Effective date: 2026-07-13
This Privacy Policy explains how Wumble s.r.o. processes personal data when people use Wumble's mobile app, server-side services and related website pages.
PN-01 Controller and contacts
Wumble is operated by Wumble s.r.o., registered office Školská 660/3, Nové Město, 110 00 Prague 1, Czech Republic, company number 23309822, VAT identifier CZ23309822. Wumble s.r.o. is the controller for core account, marketplace, trust, security, messaging, campaign and privacy-rights processing.
Privacy requests can be sent to privacy@wumble.io. Data protection officer requests can be sent to dpo@wumble.io. General business contact channels are available at https://www.wumble.io/contact-us.
If you are in the EU or EEA, you may also contact the Czech supervisory authority, the Office for Personal Data Protection, at https://uoou.gov.cz/.
PN-02 Scope and age
Creator accounts are available from age 16. Brand and Agency accounts, and accounts created or managed for an organization, may be operated only by people aged 18 or older. Creators aged 16 or 17 must also follow the capacity and parent or legal-guardian rules in the Terms of Use and in applicable law. The service helps users create accounts, manage profiles, run and apply for campaigns, exchange messages, handle business verification, manage media, request data export and request account deletion.
This Privacy Policy covers the Wumble app, Wumble server-side services and Wumble's legal website pages. It also covers social connection features when a user connects a TikTok or other supported social-media account through that provider's official authorization flow. It does not replace Wumble's Terms of Use, TikTok's or another provider's own terms and privacy policy, or any separate business agreement that may apply to a specific service.
PN-03 Data we process
We process account and authentication data, profile data, role and membership data, Creator profile details, Brand and Agency profile details, business verification and representative information, campaign and application records, messages and safe conversation context, attachments and uploaded media, portfolio items, insights and export records, notifications and preferences, privacy-rights records, account deletion records, legal hold records, security events, audit logs and website or ePrivacy data.
During Creator onboarding, the app uses the date of birth locally to check the minimum-age rule. Wumble does not send the raw date of birth to its backend or save it in the user's profile. Wumble stores only the resulting age-eligibility declaration, including whether it was confirmed, when and how it was recorded, the minimum age applied and the policy version. This allows Wumble to enforce and audit the age rule without retaining the raw date of birth.
If you connect a TikTok or other supported social account, Wumble may process the provider name, public handle or username, display name, avatar URL, profile URL or deep link, bio description, provider verification status, audience statistics such as follower or subscriber count, following count, likes count and video count, connection status, last refresh status and timestamps, and a private provider account identity or pseudonym used to prevent duplicate claims and misuse. For TikTok, the currently approved permission scopes may include user.info.basic, user.info.profile and user.info.stats where you grant them through TikTok's consent screen.
Provider access tokens, refresh tokens, app credentials, raw provider account IDs, hash secret material and raw provider API payloads are not placed in the Wumble app, public APIs, app-facing profile responses, public profiles, logs or data exports. Where provider tokens are needed to operate a connection, token exchange and provider API calls run server-side and the credentials are stored only in restricted private systems.
Wumble does not use personal data for advertising tracking or data-broker purposes. App Store privacy information is maintained separately and should be kept consistent with this Privacy Policy.
PN-04 Why we process data
We process personal data to create and manage accounts, provide Creator, Brand and Agency workflows, operate campaigns and messaging, protect users and the platform, verify business trust where required, provide data export and account deletion rights, respond to support and legal requests, prevent abuse, maintain security and comply with law.
We process the limited Creator age-eligibility declaration to enforce role eligibility, prevent access below the permitted age, apply safeguards for minors and demonstrate which age rule was accepted. We do not use this declaration for advertising targeting.
When you connect TikTok or another supported provider, Wumble processes approved provider data to verify account ownership, determine Creator onboarding eligibility, calculate audience statistics, show profile trust signals, support Brand and Agency partner review, maintain marketplace integrity, prevent duplicate account claims and abuse, and develop future Creator and Brand insights where supported by your consent, provider rules and applicable law.
For Creator accounts, Wumble may use fresh audience data to apply an eligibility rule that requires at least one verified supported social account with at least 300 followers or subscribers. TikTok follower count is mapped to Wumble's audience count. If the rule is not met, the connection becomes stale, or you disconnect the last eligible social account, Creator onboarding, marketplace visibility or eligibility for some features may be limited or degraded. Existing campaigns and conversations are not automatically deleted only because an audience count later changes.
The main legal bases are contract performance, legitimate interests, legal obligation and, where required for a specific optional activity, consent. We do not treat general Privacy Policy acknowledgement as cookie consent or marketing consent.
PN-05 Sharing, providers and transfers
We share data only where needed to operate Wumble, support users, comply with law, protect the service or enable user-directed collaboration. Creators, Brands and Agencies may see data that is intentionally shared through campaign, profile, application or messaging workflows.
Connected social account information may be shown on Creator profiles or campaign review surfaces when it is relevant to marketplace trust and partner review. This may include the provider name, handle, profile URL, avatar, public profile information and audience or statistics count. Wumble does not give Brands, Agencies or other users provider authorization credentials, renewal credentials, private provider identifiers, raw provider payloads or app credentials.
If you connect TikTok, you authorize Wumble to exchange authorization data with TikTok and call TikTok APIs within the scopes you approve. TikTok remains a separate provider with its own terms, privacy policy and consent screen. Wumble does not use scraping, private APIs, session-cookie scraping or unofficial data brokers to obtain social account data.
Wumble uses service providers for service hosting, authentication, storage, email delivery, app platform services and website operations when those services are active. Where data is transferred outside the EU or EEA, Wumble will use appropriate transfer safeguards and provide additional information where required by law.
PN-06 Retention
Wumble keeps personal data only as long as needed for the purposes described in this Privacy Policy, unless law, security, audit needs, counterparty continuity or legal hold requires a longer or different retention treatment.
Account deletion has a 30-day grace period. During that period a user can cancel the request. After the grace period, Wumble's server-side deletion process redacts, anonymizes, detaches or deletes data according to the approved data-surface policy. Shared campaign and messaging records may remain available to counterparties with the deleted actor anonymized or detached. Legal hold can pause deletion execution. To protect the service from repetitive automated or abusive request/cancel loops, self-service account deletion requests may apply a short cooldown after recent or repeated cancellation. This does not remove your right to make a privacy request; urgent or legal requests can still be sent to privacy@wumble.io.
Data export packages are available within a 90-day export window. A download link is short-lived, currently 10 minutes, and must be requested by the account owner after identity verification. To protect the service from repetitive automated load, self-service export package generation can reuse a recent available package or apply a short cooldown. This does not remove your right to make a privacy request; urgent or legal requests can still be sent to privacy@wumble.io.
If you disconnect a social account, Wumble stops refresh where technically possible, revokes or deletes provider tokens according to provider capabilities, removes or anonymizes user-facing metric state, and keeps only minimal audit and security records without tokens or unnecessary provider details. When an account is deleted, social credentials and user-linked social connection data are deleted, anonymized or detached according to Wumble's account deletion policy.
PN-07 Your privacy rights
Depending on your location and the applicable law, you may have rights to access your data, request a copy, rectify inaccurate data, request deletion, restrict processing, object to processing, request portability, withdraw consent where processing is based on consent, and lodge a complaint with a supervisory authority.
You can request data export and account deletion in the Wumble app where those features are available. You can also contact privacy@wumble.io. We may need to verify your identity before fulfilling a request.
Your data export may include social connection state and the latest user-facing metric state that Wumble stores for your account, such as the connected provider, handle, connection status and latest published audience statistics. It will not include provider authorization credentials, renewal credentials, app secrets, raw provider IDs, hash secret material or raw provider API payloads.
PN-08 Privacy choices, California and UK notes
Depending on where you live, you may have additional privacy choices under local law. If California privacy laws apply to your relationship with Wumble, you may have rights to know, access, correct, delete and limit certain uses of personal information, and to opt out of certain sale, sharing or targeted advertising uses where those activities occur.
Wumble does not currently sell personal data or use it for third-party advertising tracking. If Wumble introduces processing that requires an opt-out or preference mechanism, Wumble will provide a clear way to exercise that choice. You can contact privacy@wumble.io to ask about privacy choices that apply to you.
If you are in the UK, Wumble will handle privacy requests under applicable UK data protection and ePrivacy rules where they apply.
PN-09 Security and changes
Wumble uses technical and organizational controls designed to protect personal data, including encrypted transport, access controls, separation of operational environments, restricted service-side operations for privacy rights, audit evidence and security monitoring.
Provider credential exchange and social provider API calls run server-side. iOS clients do not receive provider authorization or renewal credentials. Provider credentials and app credentials are restricted, encrypted or otherwise protected in private systems and excluded from public APIs, app-facing profile responses, logs and data exports.
We may update this Privacy Policy when Wumble changes, law changes or our privacy practices change. The current public version is available at https://www.wumble.io/privacy.