Privacy Policy
Updated: 27 July 2026
Vibe is under active development. These rules can change — anything important gets announced in our Telegram channel.
1. The short version
We keep what the service needs to work: who you are in Telegram, your balance and payments, your environments and what you built in them, and a record of what happened. There are no ads, no analytics service and nothing about you for sale. One thing is worth knowing up front: the content of your messages to the agent leaves our servers, because that is how the agent works at all. Section 6 says exactly how.
2. Who runs this
Vibe is run by an independent developer, not by a company — there is no legal entity. The servers are rented from Hetzner in Germany. Write to support@vibe-app.net or to our Telegram group.
3. What we store
This is the real list, field by field:
- Telegram ID — the permanent identifier of your account.
- Your Telegram username and name — a snapshot for display, refreshed when you sign in.
- Email — only if you linked one yourself.
- Plan, credit balance and history — every top-up and every deduction.
- Payments — provider, payment identifier, amount, currency, status and dates. Card data is neither stored nor visible to us: the payment happens entirely at the provider.
- Environments — name, status, subdomains, your own domain if you connected one, and dates.
- Your conversation with the agent and the project files — kept for as long as the environment exists.
- Usage metering — how many tokens were spent, on which model, the calculated cost and the time. The text of your requests is not part of this record.
- An audit log — who did what: sign-ins, plan changes, payments, administrator actions.
- Your own API key, if you added one — stored encrypted, and never passed into the environment container.
- Server logs, which include IP addresses.
4. What we do not store
No card numbers and no wallet keys — those stay with the payment provider. No passwords, because Vibe has none. No advertising cookies, no tracking pixels, no analytics. The usage meter counts tokens, not the text you typed.
5. Why we store it
Every item above has a job:
- to let you in and keep you signed in;
- to run your environments and show your projects;
- to count credits fairly and show you where they went;
- to take payments and confirm them;
- to answer support requests and work out what went wrong;
- to keep the platform up, spot abuse and stop attacks;
- to send the sign-in link when you use email.
6. Where your requests to the agent go
The agent runs on infrastructure from an external AI provider. To answer you, the content of your messages and the project files it needs are sent there and processed to produce a response. This is unavoidable — without it there is no agent. So treat the chat as something that leaves the building: do not paste passwords, keys or other people’s personal data into it.
7. Who else gets data
Apart from that provider, the list is short:
- Telegram — sign-in, the bot, and Telegram Stars payments.
- CryptoBot — cryptocurrency payments.
- Resend — delivers the email with your sign-in link.
- Cloudflare — DNS, protection and traffic delivery, so it sees the requests coming to our addresses.
- Hetzner — the servers in Germany where all of this runs.
- Google Fonts — this landing page loads the Poppins font from Google, so Google sees the IP address of anyone who opens the page.
Nobody on that list receives your data for their own advertising, and we do not sell or rent it to anyone.
8. Cookies and browser storage
Two cookies: an httpOnly session cookie that keeps you signed in, and a cookie that gives your browser access to the preview of your environment. Your language and theme choice live in your browser’s local storage and never reach us. There are no advertising cookies.
9. How long we keep it
Account data lives as long as the account. The conversation with the agent and the project files live as long as the environment — delete it and they are gone with it. Payment records and the audit log stay on afterwards, because that is what we would need to answer a question about money or a dispute later. Encrypted backups rotate, so something deleted can still sit in a backup for a while before it ages out.
10. How to delete your data
Nothing here needs a form or a lawyer:
- A project — delete the environment. The chat and the files go with it and cannot be restored.
- Your email — change it or unlink it in your profile.
- Telegram — cannot be unlinked, because it is the only way into the account. Deleting the account is the way out.
- The whole account — write to support from it and ask. We delete the account with its environments and data; payment records stay for as long as we need them for accounting and disputes.
11. How we protect it
Every environment is its own container, without privileges, with its own network and its own limits. The AI provider key is not inside the container and cannot be pulled out of it: the environment reaches the provider through our internal gateway. Your own API key, if you added one, is encrypted and also stays out of the container. Backups are made regularly and stored encrypted. None of this is a certification — it is simply what is set up.
12. Children
Vibe is not intended for children under 13, which is also the minimum age for a Telegram account. If you think a child below that age has an account here, write to us and we will remove it.
13. Changes to this policy
This page will change as the service does. The date at the top shows the current version, and anything material is announced in the Telegram channel.
14. Contact
Questions about your data, or a request to delete it: support@vibe-app.net. General chat: the Telegram group.