Overview
Vylo (“the app”) is published by Chand Studios (“we”, “us”). It shows you what people nearby are reporting, and lets you post your own updates. There is no sign-up — an anonymous session is created for you. This policy explains what data the app uses and the choices you have.
The app is free to download.
Data stored on your device
The app stores your preferences locally on your device — the area you last chose, your display settings, and whether you have dismissed any prompts. What you post, follow and confirm is stored on our backend instead, because other people need to see it; those clauses are below.
Your account
You do not sign up to use the app. On first launch it creates an anonymous session on our backend, hosted by Supabase, so that the things you post and follow stay attached to you across sessions. That session is an identity on our server, not just a value on your device — it is what the rest of this policy means when it refers to your account.
You may optionally add an email address to verify your account, which we use only to send the one-time verification code and to let you recover the account. We do not ask for your real name, and there is no password to forget. Deleting the app does not delete the server-side account — email us and we will remove it.
Location
The app asks for location only while you are using it — never in the background. It requests neighbourhood-level accuracy rather than a precise GPS fix, because all it needs to know is which area to scope your feed to.
You can also mark your shared location as approximate, which publishes an area rather than a point. Posts in sensitive categories — safety, and lost and found — default to approximate, and the app warns you before a post would reveal a home address.
What you post
Anything you post — updates, questions, answers, comments, confirmations and disputes — is stored on our backend and is visible to other people in that area. Treat it as public. Your posts carry the location you chose to attach, at the precision you chose.
When you attach a photo, the app re-encodes it on your device before upload. That step deliberately discards the original file’s embedded metadata — including any GPS coordinates your camera recorded — so the image we receive does not carry a hidden location of its own.
You can delete your own posts at any time. Other people can report content, and content that breaches our rules may be removed. Some records of removed content are kept for as long as needed to enforce those rules and to handle appeals.
Push notifications
If you allow notifications, Google Firebase Cloud Messaging issues a push token for your installation, which we store so we can send you alerts about your area. The token identifies the installation, not you personally. Turn notifications off in your device settings at any time and the token stops being used. See Firebase privacy .
Advertising & consent
The app shows ads through Google AdMob. To serve ads, Google may process an advertising identifier and standard ad-request data such as your approximate location (derived from your IP address), device type and the ad slots shown.
See how Google uses advertising data .
Crash and error reporting
The app uses Google Firebase Crashlytics to record crash and error diagnostics — such as device model, operating-system version and the technical stack trace — so that problems can be found and fixed. This information is not used to identify you personally, is never sold, and no advertising profile is built from it. See Firebase privacy .
Children
The app is intended for a general audience and is not directed to children under 13. We do not knowingly collect personal information from children. If you believe a child has provided personal information, contact us and we will delete it.
Your choices
- Use the app without a network connection.
- Delete all locally stored data by clearing the app's data in Android settings, or deleting the app on iOS.
- Change or reset your advertising consent and identifier from your device settings.
- Email us to ask what data is held about your installation, or to request its deletion.
Security & retention
Data stored on your device remains there until you delete it, clear the app’s data, or uninstall the app. Crash diagnostics are retained by Firebase under its own retention schedule. We do not sell personal information.
Contact
This policy may be updated as the app evolves; the effective date above reflects the latest version.