Privacy Policy
Last updated: 28 September 2026
Tweely is run by OneVault LLC, [OneVault LLC registered address] ("we", "us"). This policy explains what personal data we collect, why, who we share it with, how long we keep it, and your rights. It covers tweely.app, twee.ly, tweely.co, tweely.chat, the chat widget and our apps.
1. Who is responsible for your data
- For accounts, profiles, public pages, billing and safety, OneVault LLC is the controller (called a "data fiduciary" in India).
- When a business uses Tweely to chat with its own customers (for example through the chat widget on its website, its chat links or its AI front desk), that business is the controller of those chats and we process them for it as a processor. Please read that business's privacy notice and send requests about those chats to the business. We will help it respond. See our Business & Widget Terms.
- Sign-in is provided by OneVault ID, which has its own privacy notice.
2. What we collect
- Account: your OneVault ID, name, email, handle, and the profile details you add.
- Phone number: if you verify a phone, your number, country, and the time and result of the check. We use it to fight spam and fake accounts, and to let you chat.
- Your content: links, photos, backgrounds, Spotlights, stickers and intake cards, chats and group chats, and the knowledge you teach your AI front desk.
- Contact details (business card): phone numbers, messaging handles, email and address that you choose to add, with the privacy level you pick for each one.
- Chats with guests: messages and any details visitors choose to send, such as a name, a booking or a complaint.
- Visitor analytics: for profile views and link clicks we record a random visitor ID (from a first-party cookie, stored hashed), the country (from our network provider), device type and the referring website. We do not store visitors' IP addresses for analytics. Bots and link previews are not counted.
- Safety data: to stop bots, spam and abuse we use Cloudflare Turnstile and keep hashed network and device identifiers for rate limits, blocks and fraud checks. We keep reports, moderation decisions, and logs of who viewed or was given access to private contact details.
- Payments: handled by Stripe. We receive your plan, billing country and payment status. We never see or store your full card number.
- Support: messages you send us.
- Technical data: server logs (IP address, browser, time, page) kept for a short time for security and fixing errors.
We do not ask for sensitive data (such as health, religion, sexual life or government ID numbers). Please do not put it in your profile, chats or AI knowledge.
3. Why we use it (and our legal basis)
| Purpose | Legal basis (EU/UK GDPR) |
|---|---|
| Run your account, pages, links, chats and groups | Contract |
| Verify your phone and keep chat free of spam | Contract; legitimate interest (safety) |
| AI front desk replies | Contract (for owners); legitimate interest of the owner (for visitors) |
| Insights for page owners | Legitimate interest; consent for the analytics cookie where the law requires it |
| Safety: spam, scams, abuse, fraud, security | Legitimate interest; legal obligation |
| Service emails and texts (codes, alerts, receipts, renewal reminders) | Contract; legal obligation |
| Product news by email | Consent, or legitimate interest where allowed (you can opt out anytime) |
| Billing, tax and accounting | Contract; legal obligation |
| Answer legal requests, enforce our terms, keep evidence for disputes | Legal obligation; legitimate interest |
Where we rely on consent, you can withdraw it at any time, as easily as you gave it. Where we rely on legitimate interest, you can object (section 11).
4. The AI front desk and automated tools
- When a visitor writes to a page with the AI front desk on, the message, recent chat history and the owner's knowledge are sent to an AI provider (OpenAI or Google Gemini) to create a reply.
- Visitors are always told they are talking to AI, and can ask for a human.
- We do not use your chats or knowledge to train our own or our providers' AI models. Our providers process data under business terms that do not allow them to train on it.
- We use automated tools (such as OpenAI moderation and Google Web Risk) to spot harmful content and unsafe links. Serious decisions, such as permanently closing an account, are reviewed by a person. We do not make decisions with legal or similarly significant effects about you based only on automated processing.
5. Who we share it with
We share data only with service providers that help run Tweely, under contracts that protect it and limit how they use it:
| Provider | What for | Where |
|---|---|---|
| Amazon Web Services | Hosting, database, email | USA |
| Cloudflare | Network, security, file storage, human checks | Global |
| Stripe | Payments and billing | USA, global |
| Web Risk link checks, Gemini AI | USA, global | |
| OpenAI | AI replies and content checks | USA |
| [SMS provider(s)] | Sending verification codes | [country] |
| OneVault | Sign-in (OneVault ID) | [country] |
We also share data: with other users as you choose (section 6); when the law requires it; to protect someone's safety; to enforce our terms and handle abuse or legal claims; and if Tweely is sold or reorganised (the new owner must protect it as this policy says).
We do not sell personal data or "share" it for cross-context behavioural advertising, and we have not done so in the past 12 months. We never share your phone number or SMS consent with third parties for their marketing.
6. What other people can see
Your public profile, links and public contact details can be seen by anyone and may appear in search engines. Private contact details are only sent to people you allow. Chats are seen by you, the people in the chat, and team members of a business page. Group members can see each other's names and messages in the group.
7. Cookies
We use a few first-party cookies: essential ones to keep you signed in and protect forms, and one analytics cookie that counts unique visitors. We do not use advertising or cross-site tracking cookies. See our Cookie Policy for the full list and your choices.
8. How long we keep data
| Data | Kept for |
|---|---|
| Account and content | Until you delete it or your account |
| Chats | Until deleted by the page owner or the account is closed |
| Phone verification records | While your account is open, plus up to 12 months to stop repeat abuse |
| Detailed visitor analytics | Up to 2 years (daily totals without personal data may be kept longer) |
| Server logs, safety logs and rate-limit data | Up to 12 months |
| Backups | Up to 35 days after deletion |
| Billing records | As long as tax law requires (often 7 years) |
| Reports, removed content, banned-account records and evidence | As long as needed for the case, to prevent a banned person returning, for legal disputes, or as the law requires |
If there is a legal dispute, an investigation or a lawful request, we may keep related data until it is fully resolved.
9. Security
We use encrypted connections (HTTPS), limited staff access, hashing of visitor and network identifiers, rate limits against scraping, and backups. No system is perfectly secure. If a breach puts your data at risk, we will tell you and the authorities as the law requires (for example, within 72 hours to the authority under GDPR and India's DPDP Rules).
10. Photos
Uploaded photos are re-encoded, which removes hidden data such as camera details and GPS location.
11. Your rights
You can edit or delete your content and delete your account in Settings, ask us for a copy of your data, and turn email alerts off in Desk. Depending on where you live, you also have these rights:
- Everyone: access, correct and delete your data, and withdraw consent.
- EU, EEA, UK and Switzerland (GDPR): access, rectification, erasure, restriction, data portability, objection (including to processing based on legitimate interest), withdrawal of consent, and the right to complain to your data protection authority.
- California and other US states (such as Colorado, Connecticut, Virginia, Texas, Oregon, Indiana, Kentucky and others with privacy laws): know what we collect and how we use it, access, delete, correct, get a portable copy, and opt out of sale, sharing, targeted ads and profiling (we do none of these). We will not treat you differently for using your rights. If we refuse your request, you can appeal by replying to our answer; if we still refuse, you can contact your state attorney general. You can use an authorised agent. We honour Global Privacy Control signals as an opt-out.
- India (DPDP Act 2023): access a summary of your data and who it was shared with, correction, completion, updating and erasure, withdrawal of consent, grievance redressal, and to nominate a person to act for you if you die or become unable to. You can complain to the Data Protection Board of India after using our grievance process.
- Sri Lanka (Personal Data Protection Act No. 9 of 2022, as amended): access, withdrawal of consent, rectification or completion, erasure, and review of decisions made only by automated processing. You can complain to the Data Protection Authority of Sri Lanka.
To use your rights, write to [privacy@tweely.app] or use Settings. We may need to confirm who you are. We answer within the time the law requires (usually one month in the EU/UK, 45 days in US states, and 90 days for grievances in India). Using these rights is free.
If you are a visitor and want data about you removed from someone's page or chat, contact that page owner, or report it to us.
12. California notice at collection
In the past 12 months we collected these categories of personal information: identifiers (name, email, handle, phone, hashed device IDs); customer records (billing details); commercial information (plans bought); internet activity (pages viewed, links clicked, referring site); coarse location (country); audio, electronic and visual information (photos and messages you upload); and inferences (none). Sensitive personal information we collect is limited to account log-in via OneVault and the content of messages to page owners, used only to provide the service, which the law allows without an opt-out. Sources, purposes, recipients and retention are described above. We do not sell or share personal information, and we do not knowingly collect it from anyone under 16.
13. Children
Tweely is only for people aged 18 and over. We do not target children and we do not knowingly collect data from anyone under 18. If we learn that a child has given us data, we close the account and delete it. If you think a child is using Tweely, please report it to [privacy@tweely.app].
14. International transfers
Tweely is hosted in the United States. If you use Tweely from another country, your data is sent to and stored in the US and other countries where our providers work. Where the law requires, we protect these transfers with the EU Standard Contractual Clauses, the UK International Data Transfer Addendum, or other lawful safeguards, and we follow any transfer restrictions set under India's DPDP Act and Sri Lanka's PDPA. You can ask us for a copy of the safeguards.
15. Law enforcement requests
We share data with police, courts or government bodies only when we receive a valid legal request, or when we believe it is needed to prevent death or serious harm. We check each request and share only what is needed. Where the law allows, we tell the person first. We report child sexual abuse material to NCMEC as US law requires.
16. Changes to this policy
We may update this policy. If a change is important, we will tell you in the app or by email before it takes effect. The date at the top shows the latest version.
17. Contact
- OneVault LLC, [OneVault LLC registered address]. Privacy: [privacy@tweely.app].
- Data Protection Officer: [DPO name and email, if appointed].
- EU representative (GDPR Art. 27): [EU representative name and address].
- UK representative: [UK representative name and address].
- India Grievance Officer: [Grievance Officer name, email and address].
- Sri Lanka contact: [Sri Lanka contact or representative, if required].