1. Who we are
Vistili is operated by YellowBench s.r.o. References to "we", "us", or "our" in this policy mean YellowBench s.r.o.
2. Information we process
We process information needed to provide the service:
- your account identifier and the display name you choose; on iOS, email/password and Sign in with Apple sign-in also use an email address where provided; Android guest access uses an anonymous Firebase account identifier;
- event details, invite membership, and your role in an event;
- photos, video stories, captions, reactions, and timestamps you choose to share;
- technical and security data required to operate, protect, and troubleshoot the service.
Camera and photo library access is used only when you choose to capture or select content. Permission is controlled in your device settings.
3. How we use information
We use this information to:
- authenticate users and manage event membership;
- store and display the event feed to event members;
- enable uploads, reactions, sharing, and host moderation;
- maintain security, reliability, and customer support.
We do not sell personal information. Vistili does not use third-party advertising or cross-app tracking.
3a. Optional usage analytics
Our updated apps offer optional usage analytics using Google Analytics for Firebase and Google BigQuery. In app versions with the Usage analytics setting, this collection is off by default and starts only after you explicitly enable it. The legal basis for this optional measurement is your consent. Declining does not prevent you from joining groups or sharing memories. The setting is available from the welcome screen and the profile or settings area; availability depends on your app version. Contact us if your version does not show it.
We use this measurement to understand navigation, discover problems with joining, uploading and reactions, and improve the interface. Our custom events use a fixed set of screen and control names, operation outcomes and media types. For interface heatmaps, we may record the centre of an activated button or other control, reduced to a 10 by 10 grid. This measures use of controls; it does not record exact touches, screen recordings, session replay or the contents of photos and videos.
Custom usage events do not include account, group or photo identifiers, names, captions, invitation codes, tokens or URLs. Google Analytics also processes a pseudonymous app-instance identifier and basic technical information, such as app version and platform, together with country and region information inferred from network data. This is pseudonymous data, not anonymous data. Google signals, advertising identifier collection and collection of granular city and device data are disabled in our analytics configuration.
You can withdraw consent in Usage analytics at any time without losing access to the service. In versions with this setting, withdrawal stops new analytics collection and resets the Analytics SDK data and identity held locally on that device. It does not automatically erase analytics already received by Google or exported to BigQuery. You can contact us to request access to or deletion of information associated with you; we may need additional information to identify the relevant records. Older app versions may use an earlier analytics implementation, so these new consent controls should not be assumed to exist in every installed version.
3c. Optional crash diagnostics
Versions with the Crash diagnostics setting offer Firebase Crashlytics separately from usage analytics. Sending crash reports is off by default. You can choose either option independently and continue using Vistili with both disabled. When enabled, diagnostics helps us investigate failures, including preparing and uploading photos or videos.
Crashlytics records technical crash reports locally. Our app sends pending reports on a later launch only if diagnostics was enabled throughout the previous app session and is still enabled. Enabling it partway through a session does not send that session retrospectively. Turning it off stops our diagnostic events and requests deletion of pending reports; it cannot recall reports already sent or a transmission already in progress.
Reports can include stack traces, exception information, app and operating-system versions, device characteristics and pseudonymous Crashlytics and Firebase installation identifiers. Our own diagnostic events use fixed screen names, upload stages, broad batch-size and duration ranges, and error categories. We do not add account, group or photo identifiers, captions, invitation codes, file paths, access tokens or media URLs to these events, and we do not attach photos, videos or screen recordings. If you also enable usage analytics, its events can appear as diagnostic breadcrumbs.
Firebase documents a 90-day retention period for crash traces and associated identifiers before removal from live and backup systems begins. Processing is not restricted to our EU BigQuery dataset. See Firebase privacy and security information. You may contact us about data rights using the details below. Availability of these controls depends on your installed app version.
4. Who can access information
Content you add is visible to members of the event. Event hosts can manage event membership and moderate or remove shared content. Avoid sharing sensitive information in captions or media.
We use Google Firebase services, including Authentication, Firestore, Cloud Storage, and Cloud Functions, as service providers to operate Vistili. These providers process data on our behalf under their applicable terms and safeguards. Firebase Authentication handles sign-in credentials. This public website is hosted by Cloudflare, which processes website request metadata such as IP addresses and technical request information to deliver and protect the website.
5. Retention and deletion
For analytics, our current Google Analytics settings use two months for event data and fourteen months for user-level data. These settings govern detailed analytics data; standard aggregated reports and provider deletion processes have separate lifetimes, and user-level retention can be renewed where activity-based reset applies. Daily analytics exports are configured for a BigQuery dataset in the EU with a default table expiration of 60 days after table creation. Provider backup and recovery retention can continue after a table expires. These analytics settings do not set the retention period for the photos, accounts or event content that you share.
We retain event data while it is needed to provide the event experience, maintain security, or meet legal obligations. You can permanently delete your account from the Event screen in the app. For a guest, this removes their membership and contributed uploads. For a host, it also removes events they created and the content inside those events. You may also contact us to request access to or deletion of information associated with you. We may ask for details needed to verify the request and identify the relevant event. See the Vistili data deletion page for the request process, deletion scope, and retention periods.
6. Security
The EU location of our BigQuery dataset does not mean that all Google or Firebase processing takes place only in the EU. Google and its service providers may process data in other countries under their applicable data-protection terms. See Google Firebase privacy and security information and Google Analytics regional privacy controls for provider information.
We use access controls and technical safeguards designed to protect event content. No method of storage or transmission is completely secure, so absolute security cannot be guaranteed.
7. Children
Vistili is not directed to children under 13. If you believe a child has provided information without appropriate permission, contact us so we can review and remove it.
8. Your choices and rights
Depending on your location, you may have rights to access, correct, delete, restrict, or object to processing of your information. You may also have the right to complain to your local data protection authority.
9. Changes to this policy
We may update this policy as Vistili changes. We will publish the current version here and update the date above.
10. Contact
For privacy questions or requests, email yellowbenchprague@gmail.com.
YellowBench s.r.o., Prague, Czech Republic
3b. Optional social sign-in
Supported versions of Vistili offer Google Sign-In and Facebook Login alongside the sign-in methods available on your platform. Availability depends on the app version and completed provider configuration. Choosing one of these methods sends the information needed to authenticate to Google or Meta and Firebase Authentication. The provider can share its account identifier, display name, email address where supplied, and profile picture URL where supplied. Firebase uses the verified credential to establish your Vistili account. Vistili does not receive your Google, Facebook or Apple password.
We request basic sign-in information only, not access to your friends list, posts or photo library held by the provider. Social sign-in does not publish your Vistili photos to Google or Facebook. On Apple platforms, our Facebook integration uses Limited Login. Automatic Meta app-event logging and advertising identifier collection are disabled in our mobile configuration. Optional Vistili usage analytics remains a separate choice and signing in does not enable it.
Group access remains associated with your Firebase account identifier. Where the app offers upgrading a guest account, it links the new sign-in method to that guest account. If that credential already belongs to another Vistili account, the app does not silently move the guest's groups or photos to it. Existing members should use their previous sign-in method when shown an account-conflict message.
Google and Meta also process authentication and security information under their own privacy policies. See Google Privacy Policy and Meta Privacy Policy.