Last updated 27 September 2026
Privacy policy
Vewn is a place to write and be read. This policy explains exactly what we store, who else touches it, and how to take it all back. It covers the Vewn website and the Vewn apps for iOS and Android.
The short version
- We store what you write and what you tell us about yourself. That is most of it.
- We do not run advertising, and we do not sell or share your data with anyone for marketing.
- We never see your card details. Payments are handled entirely by Stripe, Apple or Google.
- You can delete your account, and everything in it, from inside the app or from this website. It happens immediately, without asking us.
Who we are
Vewn is operated by Sebastian Deisinger, Doktor-Renner-Straße 1, 4210 Gallneukirchen, Austria, who is the data controller for the information described here. You can reach us about anything on this page at privacy@vewn.app.
What we collect
Almost everything we hold comes from you using the product. The one exception is the support page, which anybody can write to without an account, and which is described below.
- Your account: the email address you sign in with, or, if you use Sign in with Apple or Google, the account identifier and email address that provider gives us.
- Your profile: handle, display name, bio, profile photo, banner, and your appearance and theme settings.
- What you write: posts, including unpublished drafts, comments and replies, the tags you put on them, and any series you group them into.
- What you do: who you follow, the posts and comments you like, the posts you share, and the accounts you block.
- Images you upload for your profile photo and banner.
- Anonymous letters you send or receive. See below, because this one is different.
- Direct messages you send or receive, and who you exchanged them with. See below, because this one is different too.
- Reports you file about a post, a comment, a person, a letter or a message, including anything you type in them. Reporting a comment or a message copies the reported words, so that what happened can still be judged if they are later deleted or edited.
- Support messages you send us: the email address you give us to reply to, what the message is about, and everything you write in it. You can send one without an account and without signing in, which is what the page is for, so this is the one thing here we may hold about somebody who has no account with us. We use the address to answer you and for nothing else.
- Moderation records about you, if we ever act on a report: what was decided, how long it lasted, and whether it was later lifted or overturned. We keep the ones we withdrew as well as the ones that stood, because a record that quietly drops our mistakes is not a record.
- Notifications generated for you, and, if you turn on push notifications, a device token identifying that installation of the app.
- Your subscription status, if you subscribe to Premium: whether it is active, when the period ends, and an identifier from the payment provider.
- Ordinary server logs kept by our hosting provider, including IP addresses, for security and for keeping the service running.
- Aggregate audience measurement: which pages are viewed, the site you arrived from, and the country, browser and device type each request came from. It sets no cookie and stores nothing on your device, the identifier it counts with is discarded and regenerated every day, and it never follows you to another website.
- Aggregate performance measurement: how quickly each page loaded and responded on your device, together with the page, and the country, browser and device type of the visit. It is collected the same way as the audience measurement above, sets no cookie, stores nothing on your device, and is used only to find pages that are slow.
What we do not collect
- Card numbers or bank details. These go straight to Stripe, Apple or Google and never reach us.
- Your location. We ask no app for it and derive none from your IP address.
- Your contacts, your photo library beyond the image you deliberately pick, your microphone or your camera roll.
- Advertising or cross-site tracking data. There are no ad networks and no tracking pixels, and nothing in Vewn follows you to another website. The audience measurement described above counts pages, not people.
What we store on your device
Very little, and none of it for advertising. Everything below is either needed to sign you in or a setting you chose yourself, which is why Vewn has no cookie banner: there is nothing here to ask you about. It is listed anyway, because you should be able to check.
- On the website, a sign-in cookie, once you sign in. It is what keeps you signed in from one page to the next, and signing out clears it. The iOS and Android apps keep the same session in the app’s own storage instead and use no cookies at all.
- On the website, a theme cookie, written when you pick a theme or a light or dark mode. It holds that choice and nothing else, so a page does not paint in the wrong colours before it loads, and it lasts a year. You can delete it in your browser at any time; the app simply goes back to its default look.
- A note of where you had reached in a feed, kept by your browser only until you close the tab, so that going back returns you to the post you were reading instead of to the top.
- In the apps, the theme you last used, so the first screen paints in your colours rather than flashing white, and the date you last dismissed the Premium suggestion, so it does not ask you again straight away.
Anonymous letters
Once a day you can write to one reader chosen at random, and they never learn who you are. To make that true rather than merely promised, no app and no logged-in user can read the sender of a letter: the database refuses it outright, and every way of reading a letter deliberately returns no sender at all.
We do store who sent each letter, and we are telling you so plainly. It is how the one-a-day limit works, and it is the only thing that lets us act on a letter someone reports as abusive. It is never shown to the person who received it, and it is never shown to anyone else.
If you delete your account, letters you sent stay with the people who received them, with the link back to you erased. If a recipient chose to share a letter, it was published as a post under their name. It stays up, because publishing it was their decision and not yours.
Direct messages
You can write privately to one other person. Who is allowed to start a conversation with you is your choice, in Settings: nobody, people you follow, only people you have approved, or anyone. Once a conversation is open that setting no longer applies to it, so unfollowing somebody later does not cut off a conversation you are already having. You can close any conversation permanently, and closing it stops both sides writing.
We store the messages, who sent each one, and when. A conversation is visible to the two people in it and to nobody else. It is not indexed, it is not public, and it is not used to decide what anybody is shown.
Your messages are not end-to-end encrypted, so we are not going to tell you that we could not read them. What we will tell you is that nothing we have built can. There is no page, no report and no tool anywhere in Vewn that opens a conversation: not for support, not for moderation, not for us. That is a property of the database rather than a policy we follow.
The one exception is a message somebody reports. Reporting a message copies that message and the two immediately before it out of the conversation, freezing them, so that a person can judge what happened. Those two may be your own words, which is why the app says so before you report rather than after. Nothing else from the conversation is copied, the copy is taken once and never refreshed, and the rest of the conversation stays as unreadable to us as it was.
If you delete your account, every conversation you were part of goes with it, on both sides, and the other person keeps no copy. A frozen copy of a message of yours that was reported stays, because the report still has to be judged and evidence that vanishes when the reported account closes is not evidence.
If you turn on push notifications, a message push tells your device who wrote to you and nothing about what they wrote. The words never leave the app.
Who else processes your data
We use a small number of providers to run Vewn. Each one only receives what it needs for its job.
- Supabase: our database, sign-in and file storage, running in Frankfurt. Everything described above is stored here.
- Vercel: hosts the website and the API, also in Frankfurt, keeps the request logs mentioned above, and counts the page views and page-speed measurements described above.
- Resend: sends the six-digit code you sign in with. It receives your email address and nothing else.
- Stripe: subscriptions bought on the web. Stripe holds the payment details; we hold a subscription identifier.
- RevenueCat, with Apple and Google: subscriptions bought inside the apps. Same arrangement: they hold the payment, we hold the status.
- Expo: delivers push notifications to your device, if you turn them on.
- Klipy: provides GIF search. See below.
GIF search
When you search for a GIF, your search term is sent to our server and forwarded to Klipy. Your IP address is not, because the request is made by us, not by your device. When you actually post a GIF we tell Klipy which GIF was used, because that count is what pays for the service; we do not tell them who used it.
The GIF itself is loaded from Klipy’s servers when it is displayed, which means their servers see the IP address of anyone viewing a post containing one. That is the same as any image loaded from another site.
Why we are allowed to hold it
We are established in Austria, so the GDPR applies to everything described here, wherever you are. These are the legal bases we rely on.
- Performing our contract with you: running your account, storing what you write, showing it to the people you meant to show it to, and taking payment for Premium.
- Our legitimate interests: keeping Vewn secure, preventing abuse, acting on reports, answering support messages (including from people who have no account with us and so are not covered by the contract above), understanding in aggregate which parts of the site get read, and keeping the service working. We have weighed these against your rights and use the least data that does the job.
- Your consent: push notifications, which you choose to turn on and can turn off at any time, in the app or in your device settings.
- Legal obligation: the accounting records we are required to keep about payments.
How long we keep it
Your account and everything in it is kept until you delete it. Deleting your account removes it immediately, as described on the account deletion page.
A few things outlive a deleted account, none of them still attached to you: tags you were the first to use, which are shared topics other people’s posts still sit under; anonymous letters you sent, which now belong to the people who received them; reports you filed, so they can still be acted on; the frozen copy of any message of yours somebody reported, so that report can still be judged; any moderation record about you, so that a decision cannot be erased by closing the account it was about; payment records we are required to keep for accounting; and a tombstone row carrying no name, no words and no picture, which is what holds those things detached rather than dangling. Server logs are kept by our hosting provider on their own short retention schedule.
If you never delete your account, we keep it. We do not currently expire dormant accounts, and if we ever start doing so we will tell you first.
Support messages are the exception to both of those. One you sent while signed in is deleted along with your account. One sent without signing in is not linked to any account, which is what lets you send it when you cannot get into yours, so nothing can delete it on your behalf. We keep those while we still need them to deal with what you wrote about, and delete them once we do not. You can ask us to delete yours sooner at privacy@vewn.app.
Deleting your account
You do not have to ask us, and you do not have to reinstall anything. Go to Settings and choose Account, on the website or in either app, and confirm by typing your handle. It happens immediately and it cannot be undone. If you want to read what it does before signing in, that is at vewn.app/delete-account.
A Premium subscription bought on the web is cancelled for you as part of closing the account, before anything is deleted. If we cannot cancel it, we stop and delete nothing. One bought through the App Store or Google Play is owned by the store and only you can cancel it, so do that first or you will keep being charged for an account you can no longer sign in to.
Your rights
You can ask us to give you a copy of your data, correct it, delete it, restrict what we do with it, or object to us processing it. Most of these you can do yourself: your profile is editable in Settings, and account deletion is a button rather than a request.
For anything you cannot do yourself, write to privacy@vewn.app and we will answer within one month. If you think we have got it wrong, you can complain to a supervisory authority. Ours is the Austrian Datenschutzbehörde in Vienna, and you may also complain to the authority where you live or work.
Where your data is
Your account, everything you write and every image you upload are stored in Frankfurt, Germany, inside the EU. The servers that run Vewn are in Frankfurt too, so ordinary use of the product does not move your data outside the EU at all.
Five of the providers above are US companies, and each receives a narrow slice: Resend gets your email address to send a sign-in code, Stripe and RevenueCat handle payment, Expo delivers a push notification if you turn them on, and Vercel, which stores and serves everything in Frankfurt, processes the aggregate page counts and page-speed measurements on its own platform. Those transfers rely on the European Commission’s standard contractual clauses in our agreements with them. Klipy never receives anything identifying you, but its servers do see your IP address when your browser loads a GIF, in the same way any image hosted elsewhere would.
Children
Vewn is not for children. You must be 18 or over to have an account. That is deliberately higher than the age the law sets for consenting to an online service on your own account, which is 14 in Austria and between 13 and 16 elsewhere in the EU. If we learn that an account belongs to someone younger, we will delete it.
Changes to this policy
If we change what we collect or what we do with it, we will update this page and change the date at the top. If the change is a significant one, we will tell you in the app before it takes effect rather than relying on you to re-read this page.
Contact
privacy@vewn.app, for any question about this policy or any request about your data.