Privacy Policy

Last updated: July 26, 2026

Introduction

Vicari ("we," "our," or "us") operates the vicari.app public website, Vicari mobile application, and Chrome browser extension (collectively, the "Services"). This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our Services.

Using the Services does not mean that you consent to optional website analytics. Where we rely on consent, we ask for it separately. References to the "App" in this policy apply equally to the Chrome extension unless stated otherwise.

Information We Collect

Information You Provide

  • Account Information: When you register, we collect your name, email address, and profile information.
  • User Content: Posts, comments, photos, and other content you share on the platform.
  • Body Measurements: If you choose to provide them, we collect body measurements (height, weight, body dimensions) to help provide relevant content.

Optional Public Website Analytics

On vicari.app, we use PostHog and Vercel Analytics, including Vercel Speed Insights, only after you accept analytics. These services help us understand which public pages are useful, how long pages remain open, whether visitors encounter an app-download prompt, and whether they continue to the Vicari app, an app store, or an outbound product page.

Depending on the page and action, optional analytics may include:

  • Page type and URL path, which may contain a public username
  • Locale, approximate device and browser category, timestamps, and time on page
  • Sanitized referrer and approved campaign labels
  • Views, tab selections, shares, app prompts, app-store clicks, and outbound product clicks
  • Opaque content or product identifiers
  • A stable pa_v1_...public-profile pseudonym identifying the creator whose profile is viewed. It is not the visitor's identifier or Vicari's internal database ID, but it may be associated with the creator's public profile.

We do not use optional website analytics to collect account credentials, email addresses, body measurements, form text, messages, post text, or other user-entered content. PostHog automatic click capture, session recording, heatmaps, and person profiles for anonymous visitors are disabled. PostHog uses memory-only analytics persistence, so its anonymous browser identifier ends when the page is fully reloaded or closed.

PostHog processes Vicari's analytics project in its European cloud region in Frankfurt. Vercel provides aggregated website and performance reporting. We do not use this information for targeted advertising and do not sell it.

Your Analytics Choice

The legal basis for optional public-website analytics is your consent. PostHog and the Vercel client analytics scripts do not load before you accept. If you reject, we do not send page views, time-on-page information, or interaction events to these analytics services. The website and its links remain fully usable.

We store only your accept or reject choice in first-party browser storage so that we can respect it. This preference is not used as an analytics identifier. We also respect an enabled browser Do Not Track setting by keeping optional analytics disabled.

You can withdraw consent or change your choice at any time. Withdrawal does not affect the lawfulness of processing performed before withdrawal.

Essential Requests, Creator Statistics, and Product Clicks

Rejecting optional analytics does not disable essential hosting, security, fraud-prevention, or backend request logs. When you deliberately follow an outbound product link, Vicari may record that click against the public product identifier to operate and verify creator and shop functionality. These first-party records are separate from PostHog and Vercel analytics and are not used to recreate a rejected visitor's analytics journey. We process them based on our legitimate interests in operating, securing, and measuring the Services.

When a public profile, post, request, or product page is opened, Vicari may also count that view against the public content identifier so that the creator concerned can see aggregate statistics about their own public page. These counts identify the content viewed, not the visitor: they build no visitor profile, store nothing in your browser, and are not linked to PostHog, Vercel, or your analytics choice. To avoid counting one visitor's repeated refreshes twice, our servers briefly derive a keyed, privacy-minimized hash from network metadata; it is kept only in a short-lived server-side store for roughly ten minutes, is never saved with the counts, and is not used for any other purpose. We process these counts based on our legitimate interest in providing creators with aggregate statistics about their own public content.

Individual first-party view and product-click records are retained only as long as necessary for creator and shop reporting and, in any event, for no longer than 25 months. They are then deleted or retained only as aggregated statistics.

Information Collected Automatically

  • Device Information: Device type, operating system, unique device identifiers.
  • Usage Data: How you interact with the App, including features used and time spent.
  • Log Data: IP address, access times, and pages viewed.
  • Browser Extension Data: When you use the Vicari Chrome extension and click the extension icon on a product page, we receive the page URL to match it against products in our database. We do not store or log browsing history.

Camera and Media Access

Our App requests access to your device's camera and photo library to enable you to:

  • Take photos
  • Upload images from your gallery

We do not access your camera or photos without your explicit action. Photos are only uploaded when you choose to share them.

Chrome Extension

Our Chrome browser extension ("Vicari Extension") accesses the following:

  • Active Tab Content: When you click the extension icon, it reads product information (name, brand, price, images) from the current page's publicly available structured data (JSON-LD and Open Graph meta tags) to match products with Vicari reviews. No page content is read until you explicitly click the extension icon.
  • Authentication: The extension stores login tokens securely using Chrome's built-in storage APIs. Access tokens are held in session storage (cleared when the browser closes) and refresh tokens in local storage (persistent across sessions). Tokens are only sent to Vicari's own servers for authentication.
  • No Background Activity: The extension does not inject scripts, read page content, or collect any data unless you explicitly activate it by clicking the extension icon. There is no passive monitoring, tracking, or data collection while browsing.

The extension communicates exclusively with Vicari's servers (api.vicari.app) and our authentication provider (Supabase). No data is sent to third parties.

How We Use Your Information

We use the collected information to:

  • Provide, maintain, and improve the App
  • Send notifications about activity on your account
  • Respond to your comments, questions, and support requests
  • Monitor and analyze usage patterns and trends
  • Detect, prevent, and address technical issues and fraud
  • Personalize your experience and deliver relevant content
  • Match products you are browsing with existing Vicari reviews and posts

Sharing of Information

We may share your information in the following situations:

  • With Your Consent: When you explicitly agree to share information.
  • Public Content: Posts and profile information you make public are visible to other users and, through your public web profile, to visitors of the vicari.app website (see "Your Public Web Profile" below).
  • Service Providers: With third-party vendors who assist in operating our App.
  • Legal Requirements: When required by law or to protect our rights.
  • Business Transfers: In connection with a merger, acquisition, or sale of assets.

Your Public Web Profile

Vicari includes a public web profile at vicari.app/@your-username. It lets people who do not have the App view and share your profile, your public posts and requests, and the products you have recommended, and follow your product links to retailers. For active accounts this page is on by default.

What the public page can show

  • Your username, display name, profile photo, bio, and public badge where applicable
  • Your public posts and requests, including their media, dates, and product links
  • Your gender, height, and weight, but only if you separately choose to publish all three together on the web
  • Aggregate numbers such as your posts, requests, products, followers, and following counts

What it never shows

  • Body measurements other than the gender, height, and weight you may separately choose to publish; your other measurements remain in Vicari
  • Comments or comment authors
  • Follower or following lists
  • Your email address, phone number, date of birth, or other account details
  • Private settings, saved items, or your other in-app activity

Your control

You can turn the page off at any time in the App under Settings → Public profile. Turning it off also turns off public body-information sharing and promptly removes your profile and content from Vicari's public website and public interfaces, without changing anything inside the App. Copies held outside Vicari's systems — for example search-engine caches or screenshots — may persist for some time. If you turn the page back on later, we ask you to confirm that choice first. Body-information sharing remains off unless you enable it again separately.

Your public profile does not include your body information by default. Under Settings → Public profile, you can separately choose to publish your gender, height, and weight together. Before the first activation, we show you a specific disclosure. When enabled, these three values can be viewed by anyone on relevant Vicari public pages and may be indexed by search engines. Turning the setting off removes all three from Vicari's live public pages. It does not publish your other measurements.

Blocking another Vicari user applies inside the App. It does not prevent someone without an account from opening your public web page. If you do not want a public page, turn the setting off.

We provide default-on public profiles based on our legitimate interest in operating a public, shareable discovery experience; the setting above is also how you object to this processing. Active public profiles and eligible public posts, requests, product pages, and discovery pages may appear in Vicari's directories and sitemaps and may be indexed by search engines. After you turn your public profile off, Vicari removes those pages from its public discovery results, but search engines and other third parties may take time to update or remove copies they previously stored.

Data Security

We implement appropriate technical and organizational measures to protect your personal information. However, no method of transmission over the Internet or electronic storage is 100% secure.

Data Retention

We retain your personal information for as long as your account is active or as needed to provide you services. You may request deletion of your account and associated data at any time.

Optional public-website analytics events are kept in event-level form only as long as necessary to understand and improve the Services and, in any event, for no longer than 25 months. They are then deleted or retained only as aggregated statistics that no longer identify an individual visitor. We periodically review this period so that it remains limited to what is necessary. The local analytics choice remains in your browser until you change it or clear your browser storage.

Your Rights

You have the right to:

  • Access the personal information we hold about you
  • Request correction of inaccurate information
  • Request deletion of your account and data
  • Export your data
  • Withdraw your analytics consent or reject optional analytics at any time
  • Object to processing based on our legitimate interests, subject to applicable exceptions
  • Uninstall the Chrome extension at any time, which immediately stops all extension-related data access

Children's Privacy

Our App is not intended for users under 16 years of age. We do not knowingly collect personal information from users under 16.

Changes to This Privacy Policy

We may update this Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page and updating the "Last Updated" date.

Contact Us

If you have questions about this Privacy Policy or our privacy practices, please contact us at:

Email: privacy@vicari.app


This privacy policy is effective as of July 26, 2026.