← Home

Privacy Policy

GDPR information notice and Turkish KVKK disclosure · Effective date: 29 July 2026 · Version 1.1

This policy explains which personal data the VIBERO mobile app and viberoapp.com (the "Service") process, why and on what legal basis, who we share it with, and how you can exercise your rights. It is written to satisfy Articles 13–14 of the EU General Data Protection Regulation ("GDPR") and Article 10 of the Turkish Personal Data Protection Law No. 6698 ("KVKK") together.

1. Controller and contact

Controller: Ali Burak Baraç (developer of the VIBERO app).
Contact and data subject request channel: support@viberoapp.com

We respond to requests free of charge and within 30 days. Please state your request clearly and include enough information for us to verify your identity.

2. What we process and why

We process only what the Service needs to work. We do not profile you for advertising.

  • Identity and account data: name, username, email address and your account identifier. When you sign in with Apple or Google we receive only what is needed to create your account. Purpose: creating and securing your account.
  • Profile photo: if you choose to set one, the image is uploaded to and stored on our servers (in the European Union, see section 6), because other players need to see it next to your name. Purpose: recognising each other in matches, listings and rankings. A profile photo is optional — without one we show your initials. It is readable by signed-in users of the Service, not by the open internet, and it is deleted when you delete your account. Note that this is the only image the app uploads; see “Data that never leaves your device” below.
  • Date of birth: collected once during onboarding to confirm you meet the 18+ age requirement (see section 13). Purpose: age verification. It is never shown to other users and is not readable by them.
  • Sport data: the matches, scores, tournaments and attendance records you create, and the statistics and level calculated from them. Purpose: the core function of the Service. Your level is calculated from matches you play; it is not self-declared.
  • Location: if you allow it, your device provides coordinates which are stored against your account. Purpose: showing nearby players and listings. Other users are never shown your raw coordinates — only a coarse distance band. Discovery visibility is off by default and is controlled in Settings → Privacy.
  • User content: listing text, comments, group and club names, and reports you submit. Purpose: community features and moderation.
  • Subscription data: the state of your premium subscription and related transaction records. Purpose: unlocking what you purchased. We never receive your card or payment details; payment is handled entirely by Apple.
  • Notification record: your device push token. Purpose: match confirmations, invitations and event notifications. A notification that another player triggered normally names that player (“Ali recorded a match”), which means their name can appear on your lock screen. You can switch this off with Settings → Privacy → “Don't show names on the lock screen”; the setting is applied on the server, so it also covers notifications sent to you by others.
  • Analytics and crash data: only if you opt in. See section 4.

Data that never leaves your device

Some data stays on your device by design and is never sent to our servers:

  • Health and Apple Watch data (heart rate, calories, workout summary). Stored as a per-match summary rather than raw samples, and only locally.
  • Match videos and photos (clips, recordings, reels) and anything you import into the app's video library. The app does not upload them; if you choose to share, it goes through your device's own share sheet. The single exception is your profile photo, which is uploaded — that is described above.

3. Legal bases

Where we rely on consent you can withdraw it at any time. Withdrawal does not affect the lawfulness of processing carried out before it.

4. Analytics and crash reports (optional)

To improve the app we may use Firebase Analytics and Crashlytics. Both are off by default and are enabled only if you opt in.

  • You can be asked in two places: a one-time prompt the first time you use the app, and Settings → Privacy at any time. Either one updates the same preference.
  • This consent is device-level and is not tied to your account: your user identifier is never sent to Firebase.
  • Crash reports do not include raw error text, request bodies or addresses — only the error class and a technical code.
  • Turning the setting off stops both collections immediately.

5. Guest mode

You can use the app without an account. In guest mode your data stays on your device only and is not sent to the server. If you create an account later, your local records are migrated to it.

6. Recipients and international transfers

We do not sell your personal data and we do not share it with third parties for advertising. We rely on the following processors to run the Service:

Your core account and sport data is hosted inside the European Union (Frankfurt) and is not routinely transferred outside the EEA. Transfers to Apple, Google and RevenueCat take place under Standard Contractual Clauses pursuant to GDPR Article 46 and the relevant providers' data processing agreements.

7. Retention

8. Deleting your account: what is removed and what is not

You can delete your account from within the app (Settings → Account → Delete Account). Deletion is not a single action on a single copy of data, so we describe it precisely:

  • Deleted. Your profile, your profile photo file, your own matches, your location coordinates, your date of birth, your push tokens and the media stored on your device are removed.
  • Anonymised, not deleted. Matches and tournaments you played with other people are shared competitive records. Deleting them would rewrite another player's history and results, so the record is kept and your personal identity is detached from it. This reflects GDPR Article 17(3) and the protection of other people's rights and freedoms.
  • Retained for a limited period. Purchase/subscription events and abuse-prevention records are retained where we are required to keep them, then deleted — closed reports after 180 days. An open report is kept until the case is resolved, because deleting the account of a reported user must not erase the report against them.

9. Export your data

You can download a machine-readable copy of your data from within the app (Settings → Privacy). This also satisfies the right to data portability under GDPR Article 20. The exported file contains personal data — be careful when sharing it.

10. Your rights

Under GDPR Articles 15–22 and KVKK Article 11 you have the right to:

  • Know whether we process your data and request access to it
  • Learn the purpose of processing and whether it is used accordingly
  • Know the third parties to whom your data is transferred
  • Have inaccurate or incomplete data corrected
  • Request erasure ("right to be forgotten")
  • Request restriction of processing
  • Object to processing
  • Receive your data in a structured, commonly used format (portability)
  • Withdraw consent where processing is based on it
  • Object to a decision produced solely by automated analysis that adversely affects you
  • Claim compensation for damage caused by unlawful processing

Send requests to support@viberoapp.com.

Right to complain. If you are in the European Economic Area you may lodge a complaint with the data protection authority of your country of residence. In Türkiye you may complain to the Personal Data Protection Authority (kvkk.gov.tr).

11. Automated decision-making

Your level and statistics are calculated automatically from the matches you play. This is not a decision producing legal effects concerning you or similarly significantly affecting you within the meaning of GDPR Article 22. Decisions such as account suspension involve human review.

12. Security

Data is encrypted in transit with TLS. On the server we enforce row-level access policies: a user can only reach their own data and records shared with them. Session material is held in the device's secure keychain. No system is perfectly secure — if you find a security problem, please tell us.

13. Children's privacy

VIBERO is intended for users aged 18 and over. Community listings can involve meeting other players in person, so we do not knowingly allow minors to use the Service. We ask for your date of birth during onboarding and the server rejects an under-18 date; we ask for a date rather than a tick-box because a tick-box is not a check. We cannot verify the date independently, so if we learn that we hold data belonging to someone under 18, we delete it and close the account. A parent or guardian can tell us at support@viberoapp.com.

14. Cookies and local storage

Our website uses no advertising or tracking cookies — only functional local storage. Details: Cookie and Local Storage Policy.

15. Changes

We may update this policy. If a change is material we will notify you in the app and, where required, ask for your consent again. The effective date and version at the top of this page identify the applicable text.

16. Language

This notice is published in English only, deliberately: a single text is a single binding text, and a translation that drifts would leave you unsure which version applies to you. If you would prefer this explained in another language, write to us and we will explain it — in Turkish or in the language you write in.

17. Contact

For any question or data subject request: support@viberoapp.com

Related documents: Terms of Service · Community Guidelines · Cookie Policy

← Home