Zibly — Privacy Policy
Last updated: 11 August 2026
This Privacy Policy explains how Zibly ("we", "us", "our")
collects, uses, and shares information when you use the Zibly mobile
application and related services (the "Service").
The Service is currently in private beta. This policy may change
as the Service evolves; we'll notify you in-app when it does.
- Account info: phone number (or Google sign-in identifier),
display name, chosen username, optional email and gender.
- Profile info: avatar image, hobby selections, ghost-mode and
privacy preferences.
- Content: posts, activities, comments, mentions, photos you
upload, and reactions you place on others' messages.
b. Device features you grant access to
Each of these is requested only at the moment the feature is used, and
Zibly works without them — declining any one of them does not block
access to the app.
- Camera: to take a profile photo or a photo for a post, and to
send video during a call. Zibly does not access your camera in the
background, and no camera feed is recorded or stored by us except
the images you explicitly choose to upload.
- Microphone: to carry your voice during a voice or video call.
Calls are peer-to-peer (WebRTC) and are never recorded or stored by
Zibly.
- Bluetooth: only to route call audio to a connected headset or
speaker. We do not scan for, log, or use nearby Bluetooth devices to
locate you or to identify anyone.
- Photo library: to let you pick an existing image to upload. We
access only the specific images you select.
- Notifications: to deliver messages, waves, and activity updates.
- Location: with your explicit OS-level permission, your device's
GPS coordinates. Used to power the radar, attribute posts and
activities to a place, and validate activity check-ins. You can
toggle Ghost Mode in-app to hide your radar presence at any time.
- Device info: device model, OS version, Zibly app version, and
Firebase Cloud Messaging (FCM) push token.
- Usage info: which screens you visit, taps, errors, and
approximate session duration. Collected for product improvement;
no third-party ad-tech is used.
- Sign-in providers (Google, phone OTP): we receive the basic
identity info you authorise the provider to share.
We use the information we collect to:
- create and maintain your account
- show you other Zibly users in your radar range
- deliver messages, waves, matches, comments, and notifications
- validate GPS-based activity check-ins
- detect and prevent abuse, spam, and fraud
- diagnose crashes and improve the app
- communicate with you about the Service
We do not sell your personal information.
We share information only as follows:
- With other Zibly users, in the ways the Service is designed
(e.g. your display name + avatar appear on the radar to people
in range; your posts appear in others' feeds per the post's
visibility setting).
- With service providers that operate parts of our
infrastructure under contract:
- Google Firebase (authentication, push, crash reporting)
- Foursquare and/or Google Places (place autocomplete, venue data)
- Amazon Web Services (hosting, storage)
- OpenStreetMap contributors (map base tiles — no PII shared)
- For legal reasons, when required by law, court order, or
to protect the rights, safety, or property of users or others.
- In a business transfer (acquisition, merger), with prior
notice to you.
4. Privacy Controls
You have direct in-app controls:
- Ghost Mode — hides you from the radar.
- Last-seen visibility — All / Connections / Nearby / Nobody.
- Distance visibility — All / Connections / Nearby / Nobody.
- Block users — bidirectional; both sides hidden from each other.
- Notification mutes — per-kind (messages, waves, matches).
- Account deletion — from in-app settings; irreversible.
5. Data Retention
- Account data: retained while your account is active. Deleted
within 30 days of account deletion, except where law requires
longer retention (e.g. tax records).
- Location data: retained as long as needed for radar / presence
features; coarsened where feasible.
- Posts and messages: retained until you delete them or your
account.
- Crash and diagnostic logs: retained up to 90 days.
6. Children
The Service is not intended for users under 16. We don't knowingly
collect information from children under 16. If you believe a child
under 16 has given us information, contact us so we can delete it.
7. International Transfers
Our servers are located in the Asia-Pacific (Mumbai, India)
region. Some service providers (Google Firebase, AWS) may process
data in other regions under their own privacy commitments.
8. Security
We use industry-standard measures (encrypted transport, access
controls, JWT-based authentication) to protect your information.
No system is perfectly secure; we cannot guarantee absolute
security.
9. Your Rights
Depending on your jurisdiction, you may have rights to:
- access the personal information we hold about you
- correct inaccurate information
- delete your information
- restrict or object to certain processing
- data portability
To exercise any of these rights, email dileep.desk@gmail.com
from the email associated with your account. We respond within
30 days.
10. Changes to This Policy
We may revise this Policy from time to time. Material changes
will be communicated through the app and the "Last updated" date
above. Continued use after the revised Policy takes effect
constitutes acceptance.
For questions, complaints, or rights requests, contact us at:
dileep.desk@gmail.com