VibroCalm Privacy

Last updated 24 August 2026 · Notice 2026-08-24-v2

Privacy & Cookie Notice

This notice explains how VibroCalm handles information when you use the VibroCalm iOS app, create an account, purchase or redeem Premium, or use the web funnel at vibrocalm.app.

1. Who is responsible

The data controller is UAB Pulsetto, company code 305911800, registered office at Delčios g. 29, Vilnius, Lithuania. Questions, account deletion requests or privacy requests can be sent to info@pulsetto.tech.

2. iOS app accounts and activity

When you sign in, Apple or, where available, Google provides the account details you choose to share. These may include your email address, name and a provider-specific account identifier. Supabase provides authentication and stores the VibroCalm account, profile and app user ID needed to keep your access and preferences available across sessions.

The app may process onboarding selections, content preferences, favourites, session or playback activity, notification preferences and similar product interactions so it can provide the requested experience, remember progress, improve reliability and support your account. These wellness-related selections are not a medical diagnosis. Do not enter medical records or emergency information into VibroCalm.

3. Quiz and matched web result

Your web quiz answers and matched result are kept in your browser’s session storage so the result page can work. They are normally cleared when the tab or browser session ends, although browser session-restore features may preserve them temporarily. We do not put answers in the page URL, and we do not send raw answers or your matched wellness profile to Google Analytics or Meta.

Unless you turn analytics off, our first-party funnel telemetry may record the matched session label shown to you, such as Stillwave, Moonveil or Equa, so we can measure how result paths perform. It does not receive the raw answers, your email address or billing identity. Unless you separately turn advertising off, purchase attribution uses a different random identifier and is not used to send quiz answers or the matched routine to Meta.

4. Web analytics, advertising and storage

Analytics and advertising are on by default on the web funnel so we can measure it and improve ads; you can turn either or both off at any time and still use the quiz. Google Tag Manager and Google Analytics load unless you turn analytics off. We then measure page views and limited funnel events such as starting or completing the quiz. Event data may include a step number, question key, selected plan, checkout channel, allow-listed source or medium labels and opaque campaign or ad IDs, but not the answer selected or the wellness profile created from it.

Unless you turn advertising off, the Meta Pixel may receive a sanitised page location, browser or device information, Meta advertising click identifiers and generic events such as completing the quiz or viewing a result. Our first-party proxy creates a separate random attribution ID and binds it to this browser with a Secure, HttpOnly capability cookie. The ID and allow-listed campaign IDs may be placed in RevenueCat/Stripe checkout UTM metadata so a provider-confirmed purchase can be matched without putting quiz answers in the checkout URL.

After RevenueCat confirms a purchase, Meta may receive the Purchase event, value, currency, _fbp/_fbc, request IP address and user agent, and a pseudonymous attribution identifier. Quiz answers, the matched routine and full card details are not sent to Meta. The advertising context is retained for up to 30 days. Withdrawing advertising consent blocks future sharing for that context and sends a request to clear its stored match fields.

Your consent choice — including turning analytics or advertising off — is stored locally for up to 180 days and can be changed at any time using “Privacy choices”. Turning a choice off cannot undo processing already completed before the choice changed.

Storage or providerData and purposeTypical duration
vc:v4:midnight-mind
Session storage
Quiz answers needed to show the matched result; not sent to ad platforms.Normally until the tab or browser session ends.
vc:consent:v2
Local storage
Analytics/advertising choices, the exact notice version accepted and update time.Up to 180 days, or until the notice version changes.
Supabase funnel telemetryAfter analytics consent: allow-listed funnel events, an opaque analytics session ID and the matched session label used to measure the web journey. Raw quiz answers, contact details and billing identity are not included.Funnel events up to 180 days; abuse-control markers up to 24 hours.
vc:marketing-attribution:v2
Local storage, HttpOnly cookie and Supabase
After advertising consent: a proxy-generated vc_attr_… ID, an HttpOnly ownership capability, allow-listed campaign IDs, _fbp/_fbc, request IP address and user agent used to match a provider-confirmed purchase. It is separate from quiz answers and the matched routine.Up to 30 days. Withdrawal blocks future sharing, clears the capability and requests deletion of stored match fields.
_ga, _ga_*
Google Analytics
Distinguish visits and measure privacy-safe funnel events after analytics consent.Browser identifiers may persist for up to 2 years. Event-level data is retained for 2 months and user-level data for 14 months in the current property.
_fbp, _fbc
Meta, only if enabled
Measure provider-confirmed purchases and optimise advertising after advertising consent.Our attribution context is retained up to 30 days; Meta controls its own provider retention.
Vercel hosting logsTechnical request data used to deliver, secure and troubleshoot the site.Controlled under the hosting configuration and agreement.

5. App analytics, diagnostics and notifications

Firebase Analytics and Firebase Crashlytics may process app and device information, app-instance or user identifiers, screens and product interactions, session timing, crash reports, diagnostic logs, iOS version, device model and related technical data. Where needed to connect a support issue to an account, diagnostics may be linked to your app user ID, email address or profile name. We use this information to operate the app, investigate errors, protect accounts and understand whether features work.

Additional providers such as Sentry, Amplitude, Singular or OneSignal may process comparable analytics, attribution, diagnostics or notification data only when the corresponding service is configured. If you enable notifications, Apple and the configured notification provider process a device push token and delivery information. VibroCalm does not require precise location for its core functionality.

6. Purchases and Premium access

Apple processes App Store purchases. RevenueCat manages subscription status and Premium entitlements for App Store and web purchases. RevenueCat may process an app user or anonymous customer ID, product and package identifiers, purchase and renewal status, transaction dates, entitlement status and expiration information.

For a web subscription, Stripe processes contact, payment and billing details and RevenueCat provides the checkout, subscription-management and redemption flow. VibroCalm receives the information needed to recognise the purchase and unlock Premium; it does not receive your full payment-card number. If advertising consent is active, RevenueCat/Stripe UTM metadata may contain the separate random attribution ID and allow-listed campaign IDs. Provider-confirmed Purchase, value and currency may then be sent to Meta with pseudonymous match fields; quiz answers, the matched routine and card details are excluded.

7. Service providers, security and transfers

VibroCalm uses service providers including Supabase for accounts and app data, Apple and Google for sign-in and platform services, Firebase/Google for app analytics and diagnostics, RevenueCat for subscriptions, Stripe for web billing, and Vercel for web hosting. Sentry, Amplitude, Singular, OneSignal, Google Analytics or Meta may be used for the limited purposes described above when configured or allowed.

These providers may process information outside the European Economic Area. Their terms describe the locations and transfer safeguards they use. Provider information: Supabase Privacy, Google Privacy, Apple Privacy, RevenueCat Privacy, Stripe Privacy, Vercel Privacy and Meta Privacy.

8. Legal bases and retention

We process account, app, purchase and support information to provide the service you request and perform our agreement with you. Security, essential diagnostics and service improvement rely on our legitimate interests in operating a reliable and secure product. Optional web analytics, advertising and notifications rely on your choice or consent where required.

Account and profile data is generally kept while your account is active. Purchase records and entitlement history may be retained for contract, fraud-prevention, tax, accounting and legal obligations. Diagnostic and analytics retention depends on the provider and configured retention period. We delete or anonymise information when it is no longer needed, subject to legal and security requirements.

9. Your rights and account deletion

Depending on the circumstances, you may ask to access, correct, delete, restrict or receive your personal data, object to certain processing, and withdraw consent. You can request account deletion from the app where that option is available or contact info@pulsetto.tech. Deleting a VibroCalm account does not automatically cancel an Apple or web subscription; cancel it through the relevant subscription-management service.

You may complain to the Lithuanian State Data Protection Inspectorate or your local data protection authority.

10. Children and changes

VibroCalm is not designed for children. If you believe a child has provided personal information, contact us so we can review and remove it where appropriate. We may update this notice when the app, funnel or providers change; the current date appears at the top.

Contact support