Trust & Security at TBuddy
This page is maintained by the TBuddy team to answer common security and privacy questions about the TBuddy app. It describes practices currently in place and is not an independent certification or audit.
Account & access
Sign-in uses email/password or Google. Passwords are never seen by TBuddy — authentication is handled by our hosted auth provider.
Every account requires an 18+ confirmation and acceptance of our Terms and Community Guidelines.
Signup is protected by a simple anti-bot challenge and honeypot.
Authorization
Access to your data is enforced server-side using row-level security: a user can only read or modify the rows they own (or rows in conversations/tasks they participate in).
Admin actions are gated by a separate role table — role can't be self-assigned from the client.
Our commitments
Traffic between your device and TBuddy is encrypted in transit.
We follow a least-privilege approach: internal tools and admin access are limited to the people who need them.
We keep our platform up to date with regular security reviews and dependency updates.
What we collect
Account info you provide (display name, handle, age confirmation, optional bio, photo, city).
Content you create (tasks, posts, 24-hour stories, portfolio entries, product listings, messages, reviews).
Approximate location for matching; precise GPS coordinates for an active task are only readable by you and the matched buddy — they are not broadcast to other users.
Basic device + usage signals needed to operate the service.
What others can see
Your public profile (name, handle, bio, photo, ratings, badges) is visible to other signed-in users.
Direct messages are visible only to you and the other participant.
Verification documents (ID, selfie) are stored in a private bucket and only readable by you and the moderation team.
Safety controls in the app
Off-platform links, phone numbers and contact handoffs in chats, posts, portfolio entries, product listings and reviews are blocked automatically.
Image uploads across tasks, posts, portfolio, products, avatars and verification are screened by an AI moderation step before going public.
Meet-ups use one-time secret start/end codes so reviews are tied to real interactions.
You can block or report any user from their profile.
Wallet & payments
Every rupee moves through your in-app wallet with a clear ledger. Top-ups are done via UPI and manually verified by our admin team before credits appear — we never store card details.
Top-ups are capped at ₹10,000 per day and ₹1,00,000 per month per account. Duplicate UPI references submitted within 2 minutes are automatically deduplicated to stop accidental double-credits.
Withdrawals require a minimum of ₹100 and are frozen for 24 hours after a top-up to protect against chargeback fraud. Ad budgets that go unspent are auto-refunded to the wallet within minutes of the ad closing.
Ads & promotions
Every ad — in-app or social — is reviewed manually before it appears in feeds. Ads that break the Community Guidelines are rejected and the wallet spend is refunded.
Frequency capping runs both client-side (max 5 views per ad per user per day) and server-side, so the same person never sees the same ad on repeat.
Only the ad owner can see performance analytics (impressions, clicks, CTR) — other members only see the creative itself.
Refer & earn integrity
Referral payouts are unlocked only after the invited friend verifies their email, uploads a government ID, passes selfie verification and takes at least one meaningful action on the app (post, task, product, ad or wallet top-up).
Automated triggers block self-referrals, disposable-email chains and duplicate-device signups so the referral pool stays clean.
Retention & deletion
You can delete your account from Settings; profile, tasks, posts, stories, portfolio entries, product listings, messages and reviews tied to your account are removed or anonymised. 24-hour stories are auto-deleted after 24 hours regardless of account status.
Wallet transaction records, tax receipts, abuse reports and legal holds are retained for the periods required by law, in a restricted finance log that only the finance team can access.
Reporting a vulnerability
Found a security issue? Please email help@tbuddy.app with the subject "Security report". We respond within 24 hours.
For abuse, harassment or safety concerns, use the in-app report button or the Safety Center.
This page is editable content maintained by TBuddy. It does not constitute legal advice or an independent compliance attestation. See our Privacy Policy and Terms for binding terms.