Wandvo

← Back to Wandvo · Versión en español

Privacy Policy

Last updated: August 28, 2026

Wandvo ("we", "our", or "us") is operated from Puerto Rico, United States. This Privacy Policy explains how we collect, use, and protect your information when you use the Wandvo mobile application and website at wandvo.app.

By using Wandvo you agree to the collection and use of information as described in this policy.

1. Information We Collect

Account Information

Content You Create

Technical Information

Video & Audio

Video and audio during random video chats are transmitted peer-to-peer (WebRTC) directly between users: we do not record them, we do not store them, and we have no access to them. There is no continuous recording of your calls.

There is one exception, and we want to be precise about it. When someone presses the Report button during a video call, a single still image (one frame) of the video at that moment is captured and stored as evidence for the moderation team. No audio, no video, and nothing before or after that instant is captured.

Live stream clips: viewers of a live broadcast may record short clips (up to ~20 seconds) directly on their own device/browser. Wandvo does not store, host, or have access to these clips — the recording and any subsequent sharing to other apps happens entirely on the viewer's device, outside our servers.

2. How We Use Your Information

3. Third-Party Services

All of these act as data processors on Wandvo's behalf, under a data processing agreement and solely for the purposes described. Several are located in the United States: those transfers rely on the European Commission's Standard Contractual Clauses or on the Data Privacy Framework, depending on the provider. (Section revised on August 21, 2026.)

4. Data Sharing

We do not sell, rent, or trade your personal information to third parties. We may share data only:

5. Data Retention

Specific retention periods

These deletions are automatic: the system runs them daily; they do not depend on anyone remembering.

Kept longer, because the law requires it: payment and transaction records (tax and accounting obligations), child-safety incidents (18 U.S.C. § 2258A), and the moderation action log (so a decision can be justified if challenged). Your direct messages have no deletion deadline on our side: they are yours — you delete them, or they go with your account.

6. Age Verification and Child Safety

Wandvo is intended exclusively for users 18 years of age or older and excludes minors by design, not just by declaration: because we do not operate a service directed to children under 13 and do not knowingly collect their data, the federal COPPA statute is not, strictly speaking, the framework that applies to us — our real position is that we do not process children's data at all, and we still follow the same precautions that law would require as a matter of practice. We do not knowingly permit registration by users under 18 years of age. If we discover that a user is under 18, we will delete their account immediately. If you believe a minor has created an account, please contact us at support@wandvo.app.

We use automated image moderation on all uploaded content. Any suspected child sexual abuse material (CSAM) is immediately blocked and reported to NCMEC's CyberTipline pursuant to U.S. federal law (18 U.S.C. § 2258A), along with associated account and incident data. These incidents are retained as required by law and we cooperate fully with law enforcement.

7. Cookies and On-Device Storage

We do not use advertising or third-party tracking cookies, and we do not build advertising profiles. We use only what the app needs to work:

You can clear all of this at any time by signing out or clearing site data in your browser. (Section added 2026-08-19.)

8. Security

We implement industry-standard security measures including HTTPS encryption in transit, encryption at rest (AES-256) for our database, bcrypt password hashing, JWT authentication tokens, and rate limiting. However, no system is 100% secure and we cannot guarantee absolute security.

9. Your Rights

You have the right to:

To exercise any of these rights, write to us at support@wandvo.app. We respond within one month at most of receiving the request, extendable to three if it is particularly complex (we would tell you within the first month). To confirm you are who you say you are, it is enough for the request to come from the account's email address: we will never ask you for a copy of your ID document in order to handle a rights request.

10. Biometric Data and Facial Analysis

For your safety and content moderation, the app may run face detection on your device (for example, to confirm a person is in front of the camera). That processing happens locally on your device and in real time: it does not generate biometric templates and never leaves your device. Moderation of uploaded images is performed by our provider Sightengine on the content you post, not on a biometric profile. We never use facial recognition to identify you, and we do not sell or disclose biometric data to third parties.

Age check by selfie

Separately from the above, if you choose to verify your age by taking a selfie, that image does leave your device: it is sent to our age-estimation provider, which computes an approximate age from the face and returns a number to us. This process is designed to satisfy biometric-privacy laws such as Illinois' BIPA or Texas' CUBI on their own substantive terms — prior written notice, written consent, no sale, and prompt destruction — not merely because estimating an age differs from identifying a person. To be precise about what happens to the image:

(Section added 2026-08-19, expanded 2026-08-20 with the age check.)

11. International Users (EEA, UK) and Legal Bases

Legal basis for processing (GDPR/UK GDPR, Art. 6): we process your data to (a) perform our contract with you (creating and operating your account, processing purchases and payouts); (b) our legitimate interests in keeping the platform safe (moderation, fraud and abuse prevention, security); (c) compliance with legal obligations (tax, child safety, responding to law enforcement); and (d) your consent where applicable. You can withdraw consent at any time.

International transfers: our providers (Supabase, Stripe, Google, Sightengine) may process data in the United States or other countries. When we transfer data outside the EEA/UK, we rely on those providers' safeguards (Standard Contractual Clauses or other valid mechanisms). You may request a copy of the applicable clauses or safeguards by writing to support@wandvo.app.

Breach notification: if a security breach affecting your personal data occurs, we will notify the competent supervisory authority and affected users where required by law (under the GDPR, the authority within 72 hours of becoming aware), without undue delay.

Representative and contact: to exercise your rights or for privacy inquiries, contact us at support@wandvo.app. (Section added 2026-08-19.)

Asia-Pacific Users

If you reside in Japan, the purpose of use for your personal data is specified in Section 2 of this policy ("How We Use Your Information"), as required by the Act on the Protection of Personal Information (APPI). If you reside in South Korea, we ask for your separate, specific consent to the international transfer of your data — a PIPA requirement with no GDPR equivalent — before your data leaves the country. In both cases, neither Japan nor South Korea recognize "legitimate interest" as a general processing basis equivalent to GDPR Art. 6(1)(f); for users in those jurisdictions we rely on your consent or on performance of our contract with you. If you reside in India, you may read this policy in English and, where available among the app's languages, in the languages listed in the Eighth Schedule of the Indian Constitution.

Americas Users

If you reside in Mexico, you have the right to Access, Rectify, Cancel, and Object (ARCO rights) to the data we process about you — the same rights described in Section 9 of this policy — and we ask for your express consent for sensitive data, such as the identity document collected during creator KYC verification. If you reside in Brazil, you may contact us in Portuguese about the processing of your data under the Lei Geral de Proteção de Dados (LGPD); due to our size ("pequeno porte"), we are not required to appoint a formal Data Protection Officer. If you reside in Canada, in the event of a security breach with a real risk of significant harm we will notify the Office of the Privacy Commissioner of Canada (OPC), and we keep an internal record of all security breaches, whether reported or not, retained for 24 months, as required by PIPEDA. If you reside in Quebec, the person responsible for the protection of your information is Wandvo's owner (reachable at support@wandvo.app), and we ask for your express, separate consent for the biometric data Stripe Identity processes when verifying your identity as a creator, as required by Law 25.

Breach Notification Timelines by Country

If a security breach affects your data, these are the timelines we follow by country, so we don't have to improvise them the day it happens:

(Section expanded 2026-08-23.)

12. Governing Law

This Privacy Policy is governed by the laws of the Commonwealth of Puerto Rico and the United States of America. Any disputes shall be resolved in the courts of Puerto Rico.

13. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify users of significant changes via the app or email. Continued use of Wandvo after changes constitutes acceptance of the updated policy.

14. Contact Us

If you have questions about this Privacy Policy, contact us at:
📧 support@wandvo.app
🌐 wandvo.app