VibeFlow Privacy Policy
Effective date: 14 August 2026 · Last updated: 14 August 2026
This Privacy Policy describes how VibeFlow (“VibeFlow”, “we”, “us”) collects, uses,
discloses and protects your information when you use the VibeFlow website at sxagg.com and the
VibeFlow mobile application, and explains your privacy rights. By using the Service you agree to the
collection and use of information in accordance with this Policy.
1. Personal data we collect
While using our Service we may ask you to provide certain personally identifiable information that can
be used to contact or identify you. This data is used to provide and improve the Service.
- Account and profile data — name, email address, profile photo and the account identifier from the login provider you used.
- Content you create — posts, comments, stories, messages, media you upload, and any optional place tag you attach to them.
- Location data — see section 4, which describes this in full.
- Usage and device data — app version, device model, operating system version, and diagnostic logs used to keep the Service running.
2. Information from third-party social media services
The Service lets you sign in with an existing social media account.
- Supported third-party login providers include Facebook, Instagram and Google.
- If you grant us permission, we may collect personal data already associated with your social media account — such as your name, email address, activity data and analytics associated with that account.
3. Tracking technologies and cookies
- Cookies or browser cookies: a small file placed on your device. You can refuse all cookies in your browser settings, though this may affect Service functionality.
- Purpose: cookies let us remember your preferences and login details so you do not have to re-enter information on every visit.
4. Location Data
The VibeFlow mobile app collects and uses device location. Every location feature is
optional and off until you turn it on, and the app remains fully usable if you never grant the
permission. This section states exactly what is collected, why, who it is shared with, how long we keep
it, and how to switch it off.
4.1 What we collect
- Approximate location (network-based,
ACCESS_COARSE_LOCATION).
- Precise location (GPS-level,
ACCESS_FINE_LOCATION).
- Background location (
ACCESS_BACKGROUND_LOCATION together with a location foreground service) — collected only if you separately choose the “Always allow” sharing mode described in 4.2.
Location is read only while you are using one of the features below, and only after you have granted the
Android location permission.
4.2 Sharing your location with friends (Friends map)
- Location sharing is off by default. When you turn it on, your current coordinates and a coarse place label (for example “Petaling Jaya, Malaysia”) are stored on our servers.
- Your position is shown only to your mutual follows — people you follow who also follow you back. It is shown to nobody while sharing is off. This rule is enforced on our servers, not only in the app.
- “While using the app” mode (the default): your position is refreshed when you open the app or the map.
- “Always allow” mode (background location): your position is updated in the background roughly every 2 minutes, or after about 150 metres of movement. This mode is separately opt-in, and while it is running Android displays a permanent notification reading “Location sharing on”. You can return to “While using the app” at any time.
- Restricted areas: you can define up to 10 zones (for example home or workplace). While you are inside one, your position is hidden from everyone. This is applied on our servers, so it holds even if the app is out of date.
- Retention: we store only your most recent position — each update overwrites the previous one; we do not build a location history from it. A stored position stops being shared with anyone once it is more than 7 days old.
4.3 Place tags on posts and stories
- Adding a place to a post or story is optional and happens only when you choose it while composing.
- A place tag is stored with that content and is visible to everyone who can see the content.
- A story tagged with a place also appears on VibeFlow's story map, which is visible to all signed-in VibeFlow users for as long as the story is live (24 or 48 hours, as you chose when posting).
- Deleting the post or story removes the place tag with it.
4.4 Community rides
- When you request a ride, your pickup coordinates and your chosen destination are stored with the ride request and shown to drivers browsing nearby open requests.
- Once a ride is confirmed, and until it is completed or cancelled, your position is sent approximately every 12 seconds and shown to the other party on the trip map so you can see each other approaching. This stops as soon as the ride ends.
- Pickup and destination coordinates remain attached to the ride record as part of your trip history.
4.5 Choosing your content region
- A one-off, optional approximate reading, matched to the nearest supported region, so the app can show content relevant to where you are.
- The result is saved on your device only. These coordinates are not transmitted to our servers.
4.6 Who your location is shared with
- Other VibeFlow users, only as described above: your mutual follows on the friends map, anyone who can see content you place-tagged, and your counterparty during an active ride.
- Mapbox — we send coordinates to Mapbox to convert them into a place name, to search for destinations, and to calculate driving routes and estimated arrival times. Mapbox processes them under its own privacy policy.
- We do not sell your location data, do not share it with data brokers, and do not use it for advertising, profiling or any purpose unrelated to the features above.
4.7 Your controls
- Turn the sharing toggle off on the Friends map. Your pin disappears from every friend's map immediately and no further positions are collected.
- Choose “While using the app” instead of “Always allow” to end all background collection.
- Add restricted areas to keep chosen places permanently hidden.
- Revoke the permission at any time in Android Settings › Apps › VibeFlow › Permissions › Location. The rest of the app continues to work.
- Delete a post or story to remove the place tag attached to it.
- To have the location data we hold about you erased, email support@sxagg.com and we will action your request within 30 days.
5. How we use your personal data
- To provide and maintain our Service, including monitoring usage patterns and system health.
- To manage your account: registering you as a user and granting access to Service functionality.
- To contact you: by email, telephone, SMS or push notification about updates, security alerts and other important communications.
- To manage your requests: handling and responding to enquiries and support tickets.
- For other purposes: data analysis, identifying usage trends, evaluating promotional campaigns, and improving the Service.
6. AI moderation and third-party processing
- To provide AI moderation, submitted content is processed by third-party AI providers including OpenAI and DeepInfra (which hosts Meta Llama 4 Scout).
- Content is transmitted to these providers solely for moderation screening and is not retained by them on our behalf beyond the processing window.
- Mapbox processes location coordinates for the map, search and directions features described in section 4.
- Google Firebase Cloud Messaging processes a device token in order to deliver push notifications.
- VibeFlow does not sell submission content or personal data to any third party.
7. Security of your personal data
The security of your personal data is important to us. However, no method of internet transmission or
electronic storage is 100% secure. While we strive to use commercially acceptable means to protect your
personal data, we cannot guarantee absolute security.
8. Links to other websites
Our Service may contain links to third-party websites that we do not operate. If you click a third-party
link you will be directed to that site. We strongly advise you to review the privacy policy of every site
you visit, as we have no control over and assume no responsibility for their content or practices.
9. Deleting your account and data
- Log in to your account using your credentials.
- Go to sxagg.com/login and find the account deletion button in the navigation bar.
- Select the option to delete your account or request data deletion.
- Follow the prompts to confirm your deletion request.
You may also email support@sxagg.com from your registered address to request deletion
of your account or of a specific category of data, including location data.
10. Contact us
Questions about this Policy can be sent to support@sxagg.com, or through the
Contact Us page. See also our
Terms & Conditions.