1. Introduction
This Privacy Policy explains how we collect, use, and protect your information when you use Buddy List, provided by WexCode LLC ("we," "us," or "our"). Our Service is designed for users 16 years of age and older and operates on the principle of Data Minimization.
This Privacy Policy serves as our Notice at Collection under California law.
2. Information We Collect
We may collect personal information you provide directly and usage data:
- Identifiers: Name, Email Address, and Phone Number.
- Pseudonymized Identifiers: Internal UUIDs used for server requests and telemetry.
- Usage Data: Information about app state (foreground/background) and "Availability" status.
- Connection Data: Records of connections between users.
3. How We Use Your Data
We use your information to provide, maintain, and improve Buddy List, and to communicate with you about your account. This includes:
- Enabling friend discovery through phone number matching.
- Sending notifications about friend availability and connection requests.
- Debugging and improving the Service.
4. Contact Matching (Address Book)
To find friends, you may grant the app access to your device's contacts.
- Phone Numbers Only: We only transmit phone numbers from your address book to our server. We do not access or upload names, photos, or other contact details.
- No Persistence: These phone numbers are processed in-memory to find matches and are immediately discarded. We do not store your contact list in our database.
5. Visibility and Discovery
- Discovery: By providing your phone number, you agree that other users who already have your number in their device contacts may identify you as a user.
- Privacy Gating: Your phone number is hidden from other users by default. It is only visible to users you have explicitly approved through a connection request.
6. Third-Party Sharing
We do not sell your personal information. We may share data with service providers only as necessary to provide the Service:
- Apple: Push notification delivery (APNs).
- Fly.io: Application hosting and API logic.
- Neon: Managed database storage.
- Resend: Transactional email and verification.
All third-party service providers are contractually required to protect your data with security measures equivalent to our own.
7. Pseudonymization and Retention
Our server logs utilize UUIDs rather than raw personal information. This ensures that logs are functionally meaningless if an account is deleted. We retain technical logs for approximately 30 days for debugging purposes, after which they are purged.
8. California Privacy Rights (CCPA/CPRA)
If you are a California resident, you have the right to:
- Right to Know: Request access to the personal data we store about you.
- Right to Correct: Request correction of inaccurate personal data we hold about you.
- Right to Delete: Request that we delete your personal data.
- Right to Opt-Out: Opt out of any future "sale" of your data (we do not currently sell data).
- Right to Non-Discrimination: We will not discriminate against you for exercising these rights.
- Exercise Rights: To exercise these rights, use the "Delete Account" feature in the app or contact us at legal@wexcode.com.
9. Sensitive Personal Information
We do not collect "Sensitive Personal Information" as defined by California law (such as precise geolocation, racial/ethnic origin, or biometric data) for the purpose of inferring characteristics about you.
10. Security
We use industry-standard measures to protect your data, including encryption in transit and at rest. However, no method of transmission over the internet is 100% secure, and we cannot guarantee absolute security.
11. Activity Logging
When you use the app, we log your availability status and connection state to provide the core service. This activity logging is essential to show your friends when you're available and is disclosed in Section 2 (Information We Collect).
12. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of any material changes by posting the new policy within the app. Your continued use of the Service after changes constitutes acceptance of the updated policy.
13. Location Data
Buddy List does not collect or use your device's location data. We do not access GPS, Wi-Fi location, or any other location services.
14. Age Requirement
The Service is for users 16 years of age or older. We do not knowingly collect data from anyone under 16. If you are between 16 and 17, the privacy protections described throughout this policy—including account deletion, privacy-by-default for your phone number, and our commitment to not profile users—apply equally to you. Parents or guardians may contact us at legal@wexcode.com regarding their child's account.
15. Contact
Questions about this Privacy Policy can be directed to legal@wexcode.com.