Who we are and how to reach us
Vizdea runs vizdea.com and the Vizdea apps, and decides how personal data is used for them. For privacy questions, requests, or grievances, email info@vizdea.com with the subject Privacy request. We verify requests before acting on them so that nobody can act on your account but you.
What we collect
We collect what you give us, what the service records while you use it, and a small amount of technical data needed to keep accounts secure. The apps do not include advertising or analytics software, do not track you across other companies’ apps or websites, and do not access your contacts or location.
- Account data: your email address, username, first and last name, and a one-way salted hash of your password (we never store the password itself). Optionally, a private phone number.
- Profile content: display name, headline, bio, location, primary role, skills, interests, profile photo, the visibility you choose for each profile section, your collaboration preferences, and your startup, community, and institution memberships.
- Things you share and do: posts, polls and votes, comments, appreciations, saves, follows, connection requests and their notes, startup pages and roles, applications, reports, and appeals.
- Uploaded images: the profile photo and post images you choose, and the image descriptions you write. In the apps, you choose images through the system photo picker, and only those are uploaded. Images are stored as uploaded, so metadata inside the file, such as camera details or location, stays with it; remove it first if you do not want it shared.
- Messages: the content of direct messages, who sent and received them, and when they were read.
- Mobile sessions: when you sign in through an app, we store a device label (“Vizdea for iOS” or “Vizdea for Android”) with the session, along with when it started, when it was last used, and when it expires. You can see and sign out these sessions in Account security.
- App notifications: if you allow notifications in an app, we store the push token your phone’s system gives the app, and whether the phone is an iPhone or an Android phone, so that a notice can reach that device. The token is removed when you sign out, when your account is erased, and when Apple or Google tells us the device no longer accepts it. A notice says who did what, for example that a member sent you a message; it never carries the content of a message.
- Security logs: records of security-relevant and account actions, such as sign-up, password and email changes, sessions signed out, posts and comments created or removed, reports, moderation decisions, and privacy requests, with the time and a request ID. Web sessions and verification-code requests store a keyed hash of your IP address (and, for web sessions, of your browser’s user agent), not the raw values. Our servers’ request logs, and the short-lived counters that limit repeated requests, include IP addresses.
- Support: what you send when you contact us.
- Website analytics: only if you allow it in Analytics preferences, Google Analytics measures aggregate page use on vizdea.com, with IP anonymisation and without account identifiers or anything you post.
Why we use it
We use personal data only to run Vizdea and keep it safe:
- Create and secure your account, verify your email address, and send verification, password reset, and email-change codes.
- Show your profile and content to the people your settings allow, and deliver messages and notifications.
- Order your feed and discovery using the skills, interests, relationships, and saves or dismissals you give us. We do not infer sensitive traits, and a chronological feed is always available.
- Review reports, moderate content, prevent spam and abuse, limit repeated requests, and enforce the Terms of use.
- Keep content that was reported or removed, and the records around it, for as long as the law requires so it is available to an investigation, as described below.
- Answer support and privacy requests, and meet legal obligations.
Consent, and how to withdraw it
You consent to this processing when you create an account. You can withdraw that consent at any time, as easily as you gave it, and withdrawing does not affect processing that already happened:
- Stop processing entirely by deleting your account (see below), or by emailing info@vizdea.com from your account email if you cannot sign in.
- Limit who sees each profile section, and whether you appear in discovery, in Settings.
- Block or mute a member to stop contact with them.
- Upload only the images you want to share. The apps use your phone’s system photo picker, so they see only the photos you select, and you can use Vizdea without uploading any.
- Withdraw website analytics consent in Analytics preferences on vizdea.com.
Download your data
Request a copy in Settings, under Your data, in the app or on the web. The export is a JSON file with your account details and profile, visibility settings, community memberships, institution memberships, startup roles, the connection requests you sent and received, the people you follow, the people who follow you, your collaboration preferences, the builders you marked interested or passed on, your mutual matches, the events you hosted, your event registrations and tickets, your asks and offers, your verified links, your posts, your comments, and your direct messages, sent and received. Connections, follows, matches, event registrations and messages with a member you have blocked, or who has blocked you, are left out. A post or comment you deleted is not included: its text was erased when you deleted it. Download it from Settings on vizdea.com; it stays available for seven days.
Delete your account
In the app, go to Settings and choose Delete my account; on the web, go to Settings, then Profile, then Your data. If you cannot sign in, email info@vizdea.com from the email address on your account with the subject Delete my account. Deletion is scheduled for 21 days later, and you can cancel it from the same place until then. After 21 days we permanently erase the account, unless a hold applies, as described below.
Erasure deletes your account and sign-in details, profile, preferences, sessions and their device labels, your posts, your comments, the direct messages you sent or received, the photos you uploaded, including the files, appreciations, saves, votes, follows, connections, memberships, notifications, blocks and mutes, and the appeals and applications you filed. Security and moderation records are kept, as described below, and so are the reports you filed, no longer linked to you. The full list, step by step, is at vizdea.com/account-deletion.
The law requires us to keep content that was reported or removed so it is available to an investigation, which changes this in two ways. First, a hold. When the 21 days end, we close your account instead of erasing it if a safety or harassment report about you, your content, or a conversation with you is still open; if in the last 180 days a moderator removed something you posted or ran, or restricted your account; or if a Vizdea moderator or administrator has placed a hold on your records. You are signed out everywhere and can no longer sign in, other members can no longer see your profile, posts or comments, and your messages, posts, comments, photos and reports are kept, where only our moderators can see them. We check again every hour, erase the account as soon as no hold applies, and email you to confirm.
Second, even when no hold applies, content that is part of a report or was removed by our moderators is copied before the erasure to a store only our moderators can see: a conversation either of you reported, and your posts, comments and photos, or other members’ comments under your posts, that were reported or removed. Each copy is deleted 180 days after the report is decided or the removal was made, and never while a report it serves is still open. The same goes for a conversation you had with a member whose records are under a hold, and that member’s comments under your posts: they are copied, and deleted 180 days after the hold ends.
Communities you owned pass to their longest-standing moderator or member, or are archived if nobody is left. A startup where you were the last founder or cofounder passes to its longest-standing remaining team member, or failing that advisor, whose place on the team is verified and whose account is active; they become a cofounder. If there is nobody, the startup is closed, its roles stop taking applications, and anyone still waiting on an application is told it was declined.
How long we keep data
- Account, profile, messages, and session records: while your account exists, then erased 21 days after you request deletion, or, if a hold applies then, once it ends.
- Signed-in sessions: web sessions end after 30 days. App sign-ins last up to 30 days and end after 14 days without use. Verification codes expire after 10 minutes. Data exports: seven days.
- Server request logs, which include IP addresses: 30 days. Counters that limit repeated requests: about an hour.
- Database backups: 14 days, so erased data leaves our backups within 14 days of erasure.
- Posts and comments: while your account exists. When you delete a post or comment, it disappears for everyone at once and its text is erased at the same time, with a post’s poll options, image descriptions and images. If a report about it, or about an image in it, has not been decided yet, or your account is under a hold, it stays hidden with its content until that ends, and is then erased. For the same reasons, editing a post or comment while a report about it is undecided, or while your account is under a hold, keeps the version you replaced where only our moderators can see it.
- Direct messages: while your account exists, then erased with your account. Direct messages cannot be deleted one at a time.
- Uploaded photos: while your account exists, then erased with your account, and the files are deleted from our file storage at the same time. The images in a post you delete go with the post, as above.
- Posts, comments, images and profile photos a moderator removed: hidden from everyone but our moderators, and kept for at least 180 days after the removal, even if you delete your account, and longer if a court or authorised agency requires it.
- Copies of reported, removed or held content, made when an account is erased or such content is edited: until 180 days after the report is decided, the removal was made or the copy was taken, and never deleted while a report they serve is still open or a member they are about is under a hold.
- Kept after erasure, with no fixed end date, because we need them to investigate abuse and fraud and to meet legal obligations: security logs (detached from your account, though some entries still include your former username or account ID), moderation records (reports other members made about you or your content, the decisions on them, and the reports you filed, no longer linked to you), and records of verification codes sent to your email address.
Who we share it with
We do not sell personal data and we do not share it for advertising.
- Other members see what your visibility settings allow; direct messages are visible to you and the other member.
- Service providers process data for us and only for that purpose: Microsoft Azure hosts the service, database, file storage, and logs in its Central India region, and Azure Communication Services delivers our email; if you allow app notifications, Apple (Apple Push Notification service) delivers them to iPhones and Google (Firebase Cloud Messaging) delivers them to Android phones, and each receives the push token and the text of the notice and nothing else; Google provides website analytics only if you allow it. We require each provider to protect personal data with the same or equal protection as this policy.
- Authorities, when the law requires it or to protect someone from serious harm, including reports of child sexual abuse material described in our Child safety standards.
How we protect it
Data travels over HTTPS and is encrypted at rest by our hosting provider. Passwords are stored only as salted hashes, sessions expire and can be signed out remotely, repeated requests are limited, account and moderation actions are audit-logged, and access to production data is restricted to the people and services that need it.
Children
Vizdea is not directed at children. If we learn that a child’s personal data was provided contrary to applicable law, we delete it. Our Child safety standards are at vizdea.com/child-safety.
Changes and grievances
We will update the effective date above when this policy changes, and tell you in advance of a material change to how we use your data. If you are not satisfied with our answer to a grievance sent to info@vizdea.com, you may be able to complain to the Data Protection Board of India or your local data protection authority.