Privacy notice
Updated 2026-09-05. Seth Rose operates vibekit.dev. Contact [email protected] about your information or privacy rights.
What we use
We process account details, login sessions, team memberships, support messages, and purchase records to run your account and deliver your license. Stripe handles payment details; our application keeps payment identifiers, amount, currency, and status, rather than full card details. Our hosting, database, and email providers process information needed to run the service. Their locations may involve international transfers subject to applicable safeguards.
For source delivery, we record the accepting account and team, accepted terms and license versions, acceptance time, an opaque receipt ID, and which account requested each release and when. A receipt ID appears in the package's ZIP comment. It contains no name or email address; the account mapping stays in the protected database. It can be removed and is not conclusive evidence of who distributed a copy. Administrators may access these records to support purchases and investigate license violations. Customer applications do not report back to VibeKit for license checks.
We use essential cookies for authentication, security, and preferences. The vibekit-feedback-voter cookie is a signed, host-only, HttpOnly browser identifier with a maximum one-year lifetime. We set it when needed for anonymous voting, anonymous AI usage limits, or anonymous upload ownership, including when the public feedback board is disabled. It identifies a browser session, not an account. Optional analytics depend on the storefront's configured provider and consent setting. PostHog and Amplitude wait for the selected consent; other adapters need their own review before use. We do not sell personal information. We use data to perform the purchase agreement, meet legal obligations, and pursue legitimate interests in security and preventing unauthorized distribution. Where consent is required, you can withdraw it without affecting earlier lawful processing.
Feedback, diagnostics, and AI
Feedback can include the submitted title, message, type, page reference, image attachment, and the account that submitted it when the user is signed in. Reports, administrator replies, and attachments are private by default and have separate publication controls. The optional diagnostic snapshot is off by default, is shown to the user before submission, and can include a sanitized page/reference URL, viewport and screen values, browser language and user agent, and up to 25 screened console warnings or errors. It excludes account identity and is not collected on authentication, reset, checkout, invitation, onboarding, settings, admin, or API routes.
If the AI copilot is enabled with a real provider, it sends the submitted messages and bounded public product context needed for the answer to that selected provider. The prompt omits account email and client-supplied identity, removes query and fragment data from page context, and excludes sensitive routes. The local mock copilot does not make a provider request. Provider retention and processing terms depend on the provider and account selected for the deployed product; this template does not establish those terms.
Retention and your choices
We retain purchase and acceptance records while the license remains active and for up to six years after it ends to resolve disputes and meet recordkeeping obligations. Download event records are retained for up to twelve months, except records needed for an active dispute or a legal obligation. Unpaid acceptance records are removed after ninety days. The application generates available account or authorized-team exports for the requesting session and does not keep a separate export artifact. Section limits can produce a partial export; contact support for help with remaining data.
Account and team deletion show their effect before confirmation and use a resumable deletion record. Deletion removes or revokes account-bound access such as sessions, grants, memberships, and notifications. Feedback can remain as product data after its author or team link is removed, while private attachments follow their protected-object lifecycle. Purchase and license evidence can remain where the retention rules, a legal obligation, or an active hold applies. Account deletion can end account delivery access; contact support before deleting an account if you need help transferring permitted team administration or retaining receipts.
You may request access, correction, deletion, or a copy of your information at [email protected]. Other rights, including objection, restriction, portability, and complaints to a supervisory authority, depend on your location. We may need to verify the request and retain records required by law or an active dispute. We do not put customer names or email addresses into delivered source packages.