Effective date: July 22, 2026 Company: Vibralizer LLC (“Vibralizer,” “we,” “our,” “us”)
This Privacy Policy explains how Vibralizer handles information when you use:
- The Vibralizer application (the “App”)
- Our website (the “Site”)
- Our community channels (e.g., Discord)
- Optional activities such as email sign‑ups, surveys, or playtests.
What changed in this version: Vibralizer is transitioning its App analytics from Unity Analytics to our own first‑party analytics service. Which system your copy of the App uses depends on when that version was released:
- App versions released before July 22, 2026 (all public builds as of this date) send analytics via Unity Analytics, as described in section 1a below.
- App versions released on or after July 22, 2026 (currently invite‑only playtest builds, and all future public releases) send analytics only to Vibralizer’s own first‑party service, as described in section 1b below, and add a separate consent for crash reporting.
Quick summary (TL;DR)
What we don’t do
- We do not record, upload, transmit, or store any audio data, including content, waveforms, frequency data, or recordings. All audio visualization processing happens on‑device in real time.
- We do not transmit, store, or process media metadata (e.g., track title, artist, album) off your device. Media information obtained from the operating system’s audio API for display purposes stays entirely on‑device.
- We do not log which keys you press or what you type. Input telemetry (new versions only) is limited to counts of interactions per device type (keyboard vs. mouse vs. game controller), never their content.
- We do not store IP addresses in our own analytics database (new versions; older versions use Unity Analytics, which processes IP addresses as described below).
- We do not sell or share personal information for cross‑context behavioral advertising.
- We do not run targeted ads in the App.
- We do not have user accounts, profiles, or logins.
What we do
- App analytics: With your consent, we collect pseudonymous, product‑usage analytics to improve the App. Depending on your App version this goes to Unity Analytics (versions before July 22, 2026) or to our own service at analytics.vibralizer.com (later versions). Either way it includes a technical "signal present" indicator (Yes/No) to help us debug issues, but never the audio itself. You can turn analytics off and delete previously sent analytics at any time in Settings → Legal.
- Crash reports: Diagnostic reports (stack trace, device and graphics information, app version) may be sent to our crash‑reporting provider, Backtrace, so we can fix problems. In versions released on or after July 22, 2026 this only happens with your consent (a separate Crash Reports toggle); in older versions it happens automatically. Crash reports never contain audio or media information.
- Site: We use privacy-preserving, cookie-less analytics to measure website performance.
- Email: Our email list is voluntary; you can unsubscribe at any time.
Scope & Definitions
- Personal Information / Personal Data (“PI”): Information that identifies or can reasonably be linked to a person or household.
- De‑identified data: Information that cannot reasonably be used to identify a person or household. We maintain and use de‑identified data subject to controls that prevent re‑identification.
- Controller / Business: Vibralizer LLC (we decide why/how data is processed).
- Processor / Service Provider: Vendors that process data for us under contract (e.g., Unity, DreamHost, Cloudflare, Sauce Labs).
Audio & Media Handling (Important)
Vibralizer uses the microphone (or system audio) to drive visuals in real time. We are strictly transparent about what leaves the device:
- On-Device Processing: The analysis of frequencies and waveforms to generate visuals occurs entirely on your device.
- No Audio Data Transmitted: No audio‑related data of any kind—including volume levels, frequency data, waveforms, or content—is ever transmitted off your device.
- Media Metadata (On‑Device Only): The App may retrieve media metadata (e.g., track title, artist, album, playback state) from the operating system’s audio API to display playback information and controls within the App. This metadata is used solely for on‑screen display, is never transmitted off your device, and is not included in analytics or shared with Vibralizer or any third party. If you use the App’s on‑screen playback buttons (play/pause, next, previous, seek), analytics record only that a button was used, never what was playing. Your use of third‑party media applications (e.g., Spotify, Tidal, web browsers) remains governed by those platforms' own privacy policies.
Information We Collect
1) App Analytics (Optional; Consent‑based; Pseudonymous)
The analytics system depends on your App version, shown in the App’s menu. Both are consent‑based and controlled from Settings → Legal (older versions: Settings).
1a) Versions released BEFORE July 22, 2026 - Unity Analytics
These versions send pseudonymous product‑usage telemetry via Unity Analytics (a Unity Technologies service). Examples include: crash and performance diagnostics, App screens opened, settings toggles, feature usage, and device characteristics relevant to rendering performance (e.g., GPU model, OS version).
- Unity Analytics default data elements: IP address (network routing/security), a unique installation‑specific ID (pseudonymous analytics identifier), User ID (defaults to the installation ID), and IDFV (on Apple platforms).
- Retention: Unity retains this data no longer than 13 months, then deletes it.
- Controls: The in‑App analytics toggle stops collection; the in‑App deletion control forwards a deletion request to Unity. You may also contact Unity at DPO@unity3d.com or review Unity’s policy at unity.com/legal/game-player-and-app-user-privacy-policy.
1b) Versions released ON OR AFTER July 22, 2026 - Vibralizer first‑party analytics
These versions (currently invite‑only playtest builds; soon all public releases) send pseudonymous product‑usage telemetry only to our own analytics service (analytics.vibralizer.com), operated by Vibralizer LLC on hosting infrastructure provided by DreamHost in the United States. No third‑party analytics network receives this data, and nothing is collected or transmitted until you make a choice on the first‑run consent screen. Examples of what we collect:
- Identifiers: A randomly generated installation ID (a pseudonymous number that is not derived from your name, email, or hardware serial numbers) and a per‑launch session ID.
- App and device context: App version and build channel (e.g., demo vs. full release), operating system, and device characteristics relevant to rendering performance (e.g., GPU model, CPU, screen resolution), and whether the optional Pro upgrade is active.
- Feature usage: Which visual scenes (“Vibes”) are viewed and for how long, frame‑rate performance while viewing them, settings changes, customization actions (color palettes, playback speed, visual effects/filters), use of the on‑screen media playback buttons (the button pressed, never the media), and first‑run setup steps (e.g., how long the macOS system‑audio permission screen was shown).
- Input method: Counts of interactions per input device type (keyboard, mouse, game controller) so we know which control schemes to prioritize. We never record which keys were pressed or any text.
- Audio signal indicator: A technical "signal present" (Yes/No) state change, to debug capture issues. Never the audio itself.
- What’s NOT collected: Names, emails, precise geolocation, audio content, media metadata (e.g., track titles, artist names), typed text, or key contents.
- IP addresses: Our analytics service does not store IP addresses. Your IP address is necessarily visible in transit to deliver the data (and may appear briefly in our hosting provider’s standard web‑server security logs, which are retained for a limited period), but it is never written to the analytics database or linked to your analytics records.
- Controls: In the App, go to Settings → Legal to (a) turn analytics on/off (changes apply immediately), (b) delete previously sent analytics from our servers, and (c) view your analytics ID.
2) Crash & Error Reporting (Backtrace)
To keep the App stable, crash and error reports can be sent to Backtrace (a Sauce Labs service).
- Versions released on or after July 22, 2026: Crash reporting is consent‑based. You are asked at first run, and a separate Crash Reports toggle in Settings → Legal lets you change your choice at any time; nothing is sent before or against your choice.
- Versions released before July 22, 2026: Crash reports are sent automatically when the App crashes, on the basis of our legitimate interest in fixing defects. To object or request deletion, contact privacy@vibralizer.com.
- What a report contains: Stack traces, breadcrumb logs of recent App actions (e.g., "app quit", "audio device changed"), app version, operating system, and device/graphics information. Reports never contain audio, media metadata, or typed text.
- Network data: Backtrace receives your IP address as a technical consequence of transmitting the report.
3) Website Interactions (Logs & Metrics)
When you visit the Site, our hosting and security providers process standard technical data (such as IP address, browser type, and pages requested) in server logs for security and operations, retained for a limited period.
- Site Analytics: We use Cloudflare Web Analytics to monitor the performance and health of our Site. This service does not use cookies or local storage to track you across websites. It relies on non-identifiable metrics (e.g., page load times, browser type, coarse region).
- Cookies: We use essential cookies only if strictly necessary for Site operation and security. We do not use marketing or advertising cookies.
4) Email List (Voluntary)
If you subscribe, we process your email address (and any name you provide) to send updates, via our email delivery provider (MailerLite). You can unsubscribe anytime via the link in each email.
5) Surveys & Playtests (Occasional; Optional)
- Surveys: If we run a survey, we will describe what we collect and why at the point of collection, seek consent where required, and delete or de‑identify responses after analysis.
- Playtests: Invite‑only pre‑release builds collect the same consent‑based analytics and crash reports described in sections 1b and 2 (pre‑release builds are versions released on or after July 22, 2026), plus any feedback you choose to give us. We delete or de‑identify playtest logs after the test period unless needed to investigate critical issues or comply with law.
6) Community Channels (e.g., Discord) & Store Purchases
- Community: Your use of platforms like Discord is governed by their privacy policies. We may see your public handle and messages you send us for moderation and support.
- Store Purchases (itch.io / Steam): Purchases are handled by the store platforms. We do not receive your full payment details. We may receive limited transaction metadata (e.g., license confirmation, SKU, region, date).
How We Use Information
- Provide, secure, and improve the App and Site (e.g., performance tuning, debugging, deciding which features and platforms to prioritize).
- Communicate with you (support, updates, newsletters if you subscribed).
- Prevent fraud and protect the safety, integrity, and security of the App.
- Comply with law and enforce terms.
Data Sharing & Processors
We use service providers to help us operate the App/Site. We require these processors to protect data and use it only for our specified purposes.
- App Analytics (versions before July 22, 2026): Unity Analytics (Processor).
- App Analytics (later versions): Collected first‑party by Vibralizer LLC; stored on hosting infrastructure operated by DreamHost (Processor) and mirrored to systems controlled by Vibralizer.
- Crash Reporting: Backtrace by Sauce Labs (Processor).
- Site Analytics & Security: Cloudflare (Processor).
- Site Hosting: DreamHost (Processor).
- Email: MailerLite (Processor), if you subscribe.
International Transfers
We process and store data in the United States (including our analytics database, hosted with DreamHost in the U.S.) and may allow processors to process data in other countries. When transferring personal data from the EEA/UK to regions without an adequacy decision, we rely on Standard Contractual Clauses (SCCs) or comparable safeguards.
Retention
- App Analytics (both systems): Raw analytics events are retained no longer than 13 months from collection, then deleted (Unity enforces this for Unity Analytics; we enforce it with automated deletion for our first‑party service). You can delete your analytics sooner at any time in Settings → Legal.
- Crash Reports: Retained only as long as needed to investigate and fix the underlying issue, and no longer than 13 months.
- Email List: Retained until you unsubscribe.
- Support Communications: Retained as needed to resolve issues and maintain records.
Your Choices & Privacy Rights
In the App
Settings → Legal (older versions: Settings) lets you enable/disable analytics, enable/disable crash reports (newer versions), and delete previously sent analytics. Changes apply immediately. Deletion removes your analytics records from our servers and, for data collected by older versions, forwards a deletion request to Unity; if a deletion request cannot reach our server (e.g., you are offline), the App retries it automatically on the next launch.
Rights by Jurisdiction
Depending on where you live (e.g., EEA, UK, California), you may have rights to:
- Access, Correct, Delete: Request access to or deletion of your personal data.
- Withdraw Consent: You can withdraw consent for analytics, crash reports, or email marketing at any time.
- Object: You can object to processing based on legitimate interests (e.g., automatic crash reporting in older versions).
- Non-discrimination: We will not treat you differently for exercising your privacy rights.
- Lodge a Complaint: You have the right to lodge a complaint with your local data protection authority.
Security & Children’s Privacy
- Security: We apply reasonable administrative and technical safeguards: analytics are transmitted over encrypted connections (HTTPS/TLS), our first‑party analytics are stored pseudonymously without IP addresses, and access is restricted to Vibralizer’s founders and our disclosed processors on access‑controlled systems. However, no system is perfectly secure.
- Children: The App and Site are not directed to children under 13. We do not knowingly collect personal data from children. If you believe we have done so, contact us and we will delete it.
Contact
Email: privacy@vibralizer.com
For data collected by versions released before July 22, 2026, you may also contact Unity regarding its processing roles at DPO@unity3d.com.