Wakazi — Privacy Policy
Last updated: 16 August 2026
Data controller: Qubist LLC, the company that operates Wakazi
Privacy contact: noreply@wakazi.app
Wakazi ("Wakazi", "we") is a worldwide, location-based marketplace that connects customers who need work done with nearby skilled workers through mutual, swipe-based matching. This policy explains, in plain language, what we collect, why we collect it, and exactly who can see it.
1. What we collect
Account and sign-in
- Email address. You sign in with your email address and a password, or with your Google or Apple account. Your email address is stored on your account and is never shown to other users.
- Password-recovery and transactional emails are delivered by our email provider, Resend.
Profile information
- Your role (customer or worker), your name (workers may use a display name), and your area details: county, town, estate.
- Workers additionally provide: occupation, skills, bio, years of experience, expected rate and rate type, travel radius, languages, and availability.
- Ratings and completed-job counts accumulated from platform activity.
Identity verification
- Email verification. Before you post a job or swipe, you verify your account email address with a one-time code we email to you (delivered by our email provider, Resend). We store the fact and time of verification, and the method used — never the code itself.
- Optional government-ID verification (workers). Workers may optionally earn a Verified ID badge by uploading a photo of the front of a government ID and a selfie. The images are processed by an automated checker (an AI vision model — see section 8 for how AI requests are routed and retained) and by a trained human reviewer who always makes the final decision. ID images are deleted 7 days after the decision (immediately when you delete your account). We keep only the verification status, review flags and scores, irreversible image hashes, and your consent record — never full ID numbers. See section 5.
- Optional profile photo (avatar). Stored privately and visible only to you and users you have matched with — never in public feeds.
Location
- Precise GPS location you provide for your profile and for each job you post, stored as a geographic point.
- We use it to compute distances and rank nearby jobs and workers for matching. How much of it other users can see is described in section 3.
Jobs
- Title, description, budget and payment type, category and skills, photos, schedule, urgency, and both an approximate and an exact location point.
Activity
- Swipes (likes, passes, saves), matches, and reviews (a 1–5 rating and comment, one review per participant per match).
- In-app notifications generated for you (new matches, messages, unlocks).
Messages
- Chat text and any photos you send, stored on our servers so both participants can read the conversation history.
Purchases
- When a customer unlocks a match, the payment is processed entirely by
Apple (App Store) or Google (Play Billing). No card or bank details
ever touch Wakazi. We store only: the store (Apple/Google), the store
transaction id, the product id (
match_unlock), the amount, the currency, and the resulting payment status. We need this to unlock the match and to make double charging impossible (each store transaction id can be redeemed exactly once).
Reports and moderation data
- When you file a report we store: who reported, which user or job was reported, the reason (for example scam, no-show, inappropriate behavior, or other), your details, and the report's status.
Push notifications
- A device push token, used only to deliver notifications to your device via Firebase Cloud Messaging (Google). Tokens are stored in our database under your account and are readable only by you and our notification service.
Usage analytics and crash reports
- Product analytics. We record product-usage events (for example: the app opened, a job posted, a match created, an unlock completed, a review submitted) together with safe metadata only — internal record ids, counts, yes/no flags, category slugs, your app language, and the platform (iOS/Android). Events are processed by Firebase Analytics (Google).
- Crash reports. Release builds of the app send crash reports (error type, stack trace, device and OS class, app version) to Firebase Crashlytics (Google) so we can find and fix bugs. Development builds never send crash reports.
- When you are signed in, analytics events and crash reports may carry your opaque internal user id (a random UUID) so we can understand funnels and diagnose account-specific crashes. It is never your email, phone number, or name.
- Analytics and crash payloads never contain: email addresses, phone numbers, message contents, job description text, exact coordinates or addresses, photos, ID information, passwords, payment receipts, call audio, or referral-recipient identities. The app enforces this in code: every event passes a fixed per-event allowlist of parameter keys, and a second filter drops anything resembling an email, phone number, message text, or location before anything leaves the device.
- Opt-out: Profile → Data & privacy → “Share usage & diagnostics”. Turning it off stops analytics events and crash reports from leaving the app. The choice is stored on your device.
Security and audit logs
- Records of account and payment events used for security, fraud prevention, and debugging.
2. How we use your information
- Create and secure your account via email and password, or Google/Apple sign-in.
- Verify that accounts belong to real people: email verification before posting or swiping, and optional ID checks for the worker verified badge.
- Show you nearby jobs or workers and rank them by distance and other matching signals.
- Create a match when both sides like each other, and unlock chat, contact details, and exact location after the customer's purchase.
- Deliver in-app and push notifications about matches and messages.
- Keep the platform safe: investigate reports and prevent payment fraud. Purchase receipts are verified server-side with Apple/Google before any unlock, and the app itself is never trusted.
- Understand how the app is used (which funnels work, where flows break) and diagnose crashes, using the analytics events and crash reports described in section 1.
- Maintain security and reliability through audit logs.
We do not sell your personal data, and we do not use it for advertising profiles.
3. Location: who sees what
- Before a match is unlocked, no user ever sees your exact location.
- Worker cards shown to customers display only the worker's area (estate, town, county) and a location snapped to a grid of roughly 1 km — never the exact point.
- Job feeds show the job's approximate area, snapped to the same kind of grid. The exact job location is revealed to the matched worker only after the customer unlocks the match.
- These rules are enforced at the database level (row-level security and restricted views), not merely hidden in the app.
4. Phone numbers and contact details
- Your phone number is contact information only — it is never used to verify your account (account verification happens over email).
- Phone numbers are hidden from other users until a match is unlocked.
- After an unlock, the two participants can see each other's contact details so they can arrange the work.
5. Identity verification
Email verification (required for posting and swiping)
- Verification is a one-time code sent to your account email address, delivered by our email provider, Resend. Resend processes your email address to deliver the code.
- We store the verification result (whether and when you verified, and via which method) on your profile — never the code itself. The verification flag is written only by our server-side function — never by the app.
Optional government-ID verification (worker verified badge)
- Entirely optional — no core feature requires the badge. Workers who want the verified badge give explicit, separate consent (unticked by default) and upload a photo of the front of a government ID plus a selfie.
- The images go to private, write-only storage that no other user can read. An automated checker (an AI vision model, routed through Vercel AI Gateway to Google's Gemini models and sent with zero data retention where supported — see section 8) extracts visible details (such as name and year of birth) and flags quality or tampering concerns — it never approves or rejects. A trained human reviewer compares the ID photo with the selfie and makes the final decision.
- The images are used only to decide the badge. They are never sold and never shared beyond the automated checker and the reviewer, and we never store full ID numbers.
What we keep, and deletion
- Verification status, the decision reason, review flags/scores, and irreversible SHA-256 image hashes (used for duplicate and fraud detection) are kept while your account is active. The extracted ID details (name) are wiped when the decision is made.
- ID and selfie images are deleted 7 days after the decision (a dispute window) — and immediately when you delete your account (section 10), which also removes your profile and verification records.
- We may keep an irreversible hash of the verified identity (a "tombstone") so that an identity rejected for fraud cannot simply re-register; this hash cannot be converted back into your identity or your images.
6. Payments
- All purchases are processed by Apple or Google under their own privacy policies; Wakazi never sees, processes, or stores your card data.
- Receipts are verified server-side (Apple App Store Server API / Google Play Developer API) before a match is unlocked. Failed or unverified purchases never unlock anything.
- Payment status is written only by our server-side verification function — never by the app.
- Refunds are handled through the store refund flows (Apple / Google). When a store notifies us of a refund, the unlock is reversed: the match is re-locked and any credits earned from the purchase are withdrawn.
7. Chat
- Messages are stored on our servers and are visible only to the two participants of an unlocked match, enforced by database row-level security.
- Messages are not end-to-end encrypted. We may review message content where needed to investigate a report or safety issue; reports filed in the app are reviewed by the Wakazi team.
8. Who we share data with
We share data only with:
- Other users, strictly limited by the visibility rules in sections 3, 4 and 7.
- Apple and Google, for payment processing; Google (Firebase) additionally for push-notification delivery (Cloud Messaging) and for product analytics and crash reporting (Firebase Analytics and Firebase Crashlytics — only the allowlisted events, safe metadata and crash diagnostics described in section 1, and only while your “Share usage & diagnostics” switch is on).
- Vercel AI Gateway (Vercel Inc.) and Google, for AI features — job drafts, profile suggestions, photo analysis, translation, and the automated triage for optional government-ID verification (the ID check runs only if you opt in to the worker badge). AI requests are processed through Vercel AI Gateway, which routes them to Google (Gemini models); ID-document triage requests are sent with zero data retention where supported. Your prompts and images are used only to provide the feature, are never sold, and their content is not logged in our telemetry (metadata only). The final badge decision is made by a human reviewer at Wakazi.
- Cloudflare, for the Turnstile anti-abuse check on signup and sign-in.
- Our backend provider (Supabase), which hosts the database, authentication, file storage, and server functions that run the service.
- An email delivery provider (Resend), to deliver verification codes, password-recovery and transactional emails (receipts, match alerts).
9. Data retention
- We keep your data while your account is active.
- When you delete your account (section 10), your profile, jobs, matches, payment records, swipes, and reviews are deleted with it. Messages you sent stay visible to the other participant, attributed to a deleted account, and reports are kept for safety investigations with your account reference removed.
- Security and audit logs of account and payment events are kept for fraud prevention and debugging.
- Identity-verification retention is described in section 5.
10. Account deletion
- You can delete your account and personal data at any time directly in the app, from the profile screen. Deletion runs server-side via our delete-account function and removes your auth account, which cascades by design to your profile and related personal rows in our database.
- You can also delete your account without reinstalling the app at wakazi.app/account-deletion. The secure page verifies the account before it sends the same permanent deletion request used by the app.
- Limited records survive deletion in the forms described in section 9 (anonymized messages and reports, security audit logs); the store (Apple/Google) retains its own receipt of each purchase under its own policies, and section 5 describes the identity tombstone.
11. Security
- Sensitive fields (phone numbers, exact locations, messages) are readable only under the database row-level-security rules described in this policy.
- Trust data (ratings, verification status, credit balances) can be written only by server-side functions — never by the app or by other users.
- All traffic between the app, this website, and our backend uses encrypted connections (HTTPS/TLS).
12. Age requirement (18+)
Wakazi is for adults only. You must be 18 or older to create an account or use the service. We do not knowingly collect data from anyone under 18; if you believe a minor has an account, contact noreply@wakazi.app and we will remove it.
13. International use
Wakazi operates worldwide. Your information may be processed in countries other than your own, including where the providers listed in section 8 operate; where data crosses borders it is handled under those providers' data-processing terms.
14. Changes to this policy
We will update this policy as the product evolves and post the new version on this page with a revised "last updated" date. Material changes will be flagged inside the app.
15. Contact
Privacy questions, data-access or deletion requests, and report follow-ups: noreply@wakazi.app