← Back to Wandvo · Versión en español
Privacy Policy
Last updated: August 28, 2026
Wandvo ("we", "our", or "us") is operated from Puerto Rico, United States. This Privacy Policy explains how we collect, use, and protect your information when you use the Wandvo mobile application and website at wandvo.app.
By using Wandvo you agree to the collection and use of information as described in this policy.
1. Information We Collect
Account Information
- Username, email address, and password (stored as a bcrypt hash — we never store plain-text passwords)
- Country, age, bio, and interests you add to your profile
- Profile photo (stored as an image on our servers)
- Google account ID and public profile photo if you sign in with Google
Content You Create
- Posts, photos, and comments you publish
- Direct messages sent to mutual friends
- Live stream sessions (title, category, duration)
- Virtual gifts sent and received
Technical Information
- IP address — used for rate limiting, approximate country-level geolocation, and abuse prevention. It is generally not retained, with three exceptions that are stored: the IP of whoever submits a report (to detect false-reporting campaigns; deleted after 90 days), a hashed fingerprint of the IP when joining the waiting list (to prevent automated sign-ups), and the IP recorded when accepting the Creator Agreement (proof of acceptance, as payment regulations require).
- Device type and operating system (sent by your browser/app)
- Session tokens (JWT) stored locally on your device
Video & Audio
Video and audio during random video chats are transmitted peer-to-peer (WebRTC) directly between users: we do not record them, we do not store them, and we have no access to them. There is no continuous recording of your calls.
There is one exception, and we want to be precise about it. When someone presses the Report button during a video call, a single still image (one frame) of the video at that moment is captured and stored as evidence for the moderation team. No audio, no video, and nothing before or after that instant is captured.
- Purpose: to let a human moderator see what actually happened, instead of deciding blindly on one person's word against another's.
- Legal basis: legitimate interest in platform safety (GDPR Art. 6(1)(f)) and, where child sexual abuse material is involved, compliance with a legal obligation (GDPR Art. 6(1)(c) and 18 U.S.C. § 2258A).
- Who can see it: only moderation staff with two-factor authentication enabled and explicit permission for the reports section. Every access is logged.
- How long we keep it: the frame is automatically deleted after 90 days. The report record itself (who reported whom and why, without the image) is kept so we can detect repeat offenders.
- If you were reported: you may request access to that image and its deletion by writing to support@wandvo.app, unless it relates to an ongoing investigation or a case we are legally required to retain.
Live stream clips: viewers of a live broadcast may record short clips (up to ~20 seconds) directly on their own device/browser. Wandvo does not store, host, or have access to these clips — the recording and any subsequent sharing to other apps happens entirely on the viewer's device, outside our servers.
2. How We Use Your Information
- To create and manage your account
- To match you with other users for video chat
- To display your profile to other users
- To send 2-factor authentication codes via email
- To process virtual coin transactions and creator earnings
- To moderate content and enforce Community Guidelines
- To respond to reports and handle account issues
- To improve the app and fix technical issues
3. Third-Party Services
- Supabase — database hosting (PostgreSQL). Your data is stored on Supabase servers. Supabase Privacy Policy
- Google OAuth 2.0 — optional sign-in with Google. Google Privacy Policy
- Sightengine (France) — automated image moderation to detect inappropriate content. It is applied to photos you upload and also to frames sampled during live broadcasts, which is what allows us to cut off a stream with prohibited content immediately. Images are sent to Sightengine for analysis and are not stored by them. Sightengine Privacy Policy
- Human review of live broadcasts (added 2026-08-23). While you are broadcasting live, the most recent of those frames is made available to our moderation team in the administration panel, so that a person can check anything an automated system has flagged before a decision is made about your account. That frame is held in server memory only: it is replaced by the next one every ~30 seconds, is not written to the database or to disk, is not sent to third parties, and disappears as soon as your broadcast ends. Only administration accounts with live-moderation permission can view it. We do not record or retain your broadcasts.
- Random video chat moderation (added 2026-08-23). During a random video call, a frame is sampled roughly every 30 seconds and sent to Sightengine to detect nudity or content involving minors. For safety reasons, the frame analysed is captured by the other person's device, not yours: this prevents someone showing prohibited content from disabling their own supervision. If prohibited content is detected, the call is ended for both parties immediately. These frames are not stored — they are sent for analysis and discarded. Wandvo does not record video calls, and the server never sees the video: the call travels encrypted and directly between the two devices.
- Didit (age-estimation provider) — when you choose to verify your age with a selfie, the image is sent to a specialist provider that computes an approximate age and returns only that result to us. Wandvo does not retain the image, and the provider deletes it after analysis. See "Biometric data and facial analysis".
- Stripe — payment processor for coin and subscription purchases (Stripe Checkout), identity and age verification for creators who monetize (Stripe Identity), and creator payouts (Stripe Connect). Your card number, ID document, verification selfie, and the bank/tax information required to receive payouts are sent directly to Stripe and processed under its own privacy policy — Wandvo does not receive or store your ID document, your selfie, your full card number, or your bank account details. Stripe Privacy Policy
- STUN/TURN servers (metered.ca, Canada) — used to establish peer-to-peer video connections. They see connection metadata (network addresses) in order to route the call, but they do not see or store the content of your video or audio.
- Railway (USA) — hosting for the application server. All app traffic passes through their infrastructure.
- Vercel (USA) — hosting for the website and the in-browser application. Records technical access logs (IP, user agent) for a short period.
- Sentry (USA) — error reporting so we can fix bugs. It is configured not to send IP addresses, cookies, session headers, or request bodies.
- Anthropic (USA) — machine translation and conversational assistants. This deserves a plain sentence: if you press the translate button on a direct message, a post, or a room chat, that text is sent to Anthropic to be translated. This happens only when you explicitly ask for it; messages are never sent automatically or in the background.
- Resend (USA) — delivery of transactional email: account confirmation, password resets, and waiting-list notices. It receives your email address and the message content.
All of these act as data processors on Wandvo's behalf, under a data processing agreement and solely for the purposes described. Several are located in the United States: those transfers rely on the European Commission's Standard Contractual Clauses or on the Data Privacy Framework, depending on the provider. (Section revised on August 21, 2026.)
4. Data Sharing
We do not sell, rent, or trade your personal information to third parties. We may share data only:
- With service providers listed above (only as needed to operate the app)
- When required by law or valid legal process
- To protect the safety of our users or the public
- With the National Center for Missing & Exploited Children (NCMEC) and law enforcement: pursuant to U.S. federal law (18 U.S.C. § 2258A), we report all suspected child sexual exploitation material detected on the platform, including incident and account data
5. Data Retention
- Your account data is retained as long as your account is active
- Deleted posts and messages are removed from our database immediately
- When you delete your account, your personal data is permanently deleted within 30 days, except information we are legally required to retain: transaction and payment records (for tax, accounting, and fraud/anti-money-laundering obligations), child-safety incident records (as required by federal law), and information needed to resolve disputes or enforce our agreements. Such information is kept only for as long as required and then deleted.
- You can request account deletion from within the app (Settings → Account) or from our web deletion request page, without needing the app installed.
Specific retention periods
These deletions are automatic: the system runs them daily; they do not depend on anyone remembering.
- Frame captured when reporting — 90 days. After that the image is deleted and the report record is kept without it.
- IP address of whoever submits a report — 90 days.
- Waiting-list emails that were never confirmed — 180 days.
- Live stream chat messages — 30 days.
- Profile visit records — 90 days (the app only ever shows the last 30).
- Deleted account — 30 days from the request, cancellable during that window. Your files (photos, voice notes) are deleted too.
Kept longer, because the law requires it: payment and transaction records (tax and accounting obligations), child-safety incidents (18 U.S.C. § 2258A), and the moderation action log (so a decision can be justified if challenged). Your direct messages have no deletion deadline on our side: they are yours — you delete them, or they go with your account.
6. Age Verification and Child Safety
Wandvo is intended exclusively for users 18 years of age or older and excludes minors by design, not just by declaration: because we do not operate a service directed to children under 13 and do not knowingly collect their data, the federal COPPA statute is not, strictly speaking, the framework that applies to us — our real position is that we do not process children's data at all, and we still follow the same precautions that law would require as a matter of practice. We do not knowingly permit registration by users under 18 years of age. If we discover that a user is under 18, we will delete their account immediately. If you believe a minor has created an account, please contact us at support@wandvo.app.
We use automated image moderation on all uploaded content. Any suspected child sexual abuse material (CSAM) is immediately blocked and reported to NCMEC's CyberTipline pursuant to U.S. federal law (18 U.S.C. § 2258A), along with associated account and incident data. These incidents are retained as required by law and we cooperate fully with law enforcement.
7. Cookies and On-Device Storage
We do not use advertising or third-party tracking cookies, and we do not build advertising profiles. We use only what the app needs to work:
- A session cookie (HttpOnly) to keep you securely signed in.
- Browser local storage for your session token (if you choose "remember me"), your language, your app preferences, and interface data such as your daily streak.
You can clear all of this at any time by signing out or clearing site data in your browser. (Section added 2026-08-19.)
8. Security
We implement industry-standard security measures including HTTPS encryption in transit, encryption at rest (AES-256) for our database, bcrypt password hashing, JWT authentication tokens, and rate limiting. However, no system is 100% secure and we cannot guarantee absolute security.
9. Your Rights
You have the right to:
- Access (Art. 15) — request a copy of your personal data. You can download it yourself from the app, without asking us.
- Rectification (Art. 16) — correct inaccurate information from your profile settings.
- Erasure (Art. 17) — request deletion of your account and your data.
- Portability (Art. 20) — receive your data in a machine-readable format.
- Objection (Art. 21) — object to processing we carry out on the basis of legitimate interest, such as abuse detection. We will assess it case by case and tell you the outcome.
- Restriction (Art. 18) — ask us to freeze the use of your data while a complaint or a correction is being resolved.
- Automated decisions (Art. 22) — automated moderation can block content or restrict an account without prior human involvement. You have the right to request human review, to state your case, and to contest the decision by writing to us.
- Complaint to a supervisory authority (Art. 77) — if you believe we have not respected your rights, you may lodge a complaint with the data protection authority of your country of residence. We would like you to write to us first, but you do not need our permission.
To exercise any of these rights, write to us at support@wandvo.app. We respond within one month at most of receiving the request, extendable to three if it is particularly complex (we would tell you within the first month). To confirm you are who you say you are, it is enough for the request to come from the account's email address: we will never ask you for a copy of your ID document in order to handle a rights request.
10. Biometric Data and Facial Analysis
For your safety and content moderation, the app may run face detection on your device (for example, to confirm a person is in front of the camera). That processing happens locally on your device and in real time: it does not generate biometric templates and never leaves your device. Moderation of uploaded images is performed by our provider Sightengine on the content you post, not on a biometric profile. We never use facial recognition to identify you, and we do not sell or disclose biometric data to third parties.
Age check by selfie
Separately from the above, if you choose to verify your age by taking a selfie, that image does leave your device: it is sent to our age-estimation provider, which computes an approximate age from the face and returns a number to us. This process is designed to satisfy biometric-privacy laws such as Illinois' BIPA or Texas' CUBI on their own substantive terms — prior written notice, written consent, no sale, and prompt destruction — not merely because estimating an age differs from identifying a person. To be precise about what happens to the image:
- It is optional and requires your express permission. Before anything is sent, we ask you to tick a checkbox specifically for this. If you prefer not to, you can verify your age with an official ID document through Stripe Identity, and that route works exactly the same.
- We do not keep the photo. It is sent to the provider and discarded within the same request: it is never written to disk, never stored in our database, and never appears in our logs. The provider deletes it after analysis.
- All we retain is the outcome (approved / ID document needed), the estimated age, the method used, and the date. Never the image, and never a facial template.
- Estimation is not identification. The analysis computes an approximate age; it does not create a faceprint that could recognise you later, and it is not compared against any database of people.
- Legal basis: compliance with a legal obligation regarding child protection and age assurance, together with your express consent to process the image.
- If you reside in Illinois or Texas, or another state with a specific biometric data law, this paragraph is the prior written notice and the checkbox is your written consent; you may use the ID document route and never submit a selfie.
(Section added 2026-08-19, expanded 2026-08-20 with the age check.)
11. International Users (EEA, UK) and Legal Bases
Legal basis for processing (GDPR/UK GDPR, Art. 6): we process your data to (a) perform our contract with you (creating and operating your account, processing purchases and payouts); (b) our legitimate interests in keeping the platform safe (moderation, fraud and abuse prevention, security); (c) compliance with legal obligations (tax, child safety, responding to law enforcement); and (d) your consent where applicable. You can withdraw consent at any time.
International transfers: our providers (Supabase, Stripe, Google, Sightengine) may process data in the United States or other countries. When we transfer data outside the EEA/UK, we rely on those providers' safeguards (Standard Contractual Clauses or other valid mechanisms). You may request a copy of the applicable clauses or safeguards by writing to support@wandvo.app.
Breach notification: if a security breach affecting your personal data occurs, we will notify the competent supervisory authority and affected users where required by law (under the GDPR, the authority within 72 hours of becoming aware), without undue delay.
Representative and contact: to exercise your rights or for privacy inquiries, contact us at support@wandvo.app. (Section added 2026-08-19.)
Asia-Pacific Users
If you reside in Japan, the purpose of use for your personal data is specified in Section 2 of this policy ("How We Use Your Information"), as required by the Act on the Protection of Personal Information (APPI). If you reside in South Korea, we ask for your separate, specific consent to the international transfer of your data — a PIPA requirement with no GDPR equivalent — before your data leaves the country. In both cases, neither Japan nor South Korea recognize "legitimate interest" as a general processing basis equivalent to GDPR Art. 6(1)(f); for users in those jurisdictions we rely on your consent or on performance of our contract with you. If you reside in India, you may read this policy in English and, where available among the app's languages, in the languages listed in the Eighth Schedule of the Indian Constitution.
Americas Users
If you reside in Mexico, you have the right to Access, Rectify, Cancel, and Object (ARCO rights) to the data we process about you — the same rights described in Section 9 of this policy — and we ask for your express consent for sensitive data, such as the identity document collected during creator KYC verification. If you reside in Brazil, you may contact us in Portuguese about the processing of your data under the Lei Geral de Proteção de Dados (LGPD); due to our size ("pequeno porte"), we are not required to appoint a formal Data Protection Officer. If you reside in Canada, in the event of a security breach with a real risk of significant harm we will notify the Office of the Privacy Commissioner of Canada (OPC), and we keep an internal record of all security breaches, whether reported or not, retained for 24 months, as required by PIPEDA. If you reside in Quebec, the person responsible for the protection of your information is Wandvo's owner (reachable at support@wandvo.app), and we ask for your express, separate consent for the biometric data Stripe Identity processes when verifying your identity as a creator, as required by Law 25.
Breach Notification Timelines by Country
If a security breach affects your data, these are the timelines we follow by country, so we don't have to improvise them the day it happens:
- European Union: to the supervisory authority, within 72 hours of becoming aware (GDPR Art. 33).
- Japan: to the Personal Information Protection Commission (PPC), when the breach affects sensitive data or more than 1,000 people.
- Brazil: to the Autoridade Nacional de Proteção de Dados (ANPD), within a reasonable time.
- Canada: to the Office of the Privacy Commissioner (OPC), where there is a real risk of significant harm.
- India: to India's Data Protection Board, under the DPDP Act.
(Section expanded 2026-08-23.)
12. Governing Law
This Privacy Policy is governed by the laws of the Commonwealth of Puerto Rico and the United States of America. Any disputes shall be resolved in the courts of Puerto Rico.
13. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify users of significant changes via the app or email. Continued use of Wandvo after changes constitutes acceptance of the updated policy.
14. Contact Us
If you have questions about this Privacy Policy, contact us at:
📧 support@wandvo.app
🌐 wandvo.app