This Policy explains what personal data Vibecoder handles, why we need it, who helps us process it, and the choices you have. It covers the Vibecoder platform and your account, not the privacy practices of websites you create.

1. Who is responsible

Vibecoder is operated by Aisend, trading as Vibecoder.tech, in the Netherlands. Aisend is registered with the Netherlands Chamber of Commerce (KVK) under number 78244692. Aisend is the controller of the personal data described in this Policy.

For privacy questions or requests, email info@vibecoder.tech.

2. What this Policy covers

This Policy applies when you visit Vibecoder.tech, create or use a Vibecoder account, build or host projects through the platform, make a purchase, or contact us for support.

It does not automatically cover a website you create with Vibecoder, a third-party service you connect, or a service you visit through a link. Those services may have their own privacy notices.

3. Personal data we process

Account and identity

Your email address, account identifiers, verification status, chosen sign-in provider, and account security events. A provider such as Google or GitHub may share basic profile details when you use it to sign in.

Billing and subscription

Your plan, billing identifiers, purchase and invoice status, refunds, billing country, and related transaction records. Stripe and the merchant shown at checkout process payment details; Vibecoder does not store or display your full card number.

Projects and content

Prompts, messages, uploaded images and files, brand assets, generated code and content, project settings, saved versions, domains, publishing details, and other material you choose to add to a project.

Connections and support

Connected-service details and credentials needed to operate an integration, private preview access and feedback, and messages or files you send when asking for support.

We also process technical and usage information such as device and browser details, IP address, timestamps, request and error logs, security events, feature activity, and credit, build, and runtime usage. This helps us operate, protect, and troubleshoot the service.

If you allow optional analytics, PostHog also receives page activity, masked interface interactions and heatmap coordinates, page-performance measurements, sanitized technical errors, a pseudonymous internal account identifier after sign-in, and privacy-masked session replay data. It does not receive your email or name as an analytics identity.

4. Why we use personal data

PurposeLegal basis
Provide your account, projects, AI features, hosting, exports, and supportPerform our contract with you
Process subscriptions, credits, invoices, taxes, cancellations, and refundsPerform our contract and meet legal obligations
Protect accounts, prevent abuse, investigate incidents, and keep the service reliableOur legitimate interests in operating a safe and reliable service, and legal obligations where they apply
Monitor infrastructure and investigate security or reliability incidents using operational logsOur legitimate interests, balanced against your rights
Understand product usage, diagnose client and server errors, and watch privacy-masked session replays through PostHogYour consent
Send service messages about your account, payments, security, and material product or policy changesPerform our contract, meet legal obligations, and our legitimate interests

You can refuse or withdraw optional analytics at any time without losing access to Vibecoder. Withdrawal stops future collection and does not affect earlier lawful use.

5. AI features

We use third-party AI providers to generate content and code. Vibecoder sends the instructions and project context needed to process your request. Depending on the provider and configuration, prompts, project content, and generated outputs may be retained or used to improve or train AI models.

Only submit information you have the right to use. Avoid adding highly sensitive personal data, passwords, payment details, or other secrets to prompts unless a feature expressly requires and protects that information.

6. Who we share data with

We share personal data only when needed to operate Vibecoder or meet a legal obligation. The recipients can include:

  • cloud hosting, database, storage, and runtime providers;
  • AI gateways and model providers used for your requests;
  • Stripe and the checkout or merchant-of-record entities that process Vibecoder purchases;
  • the authentication provider you choose to use;
  • PostHog EU Cloud for optional product analytics, sanitized error monitoring, and privacy-masked session replay when you consent;
  • security and infrastructure-monitoring providers;
  • media or search providers when you request content from them;
  • professional advisers, authorities, or other parties where reasonably necessary to comply with law, protect rights, or respond to a valid legal request; and
  • a buyer or successor if Vibecoder is reorganized, financed, sold, or transferred, subject to appropriate safeguards.

Access by Aisend is limited to what is reasonably needed for support, security, abuse prevention, legal compliance, and operating the service. We do not sell personal data or use it to show third-party targeted advertising.

7. Websites you create

If a website you build collects information from its visitors or customers, you decide what it collects and why. You are responsible for providing an appropriate privacy notice, obtaining any required consent, and using that information lawfully.

Third-party services you add to a generated website have their own privacy practices. This Policy does not become the privacy policy for your website. When Vibecoder hosts a generated site, we may process limited technical and security logs needed to deliver and protect it.

8. Cookies and local storage

Vibecoder currently uses cookies and similar browser storage that are needed to sign you in, protect sessions, continue checkout, build, OAuth, and private-preview flows, and remember interface preferences. Blocking this storage can stop parts of the service from working.

PostHog analytics and session replay are optional and remain completely off until you choose "Accept cookies." If allowed, PostHog uses browser storage to maintain a pseudonymous session and connect activity across pages. Vibecoder stores your analytics choice for one year so the service can continue to honor it.

Interface analytics and replay mask visible text and form inputs. Replay blocks previews, canvases, and media. Analytics and replay exclude request and response bodies, headers, console logs, query strings, prompts, code, chats, upload payloads, displayed images, and file contents. Performance monitoring is limited to timings and Web Vitals. We do not use advertising cookies or sell analytics data.

You can change your choice at any time. Selecting "Only necessary" stops analytics and recording and clears PostHog's browser identity from that device.

9. How long we keep data

We keep account and project data while your account is active and as needed to provide Vibecoder. Project data is ordinarily retained in read-only form for up to 90 days after paid access ends, unless you delete it earlier, renew access, or a legal or security need requires temporary retention.

When you delete your account, we begin permanent deletion of the account and associated project data. Limited copies can remain temporarily in backups, logs, or deletion queues until they are safely overwritten or expire.

Billing, tax, Terms-acceptance, fraud-prevention, security, and audit records may be kept for longer where the law, dispute handling, or protection of the service requires it. Support and diagnostic information is kept only as long as reasonably needed for those purposes.

Optional PostHog analytics, error events, and session replays follow the retention configured for our PostHog EU project and are deleted when no longer reasonably needed. Withdrawing consent stops new collection; you may also ask us to delete analytics associated with your internal account identifier.

10. International transfers

Vibecoder's providers can process personal data outside the Netherlands or the European Economic Area. Where the law requires it, we rely on safeguards such as an adequacy decision, approved contractual clauses, or another recognized transfer mechanism.

11. Security

We use technical and organizational measures intended to protect personal data, including access controls, protected credentials, authenticated service routes, and security monitoring. No online service can guarantee absolute security.

Keep your account and connected-service credentials secure and contact us promptly if you believe your Vibecoder account has been compromised.

12. Your privacy rights

Depending on where you live, you may have the right to access, correct, delete, restrict, or receive a copy of your personal data, or to object to certain uses. Where processing relies on consent, you may withdraw that consent.

You can manage or delete much of your information through the Account Center. For another request, email info@vibecoder.tech. We may need to verify your identity before completing a request.

You may also complain to the Dutch Data Protection Authority or the data-protection authority where you live or work.

13. Children

Vibecoder accounts are not intended for anyone under 18. If you believe a child has provided personal data through an account, contact us so we can investigate and take appropriate action.

14. Changes and contact

We may update this Policy when Vibecoder, our providers, or the law changes. We will publish the new version and give reasonable notice if a change materially affects how we use personal data.

Questions about this Policy can be sent to info@vibecoder.tech.