Privacy
Privacy Policy
Effective Date: October 13, 2026 · Last updated September 13, 2026
Table of contents
- 1. Introduction
- 2. Summary
- 3. Information You Provide
- 4. Information Collected From Your Device
- 5. App Store Disclosures and Data Categories
- 6. Information From Third Parties
- 7. Sensitive Information
- 8. How We Use Information
- 9. AI Features
- 10. How We Share Information
- 11. Retention
- 12. Security
- 13. International Transfers
- 14. Your Rights and Choices
- 15. Children
- 16. Third-Party Services
- 17. Changes
- 18. Contact
Log Social, LLC
1. Introduction
This Privacy Policy explains how Log Social, LLC ("Log Social," "we," "us") collects, uses, shares, and protects personal information when you use Vouch — our mobile application, www.get-vouch.com, and related services (the "Service").
Vouch lets you log places you have been and share them with people you connect with. Because the Service is about real places you visit, it necessarily involves location information and photos. This policy explains exactly what that means.
This policy is incorporated into our Terms of Service. You must be 18 or older to use the Service.
2. Summary
This summary is for convenience. The full policy governs.
| We collect | Your account details, the places and experiences you log, photos you share, precise location tied to those places, your connections, contact information from your device address book, and app usage data. |
| We use it to | Run the Service, show your content to the people you choose, suggest places and people, and keep the Service secure. |
| We do not | Sell your personal information. Show you ads. Collect voice recordings or biometric data. Use tracking pixels or advertising SDKs. |
| Sensitive data | We collect precise locations. This is treated as sensitive information under California and other state laws. |
| Photos | If you use our photo-based setup, the app scans your camera roll on your device and uploads a limited number of photos automatically to build your first entries. Section 4.3 explains this in detail. |
| Contacts | If you grant contacts permission, we store contact information from your address book on our servers so we can tell you when someone you know joins Vouch. Section 4.2 explains this in detail. |
| Your controls | You can revoke any permission in your device settings, change what you share, and delete your account at any time. |
3. Information You Provide
Account and profile
When you create an account we collect your name, username, email address, and — depending on how you sign up — your phone number. We collect your date of birth to verify you are 18 or older; it is not shown to other users. You may add a profile photo, bio, hometown, college town, and current city. Where you enter a city, we store its precise coordinates and a place identifier so it can be shown on a map.
School email
If you verify a school email address, we collect and store it, and use it to associate your account with your institution.
Content you create
Places you log, ratings, captions, reviews, journals, trips, saved places, comments, and photos you attach.
Communications
If you contact support or submit feedback or a bug report, we retain what you send.
Waitlist and forms
If you join our waitlist or submit an interest form on our website, we collect your name, email address, phone number, and city or university.
4. Information Collected From Your Device
All device permissions are optional and requested before use. You can revoke them at any time in your device settings. Revoking a permission may disable the related feature.
4.1 Location
With your permission, we collect your device location only while the app is open and in use. We do not collect location in the background, and we do not track your movements over time. We have no "location history" — location is only ever stored attached to a specific place you log or a city you enter on your profile.
Location is stored at full precision, without rounding or obscuring, because the Service depends on identifying specific venues.
We also derive location from: coordinates embedded in photos you share; places you search for or select; and your approximate location from your IP address, through our analytics provider.
4.2 Contacts
If you grant contacts permission, we collect the phone numbers, and where available the associated names, in your device address book, and we store them on our servers.
We use this information to: (a) identify contacts who already have Vouch accounts, so you can follow them; (b) show you your remaining contacts, so you can invite them; and (c) notify you when a person in your address book later creates a Vouch account.
Purpose (c) requires comparing your address book against accounts created after you granted permission. That comparison cannot be performed solely on your device at the moment permission is granted, which is why the information is stored on our servers.
This is a change from our prior practice. Earlier versions of this policy stated that contact comparison happened entirely on your device and that contacts were never transmitted to or stored on our servers. As of the Effective Date above, contact information is stored on our servers for the purposes described in this section.
We do not use your contacts to build profiles of people who are not Vouch users, to market to them, or to contact them on your behalf or our own. We do not sell contact information or share it for cross-context behavioral advertising, and we do not disclose it to any party other than the service providers identified in Section 10.2.
You may revoke contacts permission at any time in your device settings. If you revoke permission, we stop collecting new contact information and delete the contact information previously stored for your account within 30 days. Deleting your account deletes it immediately, along with the rest of your account data.
We do not send messages on your behalf. When you invite a contact, Vouch opens your device's messaging app with a suggested message already filled in, which includes a link to your Vouch profile. You can edit it, and nothing is sent unless you send it.
Your own phone number is stored on our servers as part of your account and is what allows people who have you in their contacts to find you on Vouch.
4.3 Photos and camera roll
This section describes behavior that may be unexpected. Please read it.
If you grant photo library access during setup, the app:
- Scans up to 10,000 of your most recent photos on your device to read their location and timestamp metadata and group them into clusters representing places you have visited. This metadata scan happens on your device. The metadata of photos you do not share is not sent to us.
- Automatically uploads up to four photos per identified place cluster to our servers, to build draft entries for you to review. These photos are selected by the app, not chosen by you. For an active camera roll this may be dozens of photos or more.
- Sends up to 120 resized photos to Google Cloud Vision for automated labeling, so we can categorize the kind of place. This may cause photos stored in iCloud to be downloaded to your device.
You review the resulting draft entries before they are published. You can skip photo-based setup entirely and add places manually.
When you attach a photo to a post, we process it (resize and re-encode) before storage. As a result of this processing, embedded metadata such as GPS coordinates is not retained in the image file we serve to others.
4.4 Calendar
If you connect your calendar, we read calendar entries to help you log places you have been, and may write entries you create. We access this only after you connect it in settings.
4.5 Usage data
We use PostHog to understand how the Service is used — which screens are reached and where people drop off. Events are always associated with a device identifier, and, once you sign in, with your account. We link usage events to your account so we can reliably measure things like onboarding completion, which anonymous device data alone could not tell us. We send PostHog your account identifier only — not your name, email address, phone number, or location. PostHog separately derives approximate location from your IP address for its own analytics. See Section 5 for a fuller summary of what we collect and why.
4.6 Push notifications
If you enable notifications, we store a push token in order to deliver them.
We send the following notifications:
- when a person in your device address book creates a Vouch account;
- reminders to log or approve your daily experiences;
- a daily roundup of place and experience suggestions personalized to you;
- when the entries generated for your account are ready to view;
- when experiences you asked us to generate are ready for your approval.
To produce and deliver these notifications we use your account information, the contact information described in Section 4.2, the places and experiences you have logged, and the preferences inferred from them as described in Sections 8 and 9.
Notifications may reveal another user's name and activity to you, for example that a specific person followed you, liked your post, or joined Vouch. Depending on your device settings, notification content may be displayed on your lock screen and visible to anyone with access to your device.
You can disable notifications entirely in your device settings, and control individual notification types in the app where those controls are offered. Disabling notifications does not affect your ability to use the rest of the Service.
4.7 What we do not collect from your device
We do not collect advertising identifiers (IDFA/IDFV), device model, operating system version, or locale into our own systems. We do not use the Apple App Tracking Transparency framework because we do not track you across other companies' apps or websites.
5. App Store Disclosures and Data Categories
This section brings together, in one place, the categories of information the Service collects and why — matching what we declare in Apple's App Store privacy disclosures and privacy manifest. If anything here reads as new, it isn't a change in what we collect; it's us being more explicit about it.
5.1 Analytics tied to your account
As described in Section 4.5, usage analytics through PostHog are linked to your account once you sign in, in addition to a device identifier. Previously this was anonymous, device-only data. We made this change because anonymous data could not reliably tell us whether someone leaving the sign-up flow was a new or returning user, which made it impossible to accurately measure and improve onboarding. We send PostHog your account identifier only — never your name, email address, phone number, or location.
5.2 What we collect, and why
| Data | Why we collect it |
|---|---|
| Name, email, phone number | Account creation and sign-in |
| Date of birth | 18+ age check |
| Hometown / current city | Personalizing recommendations |
| Camera-roll photos and their location data | Building your profile of places you've been |
| Precise location | Recommending nearby places |
| Contacts | Finding friends already on the app, and notifying you when someone in your contacts joins |
| Gmail messages (opt-in only) | Detecting restaurant reservations |
| Product usage and screen views | Improving the app |
| Push token | Delivering the notifications you enable |
5.3 Three things worth stating plainly
- Photos are uploaded to our servers, not just read on your device. As described in Section 4.3, when you use photo-based setup we upload up to four photos per place we detect to our servers, so we can build draft entries for you to review.
- Gmail access means we access your mailbox. As described in Section 6, connecting your email is opt-in and read-only, and limited to detecting restaurant and venue reservations — we do not read, store, or process any other message content. But to be direct about what "connect your email" means in practice: we do access your mailbox to look for that information.
- Contacts are stored on our servers, not just matched on your device. As described in Section 4.2, we retain contact information from your address book so we can notify you when someone you already know joins Vouch. This is a change from our prior practice, which matched contacts on-device only.
5.4 What we do not do
- No advertising and no ad networks.
- No selling or sharing data with data brokers.
- No tracking you across other companies' apps or websites.
That last point is why the Service does not show Apple's "Allow Tracking?" prompt — the App Tracking Transparency framework applies to cross-app/cross-site tracking, which we do not do. If we ever introduce advertising, that would change, and we would revisit this policy and the related App Store disclosures before doing so.
6. Information From Third Parties
Sign-in providers
If you sign in with Google or Apple, we receive your name and email address as permitted by your settings with them. We do not receive your password.
Google Workspace / Gmail
If you connect your email account, we access messages only to identify restaurant and venue reservations, and store the venue name, date, and confirmation reference. We do not read, store, or process any other message content.
Our use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically, we do not use this data for advertising, do not sell it, do not transfer it except as necessary to provide the feature, and do not allow humans to read it except with your consent, for security purposes, to comply with law, or where the data is aggregated and de-identified.
You can disconnect at any time in settings, and revoke our access directly at myaccount.google.com/permissions.
Place data
We obtain business and venue information — names, addresses, hours, categories, coordinates — from Google Places and other providers.
7. Sensitive Information
Precise geolocation is "sensitive personal information" under the California Privacy Rights Act and comparable state laws. We collect it as described in Section 4.1.
We use precise location only to provide the Service — identifying the place you are logging, displaying it on a map, and showing it to the audience you have chosen. We do not use or disclose sensitive personal information to infer characteristics about you. Under the CPRA, uses limited to performing the service you requested do not trigger the right to limit — but you may still contact us with any request under Section 14.
Please be aware: the places you log can reveal sensitive things about you, depending on the place. Places associated with health, religion, or personal life carry the same precision as any other. Consider your audience settings before logging a place you would not want a given person to see.
We do not collect: biometric information, facial recognition or face-grouping data, voice recordings, voiceprints, audio, health records, financial account information, government identifiers, or precise information about race, ethnicity, religion, sexual orientation, or immigration status.
8. How We Use Information
We use personal information to:
- Create and maintain your account and verify your age
- Provide the Service: store your entries, display them to your chosen audience, and show you entries shared with you
- Suggest places and people you may know
- Generate draft content and summaries using AI (Section 9)
- Send transactional and service messages: verification codes, Service updates, and the notifications described in Section 4.6
- Notify you when a person in your device address book joins the Service
- Prepare the personalized daily suggestions and roundups described in Section 4.6
- Respond to support requests
- Detect, investigate, and prevent fraud, abuse, security incidents, and Terms violations
- Analyze usage to understand and improve the Service
- Comply with legal obligations and enforce our Terms
We do not use your personal information for advertising, and we do not build advertising profiles.
Legal bases (EEA/UK users)
| Purpose | Legal basis |
|---|---|
| Providing the Service, maintaining your account | Performance of a contract (Art. 6(1)(b)) |
| Location, photo library, calendar access | Consent (Art. 6(1)(a)), given via device permission |
| Storing and matching contacts, and sending notifications you enable | Consent (Art. 6(1)(a)), given via device permission; and, as to contacts who are not Vouch users, our and your legitimate interest in connecting you with people you already know (Art. 6(1)(f)) |
| Precise location as special-category-adjacent data | Explicit consent (Art. 9(2)(a)) where applicable |
| Security, fraud prevention, service improvement | Legitimate interests (Art. 6(1)(f)) |
| Age verification, responding to legal requests | Legal obligation (Art. 6(1)(c)) |
You may withdraw consent at any time by revoking the permission in device settings.
9. AI Features
We use artificial intelligence to generate suggested captions, profile summaries, and place categorizations, and to rank recommendations.
What is sent to AI providers
Depending on the feature: labels derived from your photos, names of cities you have visited, place names and categories, and — for photo categorization and caption suggestions — the photo images themselves.
Providers
Google Vertex AI (Gemini models) and Google Cloud Vision.
Isolation
Prompts contain only your own information. We do not include other users' content in requests made on your behalf.
Your profile summary and taste profile are visible only to you and are not displayed to other users.
Retention and training by providers
We do not train models on user information or photos provided. This is enforced by Google.
Accuracy
AI output may be wrong. You review and can edit generated content before it is published.
We do not make automated decisions producing legal or similarly significant effects about you.
11. Retention
We retain your personal information for as long as your account remains active. We do not automatically delete account information, content, or activity after a fixed period. Your entries, photos, and connections stay available to you — and to the audience you chose — until you remove them or delete your account.
Content you delete individually. When you delete a post, journal entry, trip, or comment, it is removed from the Service and is no longer visible to anyone.
Contacts. Contact information from your address book is retained for as long as contacts permission remains enabled and your account is active. If you revoke contacts permission, we delete it within 30 days. If you delete your account, it is deleted with the rest of your data.
Account deletion. You can delete your account in the app at any time. Deletion is immediate and permanent. It removes your profile, entries, photos, comments, and connections. Content that other users independently saved or reshared is beyond our control.
Backups. Deleted data may remain in encrypted backup archives until routine deletion cycles purge them (30 days). During that period it is isolated from further processing.
12. Security
We use technical and organizational measures to protect personal information, including encryption in transit and at rest, access controls, and authentication safeguards.
No system is completely secure. We cannot guarantee absolute security, and you share information at your own risk. If we become aware of a breach affecting your personal information, we will notify you as required by law.
13. International Transfers
Our servers are located in the United States, and personal information is only processed there.
14. Your Rights and Choices
14.1 Everyone
- Access and correct most of your information directly in the app.
- Delete your account in the app at any time.
- Control permissions — location, photos, contacts, calendar, notifications — in your device settings.
- Control who sees your content using in-app visibility settings.
- Disconnect third-party accounts in settings.
14.2 United States — state privacy rights
Depending on your state of residence, you may have the right to: know what personal information we collect, use, and disclose; access a copy; correct inaccuracies; delete it; opt out of sale, sharing for targeted advertising, or profiling with legal effects; limit use of sensitive personal information; and not be discriminated against for exercising these rights.
We do not sell or share personal information for targeted advertising, and we do not profile you for decisions with legal effects, so those opt-outs do not apply.
To exercise a right, contact explore@get-vouch.com. We will verify your identity by confirming control of the email address on your account, and may request additional information for sensitive requests. We respond within 45 days, extendable by 45 days with notice.
Authorized agents may submit requests with written permission and proof of authority.
Appeals. If we decline your request, you may appeal by replying to our response or writing to explore@get-vouch.com with "Privacy Appeal" in the subject. We will respond within 45 days. If your appeal is denied, you may contact your state Attorney General.
14.3 California — CCPA/CPRA categories
In the preceding 12 months we have collected the following categories:
| Category (Cal. Civ. Code §1798.140) | Collected | Examples | Disclosed to |
|---|---|---|---|
| A. Identifiers | Yes | Name, username, email, phone, account ID, and phone numbers and names from your device address book | Service providers |
| B. Customer records | Yes | Name, phone, email | Service providers |
| C. Protected classifications | Yes (limited) | Age/date of birth | Service providers |
| D. Commercial information | No | — | — |
| E. Biometric information | No | — | — |
| F. Internet activity | Yes | App usage events, interactions | Analytics provider |
| G. Geolocation — precise | Yes | Coordinates of logged places, profile cities | Service providers |
| H. Audio/visual | Photos only. No audio. | Photos you share | Storage, AI providers |
| I. Employment information | No | — | — |
| J. Education information | Yes (limited) | School email, institution | Service providers |
| K. Inferences | Yes | Taste profile, place suggestions | AI provider |
| L. Sensitive personal information | Yes — precise geolocation only | See Section 7 | Service providers |
Sources: you; your device (with permission); third parties you connect; place data providers. Purposes: Section 8. We do not sell or share any category.
We do not have actual knowledge of selling or sharing the personal information of consumers under 16, as the Service requires users to be 18 or older.
15. Children
The Service is for adults 18 and older. We do not knowingly collect personal information from anyone under 18. If we learn that we have, we will delete it and terminate the account. If you believe a minor has provided us information, contact explore@get-vouch.com.
Because we do not knowingly collect information from anyone under 13, the Children's Online Privacy Protection Act does not apply to the Service.
16. Third-Party Services
The Service links to third-party websites and services we do not control. Their privacy practices are their own. Review their policies before providing information.
17. Changes
We may update this policy. For material changes we will provide at least 30 days' notice by email or in-app notice before they take effect. The "Last Updated" date reflects the most recent revision.
18. Contact
Log Social, LLC Alaska Entity #10361849 at 4123 Hampton Drive, 9B, Anchorage, AK 99501, with a copy to explore@get-vouch.com.