privacy.

last updated: 14 August 2026

vrrb does exactly one thing: it lets you send a buzz to a friend from your contacts. This notice explains what data we process to do that, on what legal basis, how long we keep it — and what we deliberately never do.

Who is responsible

Burhan Tutan — independent developer, Türkiye — is the data controller for everything described here (Art. 4(7) GDPR; “veri sorumlusu” under Turkish law, KVKK).

Contact for any privacy question or request: burhan.tutan@gmail.com.

What we process

Your phone number. To create your account and to let friends find you through contact matching. You sign in with a one-time code sent by SMS.

Your display name. So your friends can see who a buzz came from. You can change it any time.

Your contacts — but never in raw form. If you allow access, the numbers in your address book are normalised to international format on your device and then irreversibly hashed on our server (HMAC-SHA256 with a secret key that never leaves the server). We do not store the raw numbers or the names from your address book; only those hashed values are compared, to find which of your friends already use vrrb. You can switch contact access off at any time in your phone’s settings.

Your buzz records. Who buzzed whom, when, and which type — needed for the app to work at all, for the mutual streak counter and badges, and for abuse protection (rate limiting, blocking).

Your push token. The address your phone gives us so a buzz can reach it.

Your mute and block choices. So we can honour who you do not want to hear from.

Sync diagnostics — numbers only. After a contact sync we store counts: how many numbers were read, how many could not be interpreted and why, which country setting was used, how long the read took. This record contains no phone numbers and no names — only counts and category labels — and it is deleted after 90 days. It exists because a bug once made some users match with almost nobody and we had no way to see where it happened.

Legal basis

Performance of the contract (Art. 6(1)(b) GDPR; Art. 5(2)(c) KVKK) — your phone number, display name, buzz records and push token. Without them there is no account and no way to deliver a buzz.

Your consent (Art. 6(1)(a) GDPR; Art. 5(1) KVKK) — the hashes of the numbers in your address book. We ask for this separately inside the app before the system permission dialog, and you can say no: the app still works, you just have to invite friends yourself. You can withdraw consent at any time by switching contact access off in your phone’s settings or by deleting your account; withdrawal does not affect processing that already happened.

Legitimate interests (Art. 6(1)(f) GDPR; Art. 5(2)(f) KVKK) — rate limiting, blocking, and the sync diagnostics above, so the service stays usable, abuse-free and debuggable.

What we do NOT do

  • We do not store the raw numbers or the names from your address book.
  • We never text, call or otherwise contact the people in your address book; invitations are sent only by you, through a channel you choose.
  • We show no ads, we do not process your data for advertising, and we do not sell or rent it to anyone.
  • There is no analytics SDK, no advertising identifier and no cross-app tracking.
  • We access no location, photos, microphone or message content.
  • There is no message content at all — vrrb has no text field, only buzzes.

Where your data is stored, and who else touches it

Database and backend: Supabase, in the Frankfurt (Germany) region. For users in the EU/EEA this is not a transfer out of the EEA. Supabase’s data processing addendum incorporates the European Commission’s Standard Contractual Clauses for the cases where its own subprocessors act outside the EEA.

Push notifications: your push token and the content of a notification (sender name, buzz type) pass through Expo’s push service (United States) and then through Apple’s notification service. Expo states that it is GDPR- and Data Privacy Framework-compliant and that notification content is not stored beyond the moment of delivery. Apple states that transfers of personal data out of the EEA, the UK and Switzerland are governed by Standard Contractual Clauses.

SMS login codes: delivered through Twilio (United States), which is certified under the EU-US Data Privacy Framework and whose data protection addendum also relies on Standard Contractual Clauses and Binding Corporate Rules.

Nothing else leaves the database. Your contact hashes, your buzz history and your streaks are never sent to any of these providers.

For users in Türkiye: the notification and SMS services above are located abroad, so those two data flows are cross-border transfers under Art. 9 KVKK. They are carried out on the basis of the standard contract published by the Turkish Data Protection Authority (KVKK Kurumu) as an appropriate safeguard. Only what is listed above is transferred — your push token, the notification content, and your phone number for the login code.

How long we keep things

Account data (phone number, display name, push token): as long as your account exists.

Contact hashes: refreshed at every sync. A hash that has not appeared in any sync for 30 days is deleted automatically — so people you remove from your address book drop out on their own.

Buzz records: there is no automatic deletion. They are what streaks, stats and badges are made of, so they are kept for as long as your account is active and are deleted with it. The activity screen in the app shows a rolling 30-day window; that is a display limit, not a deletion.

Sync diagnostics: deleted automatically after 90 days.

Deleting your account (settings → delete account) permanently removes your profile, your contact hashes, your buzz history in both directions, your streaks, your badges and your mute/block list.

Your rights

You have the right of access, rectification, erasure, restriction of processing, data portability, and the right to object to processing based on legitimate interests. Where processing is based on consent, you can withdraw it at any time.

Most of this you can do yourself inside the app: change your display name, switch contact access off, or delete your account entirely. For anything else, write to burhan.tutan@gmail.com. We answer within 30 days (KVKK) and within one month (GDPR).

You can also complain to a supervisory authority: in Türkiye the Personal Data Protection Authority (KVKK Kurumu), and in the EU/EEA the authority of the country where you live.

Children

vrrb is not directed at children under 13 and we do not knowingly collect data from them. If we learn that an account belongs to someone under 13, we delete it and its data.

Changes

If this notice changes in a meaningful way, we will tell you inside the app.