Privacy Policy

Last updated: August 3, 2026

The short version

Mood entries are stored on your device by default. Cloud sync is optional, and you can turn on end-to-end encryption so your mood entries and health data are encrypted on your device before they sync — we store only an unreadable blob. Without encryption enabled, synced entries remain readable to Vibbrancy. Account, subscription, diagnostic, support, and optional product-improvement data are described below. Vibbrancy does not sell mood entries or use them for advertising.

1. Introduction

Vibbrancy ("we," "our," or "us") is operated from Level 3/162 Collins St, Melbourne VIC 3000, Australia. We are committed to protecting your privacy. This Privacy Policy explains how we collect, use, store, and safeguard your information when you use our mobile application, website, and related services (collectively, the "Service").

By using the Service, you agree to the collection and use of information in accordance with this policy. If you do not agree, please do not use the Service.

2. Our Privacy Promise

You choose how your mood entries are stored. They stay on your device by default; optional account, sync, diagnostic, and product-improvement services are described below so you can decide which features to use.

  • On-device insight processing: Supported sentiment and entity analysis of journal entries runs on your device. Optional sync and other connected features are described separately below.
  • No advertising profile: Vibbrancy does not use mood entries to build an advertising profile or sell advertising space in the app.
  • Mood entries are not sold: Vibbrancy does not sell mood entries or share them with third parties for those parties' marketing purposes. Service providers used to operate the app are listed below.
  • Subscription-funded features: Complete subscriptions fund paid features and continued product development.

3. Data We Collect

3.1 Account Information

When you create an account, we collect your email address (for authentication and account recovery), an optional display name, and a securely hashed password. If you sign in via Google or Apple, we receive your name and email from the identity provider.

3.2 Mood & Wellness Data

By default, all mood entries are stored locally on your device only using IndexedDB and are never transmitted to our servers. If you enable Cloud Backup, your mood ratings, notes, activities, emotions, and physical symptoms are synced to our encrypted servers. You can disable Cloud Backup at any time in Settings.

3.3 Health Data (Optional)

If you enable Apple Health or Google Health Connect integrations, we requestread-only access to health signals such as steps, sleep, heart rate, workouts, and other metrics you choose to share. Vibbrancy can display those signals alongside mood history as context for correlation-aware review; a correlation does not establish a cause or diagnosis.

Health data is first cached locally on your device for offline access and analysis. If you use cloud-backed account features, encrypted copies of synced health samples and daily summaries may also be stored on our servers so they can sync across your devices. We do not write data back to Apple Health or Health Connect, we do not sell it, and we do not share it with advertisers.

3.4 Product Improvement Metrics (Optional)

A separate control called Share Product Improvement Metrics is off by default. If you turn it on, Vibbrancy can send a delayed batch containing only whether you completed your first check-in, completed your third check-in, or opened Mood Garden after a check-in, together with your platform, app version, and install week. The batch does not contain mood ratings, notes, emotions, health data, account details, exact event times, advertising or device identifiers, campaign labels, or precise location.

Authentication is used transiently for abuse prevention but is not stored with a batch. Ordinary hosting and network infrastructure processes connection metadata when delivering the request. You can withdraw at any time to stop queued and future batches. Because stored rows are not linked to an account, we cannot locate a prior row by account for deletion.

3.5 Location (Not Collected)

Vibbrancy does not receive or store your location. It is used only to make two features work, and it stays on your device.

  • What it's for: comparing your mood with local weather and daylight hours, and showing crisis helpline numbers for the right country.
  • Where it lives: on your device, in the app's own storage. It is excluded from account sync, and our servers strip it if any older version of the app sends it.
  • The iOS and Android apps cannot read your device location at all. They do not request the location permission, so there is nothing to grant or revoke. You choose a city yourself if you want weather features.
  • Weather and place lookups go direct from your phone. When you use those features, the coordinates for your chosen city are sent from your device straight to the weather and geocoding providers (Open-Meteo, and OpenStreetMap's Nominatim or BigDataCloud for place names). Those requests do not pass through Vibbrancy, and we never see them. Each provider handles requests under its own privacy policy.

4. How We Use Your Data

  • Account management: To authenticate you, manage your account, and send account-related emails (password resets, security alerts).
  • Service delivery: To provide mood tracking features and sync data across your devices (if enabled).
  • Health context: To display optional health signals such as sleep, activity, and heart rate alongside mood history for correlation-aware review.
  • Subscription management: To process payments and manage your subscription through our payment processors.
  • Customer support: To identify you and resolve issues when you contact support.
  • Diagnostics, aggregate store reports, and optional product metrics: To fix errors, evaluate aggregate app-store acquisition trends, and—only with separate consent—count coarse product milestones. Vibbrancy does not use Firebase Analytics or default-on behavioural event tracking.
  • Marketing (opt-in only): To send product updates and tips only if you explicitly opt in. You can unsubscribe at any time.

5. Third-Party Data Processors

We do not sell your personal data. We share data with the following categories of processors, each bound by data processing agreements:

  • Subscription & billing (RevenueCat): Your email address and display name are shared with RevenueCat, our subscription management processor, to manage billing and provide customer support. RevenueCat processes this data under their Data Processing Addendum. No mood or health data is shared.
  • Cloud hosting (Railway, PostgreSQL): Encrypted account and mood data (if Cloud Backup is enabled) is stored on our hosting infrastructure.
  • Email delivery: Transactional email services for account-related notifications.
  • App stores (Apple App Store, Google Play): Subscription purchases are processed by the respective app store. Store links can include allowlisted campaign labels or, when the browser provides a recognised search-engine referrer, only the engine name and an organic label. We do not put search queries, mood entries, journal text, or a Vibbrancy account identifier in those links. Apple and Google can provide aggregate acquisition reports under their own privacy terms. We do not handle payment card details directly.

6. Legal Basis for Processing (GDPR)

If you are located in the European Economic Area (EEA), United Kingdom, or Switzerland, we process your data under the following legal bases:

  • Contract (Art. 6(1)(b)): Account data, mood data sync, and subscription management — necessary to provide the Service you signed up for.
  • Legitimate interest (Art. 6(1)(f)): Sharing email/display name with our subscription processor for customer support; diagnostic and security monitoring; and aggregate app-store acquisition reporting.
  • Consent (Art. 6(1)(a)): Marketing communications (opt-in); optional health data integrations; and optional product-improvement milestone batches.

7. Your Rights

Regardless of your location, you have the following rights:

  • Access: Request a copy of all data we hold about you.
  • Rectification: Update incorrect personal information via Settings or by contacting us.
  • Erasure: Delete your account and all associated data. Local data is deleted immediately; cloud data is permanently purged within 30 days.
  • Data portability: Export your mood data in JSON or CSV format from Settings.
  • Withdraw consent: Disable Cloud Backup, health integrations, marketing emails, or product-improvement metrics at any time.
  • Restriction / Objection: Request restriction of processing or object to processing based on legitimate interest.
  • Lodge a complaint: You may lodge a complaint with a supervisory authority in your jurisdiction (for Australian residents: the OAIC).

To exercise these rights, use the in-app Settings or email us. We will respond within 30 days.

8. Data Security

Vibbrancy uses HTTPS for network traffic, bcrypt password hashing, and JWT-based authentication. Synced data is encrypted in transit and at rest on our infrastructure. If you additionally enable end-to-end encryption, your mood entries and health data are encrypted on your device with a key we never receive, so we cannot read them at all; without it, synced entries remain readable to Vibbrancy. No system is completely secure, and the safeguards that apply depend on the features you choose.

9. Data Retention

  • Account data: Retained until you delete your account.
  • Mood data (cloud): Retained until you delete individual entries or your account.
  • Mood data (local): Remains on your device until you clear app data or uninstall.
  • Deleted accounts: All cloud data permanently purged within 30 days of deletion request.
  • RevenueCat attributes: Cleared from RevenueCat upon account deletion.
  • Product-improvement batches: Raw unlinked rows are retained for no more than 90 days, then only platform, app-version, install-week cohort totals are kept. Reports suppress cohorts with fewer than five batches.

10. International Data Transfers

Our servers and some processors are located outside Australia and the EEA. Where data is transferred internationally, we ensure appropriate safeguards are in place, including standard contractual clauses and processor data processing agreements.

11. Children's Privacy

The Service is not intended for children under 13 (or 16 in the EEA). We do not knowingly collect personal information from children. If you believe we have collected information from a child, please contact us immediately and we will delete it.

12. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by email or through the application and update the "Last updated" date. Continued use of the Service after changes constitutes acceptance of the revised policy.

13. Contact Us

If you have questions about this Privacy Policy or wish to exercise your rights, contact us at:

Vibbrancy
Level 3/162 Collins St
Melbourne VIC 3000, Australia
Email: privacy@vibbrancy.app
Response time: Within 30 days