1. INTRODUCTION
This Privacy Policy describes how Vibrato World LLC (“Vibrato,” “we,” “us,” or “our”) collects, uses, processes, and shares personal information through our mobile application, website, and related services (collectively, the “Platform”). This Policy applies to all users, including those who offer services (“Hosts”) and those who book services (“Guests”).
Vibrato World LLC operates the Platform under the brand name SEYA. Where the SEYA application uses the term “Source,” that term means “Host” as used in this Policy; where the application uses the term “Seeker,” that term means “Guest.”
By accessing or using the Platform, you acknowledge that you have read and understood this Privacy Policy.
2. CONTROLLER AND RESPONSIBLE ENTITY
Vibrato World LLC is the data controller for personal data collected through the Platform.
Contact: legal@seya.world
Mailing address: Vibrato World LLC, Attn: Privacy, 572 Grand Street, G1805, New York, NY 10002
State of formation: Delaware, United States
We will acknowledge privacy requests within ten (10) business days and respond substantively within forty-five (45) days, subject to any extension permitted by applicable law.
3. INFORMATION WE COLLECT
We collect information in three ways: directly from you, automatically via technology, and from third-party sources.
The categories of personal information described in Sections 3.1–3.3 are collected and used for the business and commercial purposes described in Section 5 (How We Use Your Information), and disclosed as described in Section 7 (How We Share Your Information).
Sensitive Personal Information / Sensitive Data. Certain information we collect may be considered “sensitive” under some privacy laws, including precise geolocation and information relating to government-issued identification and identity verification. We process sensitive information only as necessary to provide the Platform, maintain trust and safety, comply with law, and for the other purposes described in Section 5. Where required, we obtain your consent — for example, for precise location through your device permissions, and for identity verification through the notice and consent described in Section 4.
Sale / Sharing for Targeted Advertising. Vibrato World LLC does not sell personal information. Vibrato World LLC does not share personal information for cross-context behavioral advertising (also called “targeted advertising”) as those terms are defined under certain U.S. privacy laws. If our practices change, we will provide any required notice and opt-out rights.
Retention (Summary). We retain personal information for as long as reasonably necessary for the purposes described in this Policy, and as required or permitted by law. See Section 9 (Data Retention) for additional detail and typical retention timeframes.
Your Privacy Rights. Depending on where you live, you may have rights to access, delete, correct, and/or receive a copy of certain personal information, and to opt out of certain processing where required by law. See Section 10 (Your Rights) for details on how to exercise these rights.
3.1. Information You Provide
- Account Data: Name and email address. Authentication is performed using a one-time passcode sent to your email address, or through Sign in with Google or Sign in with Apple; we do not collect or store account passwords. If you register as a Host, we also collect a mailing address for tax and contract purposes.\
- Profile Data: Biography or personal description, interests and skill tags, and profile photograph.\
- Video Portrait (Hosts only): If you register as a Host, you must record or upload a short video portrait before you can publish your first listing. Your video portrait is displayed on your public Host profile so that Guests can see and hear from you before deciding whether to book a session. We use video portraits only for display on your profile. We do not analyze video portraits to identify you, to generate facial recognition or facial geometry data, or to compare them against your identity verification records. You may replace your video portrait at any time from your profile settings.\
- Listing Content (Hosts only): Session titles, descriptions, categories, pricing, duration, availability, and the venues you select.\
- **Identity Verification (Hosts Only):**The outcome of the identity verification described in Section 4, together with limited identifiers necessary to associate that outcome with your account. Vibrato does not receive or store images of your identification document, and does not collect biometric information. Our verification provider may collect additional identifiers directly from you as part of that process, and its handling of that information is governed by its own privacy policy.\
- Payment & Transaction Information: Vibrato World LLC does not collect, store, or process your full credit card numbers, bank account credentials, or payment security codes. All financial transactions are processed by third-party payment processors (e.g., Stripe). We only receive and retain information necessary to manage your bookings and account, which may include:\
- Payment tokens or IDs (used to securely charge your card without accessing the actual number).\
- Transaction history (date, amount, and payment status).\
- Limited payment instrument details (e.g., the last four digits of your card/bank account, card brand, and expiration date).\
- Billing address and postal code.\
- Session Data: Booking details, cancellation reasons, and post-session ratings/reviews.\
- Communications: Content of in-app messages between users and communications with Vibrato support.\
- Voice Interactions (“Talk to SEYA”). The Platform offers an optional voice-based conversational feature that helps you draft your profile and your session listings. When you choose to use this feature:\
- Audio. Your device microphone captures what you say while the feature is active. Audio is transmitted to a third-party AI service provider acting on our behalf in order to generate a response and a written transcript. We do not retain your voice recordings. Audio is processed for the duration of the conversation and is not stored by Vibrato once the conversation ends.\
- Transcripts. A written transcript of the conversation is generated so that the feature can produce draft text for you. Transcripts are retained only as long as needed to produce and deliver that draft, and are deleted within thirty (30) days.\
- Generated content. Any profile text, listing text, tags, or categories the feature drafts for you are shown to you for review and editing. Once you accept them, they become part of your profile or listing and are retained as Profile Data.\
- Derived preference information. We may derive information about your interests and communication preferences from your voice interactions in order to improve the relevance of matches and recommendations shown to you. This derived information is retained while your account is active and is deleted when your account is deleted.\
- Your control. Using Talk to SEYA is entirely optional. Every screen where it appears also offers a standard text entry alternative. Microphone access is requested at first use and can be revoked at any time in your device settings. You may dismiss a conversation at any point, and if you do, any partial conversation data is discarded.
3.2. Information Collected Automatically
- Location Data:\
- Precise location: With your permission, we use your device’s location while you are using the app to show you sessions and venues near you and to provide directions to a confirmed venue. We do not collect your location in the background, we do not track your movements, and we do not use location to verify your attendance at a session.\
- Approximate location: We may derive approximate location from IP address and other technical signals.\
- Your controls: You can enable or disable precise location at any time through your device settings. If you disable precise location, certain features (such as nearby suggestions and directions to a venue) may be limited.\
- Device & Usage Data: IP address, device model, OS version, unique device identifiers, browser type, crash logs, and interaction metrics (pages viewed, time spent, features used).\
- AI Interaction Data: Inputs you provide to our AI features (for example, prompts for bio generation) and de-identified behavioral signals used to improve matching and ranking.
3.3. Information from Third Parties
Connected Accounts: If you sign in using Google or Apple, we receive tokenized authentication information and the name and email address permitted by your settings with that provider. If you use Sign in with Apple, you may choose to share a private relay email address instead of your personal address.
3.4. Cookies, Analytics, and Similar Technologies
We and our analytics providers use cookies, software development kits, mobile identifiers, and similar technologies to operate the Platform and understand how it is used.
- Strictly necessary technologies keep you signed in, maintain your session, secure the Platform, and remember your preferences. The Platform cannot function without these.\
- Analytics technologies help us understand which features are used, diagnose crashes, and measure performance. We use PostHog, which we host ourselves, and Google Analytics for Firebase.\
- We do not use advertising or cross-context behavioral tracking technologies, and we do not permit third parties to collect information through the Platform for their own advertising purposes.\
- Your choices. On mobile, you can limit ad tracking and reset your advertising identifier through your device settings; on iOS, the Platform does not request App Tracking Transparency permission because we do not track you across other companies’ apps or websites. On our website, you can control cookies through your browser settings, though disabling strictly necessary cookies may prevent parts of the site from working. We currently do not respond to browser “Do Not Track” signals, as no common standard for them has been adopted; we do honor Global Privacy Control signals where required by applicable law.
4. IDENTITY VERIFICATION NOTICE
Purpose. To verify identity, prevent fraud and impersonation, and support the safety of in-person sessions, Hosts are required to complete identity verification before publishing a listing. Verification is performed by a third-party identity verification provider acting on our behalf.
What the verification involves. You submit an image of a government-issued identification document, which the provider examines to confirm that the document appears genuine and that the information on it matches the information on your account.
What Vibrato receives. Vibrato receives only the outcome of the verification - such as verified or not verified - together with limited non-biometric identifiers necessary to associate that outcome with your account, and any reason codes returned for a failed verification. Vibrato does not collect, receive, or store images of your identification document. Retention of the document image is governed by the provider’s own privacy policy and retention practices.
Biometric information. Vibrato does not collect, capture, receive, or store biometric identifiers or biometric information, and our verification process does not involve facial recognition, facial geometry scanning, or liveness detection. Vibrato does not sell, lease, trade, or otherwise profit from biometric information. If Vibrato introduces any verification method involving biometric processing in the future, we will update this Policy, provide the notice required by applicable law, and obtain your consent before that processing begins.
Who this applies to. Identity verification is required only of Hosts. Guests are not identity-verified. If you do not complete verification, you may continue to use the Platform as a Guest but may not publish a listing.
Vibrato may change its identity verification provider from time to time. Any replacement provider will be subject to contractual confidentiality and security obligations.
5. HOW WE USE YOUR INFORMATION
We process data for the following specific business purposes:
5.1. Service Delivery
- Facilitating bookings, payments, and payouts.\
- Matching Hosts and Guests using AI algorithms based on compatibility, skills, and location.\
- Enabling Guests to evaluate Hosts before booking, including through Host profiles, video portraits, listing content, and ratings and reviews.\
- Providing AI-generated content assistance (e.g., “Write my Bio”).
5.2. Safety, Trust & Security
- Verification: Verifying identities to prevent fraud, impersonation, and catfishing.\
- Monitoring: Using automated systems to detect patterns indicative of fraud, harassment, or Terms violations (e.g., duplicate accounts, off-platform payment attempts). We do not use these systems to evaluate Host performance or instruct Hosts on how to perform Sessions.\
- Location Features: Where you grant location permission, using device location to show you sessions and venues near you and to provide directions to a confirmed venue. We do not track your location in the background, and we do not use location to verify your attendance at a session.
5.3. Analytics & Development
- Using de-identified or aggregated information to improve matching accuracy and search relevance.\
- Analyzing marketplace liquidity, retention, and session quality.
5.4. Legal Compliance
- Complying with tax obligations (e.g., 1099 issuance).\
- Responding to valid law enforcement requests and subpoenas.
6. ARTIFICIAL INTELLIGENCE AND AUTOMATED DECISION MAKING
Vibrato World LLC is an AI-first platform. We use automated systems and machine learning to help operate the Platform, including personalization, matchmaking, content assistance, and safety monitoring.
6.1. AI features we provide
Our AI-enabled features may include:
-
Matchmaking and discovery: ranking and recommending Hosts/Guests based on profile information, session history, behavioral signals, and (if enabled) location.
-
Content assistance: helping draft profile text, tags, and other user-facing content you request (for example, “Write my Bio”).
-
Safety and integrity: identifying suspected fraud, harassment, discrimination, or policy violations and routing those signals for review.
6.2. Data sent to AI processing providers
When you use AI-enabled features, certain inputs you provide - such as prompts, draft text, relevant context, and, where you use Talk to SEYA, the audio of your conversation - may be processed by third-party AI service providers acting as our service providers. We do not permit third-party AI providers to use data processed on our behalf to train their models.
6.3. Model improvement
We may use de-identified or aggregated information derived from Platform usage - including interaction metrics, booking outcomes, ratings, and safety outcomes - to improve our matching, ranking, and safety systems. We do not use the content of your private in-app messages to train models that are used for any purpose other than safety and fraud detection. We do not permit third-party AI providers to use data processed on our behalf to train their models. Where required by applicable law, we will provide you with choices regarding certain model-improvement uses.
6.4. Automated decisions and human review
Automated systems may influence: (i) the order in which results are shown, (ii) the recommendations you receive, and (iii) whether an account is flagged for potential policy violations. Significant decisions affecting your access to the Platform (for example, permanent suspension after investigation) are subject to meaningful human review upon appeal.
6.5. Your choices
Depending on your location and applicable law, you may have the right to:
-
opt out of certain automated profiling (where required), and/or
-
request information about the logic involved in significant automated decisions, and request human review.\
You can exercise these rights as described in Section 10.
7. HOW WE SHARE INFORMATION
7.1. With Other Users
- Public Profile: Your name, profile photograph, biography, and interests and skill tags are visible to other users, along with the ratings and reviews you receive. If you are a Host, your video portrait and your listing content are also publicly visible on the Platform. Consider what you are comfortable sharing publicly before recording your video portrait.\
- Booking Details: Upon confirmed booking, relevant contact and location info is shared with the counterparty.
7.2. With Service Providers
- Payments and identity verification: our payment and identity verification provider, currently Stripe, Inc., which processes payments, handles payouts to Hosts, and performs the identity verification described in Section 4. Stripe’s handling of your information is also governed by Stripe’s own privacy policy.\
- Maps and venue information: We use the Google Maps API(s) for venue search, address autocomplete, geocoding, and directions. Google’s Privacy Policy, available at https://policies.google.com/privacy, is incorporated into this Policy by reference.\
- Cloud hosting and infrastructure providers, which store and process Platform data on our behalf.\
- Communications providers, which deliver transactional email and push notifications on our behalf.\
- Product analytics providers, which help us understand how features are used, diagnose crashes, and measure performance.\
- AI service providers - currently OpenAI and Anthropic - which process inputs for the AI-assisted features described in Section 6. Data sent to these providers is limited to what is necessary for the requested feature. We do not permit these providers to use data processed on our behalf to train their models.\
We may change service providers within these categories from time to time. If we add a new category of third party with whom we share personal information, we will update this Policy as described in Section 13.
7.3. Legal & Safety Disclosures
- Emergency and Safety Features. The Platform provides access to safety information, including emergency service numbers and guidance for meeting others in person, and allows you to end a Session at any time or report a safety concern. The Platform does not provide an emergency alert, panic button, emergency contact notification, or live location sharing feature, and does not monitor sessions in real time. Your mobile device may offer location sharing and emergency features independently of the Platform; those are provided by your device manufacturer, operating system, or carrier, not by Vibrato, and Vibrato does not receive information through them. If you believe you are in immediate danger, contact local emergency services directly by dialing 911. If Vibrato introduces emergency features in the future, we will update this Policy and describe the associated data practices before they become available to you.\
- Law Enforcement and Imminent Harm. We may provide information to law enforcement or emergency services in response to a valid legal request, or where we believe in good faith it is necessary to prevent imminent harm, consistent with applicable law.
8. DATA SECURITY
- We implement reasonable administrative, technical, and organizational measures designed to protect personal information against unauthorized access, destruction, loss, alteration, or misuse. These measures may include access controls, encryption in transit, logging and monitoring, and vendor security reviews. No method of transmission or storage is completely secure; therefore, we cannot guarantee absolute security.\
- Security Incident Notification. If we become aware of a security incident that affects your personal information, we will notify you and, where required, relevant regulators, consistent with applicable law and the information available to us at the time.
9. DATA RETENTION
We retain personal information for as long as reasonably necessary to provide the Platform, comply with legal obligations, resolve disputes, enforce our agreements, and maintain safety and integrity. Retention periods vary based on the type of data and the purposes for which it is processed, including the following:
-
Account and profile data: retained while your account is active. After account closure, we delete or de-identify account and profile data within thirty (30) days, except where retention is required or permitted under this Policy.
-
Transactional records (bookings, payments, payouts, tax records): retained for 7 years for tax, accounting, and audit purposes.
-
Messages and support communications: retained for thirty-six (36) months to provide support, investigate safety incidents, and enforce our policies, unless a longer retention period is required due to a dispute, claim, or legal obligation.
-
Precise location data: retained for thirty (30) days (or shorter where feasible) unless needed for safety investigations, fraud prevention, or legal compliance.
-
Identity verification outputs (e.g., verification status, tokens, device association): retained for five (5) years after account closure or last activity to prevent fraud, enforce bans, and maintain Platform safety. Vibrato does not retain identification document images.
-
Safety and integrity records (reports, investigations, enforcement actions): retained for seven (7) years.
-
Analytics and aggregated data: we may retain de-identified, aggregated, or anonymized data for longer periods for trend analysis and service improvements.
-
Voice interaction data: voice recordings are not retained. Transcripts generated by Talk to SEYA are deleted within thirty (30) days. Content you accept into your profile or listing is retained as profile data.
-
Video portraits: retained while your Host profile is active. If you replace your video portrait, the prior version is deleted within thirty (30) days. Following account closure, video portraits are deleted within thirty (30) days.
-
Records of agreement acceptance: records of your acceptance of our Terms of Use, this Policy, and (for Hosts) the Source Services Agreement - including the version accepted and the date and time of acceptance - are retained for seven (7) years following account closure. For Hosts, contract records are retained for at least six (6) years as required by applicable law.
We may retain information for longer periods where required by law, requested by law enforcement, or reasonably necessary to establish, exercise, or defend legal claims.
10. YOUR RIGHTS
Depending on the state in which you reside, you may have the right to:
- Access/Portability: Request a copy of your data.\
- Correction: Update inaccurate info.\
- Deletion: You can delete your account at any time from within the SEYA app, under Settings. When you delete your account or otherwise request deletion, we will delete or de-identify personal information associated with your account, subject to limited exceptions described in this Policy (for example, records we must retain for tax/accounting, safety and fraud prevention, dispute resolution, or legal compliance). Some information may persist in backups for a limited period, but we will maintain it in accordance with this Policy and restrict access to it.\
- Opt-Out: Opt-out of marketing communications or specific automated profiling.
To exercise these rights, contact: legal@seya.world. We will not discriminate against you for exercising any of these rights.
11. INTERNATIONAL DATA TRANSFERS
The Platform is offered to users in the United States only. The SEYA application is distributed only in United States app stores, and sessions are available only in United States locations. The Platform is not directed to, and is not intended for use by, individuals in the European Economic Area, the United Kingdom, or Switzerland.
Vibrato World LLC is based in the United States, and all personal information collected through the Platform is processed and stored in the United States. If you access the Platform from outside the United States, you understand that your information will be transferred to and processed in the United States, where data protection laws may differ from those in your location.
12. CHILDREN’S PRIVACY
The Platform is strictly for users 18 years of age and older. We do not knowingly collect data from minors. Accounts identified as belonging to minors will be terminated immediately.
13. CHANGES TO THIS POLICY
We may update this Policy to reflect changes in our services, technology, or legal obligations. We will post the updated Policy with a revised “Last Updated” date. For material changes, we will provide notice by email or in-app notification at least ten (10) days before the change takes effect. Where a material change involves a new category of sensitive information, a materially different use of information you have already provided, or a new disclosure of personal information to third parties, we will obtain your affirmative consent before that change applies to you.