Privacy Policy

How Vibecraft collects, uses, shares, stores, and protects service data.

Effective: June 18, 2026

This page explains the current operating privacy rules for accounts, prompts, uploads, generated content, billing records, and security logging. It is separate from the Usage Policy, which defines platform behavior rules, enforcement, credits, and suspensions.

User data is treated as private by default. Access to stored account data is intended to be limited to the authenticated account owner, except where limited operator or processor access is required to run, secure, support, or comply with legal obligations of the service.

1. Operator And Scope

Who runs Vibecraft and what this page covers.

  • Vibecraft is currently operated as a managed online AI studio service under active operator control.
  • This Privacy Policy applies to Vibecraft accounts, prompts, uploads, generated outputs, billing records, support interactions, and security logs.
  • Effective date: June 18, 2026. This page may be updated as the service, infrastructure, or provider stack changes.

2. Data We Collect

The categories of data required to operate the product.

  • Account and identity data such as email address, display name, and sign-in provider information.
  • Product data such as prompts, chat turns, uploaded images, generated images, generated text, model selections, and parameter choices.
  • Billing and service records such as credit ledger entries, usage totals, redemption activity, request status, and failure logs.
  • Security and abuse-prevention data such as login events, IP-related abuse signals, rate-limit events, and operator audit logs.

3. How We Use Data

Why this information is processed.

  • To authenticate users, maintain accounts, and keep sessions secure.
  • To deliver chat responses, image generation, smart generation workflows, and related creative features.
  • To calculate usage, enforce credit balances, apply billing rules, and prevent fraud or abuse.
  • To investigate failures, improve reliability, monitor provider behavior, and protect the platform and provider accounts.

4. Providers And Processors

Where data may be processed outside the core app.

  • Vibecraft may use third-party identity, hosting, storage, database, logging, and AI model providers to operate the service.
  • Prompts, images, and generation instructions may be transmitted to external AI providers when needed to deliver requested outputs.
  • We use cookies and similar technologies, together with third-party analytics and measurement tools, to understand how the service is used and to improve and promote it; these tools may set cookies and receive aggregate usage and device information.
  • We do not sell personal data. We may disclose limited information where required for security, fraud prevention, legal compliance, or protection of service infrastructure.

5. Content Moderation And Third-Party Processing

Third-party services used to screen requests for safety before processing.

  • Before a request is processed, its prompt text and any uploaded images are sent to third-party content-moderation services — such as OpenAI and Google — solely to screen for policy-violating content.
  • This screening is transient and used only for safety: the moderated content is checked in real time and that content is not used to build advertising or marketing profiles.
  • We log moderation outcomes and category scores (not necessarily the full content) for safety, abuse prevention, and enforcement of our Acceptable Use rules.
  • Under those providers' API terms, data sent for moderation is not used to train their models.
  • The legal basis for this processing is our legitimate interest in keeping the platform safe and enforcing our Terms of Use.

6. Retention

How long records may remain in service systems.

  • Account, billing, redemption, and abuse-prevention records may be retained as long as reasonably necessary for service operation, fraud prevention, and audit purposes.
  • Prompts, chat history, uploaded assets, and generated outputs may be retained until deleted by the user, removed by the operator, or cleared by product retention rules.
  • System backups, logs, and provider-facing request traces may remain for a limited period after deletion from the main product interface.

7. User Requests And Rights

What users may ask us to do with their data.

  • You may request account closure, deletion review, or correction of obvious account information errors through the current Vibecraft support channel.
  • You may also delete your own stored playground conversations directly from the product interface when that control is available.
  • Some records may be retained when reasonably required for billing integrity, fraud prevention, abuse investigations, legal obligations, or security review.
  • Deletion requests may not remove data already processed by third-party providers under their own service operations and retention controls.

8. Security, Age Limit, And Contact

Baseline user-safety and access assumptions.

  • We use authentication, session controls, rate limits, access controls, and logging, but no system can guarantee absolute security.
  • Do not submit highly sensitive personal, financial, medical, or confidential regulated information into Vibecraft.
  • Vibecraft is not intended for children. You must be at least 13 years old, or older if required by your local law, to use the service.
  • For privacy questions, deletion requests, or policy concerns, contact Vibecraft Support at contact@ouni.space.