Privacy Policy

Effective date: July 20, 2026

VibeKit ("we", "us", "our") operates the VibeKit platform, the website at vibekit.bot, the iOS application, the web dashboard at app.vibekit.bot, the CLI, and published npm packages (collectively, the "Service"). VibeKit is the data controller for the personal data described in this policy; contact details are in Section 11. This policy explains what data we collect, how we use it, who we share it with, and your rights.

By using the Service you also agree to our Terms of Service.

1. Information We Collect

2. How We Use Your Data

3. Data Storage & Security

Data is stored on AWS infrastructure in us-east-2 (Ohio). All connections to the Service use HTTPS/TLS.

BYOK credentials and environment variables are encrypted at rest with AES-256-GCM. Each user's data is encrypted with a per-user key derived from a master key via HKDF-SHA256 with the account UUID as salt, master-key compromise alone does not expose any single user's data. Plaintext credentials are only held in process memory at request time and are never written to logs, telemetry, analytics, or backups. We redact known secret formats (sk-, sk-ant-, sk-proj-, GitHub tokens, JWTs, and others) from any text that gets logged.

Each app runs in its own AWS Fargate task with an isolated workspace. Per-tenant shell access is sandboxed by a bwrap wrapper at the OS layer. Database access is gated by Postgres row-level security so users only read and write their own rows.

No system is perfectly secure. If a breach affects your personal data, we will notify you and the relevant authorities as required by applicable law.

Your apps' own visitors. Apps you build and host on VibeKit may collect data from their own end users (signup forms, databases, email features). That data belongs to you, the app owner, and is processed by VibeKit only as your hosting infrastructure. You are responsible for your app's own privacy disclosures and legal compliance toward its users; this policy covers VibeKit's users, not the visitors of apps our users operate.

4. Third-Party AI Services

VibeKit routes your AI requests to third-party providers. The routing depends on whether you've configured BYOK:

4a. Two routing paths

4b. What data is sent to AI providers

We do not send your email, payment information, password, BYOK credentials, or any other account secret to AI providers.

4c. Who data may be sent to

Anthropic and OpenAI do not train models on API data, on either the BYOK or platform-credit route. OpenRouter, the aggregator we use for the non-BYOK route, may use prompts and responses to improve their product under the data-discount setting we've enabled (see Section 4a above); they have stated this is not used for model training. Free-model pool operators are an exception: the third parties serving free-tier requests set their own data practices, and some may use inputs to improve or train their models, if that matters for your content, use a paid provider or BYOK. Data sent to AI providers is never used for advertising by us.

4d. Your consent

Before first use of the AI agent, you're asked to acknowledge data sharing with third-party AI services. You can withdraw consent by removing your BYOK credentials and discontinuing use of the agent.

4e. Other third-party services

5. Cookies and Analytics

The marketing pages on vibekit.bot use Google Analytics (GA4) to measure aggregate traffic. The dashboard and iOS app do not use third-party analytics. We use a small number of first-party cookies for session management and one (vk_referral) to attribute referral signups.

Google signals (Advertising Features). Our GA4 property has Google signals enabled on the marketing pages. For visitors who are signed in to a Google account and have consented to ads personalization, Google may associate their visit with Google's own account information, which can include location, search history, YouTube history, and data from sites that partner with Google, to give us cross-device and aggregate demographic/interest reporting. We only ever see this in aggregate (e.g. age brackets, gender, interest categories); we never receive data that identifies an individual, and we do not use it for ad targeting. We adhere to Google's Advertising Features policy. You can review or turn off this association at any time via Google Ads Settings and My Activity, or opt out of Google Analytics entirely with the Google Analytics opt-out browser add-on.

6. Data Retention

Agent transcripts and app data are retained while your account is active. You can delete an app (and its transcripts, files, env vars, and Fargate task) from the dashboard at any time. Account deletion removes all associated data within 30 days, except aggregated billing records we are required to retain for tax or accounting purposes. Audit-log entries (security events) are retained for 12 months.

7. Your Rights

Depending on where you live, you may have rights under the GDPR (EEA/UK), CCPA/CPRA (California), or similar laws. You can:

We do not sell or share your personal information as those terms are defined under the CCPA/CPRA, and we do not discriminate against you for exercising any privacy right.

8. International Transfers

VibeKit infrastructure is in the United States (AWS us-east-2). If you access the Service from outside the US, your data will be transferred to and processed in the US. We rely on AWS's GDPR-compliant data-processing terms and Standard Contractual Clauses where applicable.

9. Children's Privacy

The Service is not intended for users under 13. We do not knowingly collect data from children under 13. If you believe we have collected data from a child, contact [email protected] and we will delete it.

10. Changes

We may update this policy. Material changes will be communicated through the platform with at least 30 days' notice for paying users where reasonable.

11. Contact

Privacy questions and general support: [email protected].


Terms of Service · ← Back to VibeKit