1. Data we collect
Account data
- Email address, display name, and avatar (if provided).
- Authentication identifiers from sign-in providers (e.g. Google).
Usage data
- Prompts you submit and the resulting video metadata (URL, duration, status).
- Credit transactions, subscription status, and referral activity.
- Share-click events (channel, video ID, referrer code) used for product analytics.
- Basic technical logs (IP address, user agent) to operate and secure the Service.
Payment data
Card data is processed directly by Stripe — we do not see or store your full card number.
2. How we use your data
- To provide the Service: generate videos, manage your credits, and deliver outputs.
- To prevent abuse: rate limits, fraud detection, content moderation logs.
- To communicate with you: transactional emails (e.g. video ready, receipts) and, with your consent, product updates.
- To improve the Service: aggregate analytics on feature usage and conversion.
We do not sell your personal data.
3. Legal bases (GDPR)
We rely on: (a) contract — to provide the Service you signed up for; (b) legitimate interests — to keep the Service safe and improve it; (c) consent — for optional marketing emails; and (d) legal obligation — to retain billing records.
4. Sharing with third parties
- Replicate — receives your prompt to generate the video.
- Stripe — processes payments.
- Supabase / Lovable Cloud — hosts our database, auth, and storage.
- Email provider — sends transactional and lifecycle emails.
These providers process data on our behalf under data processing agreements.
5. Data retention
- Account data: kept while your account is active.
- Generated videos: kept until you delete them or close your account.
- Billing records: retained up to 7 years to meet tax / accounting obligations.
- Deleted accounts: 30-day grace period (see below), then purged.
6. Your rights
If you are in the EU/UK (GDPR) or California (CCPA), you have the right to:
- Access the personal data we hold about you.
- Export your data in a machine-readable format.
- Correct inaccurate data.
- Delete your account and associated data.
- Object to or restrict certain processing.
- Withdraw consent for marketing at any time.
You can exercise the export and delete rights directly from your Profile page. For all other requests, email support@vibevid.ai; we respond within 30 days.
7. Account deletion
When you request deletion from your profile, your account enters a 30-day grace period (you can cancel during this window). After 30 days, we permanently purge your profile, videos, credit transactions, referrals, subscriptions, and authentication record. Anonymized analytics events may be retained.
8. Security
We use Lovable Cloud's managed Postgres with row-level security, encrypted in transit (TLS) and at rest. No system is 100% secure, but we take reasonable measures to protect your data.
9. International transfers
Your data may be processed in the EU, US, or other regions where our providers operate. Where required, we rely on Standard Contractual Clauses for transfers outside the EEA/UK.
10. Children
VibeVid AI is not directed at children under 13. If we learn we collected data from a child without parental consent, we will delete it.
11. Changes
We will announce material changes in-app or via email. The "Last updated" date at the top of this page indicates the latest version.
12. Contact
Privacy questions or rights requests: support@vibevid.ai.