Tweely

Privacy Policy

Last updated: 28 September 2026

Tweely is run by OneVault LLC, [OneVault LLC registered address] ("we", "us"). This policy explains what personal data we collect, why, who we share it with, how long we keep it, and your rights. It covers tweely.app, twee.ly, tweely.co, tweely.chat, the chat widget and our apps.

In short: we collect what we need to run Tweely and keep it safe. We do not sell your personal data, we do not "share" it for targeted ads, and we do not use your chats to train AI models. You can see, get a copy of, correct and delete your data.

1. Who is responsible for your data

2. What we collect

We do not ask for sensitive data (such as health, religion, sexual life or government ID numbers). Please do not put it in your profile, chats or AI knowledge.

3. Why we use it (and our legal basis)

PurposeLegal basis (EU/UK GDPR)
Run your account, pages, links, chats and groupsContract
Verify your phone and keep chat free of spamContract; legitimate interest (safety)
AI front desk repliesContract (for owners); legitimate interest of the owner (for visitors)
Insights for page ownersLegitimate interest; consent for the analytics cookie where the law requires it
Safety: spam, scams, abuse, fraud, securityLegitimate interest; legal obligation
Service emails and texts (codes, alerts, receipts, renewal reminders)Contract; legal obligation
Product news by emailConsent, or legitimate interest where allowed (you can opt out anytime)
Billing, tax and accountingContract; legal obligation
Answer legal requests, enforce our terms, keep evidence for disputesLegal obligation; legitimate interest

Where we rely on consent, you can withdraw it at any time, as easily as you gave it. Where we rely on legitimate interest, you can object (section 11).

4. The AI front desk and automated tools

5. Who we share it with

We share data only with service providers that help run Tweely, under contracts that protect it and limit how they use it:

ProviderWhat forWhere
Amazon Web ServicesHosting, database, emailUSA
CloudflareNetwork, security, file storage, human checksGlobal
StripePayments and billingUSA, global
GoogleWeb Risk link checks, Gemini AIUSA, global
OpenAIAI replies and content checksUSA
[SMS provider(s)]Sending verification codes[country]
OneVaultSign-in (OneVault ID)[country]

We also share data: with other users as you choose (section 6); when the law requires it; to protect someone's safety; to enforce our terms and handle abuse or legal claims; and if Tweely is sold or reorganised (the new owner must protect it as this policy says).

We do not sell personal data or "share" it for cross-context behavioural advertising, and we have not done so in the past 12 months. We never share your phone number or SMS consent with third parties for their marketing.

6. What other people can see

Your public profile, links and public contact details can be seen by anyone and may appear in search engines. Private contact details are only sent to people you allow. Chats are seen by you, the people in the chat, and team members of a business page. Group members can see each other's names and messages in the group.

7. Cookies

We use a few first-party cookies: essential ones to keep you signed in and protect forms, and one analytics cookie that counts unique visitors. We do not use advertising or cross-site tracking cookies. See our Cookie Policy for the full list and your choices.

8. How long we keep data

DataKept for
Account and contentUntil you delete it or your account
ChatsUntil deleted by the page owner or the account is closed
Phone verification recordsWhile your account is open, plus up to 12 months to stop repeat abuse
Detailed visitor analyticsUp to 2 years (daily totals without personal data may be kept longer)
Server logs, safety logs and rate-limit dataUp to 12 months
BackupsUp to 35 days after deletion
Billing recordsAs long as tax law requires (often 7 years)
Reports, removed content, banned-account records and evidenceAs long as needed for the case, to prevent a banned person returning, for legal disputes, or as the law requires

If there is a legal dispute, an investigation or a lawful request, we may keep related data until it is fully resolved.

9. Security

We use encrypted connections (HTTPS), limited staff access, hashing of visitor and network identifiers, rate limits against scraping, and backups. No system is perfectly secure. If a breach puts your data at risk, we will tell you and the authorities as the law requires (for example, within 72 hours to the authority under GDPR and India's DPDP Rules).

10. Photos

Uploaded photos are re-encoded, which removes hidden data such as camera details and GPS location.

11. Your rights

You can edit or delete your content and delete your account in Settings, ask us for a copy of your data, and turn email alerts off in Desk. Depending on where you live, you also have these rights:

To use your rights, write to [privacy@tweely.app] or use Settings. We may need to confirm who you are. We answer within the time the law requires (usually one month in the EU/UK, 45 days in US states, and 90 days for grievances in India). Using these rights is free.

If you are a visitor and want data about you removed from someone's page or chat, contact that page owner, or report it to us.

12. California notice at collection

In the past 12 months we collected these categories of personal information: identifiers (name, email, handle, phone, hashed device IDs); customer records (billing details); commercial information (plans bought); internet activity (pages viewed, links clicked, referring site); coarse location (country); audio, electronic and visual information (photos and messages you upload); and inferences (none). Sensitive personal information we collect is limited to account log-in via OneVault and the content of messages to page owners, used only to provide the service, which the law allows without an opt-out. Sources, purposes, recipients and retention are described above. We do not sell or share personal information, and we do not knowingly collect it from anyone under 16.

13. Children

Tweely is only for people aged 18 and over. We do not target children and we do not knowingly collect data from anyone under 18. If we learn that a child has given us data, we close the account and delete it. If you think a child is using Tweely, please report it to [privacy@tweely.app].

14. International transfers

Tweely is hosted in the United States. If you use Tweely from another country, your data is sent to and stored in the US and other countries where our providers work. Where the law requires, we protect these transfers with the EU Standard Contractual Clauses, the UK International Data Transfer Addendum, or other lawful safeguards, and we follow any transfer restrictions set under India's DPDP Act and Sri Lanka's PDPA. You can ask us for a copy of the safeguards.

15. Law enforcement requests

We share data with police, courts or government bodies only when we receive a valid legal request, or when we believe it is needed to prevent death or serious harm. We check each request and share only what is needed. Where the law allows, we tell the person first. We report child sexual abuse material to NCMEC as US law requires.

16. Changes to this policy

We may update this policy. If a change is important, we will tell you in the app or by email before it takes effect. The date at the top shows the latest version.

17. Contact