This Privacy Policy explains what information WaveLen LLC ("WaveLen," "we," "us") collects through the WaveLen mobile app, why we collect it, and the choices you have. By using WaveLen you agree to the collection and use of information as described here.
Account information. Email address, password (stored by Firebase Authentication, never in plain text by us), username, bio, profile photo, and date of birth (used only to confirm you meet our minimum age requirement — see Section 6).
Content you create. Posts, comments, likes, saves, messages, voice notes, and any photos or videos you upload.
Social graph. Who you follow and who follows you, and the visibility group (e.g. Close Friends, Family, Inner Circle) you assign to posts and followers.
Contacts (optional). If you choose to use "Find friends from your contacts," we read the email addresses in your device's contact list and convert them to one-way SHA-256 hashes on your device before checking for matches against other WaveLen users' hashed emails — the actual email addresses in your contacts are never sent to or stored by us. This requires granting contacts permission on your device, and you can decline it entirely.
Being found by people who know you. When you sign up, we store a one-way SHA-256 hash of your own email address (never the address itself) so that other users who have your email in their contacts can find you with "Find friends." You can turn this off anytime in Settings → Privacy ("Let people find me by email"), which deletes the stored hash. It is off for users under 18, and they are never shown in anyone's suggestions.
Communications data. Direct messages and voice notes you send to other users, stored to deliver them and let you view your conversation history.
Device, diagnostic, and usage data. We use Firebase Crashlytics to collect crash and error reports (device model, OS version, and a pseudonymous identifier tied to crashes, not your name or email) so we can find and fix bugs. We use Firebase Performance Monitoring to measure how quickly the app starts and loads, how smoothly screens draw, and how long key screens such as your feed and profiles take to load; these measurements come with your device model, OS version, app version, IP address, and a Firebase installation identifier, and we do not attach your WaveLen account ID to them. We use Firebase Analytics to understand how WaveLen is used: which screens are opened, and that actions such as signing up, posting, commenting, following, and sending messages happened, along with their type (for example, a photo post or a voice message) but never their content. Analytics events are associated with your WaveLen account ID, a random internal identifier that is not your name or email, so we can see how usage changes over time. They also include device and app information Firebase collects automatically, such as device model, OS version, app version, language, and an approximate location that Google derives from your IP address. We turn off Firebase's collection of your advertising ID, and we do not use this data for advertising. We use Firebase Cloud Messaging to deliver push notifications, which requires a device push token.
Daily time limit. If you set a daily time limit, we count how many minutes you use WaveLen each day (on the app and website together) so we can pause everything but messages once you reach it. Only you can see this count; it's kept per day, and deleted with your account.
Time zone. We store your device's time zone (for example "America/Chicago") so quiet hours and your daily notification limit follow your own clock. Only you can see it, and it's deleted with your account.
Automated content moderation. To find content that breaks our Terms of Service, some of what you upload is checked automatically by our service providers, before or shortly after other people can see it:
If a check flags your content, it may be hidden and sent to our team for review. If text is flagged as a possible child-safety concern, your ability to send messages is paused until a person reviews it.
When we hide or remove something of yours, we tell you what and why under Settings → Account status in the app or on the website, where you can also appeal a decision about hidden content. That record keeps a short excerpt of the affected text and anything you write in an appeal, and is deleted with your account. We don't send these notices for child-safety flags, which always go to a person.
Video captions. When you post a video or add one to your profile, its audio is sent to Google Cloud Speech-to-Text to create automatic captions. The transcript is saved with the video as a caption file that anyone who can see the video can turn on, is checked by the text moderation described above, and is shown to our review team with the video. Captions are deleted when the video or your account is deleted.
We do not sell your personal information, and we do not use your content or messages to serve third-party advertising.
We use the following service providers to operate WaveLen. Each processes data on our behalf under its own data processing terms:
We may also disclose information if required by law, to protect the rights and safety of WaveLen or our users, or in connection with a merger, acquisition, or sale of assets (with notice to you where required).
Other users can see any content you post publicly or share with a visibility group, including your username, profile photo, bio, and posts. Anyone you message can see the content of those messages. A post you share with everyone can also be opened from a link to it (wavelen.app/p/...) by someone without a WaveLen account, showing that post with your username and profile photo. These links don't work for posts shared with a Circle, for private accounts, or for anyone under 18, and the pages are marked so search engines don't list them.
We retain your account information and content for as long as your account is active. If you delete a post, comment, like, or follow, it is removed immediately. If you delete your account, we keep it (hidden from everyone else) for 30 days so you can restore it, then delete it. Messages you send remain visible to the other participant even if you later delete your account, since deleting your account only removes your own copy of the conversation and identity from it.
Crash, performance, and usage data is held by Google on our behalf for a limited time and then deleted automatically: crash reports for 90 days; performance data for 30 days where it's linked to an IP address and 60 days otherwise; individual Analytics events for 2 months; and the information Analytics keeps about you as a user, including the account ID it's associated with, for 14 months after your last activity. Summary reports that don't identify you may be kept longer. Deleting your WaveLen account doesn't remove this data immediately; it expires on that schedule.
When content is flagged or held for review, a report about it (which may include the content or a video's transcript) is kept until the account that posted it, or the account that reported it, is deleted.
Export your data. Sign in and go to Settings → Your Data → Download your data for a JSON export of your profile, posts, comments, likes, saves, and follows.
Delete your account. Sign in and go to Settings → Account → Delete account. Your account is hidden from everyone right away and permanently deleted 30 days later: your profile, posts, comments, likes, saves, follows, and notifications, and your identity in your conversations. If you change your mind, sign back in within those 30 days to restore it; you can also choose to delete it immediately at that point. Once deleted, it cannot be undone.
Notification preferences. You can disable push notifications entirely, or by category, from Settings after signing in.
Private account. Go to Settings → Privacy → Private account. While it's on, only people you approve can follow you and see your posts and stories; anyone else still sees your username, photo, bio and post count. You can switch back to public at any time, which also approves anyone waiting on a follow request.
Usage and performance data. In the current version of the app, go to Settings → Privacy → "Help improve WaveLen" to turn off Analytics and Performance Monitoring on your device at any time. Crash reports stay on so we can fix bugs that stop the app from working.
Depending on where you live, you may have additional rights over your personal information (for example, under the GDPR or CCPA), including the right to access, correct, or object to processing of your data. Contact us using the details below to exercise these rights.
WaveLen requires users to be at least 16 years old. We ask for your date of birth at signup and reject registrations from anyone younger. WaveLen is not directed at children, and we do not knowingly collect personal information from anyone under our minimum age. If we learn that we have collected information from a user under the required age, we will delete that account and its data.
Accounts belonging to users aged 16-17 get a few additional protections: direct messages can only be started by accounts that already follow each other back, and 16-17 accounts are left out of "people you may know" and similar suggestion features. In the current version of the app, Analytics and Performance Monitoring are also turned off for these accounts (crash reports are still collected so we can fix bugs). These protections lift automatically once the account turns 18. New 16-17 accounts also start as private accounts (see Private account above); they can switch to public in Settings at any time, and an account stays private until its owner changes it.
We use industry-standard safeguards, including Firebase Authentication and access-controlled databases, to protect your information. No method of transmission or storage is 100% secure, and we cannot guarantee absolute security.
Our service providers may process and store data in countries other than your own. By using WaveLen, you consent to your information being transferred to and processed in such countries.
We may update this Privacy Policy from time to time. If we make material changes, we will notify you in-app or by email before they take effect. Continued use of WaveLen after changes take effect constitutes acceptance of the updated policy.
Questions about this policy or your data can be sent to wavelenapp@outlook.com.