Vatulo Privacy Policy
In effect from 7 September 2026
This policy covers the Vatulo mobile app and the website at vatulo.com. Vatulo helps people find house parties and decide who comes to theirs. This explains what we collect, why, who else can see it, how long we keep it, and how to get rid of it.
We have written it to be read. Where a section is short, it is because the honest answer is short.
Who we are, and who is responsible
Vatulo, Montreal, Quebec, Canada.
Under Quebec's Act respecting the protection of personal information in the private sector (Law 25), an enterprise must name the person in charge of protecting personal information and publish their contact details. At Vatulo that person is the Founder, reachable at vatulosupport@gmail.com. Write to that address for anything in this policy — access, correction, deletion, complaints, or a question about how something works.
What we collect
Things you tell us when you sign up
- Email address, and a password (stored only as a hash — we never see it).
- First name and username.
- Date of birth. Vatulo is 18+ and we use this to enforce that and to show your age on your profile.
- Gender. Required, and one of woman, man, non-binary, or prefer not to say. It is shown to other people only as part of a party's aggregate ratio, never attached to you individually, and never when fewer than five guests are on a list.
- At least one photo.
Things you add later
Bio, interests, music preferences, vibe tags, profile prompts, university and programme, further photos, and optionally a phone number.
Things that happen as you use Vatulo
- Parties you host, apply to, are accepted to, commit to, or check into.
- Every party you swipe on, and which way. Passing, saving and applying are all recorded and kept, so a party you have answered does not come back. Hosts never see that you passed on theirs.
- How you looked at it. For each card, roughly how long it was on screen and whether you opened the full party page. We use this for one thing: if several applications in a row are sent without reading anything, the app asks you to open a party before applying again. It is not shown to hosts and it does not affect whether you are accepted.
- Messages and photos you send, and who you send them to.
- Reviews you leave and reports you make.
- Friend requests, friendships, people you have removed from your Crowd, and people you have blocked.
- A device push token, so we can notify you, and which platform it is for.
- Every display name and username you have used. Changing either is limited — a name once every 30 days, a username once every 60 — and each change is recorded. The list is for moderation: it is never shown to another user, never shown to you as a list, and it is deleted when you delete your account.
- Security records: rate-limit events and risk events, used to detect abuse.
Addresses. A party's exact address is given to you only after you commit to attending, and only once the host's chosen release time has arrived — some hosts release on commitment, others hold it until a day, three hours, or an hour before the party starts. Hosts supply the address; we store it and release it under those two conditions and no other.
What we do not collect. We have no advertising identifiers, no third-party analytics or tracking SDKs, and no social-media login that would report back to the network you signed in with.
Location
Your location never leaves your phone.
If you allow it, Vatulo reads your device's location and uses it on the device to work out how far away a party is. That calculation happens locally. We do not transmit, store, or log your coordinates, and there is no column anywhere in our database that holds a user's position.
The one address we do store is the one a host types in for their own party, so it can be given to guests who commit — described under "Addresses" above. That is a place, supplied deliberately; it is not a record of where anybody is.
Parties themselves carry a deliberately coarse published position — a neighbourhood-level point, not the address — which is what distances are measured against.
You can decline location entirely. The app works without it; you just will not see distances.
What we do with it, and why we are allowed to
- Run the product: show you parties, let hosts choose guests, deliver messages.
- Keep people safe: enforce 18+, apply rate limits, investigate reports, and act on moderation decisions.
- Send you notifications you have not turned off.
- Send transactional email — confirming your address, resetting your password.
Most of this rests on the consent you give by creating an account and using the features concerned, and you can withdraw that consent by deleting your account. Some of it does not: enforcing the age limit, investigating reports, and keeping records that let us recognise abuse are things we do because the service cannot be operated safely otherwise, and because law and the App Store rules require it. Where we rely on that rather than on your consent, we say so in this policy.
We do not sell your personal information, we do not use it for advertising or share it with advertisers, and we do not use it to train machine-learning models.
Who else can see what
- Other users see your profile as your privacy settings allow: name, username, age, photos, bio, interests, prompts, reputation and badges. You control the audience for individual fields in the app.
- Hosts of parties you apply to see your profile and how many friends you have in common.
- Anyone who can open a party can see who is going to it, and that includes you once you are on the guest list. They see the same three things about every guest: main photo, first name, age. Being on the list is all it reveals — nothing further about your profile follows from it, and a guest list is never visible to anyone who could not already open the party itself.
- Your profile discoverability setting decides whether hosts can come across you without knowing you. Open to invites means a host may be shown your profile among suggested guests, and may invite you. Private means a host reaches you only if you apply to their party or already have a connection to you — and then they do see your full profile, because a host has to be able to judge an application. Private does not take you off the guest list of a party you chose to join, and it does not hide your first name, main photo or age from people who can already see you elsewhere in the app.
- The size of your Crowd appears on your profile, and tapping it opens the list. Both follow the audience you choose for your Crowd in privacy settings — set it to nobody and the number is withheld as well as the names, because a count is itself a fact about you.
- Nobody sees your gender individually. It appears only inside a party's aggregate ratio, and only when at least five guests are on the list — below that the ratio is withheld entirely, because a ratio over a handful of people identifies them.
- Nobody sees your email address, your phone number, or your date of birth. Other people see your age, not your birthday.
Automated processing
Three parts of Vatulo act on your information without a person involved, and Law 25 says you should be told which:
- The order of your discovery deck. Parties are ranked using what you have said you like, how far away they are, who else is going, how recently they were posted, and what you have swiped on before. This decides what you are shown first. It does not decide anything about you.
- The order you appear in to a host. If you are open to invites, hosts looking for guests are shown eligible people in a ranked order rather than an arbitrary one. The ranking uses how well the party matches what you have said you like — music, interests, the kind of night, the size of room — how many people you and the host know in common, and a deliberately random element that is reshuffled daily so the same people are not always shown first. It affects the order you appear in, not whether a host may invite you, and no host sees the ranking or the reasons behind it.
- Anti-spam friction and rate limits. If several applications in a row go out without any party being opened, the app asks you to read one before applying again. Separately, automatic rate limits cap how often certain actions can be repeated. Both restrict what you can do for a short period.
No automated system decides whether you get into a party. A host does, one guest at a time. And no account is suspended or restricted purely automatically — a person reviews the report first.
If an automated limit has affected you and you think it is wrong, write to vatulosupport@gmail.com. You are entitled to be told the main factors involved and to have a person look at it.
Where your information is held
| Provider | What it handles | Where |
|---|---|---|
| Supabase | Database, authentication, file storage | Canada (ca-central-1) |
| Expo | Push delivery. Receives a device push token and the notification text | United States |
| Resend | Transactional email. Receives your email address | United States |
| Apple / Google | App distribution, and the push transport underneath Expo | United States |
Your account data — profile, messages, photos, everything in the database — is stored in Canada. Push notifications and transactional email necessarily pass through providers in the United States, which means the information in them can be subject to United States law, including lawful access requests there. What those providers receive is limited to what they need: an email address for Resend, a device token and the text of the notification for Expo.
Each of these acts as our processor and is bound to use what it receives only to provide the service to us.
How long we keep things
While your account exists, we keep what is listed above so the product can work. When you delete your account, most of it goes immediately — see below.
Some things outlive the account, and each one has a reason:
- Reports, and the moderation decisions taken on them. These are somebody else's account of being harmed. Deleting your account should not erase it.
- Reviews, both the ones written about you and the ones you wrote about other people. A host's rating is built from many guests; removing yours would quietly rewrite somebody else's reputation.
- Parties that already happened, including ones you hosted. Other people attended them and their own records refer to them.
- Message tombstones. The words and any images are deleted; a marker stays so the conversation still reads sensibly for the person you were talking to.
- Security records — rate-limit and risk events. Their whole purpose is to recognise a pattern of abuse, which a new account would otherwise reset.
After deletion these are attached to an account carrying no name, username, photo, bio, email or phone number. We keep them under our legitimate interest in keeping the community safe, and we do not use them for anything else.
Deleting your account
You can delete your account from Settings, in the app. It is permanent. You do not need to ask us, and you do not need a reason.
When you do, we erase your name, username, photos, bio, interests, vibe tags, music preferences, prompts, university, programme, phone number, gender and avatar, replace your email with an unusable placeholder, end every session, and delete your push tokens, devices, filters, saved invite lists, friendships, blocks, swipes and notifications. Parties you were hosting that had not happened yet are cancelled, and your guests are told. Messages you sent become tombstones so the thread still reads sensibly for the other person, but the words and any images are gone.
If you cannot get into the app to do it — a lost password, a locked account — write to vatulosupport@gmail.com and we will do it for you once we can establish that the account is yours.
Your rights
You can:
- Access the personal information we hold about you.
- Correct anything inaccurate. Most of this you can do yourself in the app.
- Delete your account and the information that goes with it.
- Withdraw consent, by deleting your account.
- Receive a copy of the information you gave us, in a structured, commonly used technological format, and ask us to send it to someone else — the portability right under Law 25.
- Ask us to stop disclosing your information or to de-index it, under Law 25.
Write to vatulosupport@gmail.com. We will answer within 30 days. There is no charge.
If you are not satisfied with our answer, you can complain to the Commission d'accès à l'information du Québec (cai.gouv.qc.ca) or, outside Quebec, to the Office of the Privacy Commissioner of Canada (priv.gc.ca). You do not have to go through us first.
The website
vatulo.com sets no cookies, runs no analytics, and embeds nothing from a third party — the typeface is served from our own domain rather than linked from a font network, so that reading this page does not report you to anyone. Our host, GitHub Pages, records ordinary server access logs, which we do not have access to and do not use.
Children
Vatulo is for adults. You must be 18 or older. We do not knowingly collect information from anyone under 18, and we delete accounts we find. If you believe someone under 18 has an account, tell us at vatulosupport@gmail.com and we will act on it.
Security
Every table in our database is protected by row-level security, so what you are allowed to see is enforced by the database itself rather than by the app asking nicely. Passwords are hashed. Traffic is encrypted in transit. Exact addresses are released only against a confirmed commitment.
No system is perfect. If we discover a confidentiality incident that presents a risk of serious injury, we will notify the people affected and the Commission d'accès à l'information as Law 25 requires, and we keep a register of such incidents.
Changes
If we change this policy materially we will tell you in the app before the change takes effect, and update the date at the top. Continuing to use Vatulo after that means the new version applies to you.
This page is also available in French. Where the two differ, the French version prevails.