Privacy Policy
This Privacy Policy explains how Veylo collects, uses, stores, shares, and protects information when students use the Veylo campus social app and related support pages.
Who Operates Veylo
Veylo is operated by John Tawadros, an individual based in Queensland, Australia. In this Privacy Policy, “Veylo”, “we”, “us”, and “our” refer to John Tawadros as the operator of the Veylo service.
Information We Collect
Veylo may collect the following information when you use the app:
- Account information, including email address and authentication identifiers.
- Profile information, including first name, last name, display name, username, university, campus, degree or course, year level, and student email verification status.
- Campus status information, including general campus, zone label, visibility choice, status text, and status update times.
- Social information, including friend requests, accepted friend connections, group membership, messages, feed posts, feed comments, report submissions, block lists, and related timestamps.
- Profile photo information, including pending profile photo submissions and approved public avatar URLs.
- Notification information, including Expo push tokens, device type, token status, last-seen times, notification preferences, and in-app notification records.
- Optional support or beta feedback information, including your message, the screen you identify, severity, app version, platform, operating system version, app ownership, and execution-environment details when you send feedback through the app.
Location And Campus Presence
Veylo uses device location only when you choose a location-based campus status feature. A manual campus check uses foreground location permission. If you enable automatic campus tracking, Veylo also requests background location permission and registers campus geofences so the operating system may notify the app when your device enters or leaves a supported campus area while the app is in the background. Background behaviour depends on your device, operating system, permission settings, and platform limitations.
To determine campus presence, the app obtains coordinates from the device and compares them on the device with configured campus zones. If a fresh position is unavailable, the app may use a recent last-known location that is no more than approximately five minutes old. In the normal campus-status flow, Veylo sends its backend only the derived result, such as on-campus or off-campus, a campus or zone label, and related status times. Veylo does not intentionally send or store exact GPS coordinates in its backend as part of that normal flow. Your device operating system and Apple or Google location services may process exact location information to provide the location result under their own terms and privacy practices.
You can turn off automatic campus tracking in Veylo and can revoke location permission in your device settings. Turning it off stops future automatic checks, but it does not by itself erase a campus status already stored in Veylo. You can update or hide that status using Veylo’s privacy controls or delete your account.
How We Use Information
We use information to provide app functionality, including:
- Creating and managing accounts.
- Helping users choose university, campus, and degree details.
- Showing campus status to accepted friends according to app privacy controls.
- Supporting friend discovery, friend requests, messages, group chats, and campus feed posts.
- Reviewing profile photo submissions before they become public profile pictures.
- Sending optional push notifications for friend requests, messages, reactions, and campus status alerts when you allow them.
- Maintaining security, preventing abuse, responding to reports, debugging issues, and improving reliability.
Storage And Service Providers
Veylo uses Supabase for authentication, database storage, file storage, and related backend services. Supabase stores the account, profile, privacy, safety, campus status, feed, notification, and messaging records needed for the app to function. Expo processes push notification tokens and payloads for delivery. Apple Push Notification service and Google’s Firebase Cloud Messaging may then deliver those notifications to devices. Apple, Google, and the operating system may also provide native platform and location services. Veylo’s public legal and support pages are hosted using GitHub Pages.
We do not sell personal information and we do not use third-party advertising SDKs in the current app.
Push Notifications And Notification Content
If you enable notifications, Veylo stores the information needed to address and manage them, including an Expo push token, device type, whether the token is enabled, its last-seen time, and your notification preferences. Veylo may also store an in-app notification record containing the recipient, actor, title, body, routing information, read time, and related timestamps.
Depending on the alert, a push notification may include a sender or actor name, a group name, a campus-status event, or a preview of a message of up to approximately 80 characters. It may also include identifiers or links needed to open the relevant screen. Veylo sends this payload through the Expo Push Service, which forwards it to Apple Push Notification service or Google’s Firebase Cloud Messaging. Those providers process the token and notification content for delivery. Expo may temporarily hold notification content in memory or delivery queues, and authorised personnel may be able to access it while diagnosing a delivery problem.
Depending on the recipient’s device settings, notification content may appear on a lock screen and may be visible to anyone who can view that device. You can disable notification categories in Veylo or disable all Veylo notifications in your device settings. Disabling notifications stops future push attempts but does not retract a notification already delivered or remove information already stored on another user’s device or in their Veylo notification history.
Overseas Storage And Processing
Veylo is operated from Australia, but some service providers process or store information overseas. Veylo’s current core Supabase backend is hosted in Singapore. Push notification information may be disclosed to or processed by Expo, Apple, Google, and their service providers in the United States and other countries in which they operate. GitHub may also process standard website request information, such as an IP address and browser or device information, when you visit Veylo’s public legal or support pages.
Privacy and data-access laws in those countries may differ from Australian law. We limit information sent to each provider to what is reasonably required for the relevant service and use the access controls and security features available to us. Provider infrastructure, subprocessors, and processing locations can change. You can contact us for current information about the providers and overseas locations known to Veylo.
Sharing
Veylo shares app content with other users only as needed for the social features you use, such as friend connections, profile views, group membership, feed posts, messages, and campus status visibility. We also share limited information with the service providers described above so they can host the service, process location results supplied by the device, and deliver notifications. We may disclose information if required by law, to protect users, or to investigate abuse and safety issues.
Profile Photos, Reports, And Moderation
Newly submitted profile photos are stored as private pending review items until they are manually approved. Reports are routed for manual review, and blocks are used to restrict contact and visibility between the people involved.
Account And Data Deletion
You can delete your account directly in the app from Profile > Delete account. This removes your profile and associated in-app data, including your statuses, friend connections, feed posts, feed comments, messages, notification tokens, and pending profile photo submissions. Veylo does not claim a separate report-retention period in this beta; any future retention policy will be published before it takes effect.
Age Restrictions
Veylo is intended for university students and is not directed to children under 13. Users must meet the minimum age required by applicable law and by the applicable app-store rules in their region.
Contact
Veylo is operated by John Tawadros in Queensland, Australia. For privacy questions, data requests, or questions about overseas processing, contact support@veylo.app.