Effective date: 19 August 2026
Our first responsibility is to the people who use Vibebo. Privacy and safety are considered from the moment we design a feature as a governing policy.
Vibebo is built for anonymous participation. We do not reveal the identity of an anonymous sender to the person receiving their submission or to other users when they used Vibebo. Paying for Vibebo does not provide greater access to an anonymous sender’s identity or Vibebo’s internal safety information.
Anonymous does not mean unaccountable. Vibebo may process limited information internally where reasonably necessary to prevent abuse, enforce blocks, investigate reports, moderate content, secure the Service and protect users. We use that information for defined purposes, not to turn anonymity into surveillance.
This Privacy Policy explains how Webcilo Inc. Limited collects, uses, shares and protects personal information when people use Vibebo.
1. WHO WE ARE
Vibebo is provided by Webcilo Inc. Limited (“Webcilo”, “Vibebo”, “we”, “us” or “our”).
Webcilo Inc. Limited is a private company limited by shares registered under the laws of the Federal Republic of Nigeria.
RC Number: 1974231
Registered address: 5 Ndi-Orji Road, Umaju, Mpam, Imo State, Nigeria
For the personal information described in this Privacy Policy, Webcilo Inc. Limited is generally the controller unless we expressly explain that a different arrangement applies.
Vibebo is used in different countries. The privacy laws that apply can therefore depend on where you are and on the processing involved.
HOW THIS POLICY APPLIES
This policy explains our general privacy practices. Where the law in a particular country or region gives you additional rights or requires additional information, the relevant jurisdiction-specific section near the end of this policy applies alongside the rest of this policy.
Privacy and data-protection requests can also be submitted using the contact route at vibebo.com/contact and should be marked “Data Protection” where possible.
2. HOW PRIVACY LAWS APPLY TO VIBEBO
Webcilo Inc. Limited is established in Nigeria, and our processing is subject to the Nigeria Data Protection Act 2023 and other applicable Nigerian law. Because Vibebo can be used in other countries, privacy and data-protection laws in those places may also apply to particular processing. Where they do, we comply with the mandatory requirements that apply to us.
This policy explains our practices wherever you use Vibebo. Additional information for Nigeria and the United Kingdom appears near the end of this policy. Those sections supplement, rather than replace, the rest of this policy.
3. WHO THIS POLICY APPLIES TO
This policy applies when you:
- create or manage a Vibebo account or profile;
- visit a Vibebo page, profile or Channel;
- send an anonymous message, question, opinion, feedback, wish or other response;
- attach a voluntary hint to a submission;
- receive or manage submissions;
- publish or interact with content on VibeboX or another public area;
- react, comment, follow, save or share content;
- join, administer or participate in a Channel;
- use blocking, reporting or moderation features;
- contact support or make a complaint;
- buy a subscription or paid feature; or
- use our website, apps or related services.
4. WHAT “ANONYMOUS” MEANS ON VIBEBO
When Vibebo describes a submission as anonymous, it means that Vibebo does not present the sender’s identity to the recipient or other users merely because the sender made that submission.
It does not mean that no technical or personal information is processed by Vibebo.
To operate an anonymous service safely, we may need to recognise the same browser, device, visitor, account or activity pattern internally. For example, we may need to recognise that a participant has previously been blocked so that the block can continue to work.
We may therefore use internal identifiers and limited technical or behavioural signals for safety, security, moderation, abuse prevention and other purposes described in this policy.
We do not provide recipients with raw IP addresses, device identifiers, technical fingerprints or internal safety profiles as clues about who sent an anonymous submission.
5. SENDER-PROVIDED HINTS
Where available, a sender may choose to include a hint with an anonymous submission.
A hint is information the sender voluntarily chooses to reveal. It is not an inferred clue generated by Vibebo from an IP address, device, location, network or behavioural profile.
The recipient may be able to view the hint. If the interface explains that the submission or hint can be published, the sender should only provide information they are comfortable potentially becoming public.
6. INFORMATION WE COLLECT
The information we process depends on how you use Vibebo.
6.1 Account and profile information
We may collect information such as:
- username, display name or profile name;
- email address;
- password or authentication credentials in protected form;
- profile image, biography or other profile information;
- date of birth or age information where provided or required;
- account, privacy, notification and moderation settings;
- subscription or plan status;
- account creation, login and security information; and
- other information you choose to add to your account.
6.2 Anonymous submissions
When a person sends something through Vibebo, we may process:
- the text or other content of the submission;
- media or attachments included by the sender;
- a voluntary sender hint;
- the profile, link or Channel to which it was submitted;
- the date and time of submission;
- an internal submission identifier; and
- limited safety and technical information described below.
The recipient receives the submission as anonymous unless the sender voluntarily includes identifying information in the content or hint.
6.3 Sender and visitor safety information
To prevent abuse and make safety controls work, we may create or maintain an internal sender, visitor, browser or device profile or identifier.
Depending on the feature and the risk involved, this may include:
- an internal visitor, sender, browser or device identifier;
- IP address and information derived from an IP address;
- browser type and version;
- operating system and device category;
- network or connection information;
- timestamps and activity frequency;
- rate-limiting and anti-spam information;
- block relationships;
- reports associated with activity;
- moderation or enforcement history;
- indicators of suspicious, automated, manipulative or abusive behaviour; and
- other limited signals reasonably necessary to secure the Service or protect users.
We do not collect this information for the purpose of selling sender identity clues to recipients.
6.4 Profile visits and audience activity
When a person visits or interacts with a Vibebo profile, page, link or Channel, we may measure information such as:
- page, profile or Channel visits;
- date and time;
- referring source or campaign information;
- broad geographic information derived from technical data;
- device category, browser or operating system;
- new or returning activity;
- interactions with features or content; and
- other usage events needed to understand audience activity.
This information may be used to produce privacy-protected audience insights for the relevant account or Channel and to improve Vibebo.
6.5 Aggregate audience insights
Vibebo is designed so that recipient-facing analytics describe audiences and patterns rather than expose individual visitors or anonymous senders.
We may therefore:
- aggregate information before showing it to an account holder;
- suppress a statistic where too few eligible people are represented;
- reduce geographic precision;
- group devices or attributes into broader categories;
- avoid exposing exact individual timelines;
- prevent analytics from being linked to a specific anonymous submission; and
- apply other privacy thresholds where a result could make an individual reasonably identifiable.
For example, we may show that a profile received a certain number of visits or that activity increased during a period without showing that a particular anonymous sender used a particular device from a particular location immediately before sending a message.
6.6 Public content and interactions
Some Vibebo content can become public.
Where a recipient chooses to publish an anonymous submission with a response, we may process and display:
- the submitted content;
- any material the publishing feature permits to accompany it;
- the recipient’s response;
- comments;
- reactions;
- saves;
- follows;
- shares; and
- associated engagement information.
Publishing a submission does not by itself publish Vibebo’s internal technical information about the sender.
A sender may nevertheless identify themselves through the words, media or voluntary hint they choose to include.
6.7 Channels and collaborative access
Where an account holder creates or uses a Channel, we may process:
- Channel name and configuration;
- owners, administrators and authorised members;
- permissions and access history;
- submissions made to the Channel;
- moderation and publishing activity; and
- collaboration records needed to operate the feature.
Authorised Channel members may be able to see information that would otherwise be available only to an individual account holder, subject to their assigned permissions.
6.8 Blocks, reports and moderation
If content, a sender, visitor or account is blocked or reported, we may process:
- the relevant content and identifiers;
- the reason for the block or report;
- evidence supplied with the report;
- related activity reasonably necessary to investigate;
- moderator decisions and notes;
- enforcement history;
- appeals or complaints; and
- correspondence about the case.
6.9 Support and communications
If you contact us, we may process your contact details, account information, correspondence and other information reasonably necessary to respond, investigate or resolve the matter.
6.10 Payments and subscriptions
Where paid services are offered, we may process:
- account and plan information;
- transaction references;
- billing country or address where required;
- payment status;
- refunds, cancellations and disputes; and
- records needed for accounting, tax and fraud prevention.
Payment card or bank information may be processed directly by our payment provider rather than stored by Vibebo. The relevant payment provider will be identified where required.
6.11 Technical, diagnostic and security logs
Our systems may process server requests, IP addresses, timestamps, browser and device information, error logs, diagnostic events, security events and other information needed to operate, troubleshoot and secure Vibebo.
6.12 Cookies, local storage, SDKs and analytics
We use cookies and similar technologies for functions such as authentication, security, preferences and analytics.
We also use Google Analytics to help us understand how Vibebo itself is used. Google Analytics is separate from the recipient-facing audience insights described above.
Our Cookie & Tracking Technologies Policy explains the technologies, purposes and choices in more detail.
7. SPECIAL CATEGORY OR HIGHLY SENSITIVE INFORMATION
Vibebo does not ask anonymous senders to provide special category information such as health information, religious beliefs, political opinions, sexual orientation or biometric information merely to use the ordinary messaging feature.
However, because users choose what to write, a submission or report may contain sensitive information.
Where such information is personal information, we process it only where we have a lawful basis and any additional legal condition required by applicable law for that type of information. We may restrict or delete information where we do not need it or cannot lawfully process it.
Do not submit another person’s sensitive personal information unless you have a lawful and appropriate reason to do so.
8. WHERE INFORMATION COMES FROM
We may obtain information:
- directly from you;
- automatically from your browser, device, app or interaction with Vibebo;
- from another Vibebo user, for example when they report content or invite you to a Channel;
- from payment, security, analytics or other service providers; and
- from public or lawful sources where reasonably necessary to investigate fraud, abuse, security incidents or legal claims.
9. WHY WE USE INFORMATION AND OUR LAWFUL BASES
We use personal information only where we have a lawful basis under applicable law.
Depending on the processing, our bases may include performance of a contract, legitimate interests, legal obligation and consent.
Purpose: create, authenticate and operate an account.
Typical information: account, profile, authentication and settings information.
Typical lawful basis: performance of our contract with the account holder.
Purpose: deliver anonymous submissions and operate recipient features.
Typical information: submissions, internal identifiers, routing and timestamps.
Typical lawful basis: performance of our contract where applicable and our legitimate interests in providing the Service to senders, recipients and visitors.
Purpose: prevent spam, abuse, harassment, fraud and circumvention of blocks.
Typical information: sender/visitor safety information, technical signals, block relationships and activity patterns.
Typical lawful basis: our legitimate interests in protecting users and the integrity of Vibebo; legal obligation where a specific law requires processing.
Purpose: investigate reports and moderate content.
Typical information: content, reports, safety signals, enforcement records and correspondence.
Typical lawful basis: legitimate interests and, where applicable, legal obligation.
Purpose: comply with online-safety obligations, valid legal process and other legal duties.
Typical information: information relevant to the legal requirement.
Typical lawful basis: legal obligation and, where appropriate, legitimate interests.
Purpose: provide privacy-protected audience insights.
Typical information: profile visits, engagement events, broad attributes and aggregate statistics.
Typical lawful basis: performance of a contract where analytics form part of an account service and/or legitimate interests in helping users understand and improve their Vibebo presence, subject to privacy safeguards.
Purpose: understand and improve Vibebo itself.
Typical information: product usage, diagnostic and analytics information.
Typical lawful basis: legitimate interests, consent, or another basis permitted by applicable law depending on the technology and configuration used.
Purpose: operate cookies and similar technologies for analytics where permitted.
Typical information: information needed to produce aggregate service-usage statistics.
Typical lawful basis: consent, legitimate interests or another basis permitted by applicable law, together with any device-storage or access rules that apply in your location.
Purpose: respond to support, safety or privacy enquiries.
Typical information: contact details, correspondence and relevant account or activity information.
Typical lawful basis: contract, legitimate interests and/or legal obligation depending on the request.
Purpose: process subscriptions and payments.
Typical information: account, transaction and billing information.
Typical lawful basis: contract and legal obligation.
Purpose: send direct marketing where used.
Typical information: contact details and communication preferences.
Typical lawful basis: consent or legitimate interests where permitted by applicable data-protection and electronic-marketing rules. You can opt out of marketing at any time.
Purpose: establish, exercise or defend legal claims and protect rights.
Typical information: relevant account, content, safety, transaction or correspondence records.
Typical lawful basis: legitimate interests and legal obligation where applicable.
10. OUR LEGITIMATE INTERESTS
Where we rely on legitimate interests, those interests may include:
- operating and improving Vibebo;
- protecting users from harassment, abuse and unwanted contact;
- making blocks effective;
- preventing spam, fraud, manipulation and security attacks;
- investigating reports;
- enforcing our Terms and safety rules;
- understanding service performance;
- providing useful, privacy-protected audience insights;
- protecting Webcilo and others from legal or security threats; and
- establishing, exercising or defending legal claims.
We assess whether the processing is necessary and whether our interests are overridden by the rights and interests of the people affected. We do not treat “legitimate interests” as permission to collect information without limits.
11. PRIVACY BY DESIGN FOR ANONYMOUS SENDERS
Our privacy design follows these principles:
- Vibebo may recognise a sender internally where necessary for safety;
- the recipient does not receive the sender’s internal identity or technical profile;
- subscriptions do not unlock internal sender identity clues;
- hints are chosen by senders, not manufactured from technical data;
- audience analytics are designed to describe groups rather than individuals; and
- information collected for safety is not repurposed into recipient-facing entertainment or curiosity features merely because it could be commercially valuable.
We may change technical methods as the Service develops, but a material change to these privacy purposes will be reflected in this policy before or when required by law.
12. HOW WE SHARE INFORMATION
We may share personal information where reasonably necessary with:
- cloud hosting and infrastructure providers;
- content-delivery, security and anti-abuse providers;
- analytics providers, including Google Analytics;
- email, notification and communications providers;
- payment processors and app stores;
- customer support providers;
- moderation or safety service providers;
- professional advisers such as lawyers, auditors and accountants;
- corporate transaction counterparties where subject to appropriate safeguards; and
- regulators, courts, law-enforcement bodies or other competent authorities where disclosure is required or permitted by law.
We require processors acting on our behalf to process personal information under appropriate contractual terms and security requirements.
We do not sell an anonymous sender’s identity or internal safety profile to recipients.
13. GOOGLE ANALYTICS
We use Google Analytics to understand how people use Vibebo and to improve the Service.
Depending on our configuration, Google Analytics may process information such as page views, events, browser/device characteristics, approximate location and first-party identifiers used to distinguish users or sessions.
We do not use Google Analytics as a recipient-facing sender-identification tool.
Where applicable law requires consent before we use non-essential analytics technologies, we will obtain that consent. Where applicable law permits analytics under another lawful mechanism or exception, we may rely on that mechanism only when its conditions are met. Our Cookie & Tracking Technologies Policy provides further information, including UK-specific information about storage and access technologies.
14. INTERNATIONAL PROCESSING AND TRANSFERS
Webcilo Inc. Limited is established in Nigeria. Information may therefore be processed in Nigeria in connection with the operation of Vibebo.
We may also use service providers located in the United Kingdom, United States, European Economic Area or other countries.
When personal information is transferred across borders, we use safeguards required by the laws that apply to the transfer. Depending on the circumstances, this may include:
- adequacy decisions or regulations;
- approved standard contractual clauses or data-transfer agreements;
- contractual addenda or other approved transfer terms;
- another legally recognised safeguard; or
- a statutory exception where it is appropriate to rely on one.
We also assess the security and data-protection arrangements of relevant providers.
You can contact us for more information about the safeguards relevant to a particular transfer.
15. HOW LONG WE KEEP INFORMATION
We do not keep personal information merely because storage is available.
We determine retention according to the purpose for which information is used, the sensitivity and risk of the information, user expectations, legal requirements, the need to enforce blocks or safety measures, dispute and complaint periods, security needs and backup cycles.
In general:
- account and profile information is kept while an account is active and for a limited period after closure where needed for deletion processing, security, disputes, legal obligations or backups;
- private submissions are kept while needed to provide the inbox or until they are deleted, subject to limited backup, moderation, safety or legal retention;
- published content may remain while it is published or until deleted, removed or no longer required, subject to legal and backup needs;
- raw technical logs and individual-level analytics are retained for shorter periods than information needed to maintain an account, and are deleted, reduced or aggregated when the individual-level detail is no longer necessary;
- block-related identifiers may be retained for as long as needed to make a block effective and to prevent straightforward circumvention;
- reports, moderation and serious-abuse records may be retained for as long as reasonably necessary to investigate, handle appeals, recognise repeated abuse, comply with law and protect users;
- payment, tax and accounting records are retained for periods required by applicable financial and tax law; and
- genuinely anonymous aggregate statistics may be retained for longer because they no longer identify an individual.
We maintain an internal retention schedule and periodically review whether identifiable information is still necessary.
16. SECURITY
We use technical and organisational measures intended to protect personal information against unauthorised access, loss, alteration, disclosure or destruction.
Depending on the system and risk, measures may include:
- encryption in transit and, where appropriate, at rest;
- access controls and restricted administrative permissions;
- pseudonymous internal identifiers;
- security and audit logging;
- rate limiting and abuse detection;
- authentication and session controls;
- backups and recovery processes;
- vulnerability and dependency management;
- processor security review; and
- incident-response procedures.
No online system can guarantee absolute security.
17. DATA BREACHES
We maintain procedures for investigating personal-data breaches and assessing whether notification to affected individuals, regulators or other competent authorities is required.
Where applicable law requires us to notify a regulator or affected individuals, we will do so within the timeframe and in the manner required by that law.
18. CHILDREN AND YOUNG PEOPLE
Our Terms currently require a person to be at least 18 to create an account, submit User Content, send an anonymous submission, manage a Channel or purchase a paid service, unless we expressly provide a different age rule for a particular feature or jurisdiction.
People aged 13 to 17 may only access parts of Vibebo expressly made available to them and where any required parental or guardian involvement is satisfied. Use by children under 13 is not permitted.
Age restrictions do not remove our responsibility to assess whether children are nevertheless likely to access an in-scope service.
Where applicable, we consider children’s best interests and use age-appropriate privacy and safety measures. These may include higher privacy defaults, reduced collection, restrictions on profiling, limits on location precision, appropriate age-assurance measures and additional content-safety protections.
19. AUTOMATED SAFETY SYSTEMS AND PROFILING
We may use automated systems to detect or prioritise spam, abuse, suspicious activity, security threats or potential rule violations.
These systems may consider signals such as submission frequency, reports, blocks, technical indicators, repeated activity patterns or previous enforcement information.
Automated safety processing is not used to provide recipients with clues about an anonymous sender’s identity.
Where applicable law provides rights in relation to a significant decision based solely on automated processing, we will provide the required information and safeguards, which may include an opportunity to obtain human review or challenge the decision.
20. YOUR DATA-PROTECTION RIGHTS
Depending on your location, the circumstances and the lawful basis used, applicable data-protection law may give you rights to:
- obtain confirmation that we process your personal information and request access to it;
- correct inaccurate or incomplete information;
- request deletion of information;
- request restriction of processing;
- receive certain information in a portable format;
- object to certain processing;
- withdraw consent where processing is based on consent; and
- obtain safeguards in relation to certain automated decisions.
These rights are not absolute. A legal exemption or competing obligation may apply in some circumstances.
To exercise a right, use the contact route at vibebo.com/contact and identify the request as a data-protection request.
We may ask for information reasonably necessary to verify that the request relates to you. We will not require more identification than is proportionate to the request.
21. RIGHTS REQUESTS FROM ANONYMOUS SENDERS
Because Vibebo is designed so that anonymous senders do not have to identify themselves to recipients, locating anonymous activity for a rights request can be more difficult.
We may ask you for information that enables us to locate the relevant record, such as an internal identifier available on your device, the approximate time of submission, the destination profile or other information reasonably necessary to find and verify the record.
We will not reveal an anonymous sender’s identity to a recipient merely because either person makes a data-protection request.
22. YOUR RIGHT TO OBJECT
Where we rely on legitimate interests, you may have the right to object to processing relating to your particular situation.
You have an absolute right to object to processing of your personal information for direct marketing.
Where applicable law requires an objection mechanism for a cookie or similar technology, we will provide the required way to object.
You can exercise an applicable objection through the privacy/cookie controls made available by Vibebo or through our data-protection contact route.
23. WITHDRAWING CONSENT
Where we rely on consent, you can withdraw that consent at any time using the relevant setting or by contacting us.
Withdrawal does not make processing carried out before withdrawal unlawful.
24. DATA-PROTECTION COMPLAINTS
If you believe we have handled your personal information incorrectly, you can make a data-protection complaint through vibebo.com/contact and mark it “Data Protection Complaint”.
We handle data-protection complaints in accordance with applicable law. Our process includes:
- providing an accessible way to make the complaint;
- acknowledging receipt within any period required by applicable law;
- taking appropriate steps to investigate without undue delay;
- keeping you appropriately informed; and
- notifying you of the outcome.
You may also have the right to complain to the data-protection regulator or supervisory authority in your jurisdiction. Additional information for Nigeria and the United Kingdom appears below.
You do not have to complain to us before exercising a right to approach a regulator where the law gives you that right.
25. THIRD-PARTY LINKS AND SERVICES
Vibebo may contain links to third-party services. A third party that independently determines how it processes your personal information is responsible for its own privacy practices.
Review the third party’s privacy information before providing personal information to it.
26. ADDITIONAL INFORMATION FOR USERS IN NIGERIA
For people in Nigeria, the Nigeria Data Protection Act 2023 and related requirements overseen by the Nigeria Data Protection Commission (“NDPC”) apply to Webcilo’s processing where applicable.
Depending on the circumstances, the Act provides rights including the right to be informed, access personal data, request rectification, object to or restrict processing, request data portability or erasure, obtain safeguards in relation to certain automated decisions, withdraw consent where applicable, and complain to the NDPC.
You can exercise applicable rights through vibebo.com/contact. You may also contact or complain to the NDPC using the channels published by the Commission.
27. ADDITIONAL INFORMATION FOR USERS IN THE UNITED KINGDOM
For people in the United Kingdom, the UK GDPR, Data Protection Act 2018, PECR and other applicable UK privacy rules may apply to relevant processing.
Where UK complaint-handling rules apply, we provide a clear complaint route, acknowledge qualifying data-protection complaints within 30 days, investigate appropriately and communicate the outcome.
Where a personal-data breach is notifiable under UK GDPR, we notify the Information Commissioner without undue delay and, where feasible, within 72 hours after becoming aware of it.
Our UK GDPR representative is Stackweaver Limited, Company No. NI738441, 17 Sandel Village, Knocklynn Rd, Coleraine, BT52 1WW, United Kingdom. Email: [email protected]. Stackweaver acts as our contact point in the United Kingdom for matters relating to Webcilo’s UK GDPR obligations.
The Cookie & Tracking Technologies Policy contains additional UK-specific information about PECR and storage/access technologies.
28. CHANGES TO THIS POLICY
We may update this policy when our products, providers, processing or legal obligations change.
Where we begin using personal information for a materially new purpose, we will provide the required information before or when the new processing begins.
Where a change materially affects users, we will take reasonable steps to bring it to their attention.
The effective date at the top of this policy shows when the current version applies.
29. CONTACT US
Webcilo Inc. Limited
RC Number: 1974231
5 Ndi-Orji Road
Umaju, Mpam
Imo State, Nigeria
Privacy requests and complaints: use the contact method published at vibebo.com/contact and mark the request “Data Protection”.