This Privacy Policy explains how Twelve ("we", "us", or "our") collects, uses, shares, and protects your personal information when you use the Twelve mobile application, website (twelve-app.com), and related services (collectively, the "Services").
Twelve is a creator monetization platform for the Health, Nutrition and Fitness vertical. We combine TikTok-style content discovery with built-in monetization tools — one app, one vertical, zero ads. This Privacy Policy applies to all users of our Services, including Creators (content producers) and Learners (content consumers).
By using our Services, you agree to the collection and use of information in accordance with this policy. If you do not agree, please do not use the Services.
1. Data Controller
Twelve
The data controller responsible for your personal data is:
Contact: support@twelve-app.com
Website: www.twelve-app.com
If you have any questions or concerns about how we handle your data, or if you wish to exercise your rights under applicable data protection laws, please contact us at the email address above.
2. Information We Collect
2.1 Information You Provide Directly
We collect information you voluntarily provide when creating an account, applying as a Creator, or using our Services:
- Account Registration: Name, email address, phone number, password, date of birth, and profile picture.
- Creator Application: Areas of expertise, social media handles or links, community size, and your response to "Why do you want to join Twelve?"
- Creator Profile: Community name, community description, biography, profile photo, and service listings (including descriptions, pricing, packages, FAQs, and gallery images).
- Learner Profile: Selected interest topics (from our taxonomy of 37 interest categories across Fitness, Nutrition, Mental Wellness, and Health).
- Content You Upload: Videos, images, community posts, comments, messages, course materials, and service deliverables.
- Communications: Messages sent through our direct messaging (DM) system, including paid DMs and custom offer conversations.
- Payment Information: Billing details processed by our payment partners (Stripe, Apple, Google). Twelve does not store your full credit card number.
- Reviews and Ratings: Reviews you leave for Creators and services.
- Support Requests: Any information you provide when contacting our support team.
2.2 Information Collected Automatically
When you use our Services, we automatically collect certain technical and usage information:
- Device Information: Device type, operating system, unique device identifiers, app version, and mobile network information.
- Usage Data: Pages and screens viewed, time spent on content, features used, search queries, tap and scroll interactions, and navigation patterns.
- Video Viewing Data: Which videos you watch, how long you watch them, whether you complete a video, and your engagement (likes, comments, shares, bookmarks).
- Quiz and Skill Data: Your responses to AI-generated quizzes, quiz accuracy, number of attempts, and the resulting skill level calculations across our four skill categories.
- Location Data: Approximate location based on your IP address (we do not collect precise GPS location).
- Log Data: IP address, browser type, referring/exit pages, timestamps, and crash reports.
- Push Notification Tokens: Device tokens for delivering push notifications via Firebase Cloud Messaging, if you opt in.
2.3 Information from Third Parties
We may receive information about you from third-party services:
- Authentication Providers: If you sign in using Google Sign-In or Apple Sign-In, we receive your name, email address, and profile picture.
- Payment Providers: Stripe, Apple, and Google provide us with transaction confirmations, subscription status, and payout information. We do not receive or store your full payment card details.
- Analytics Providers: We use analytics services (such as Sentry for error tracking) that may collect anonymised usage data.
3. How We Use Your Information
We use the information we collect for the following purposes:
3.1 Providing and Improving the Services
- Creating and managing your account.
- Displaying the personalised video feed based on your interests and viewing history.
- Processing payments, subscriptions, and Creator payouts via Stripe Connect.
- Facilitating the Freelance Marketplace: order creation, delivery tracking, and dispute resolution.
- Enabling communication between Creators and Learners through DMs and custom offers.
- Delivering push notifications about orders, messages, community updates, and account activity.
3.2 AI Processing
- Transcribing uploaded videos using speech-to-text AI to generate searchable text and enable content tagging.
- Automatically tagging and categorising video content into our interest taxonomy using AI classification.
- Generating quiz questions from video transcripts using AI to enhance the learning experience.
- Calculating and updating your skill levels based on watch time and quiz performance across Fitness, Nutrition, Mental Wellness, and Health.
- Populating public leaderboards with usernames and skill data.
3.3 Personalisation
- Recommending content, Creators, and services based on your interests, viewing behaviour, and skill levels.
- Customising your content feed through our organic discovery algorithm (Twelve does not use ad-based ranking).
3.4 Safety and Security
- Detecting and preventing fraud, abuse, and violations of our Terms and Conditions.
- Verifying Creator identities through the vetting and application process.
- Monitoring content for compliance with our community guidelines and health safety standards.
3.5 Communication
- Sending you account-related notifications (e.g., Creator application status, order updates, payout confirmations).
- Sending promotional communications about new features or services (you can opt out at any time).
3.6 Analytics and Research
- Understanding how users interact with our platform to improve features and user experience.
- Generating aggregated, anonymised statistics about platform usage, Creator performance, and learning outcomes.
4. Legal Bases for Processing (GDPR)
If you are located in the European Economic Area (EEA), United Kingdom, or another jurisdiction that requires a legal basis for processing personal data, we rely on the following:
- Contract Performance: Processing necessary to provide you with the Services you have requested.
- Legitimate Interests: Processing necessary for our legitimate business interests, such as improving our Services, preventing fraud, ensuring platform safety, and marketing.
- Consent: Processing based on your explicit consent, such as sending promotional communications, processing push notification tokens, and AI processing of your content. You may withdraw consent at any time.
- Legal Obligation: Processing necessary to comply with applicable laws, such as tax reporting, financial regulations, and responding to lawful government requests.
5. How We Share Your Information
We do not sell your personal data. We share your information only in the following circumstances:
5.1 With Other Users
- Your public profile information (name, profile picture, bio, skill levels) is visible to other users.
- Your leaderboard rankings (username, skill levels, watch time) are publicly visible.
- Reviews you leave are publicly associated with your profile.
- Messages you send to Creators or Learners are visible to the recipients.
- For Creators: your service listings, community information, and public content are visible to all users.
5.2 With Service Providers
We share data with trusted third-party service providers who assist us in operating the platform:
- Stripe: Payment processing and Creator payouts (Stripe Connect Express).
- Apple and Google: In-app purchase processing for community subscriptions.
- Bunny CDN: Video content delivery and streaming.
- Firebase (Google): Push notification delivery.
- OpenAI: Video transcription via the Whisper API. Audio data from uploaded videos is sent to OpenAI for transcription.
- Anthropic: AI content tagging and quiz generation. Video transcripts are sent to Anthropic's Claude API.
- Sentry: Error tracking and crash reporting.
- Mailgun: Transactional email delivery.
5.3 For Legal Reasons
We may disclose your information if required to do so by law, or if we believe in good faith that such action is necessary to comply with a legal obligation, protect the rights or safety of Twelve or its users, or investigate potential violations of our Terms.
5.4 Business Transfers
If Twelve is involved in a merger, acquisition, or sale of assets, your personal data may be transferred as part of that transaction. We will notify you before your personal data is transferred and becomes subject to a different privacy policy.
6. Data Retention
We retain your personal data for as long as your account is active or as needed to provide you the Services. Specific retention periods:
- Account Data: Retained for the duration of your account. If you request deletion, we will delete or anonymise your data within 30 days, except where legally required to retain it.
- Video Content and Transcripts: Retained for as long as the content remains published. Deleted content is removed within 30 days.
- Skill and Quiz Data: Retained for the duration of your account to maintain your learning progress.
- Payment and Transaction Records: Retained for a minimum of 7 years to comply with tax and financial reporting obligations.
- Chat Messages: Retained for the duration of your account.
- Log Data and Analytics: Retained for up to 24 months, then aggregated or deleted.
7. Data Security
We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, alteration, disclosure, or destruction. These measures include:
- Encryption of data in transit using TLS/SSL.
- Secure password hashing (passwords are never stored in plain text).
- JWT-based authentication with secure token management.
- Role-based access controls limiting who can access user data internally.
- Regular security reviews of our infrastructure and codebase.
- Use of Redis for secure session management.
While we take reasonable precautions, no method of transmission over the internet or method of electronic storage is 100% secure. We cannot guarantee absolute security of your data.
8. Your Rights
8.1 Rights Under GDPR (EEA/UK Users)
- Right of Access: You can request a copy of the personal data we hold about you.
- Right to Rectification: You can request correction of inaccurate or incomplete data.
- Right to Erasure: You can request deletion of your personal data ("right to be forgotten"), subject to legal retention requirements.
- Right to Restriction: You can request that we restrict processing of your data in certain circumstances.
- Right to Data Portability: You can request your data in a structured, machine-readable format.
- Right to Object: You can object to processing based on legitimate interests, including profiling for content recommendations.
- Right to Withdraw Consent: Where processing is based on consent, you can withdraw it at any time without affecting the lawfulness of prior processing.
8.2 Exercising Your Rights
To exercise any of these rights, contact us at support@twelve-app.com. We will respond to your request within 30 days. We may ask you to verify your identity before processing your request. If you are in the EEA or UK, you also have the right to lodge a complaint with your local data protection supervisory authority.
8.3 Account Deletion
You can request full deletion of your account and associated data by contacting us at support@twelve-app.com. Upon deletion:
- Your profile, content, skill data, and messages will be permanently removed.
- Your reviews may be anonymised rather than deleted to preserve the integrity of Creator ratings.
- For Creators: outstanding payouts will be processed in the next scheduled payout cycle before account closure.
- Transaction records will be retained as required by law.
9. International Data Transfers
Twelve is operated from Romania. Your data may be transferred to and processed in countries outside of your country of residence, including:
- The United States (where our cloud infrastructure providers, AI processing services, and payment processors operate).
- The European Union (where our primary servers are located).
When we transfer data outside of the EEA/UK, we ensure that appropriate safeguards are in place, such as Standard Contractual Clauses (SCCs) approved by the European Commission, or reliance on adequacy decisions where applicable.
10. Children's Privacy
Twelve is not intended for children under the age of consent for online services in their country (typically 13 or 16, depending on jurisdiction). We do not knowingly collect personal data from children below the applicable age of consent.
If we become aware that we have collected personal data from a child below the applicable age of consent, we will take steps to delete that information as quickly as possible. If you believe a child has provided us with personal data, please contact us at support@twelve-app.com.
11. Cookies and Tracking Technologies
Our mobile application does not use traditional browser cookies. However, we use the following tracking technologies:
- Device Identifiers: We use device identifiers (such as IDFA on iOS and GAID on Android) for analytics and to improve app performance. You can reset or limit these identifiers through your device settings.
- Firebase Analytics: We use Firebase for push notification delivery and may collect anonymised usage analytics.
- Sentry: We use Sentry for error tracking, which collects device and app state information when errors occur.
On our website (twelve-app.com), we may use essential cookies for authentication and session management. We do not use third-party advertising cookies. Twelve does not show ads.
12. Third-Party Links and Services
Our Services may contain links to third-party websites, services, or content that are not owned or controlled by Twelve. We are not responsible for the privacy practices of these third parties. We encourage you to review the privacy policies of any third-party services you access through our platform.
This includes but is not limited to: Creator social media profiles linked from the platform, external websites referenced in community posts, and the privacy policies of Apple, Google, Stripe, and other service providers.
13. Push Notifications
With your permission, we send push notifications through Firebase Cloud Messaging. These notifications may include:
- Order status updates (new orders, deliveries, completions).
- New messages and custom offers in your DMs.
- Community activity (new posts, replies).
- Creator application status updates.
- Payout confirmations.
- Platform announcements and feature updates.
You can manage or disable push notifications at any time through your device's settings. Disabling push notifications does not affect your ability to use the Services.
14. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. If we make material changes, we will notify you by email or through a prominent notice within the app before the changes take effect.
We encourage you to review this Privacy Policy periodically. Your continued use of the Services after any changes constitutes your acceptance of the updated policy.
15. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:
Email: support@twelve-app.com
Website: www.twelve-app.com
We aim to respond to all enquiries within 30 days.
Your privacy matters to us.
Twelve — One app. One vertical. Zero ads.