Legal
Privacy Policy
Last updated October 2026
The short version: we collect only what we need to build, host and secure your websites. We don’t sell or share your data for advertising, we use a single essential cookie, and the websites you publish with us load no trackers, no Google Fonts and no third-party images. You can download or delete your data at any time from your Account page.
1. Who we are
VibeToApp is operated by VibeToApp LLC, a Wyoming limited liability company, [REGISTERED ADDRESS] (registration: [COMPANY REGISTRATION NUMBER]) — “we”, “us”. We are the controller for the personal data described in this policy, except where we say we act as a processor for our customers (section 4).
Privacy contact: [email protected].
EU representative: [EU REPRESENTATIVE (Art. 27 GDPR) — required if the company is not established in the EU]. UK representative: [UK REPRESENTATIVE — required if the company is not established in the UK].
2. What we process, why, and on which legal basis
| Purpose | Data | Legal basis (GDPR) |
|---|---|---|
| Your account and sign-in | Name, email, password (stored only as a scrypt hash), plan, sign-in times, session records, the version of the Terms you accepted and when, and whether you asked for product news | Contract (Art. 6(1)(b)) |
| Building and editing your websites with AI | Your prompts and business description, site content, images you choose, chat messages with the assistant, version history | Contract (Art. 6(1)(b)) |
| Trying the builder before you sign up (guest site) | Your prompt, the site built for you and your chat edits, linked to a random guest ID in a cookie; a keyed hash of your IP address to count the daily free preview (deleted after 2 days). No tracking, no profiling | Steps at your request before a contract (Art. 6(1)(b)); legitimate interests (Art. 6(1)(f)) for abuse limits |
| Researching your business online (only when you give us a business name, website or profile) | Public information about that business: name, address, phone, opening hours, website text, logo, colours, public reviews | Contract (Art. 6(1)(b)) for you; legitimate interests (Art. 6(1)(f)) for the public data of the business — see section 5 |
| Hosting and publishing your sites, custom domains and domain orders | Site content, sub-domain, custom domain, DNS verification data, domain orders | Contract (Art. 6(1)(b)) |
| Usage limits, AI request logs and troubleshooting | Request type, time, model, duration, errors, and the prompt text (removed after 90 days) | Legitimate interests (Art. 6(1)(f)): running a reliable, fairly-limited service |
| Halal content policy | The text of a request or site that our policy check flagged (excerpt removed after 90 days) | Contract (Art. 6(1)(b)) — our Terms only allow halal businesses; legitimate interests (Art. 6(1)(f)) |
| Security and abuse prevention | IP address and email of sign-in attempts (kept in memory for 10 minutes for rate limiting), IP address of form submissions (in memory for 1 minute) | Legitimate interests (Art. 6(1)(f)): protecting accounts and the service |
| Plan upgrades and support | Upgrade requests, messages you send us | Contract (Art. 6(1)(b)) |
| Handling privacy requests | Type of request, email, dates, outcome | Legal obligation (Art. 6(1)(c)) and accountability (Art. 5(2)) |
We do not use your data for advertising, we do not sell it, and we do not build marketing profiles. We don’t send marketing emails.
3. AI processing
To write and edit your site, your prompts, business description, research results and site text are sent to the AI model provider listed in section 6. The provider processes them on our behalf to return a result. [Confirm with the provider and state here: inputs are not used to train models / retention period at the provider.] The AI does not make decisions about you that have legal or similarly significant effects. Our halal policy check decides whether a business or piece of content fits our Terms; if you think a decision is wrong, reply to it or email us and a person will review it.
4. Your visitors and leads — we act as your processor
When people visit a site you published with VibeToApp or send a message through its contact form, you are the controller of their data and we process it on your behalf under our Data Processing Agreement, which forms part of the Terms. In short:
- Contact-form messages (name, email, phone, message) are stored for you in your dashboard and deleted automatically after 24 months; you can delete them earlier at any time.
- Page-view statistics are counted without cookies: we store only the number of views per page and day. Visitors’ IP addresses and browser details are not stored (the browser type is only checked in memory to ignore bots).
- Published sites set no cookies, load fonts and images from our own servers, and only load Google Maps after a visitor clicks “Show map”.
- Every published site gets an automatic privacy page at
/privacynaming you as controller and VibeToApp as processor. Please check it and complete it if your business does more with the data.
5. Information about businesses we research (Art. 14 GDPR)
When a customer asks us to build a site for a business, we look up publicly available information about that business so the site is accurate. For sole traders and small businesses this can include personal data such as the owner’s name, business phone number, address and public reviews. Sources: the business’s own website (read by our crawler, VibeToAppBot, which respects robots.txt), Wikipedia, licensed search APIs where configured, Exa. Our Terms only allow customers to request research about businesses they own or are authorised to represent.
The research result is cached for at most 2 days and otherwise only kept as part of the customer’s site draft, which the customer controls. Information from Google Places is removed from the stored research after 30 days at the latest; we keep only Google’s place ID. If you believe a site uses information about you without permission, email [email protected]; you can object (Art. 21) and ask for erasure, and we will act on it.
6. Who receives data
We use these service providers (“sub-processors”), bound by data processing terms:
| Provider | Purpose | Location |
|---|---|---|
| [HOSTING PROVIDER] | Servers that run the platform and host published sites; stores the database and image cache | [HOSTING LOCATION] |
| OrcaRouter (AI model gateway) | Generating and editing site content; halal content classification | [COUNTRY — verify] |
| Exa Labs, Inc. (exa.ai) | Searching public information about the business the customer asked us to build a site for | USA |
The full list, with the data each one receives and the transfer safeguards, is on our sub-processor page. Some requests go to independent services that receive no account data: public search engines and websites (only the business being researched), Unsplash/Pexels (photo searches by our server), Let’s Encrypt (domain names for TLS certificates) and DNS services. Google Maps is loaded by a visitor’s browser only after they click “Show map”. We may also disclose data if the law requires it, or to protect our rights, or to a successor if our business is transferred (with notice to you).
7. International transfers
Some providers are located outside the EU/EEA and the UK, mainly in the USA. Where a country has no adequacy decision, transfers rely on the EU-US Data Privacy Framework (for certified providers) or the European Commission’s Standard Contractual Clauses (and the UK Addendum), with additional measures where needed. You can ask us for a copy of the relevant safeguards. [Verify each provider’s mechanism.]
8. How long we keep data
| Data | Retention |
|---|---|
| Account, sites, chats, version history (last 40 versions per site), domain orders | While your account exists; deleted immediately when you delete your account |
| Guest sites (built before signing up) | Deleted automatically after 7 days unless you create an account or log in, which moves the site into your account |
| Contact-form messages (leads) | 24 months, or earlier when you delete them |
| AI request logs | Prompt and error text removed and the log unlinked from you after 90 days; anonymous metrics kept |
| Halal policy flags | Quoted text removed after 90 days |
| Sign-in sessions | 30 days (expired sessions are purged daily) |
| Page-view counts (no personal data) | 24 months |
| Business research cache | Up to 2 days |
| Accounts with no sites and no sign-in | Deleted after 24 months of inactivity |
| Log of privacy requests | 36 months |
| Backups | [Describe backups once configured — e.g. encrypted, deleted within 30 days] |
A cleanup job applies these periods automatically every day.
9. Cookies and similar technologies
VibeToApp uses one cookie once you sign in, or one guest cookie while you try the builder without an account. Each is strictly necessary for what you asked for, so no consent banner is needed (Art. 5(3) ePrivacy Directive and its national implementations).
| Name | Type | Purpose | Duration |
|---|---|---|---|
sf_session | Cookie (first-party, HttpOnly, Secure, SameSite=Lax) | Keeps you signed in | 30 days or until you sign out |
sf_guest | Cookie (first-party, HttpOnly, Secure, SameSite=Lax) | Only if you build a site before signing up: links you to that guest site so you can see it and save it to your account | 7 days, removed when you sign up or log in |
sf_pending_prompt | Local storage | Remembers the idea you typed on the home page while you sign up; removed once the build starts | Until used |
sf_tip_edit | Local storage | Remembers that you dismissed a tip in the builder | Until you clear your browser data |
We use no analytics, advertising or social-media cookies, and our pages load no third-party scripts or fonts. Sites published with VibeToApp set no cookies at all.
10. Your rights
Under the GDPR and UK GDPR you have the right to access your data, have it corrected, deleted or restricted, to data portability, and to object to processing based on legitimate interests. Where we rely on consent, you can withdraw it at any time.
- Download your data: Account → Your data → “Download my data” (a complete JSON export).
- Delete your account and data: Account → Delete account. Your sites go offline immediately and your data is erased from our live systems.
- Correct your data: edit your profile on the Account page, or email us.
- Anything else (including if you are a visitor of a customer’s site or a business we researched): email [email protected]. We answer within one month and may ask you to confirm your identity. Requests about a customer’s site visitors are passed on to that customer, who is the controller.
11. Complaints
If you are unhappy with how we handle your data, please contact us first. You also have the right to lodge a complaint with a supervisory authority, in particular in the EU country where you live or work. Our lead authority is [LEAD SUPERVISORY AUTHORITY]. In the UK you can contact the Information Commissioner’s Office (ico.org.uk).
12. Security
Passwords are hashed with scrypt and a unique salt; sessions use random 256-bit tokens in HttpOnly cookies; sign-in and contact forms are rate-limited; API keys for our providers are never sent to browsers; all traffic is encrypted with TLS; and our pages send strict security headers. No system is perfectly secure; if a breach affects you, we will inform you and the authorities as the law requires.
13. Children
VibeToApp is not intended for anyone under 16, and you must be at least 16 to create an account. If you believe a child has given us personal data, contact us and we will delete it.
14. Notice for California residents (CCPA/CPRA)
In the last 12 months we collected the categories described in section 2: identifiers (name, email, IP address), customer records, internet activity (sign-in and usage logs), commercial information (plan and domain orders) and content you provide. We use them only for the business purposes in this policy. We do not sell or share personal information (including for cross-context behavioural advertising), and we do not use sensitive personal information to infer characteristics. You have the right to know, access, correct and delete your personal information and not to be discriminated against for exercising these rights. Use the Account page or email [email protected]; you may use an authorised agent.
15. Changes
We will post updates here and update the date above. If a change materially affects how we use your data, we will tell you in the app or by email before it takes effect.