect explicit or violent content: those found to be such are removed. If you believe a removal was wrong, you can contest it using the moderation contact details in the Terms of Service: the decision will be reviewed by a person.
4. What other users can see
The following are visible to other registered users: your photos, name and username, your age and the zodiac sign derived from it, description, city, gender, interests, any linked gaming identifiers, the "Verified" badge if you obtain it, your online presence status, your room and your avatar's appearance. Text and voice messages you send in a room chat are seen, or heard live, by whoever is in the room at that moment. This is the very purpose of the app, and we encourage you to publish only what you are happy to make visible.
The following are never visible to other users: your email address, your password, your exact date of birth, your verification selfie, the detailed history of your virtual currency, your purchases, the reports you have sent and the blocks you have set.
The content of private conversations is accessible only to their participants. Remember, however, that the recipient may keep a copy by means outside the Service, over which we have no control.
5. Minimum age and protection of minors
The Service is reserved for people aged 18 or over. Your date of birth is requested at sign-up and cannot be changed afterwards. We do not knowingly process data of minors: if there are indications that an account belongs to a minor, the account is closed and its data deleted. If you believe a minor is using the Service, please let us know using the contact details in section 12.
6. Service providers and transfers outside the EU
To provide the Service and handle communications we use the providers listed below. When they process data on our behalf, they act as data processors under the applicable agreements; for any processing they carry out for their own purposes, they act in the roles described in their own privacy policies.
| Provider | Role |
|---|---|
| Google Ireland Ltd. / Google LLC — Firebase platform | Authentication, profile and content database, real-time database for presence and rooms, image storage, execution of the application logic, push notifications, hosting of the web version, crash reports (Crashlytics) and usage statistics (Google Analytics for Firebase). |
| Google Ireland Ltd. / Google LLC — Google Cloud Vision | Automated analysis of profile photos to detect explicit or violent content. Images are processed on our behalf only for the duration of the analysis. |
| Google Ireland Ltd. / Google LLC — AdMob | Serving and measuring advertising, subject to consent where required, and confirming that rewarded content has been viewed. |
| Apple Distribution International Ltd. — App Store; Google Ireland Ltd. — Google Play | Payment for in-app purchases and handling of refund requests, as independent controllers. They share with us only the data needed to verify a purchase; when a store asks us about a refund request, we send it the information described in the Terms of Service (section 7.4). |
| Plus Five Five, Inc. — Resend | Sending the transactional emails needed to manage your account, such as address verification and password recovery. |
| Cloudflare, Inc. — Email Routing | Forwarding emails sent to the public addresses of the wevospace.com domain. |
| Google Ireland Ltd. / Google LLC — Gmail | Receiving, storing and managing messages sent to the Service's public contact addresses. |
Data are hosted on infrastructure located in the European Union and in the United States. Transfers to third countries take place on the basis of the adequacy decision for the EU-U.S. Data Privacy Framework and, additionally and as a precaution, the standard contractual clauses adopted by the European Commission, supplemented by technical measures such as encryption in transit and at rest.
Apart from the providers listed above, your data are not disclosed to third parties, except where necessary to comply with a legal obligation, to respond to a lawful request from a judicial authority, or to establish, exercise or defend legal claims.
7. Advertising and device identifiers
The Service may show advertising, including rewarded content that you choose to watch. When you first open the app you are shown a consent form that lets you choose whether to accept personalised advertising, based on your device's advertising identifiers.
If you do not consent, you will still see ads, but they will not be personalised based on your advertising profile. You can change your choice at any time from the app's settings, and you can also reset or limit the advertising identifier from your device's settings.
The usage statistics described in section 2 do not use the advertising identifier, are not used to show you ads and are not passed to third parties for their own purposes.
The public website is purely informational: it does not allow you to create an account or access the Service and, at present, it does not use analytics, advertising cookies or other profiling tools.
8. Retention periods
| Data | Retention |
|---|---|
| Account, profile, photos, connections, conversations, room, virtual currency | For as long as the account exists. Deleted when the account is deleted. |
| Online presence and avatar position | Ephemeral data, removed when you leave the room or disconnect. |
| Text messages in room chats | Deleted automatically after 24 hours; the clean-up runs once a day, so at the latest within 48 hours. |
| Voice messages in rooms | Can only be heard live; deleted automatically within a few minutes. |
| Verification selfie | Until a decision is made on the request, then deleted. Only the outcome, i.e. the badge, remains for as long as the account exists. |
| Purchase records (transaction, product, coins credited, internal account identifier) | Also after the account is deleted, for as long as needed to handle refunds the store may notify later and to comply with accounting and tax obligations. |
| Crash reports | 90 days. |
| Usage statistics | Event-level data, 2 months; aggregated reports, which cannot be traced back to you, may be kept longer. |
| Push notification tokens | Until you revoke the permission, uninstall the app or delete your account. |
| Technical and security logs | A limited period, normally no longer than twelve months. |
| Moderation reports and measures taken | Up to twenty-four months, including after the account of the user concerned has been deleted, reduced to the minimum necessary, as a security record (legitimate interest) and to protect our rights in the event of a dispute. |
When an account is deleted, its data are removed from active systems without undue delay. Residual copies may remain in the infrastructure providers' backups for a technically limited period, after which they are overwritten.
9. Security measures
We take technical and organisational measures appropriate to the risk, including: encryption of communications in transit and of data at rest; storage of passwords entrusted to the authentication provider in non-reversible form that is not accessible to us; access rules that prevent a user from reading or changing another user's data; execution of sensitive operations — sending messages, virtual currency transactions, account deletion — exclusively in server-side logic that the app cannot alter; rate limits against automated use.
No system, however, is completely secure. In the event of a personal data breach likely to result in a high risk to your rights and freedoms, we will make the notifications required by Articles 33 and 34 GDPR.
10. Your rights
With regard to your personal data, you can exercise the rights provided by Articles 15–22 GDPR: access to your data and to information about the processing; rectification of inaccurate data; erasure; restriction of processing; portability in a structured, machine-readable format; objection to processing based on legitimate interest; withdrawal of consent at any time, for processing based on consent, without affecting the lawfulness of processing carried out before the withdrawal.
The quickest ways are inside the app:
- Edit or correct your data — from your profile screen;
- Withdraw advertising consent — from Settings → Account;
- Object to usage statistics and error reports — from Settings → Account → Usage statistics and diagnostics;
- Delete your account and its data — from Settings → Account → Delete account.
For any other request you can write to the contact details below: we reply within one month of receipt, extendable by two further months for particularly complex requests, in which case we will tell you the reasons for the delay. If you believe the processing breaches the law, you have the right to lodge a complaint with the Italian Data Protection Authority (Garante per la protezione dei dati personali, www.garanteprivacy.it) or with the supervisory authority of the country where you habitually reside.
11. Changes to this policy
This policy may be updated to reflect changes to the Service, to the providers used or to the legal framework. The current version is always published on this page, with its version number and effective date at the top of the document. Material changes are announced in the app with reasonable notice.
12. Data controller and contacts
The controller of the personal data collected through the Service is the natural person who currently runs Wevo as an individual, identified below pursuant to Article 13(1)(a) GDPR. No data protection officer has been appointed, as the conditions of Article 37 GDPR are not met.
- Data controller
- Diego Riccardi
- Contact for exercising your rights and any matter concerning personal data
- privacy@wevospace.com
- Website
- wevospace.com
When contacting us, please state the username associated with your account, so that we can correctly identify the data your request concerns. We may ask for further information where we have reasonable doubts about the requester's identity, pursuant to Article 12(6) GDPR.