Privacy Policy
Effective date: August 27, 2026
Worlduu (the "Service", "we") is a global event-based social platform. We comply with applicable privacy laws. This policy explains what information we collect and how we handle it.
1. Information We Collect
Account information
- Email sign-up: email address, password (stored as a hash by our authentication processor, Supabase)
- Google sign-in: your Google account email and basic profile info (name, profile photo URL)
- Profile: nickname, avatar, country, languages, interests, bio, preference answers
Service usage
- Event activity: hosting, participation, views, live viewing, and chat participation records
- Chat messages and their automatic translations
- Uploaded content: videos and photos (location metadata (EXIF GPS) is removed from photos on your device before upload)
- Matching: a synthesized profile text and embedding used for AI persona matching (direct identifiers such as contact details are excluded)
Payments and payouts
- Credit top-up, spend, gift, and donation history (ledger records)
- We do not store card details; payments are processed by Stripe
- For withdrawals: Stripe Connect account linkage (identity verification (KYC) is performed and held by Stripe)
Automatically collected
- Access and device signals: IP address (stored at sign-up, and kept temporarily for anti-abuse measures such as rate limiting), hashed email/device-fingerprint signals, browser information
- Location-spoofing detection: we keep your single most recent location coordinate provided during actions such as joining an event (no movement history is stored, and detection records use speed/distance figures instead of coordinates)
- Cookies: login session, language preference (no advertising or tracking cookies)
- Error logs (Sentry): technical logs for incident diagnosis
2. How We Use Information
- Account management (sign-up, authentication, account protection) and providing the Service (map discovery, events, matching, translated chat, live streaming, VOD)
- AI persona matching and profile summaries; automatic chat translation
- Credit payments, gifts, donations, withdrawal settlement, and host console subscription billing
- Preventing abuse (multi-accounting, location spoofing, payment fraud) and handling disputes
- Notifications (in-app, web push, email — non-transactional email can be opted out)
- Meeting legal obligations (e.g., retention of transaction records)
3. Processors and International Transfers
We engage the following processors; some are located outside your country. Only the content necessary for each task is shared (e.g., message text for translation), and each processor handles data solely to perform its service.
| Processor | Purpose | Location |
|---|---|---|
| Supabase (AWS) | Database, authentication, realtime | South Korea (Seoul region) |
| Vercel | Web hosting | US and global edge |
| Stripe | Payments, payouts, KYC | US |
| Social sign-in, maps | US and others | |
| Amazon Web Services | Live streaming (IVS), media storage (S3), delivery (CloudFront) | South Korea (Seoul) and global edge |
| DeepL | Automatic message translation | Germany (EU) |
| OpenAI | Profile embeddings and summaries | US |
| Resend (AWS SES) | Email delivery | Japan (Tokyo region) |
| Sentry | Error logging | US |
4. Retention and Deletion
- Account data: anonymized without undue delay upon account deletion (nickname, profile, bio, and other identifying elements are removed).
- Transaction and settlement records: retained for statutory periods required by commerce laws (e.g., transaction records up to 5 years), then destroyed.
- Anti-abuse records (sign-up signals and location-spoofing detection records): may be retained after account deletion to prevent ban evasion.
- Chat and content: processed so the author is no longer identifiable after deletion (preserving conversation context for other participants).
5. Your Rights
- You can view and edit your profile, and delete your account, from Settings.
- You can opt out of non-transactional email notifications (financial-record notices excepted).
- Requests for access, correction, deletion, or restriction can be sent to the contact below.
6. Security
- Encryption in transit (TLS); database access controls (row-level security, least privilege)
- Hashed passwords; no card data stored (delegated to Stripe)
- Photo location metadata (EXIF GPS) removed before upload; email/device-fingerprint signals stored hashed
- Audit logging of operator actions
7. Children
The Service is not directed to children under 14 (or the equivalent minimum age in your jurisdiction) and does not knowingly allow their registration.
8. Privacy Contact
- Privacy officer: Worlduu Operations Lead
- Contact: worlduu.official@gmail.com
9. Changes to This Policy
We will announce changes in the Service at least 7 days before they take effect (30 days for changes unfavorable to users).