Privacy & permissions

Privacy policy

TribeLines Privacy Policy

Applies to the TribeLines beta (beta-1.4.0). Maintained by the TribeLines app owner. This policy describes the app as built; it is not a certification, audit outcome or legal advice.

1. What we collect

Account

Email address, password (hashed by our auth provider, never stored in app tables), user ID, username.

Required to have an account.

Profile

Display name, bio, headline, city, avatar, anthem (track URL, title, artist, provider), social links.

Username required; everything else optional.

Location

Precise coordinates when you drop a Tribe (pins, your last known point, Tribe Grounds), plus a movement trail only while you run a moving Tribe beacon. A place label / venue type is derived by reverse-geocoding your coordinates server-side.

Optional and asked for at the moment of use. Location is foreground-only in this beta — there is no background tracking.

Content

Photos, videos and audio you post into a pin; pin titles, captions, notes and vibes; in-tribe messages; articles and post likes; reactions; your social graph (Kin, Top Five, saved grounds, blocks); reports you file.

All optional.

Notifications

In-app notifications and walkthrough alert preferences (preferences stored on your device).

Optional.

Product analytics

Event names, page path, and a user ID when signed in or a random session id when not. First-party only — no ad networks, no cross-app or cross-site tracking.

Optional: switch it off on the Privacy & permissions screen.

Diagnostics

App version, user agent, platform, language, timezone, screen/viewport, memory and connection info; a recent in-app activity log; an optional screenshot and visual context; any contact detail you type into the feedback form.

Only sent when you submit feedback or a bug report. The activity log can be switched off or cleared on the Privacy & permissions screen.

AI features

Pin and tribe text sent to our AI gateway to generate Tribe Vibe, Chief Assist and recaps.

Optional feature.

We do not collect contacts or address book, calendar, SMS, call logs, health or fitness data, financial or payment data (payments are not part of this beta), advertising identifiers, device IDs, browsing history outside the app, biometrics, or data on race, ethnicity, religion, politics or sexual orientation.

2. How we use it

To run the app: placing and showing pins, moving a Tribe beacon while you run one, delivering media and chat to your Kin, publishing your profile and articles, sending in-app notifications, generating optional AI text, answering your feedback, and measuring product usage so we can improve the beta.

We do not use any data for tracking or advertising. There are no ad SDKs, attribution SDKs or data brokers in this app, and we do not link your activity to other companies' apps or websites.

3. Sharing

We do not sell your data and we do not share it with third parties for their own purposes. The services below process data on our behalf, only to deliver a function you asked for:

Managed backend (Postgres, auth, storage — Lovable Cloud)

All app data

Hosting, authentication and media storage · processor / sub-processor

Mapbox

Coordinates for map tiles, search and reverse geocoding. Geocoding runs server-side and carries no account identifiers.

Map rendering and venue recognition · processor / sub-processor

AI gateway (google/gemini-2.5-flash)

Pin and tribe text for Tribe Vibe, Chief Assist and recaps

Optional AI features · processor / sub-processor

Content you choose to make public — your profile page, articles, and any Tribe you drop publicly — is visible to anyone with the link. All data is encrypted in transit (HTTPS/TLS) between the app, our backend, storage, and the services above.

4. How long we keep it

  • Tribes are ephemeral: each pin expires at its set time — one hour by default, extendable by your chosen duration or streak rewards. Expired pins stop being served.
  • A moving Tribe's breadcrumb trail exists only while that beacon runs and is discarded with the pin.
  • Media lives in a private bucket and is served only through short-lived signed links. Downloads are gated by the pin's download permission and brand usage flags.
  • Bug screenshots live in a separate private bucket readable only by admins through signed links, and are only created when you attach one.
  • Profile details, articles, messages and your social graph are kept until you change or delete them, or until your account is deleted.
  • Analytics, walkthrough and bug-report records do not yet have a fixed retention window in the beta. The owner is finalising these windows and a scheduled purge before public launch; until then you can switch analytics and the diagnostic trail off, and ask us to delete your records.

Access to every table is restricted by row-level security, and admin permissions are checked server-side against a dedicated roles table — never a client-side flag.

5. Deleting your data

Deleting your account removes your auth user, and that cascades to your profile, pins, media rows, messages, memberships and reactions.

You can also remove things individually at any time: delete a post or media item, end a Tribe early, clear any profile field, delete an article, block a Kin, or clear the diagnostic activity trail on your device.

To request deletion during the beta, send a deletion request through the feedback form below and we will delete your account and content. A self-serve in-app "Delete my account" control and a public deletion-request URL are being added before store submission.

6. Your choices

  • Location: granted or revoked in your device settings; the app asks at the moment of use.
  • Moving Tribes: opt-in per pin, and you can stop the beacon at any time.
  • Camera, microphone and photo library: only used when you choose to post media.
  • Product analytics: opt out on the Privacy & permissions screen.
  • Diagnostic activity trail: switch off or clear on the same screen; nothing is sent unless you submit a report.
  • Notifications and walkthrough alerts: opt-in, and can be turned off in your profile.

7. Children

TribeLines is not directed at children, and accounts are intended for users aged 13 and over.

8. Contact and pending items

Reach us about privacy, deletion or a safety concern through the feedback form, which goes to the same inbox as bug reports.

Still to be finalised by the app owner before public launch, and deliberately not stated here until they are: the registered legal entity and address of the data controller, a dedicated privacy contact address, fixed retention windows for analytics and support records, and region-specific commitments such as a UK/EU representative and CCPA disclosures.