Privacy Policy

Effective date: August 7, 2026

VibeKit ("we", "us", "our") operates the VibeKit platform, the website at vibekit.bot, the iOS application, the web dashboard at app.vibekit.bot, the CLI, and published npm packages (collectively, the "Service"). VibeKit is the data controller for the personal data described in this policy; contact details are in Section 11. This policy explains what data we collect, how we use it, who we share it with, and your rights.

By using the Service you also agree to our Terms of Service.

1. Information We Collect

2. How We Use Your Data

3. Data Storage & Security

Data is stored on AWS infrastructure in us-east-2 (Ohio). All connections to the Service use HTTPS/TLS.

BYOK credentials and environment variables are encrypted at rest with AES-256-GCM. Each user's data is encrypted with a per-user key derived from a master key via HKDF-SHA256 with the account UUID as salt, master-key compromise alone does not expose any single user's data. Plaintext credentials are only held in process memory at request time and are never written to logs, telemetry, analytics, or backups. We redact known secret formats (sk-, sk-ant-, sk-proj-, GitHub tokens, JWTs, and others) from any text that gets logged.

Each app runs in its own AWS Fargate task with an isolated workspace. Per-tenant shell access is sandboxed by a bwrap wrapper at the OS layer. Database access is gated by Postgres row-level security so users only read and write their own rows.

No system is perfectly secure. If a breach affects your personal data, we will notify you and the relevant authorities as required by applicable law.

Your apps' own visitors. Apps you build and host on VibeKit may collect data from their own end users (signup forms, databases, email features). That data belongs to you, the app owner, and is processed by VibeKit only as your hosting infrastructure. You are responsible for your app's own privacy disclosures and legal compliance toward its users; this policy covers VibeKit's users, not the visitors of apps our users operate.

4. Third-Party AI Services

VibeKit routes your AI requests to third-party providers. The routing depends on whether you've configured BYOK:

4a. Two routing paths

4b. What data is sent to AI providers

We do not send your email address, payment information, VibeKit account password, or BYOK model-provider credentials to AI providers. The exception is a credential intentionally returned by a connected-account tool after the separate confirmation described in Section 5.

4c. Who data may be sent to

Anthropic and OpenAI do not train models on API data, on either the BYOK or platform-credit route. OpenRouter, the aggregator we use for the non-BYOK route, may use prompts and responses to improve their product under the data-discount setting we've enabled (see Section 4a above); they have stated this is not used for model training. Free-model pool operators are an exception: the third parties serving free-tier requests set their own data practices, and some may use inputs to improve or train their models, if that matters for your content, use a paid provider or BYOK. Data sent to AI providers is never used for advertising by us.

4d. Your consent

Before first use of the AI agent, you're asked to acknowledge data sharing with third-party AI services. You can withdraw consent by removing your BYOK credentials and discontinuing use of the agent.

4e. Other third-party services

5. Connected Accounts

If you use Connections to link a third-party account (for example Gmail, Slack, Notion, GitHub, Jira, HubSpot, Stripe) to one of your apps, the OAuth flow is operated by our integration provider, Composio. Composio receives and stores the access token for that account; VibeKit does not receive your account password or the OAuth token used to establish the connection. What we store is a bookkeeping record: which app is linked to which application, the connection's status, and timestamps.

Data that flows through a connected account. When your agent uses a connection, the request is made server-side by VibeKit through Composio to that provider, and the provider's response is returned to your agent so it can act on it. That content, for example the body of an email, the rows of a spreadsheet, or the text of an issue, therefore passes through Composio and VibeKit, and then into your agent's context, which means it is also sent to the AI provider handling that request under Section 4 above. Some provider tools can intentionally return sensitive credentials such as API keys, access tokens, passwords, or database connection strings. Before running one, the Service requires a separate, explicit confirmation phrase from you and warns that the result will enter the agent transcript and the active AI provider's context. VibeKit records that a sensitive tool was confirmed and executed, but does not separately log its arguments or returned value. Do not connect an account, or approve a sensitive credential request, unless you are willing to have that content processed by an AI model. We do not retain the content of connected-account responses beyond the agent transcript for that conversation, which is deleted with the app.

Actions. Connections can write, not just read. Actions your agent takes, such as sending an email or creating a record, happen inside the provider's systems and are recorded by that provider under its own policy. We log the app, the application, and the name of the action taken, so the activity is auditable; we do not log the contents of what was sent.

You can disconnect any account at any time from that app's Connections screen. Disconnecting revokes the agent's access going forward and asks Composio to revoke the stored token. Data the provider already holds, and actions already taken, are governed by that provider's policy. Composio's own privacy policy is available at composio.dev/privacy.

6. Cookies and Analytics

We use Google Analytics (GA4) to measure aggregate traffic, both on the marketing pages at vibekit.bot and on the signed-in web dashboard at app.vibekit.bot. On the dashboard this measures product usage (which pages are visited, and aggregate patterns) so we can see where the product is confusing or broken; we do not send your prompts, file contents, agent transcripts, or credentials to Google Analytics. The iOS app contains no third-party analytics at all. We use a small number of first-party cookies for session management and one (vk_referral) to attribute referral signups.

Consent. If you are in the EEA, the UK, or Switzerland, analytics and advertising storage are set to denied before anything loads, and stay denied unless you accept in the banner we show you. Declining is a real choice that we remember: Google Analytics then sets no cookies and records no advertising identifiers for you, and the rest of the Service works exactly the same. You can change your mind by clearing this site's data in your browser, which brings the banner back. Outside those regions analytics runs by default, and the opt-outs below are always available to everyone.

Google signals (Advertising Features). Our GA4 property has Google signals enabled, and because Analytics runs on the dashboard as well as the marketing pages, this applies to signed-in visits too. For visitors who are signed in to a Google account and have consented to ads personalization, Google may associate their visit with Google's own account information, which can include location, search history, YouTube history, and data from sites that partner with Google, to give us cross-device and aggregate demographic/interest reporting. We only ever see this in aggregate (e.g. age brackets, gender, interest categories); we never receive data that identifies an individual, and we do not use it for ad targeting. We adhere to Google's Advertising Features policy. You can review or turn off this association at any time via Google Ads Settings and My Activity, or opt out of Google Analytics entirely with the Google Analytics opt-out browser add-on.

7. Data Retention

Agent transcripts and app data are retained while your account is active. You can delete an app (and its transcripts, files, env vars, and Fargate task) from the dashboard at any time. Account deletion removes all associated data within 30 days, except aggregated billing records we are required to retain for tax or accounting purposes. Audit-log entries (security events) are retained for 12 months.

8. Your Rights

Depending on where you live, you may have rights under the GDPR (EEA/UK), CCPA/CPRA (California), or similar laws. You can:

We do not sell or share your personal information as those terms are defined under the CCPA/CPRA, and we do not discriminate against you for exercising any privacy right.

9. International Transfers

VibeKit infrastructure is in the United States (AWS us-east-2). If you access the Service from outside the US, your data will be transferred to and processed in the US. We rely on AWS's GDPR-compliant data-processing terms and Standard Contractual Clauses where applicable.

10. Children's Privacy

The Service is not intended for users under 13. We do not knowingly collect data from children under 13. If you believe we have collected data from a child, contact [email protected] and we will delete it.

11. Changes

We may update this policy. Material changes will be communicated through the platform with at least 30 days' notice for paying users where reasonable.

12. Contact

Privacy questions and general support: [email protected].


Terms of Service · ← Back to VibeKit