Viby
Back to Vibzy
YOUR DATA

Privacy Policy

Last updated 8 August 2026

This Policy explains how personal data is handled by Vibzy's website, mobile applications, iOS share extension, APIs, and related social features. It reflects the behavior found in the current source code and marks operational or legal facts that the code cannot establish.

Operator review requiredPre-launch legal draft. The product audit could not establish the operating legal entity, address, launch jurisdictions, production hosting and AI providers, or final retention schedule. The marked items must be completed and reviewed by qualified counsel before publication or launch.

1. Controller and contact details

[OPERATOR INPUT REQUIRED: insert the full identity and postal address of the data controller, company or registration number, privacy contact, establishment, and—if required—data protection officer and EU/UK representative details.]

Until those details are completed, privacy and account-data questions may be sent to hello@vibzy.ai. The repository alone cannot confirm who legally controls the data.

2. Data covered by this Policy

This Policy covers data handled when you browse Vibzy, create or use an account, build a profile, submit or interact with a post, comment, vote, use Bot Hunt, follow someone, report content, use the camera-based Find on Vibzy feature, or send a public link through the share extension.

Third-party source platforms and app stores handle information under their own notices. Their processing is not controlled by this Policy.

3. Account and profile data

Vibzy stores your email address, handle, display name, optional biography, password hash for password accounts, account status, XP and level information, timestamps, interests, pet selection and pet name. If you upload a profile image, the image bytes and file type are stored in the application database.

For Google or Apple sign-in when enabled, Vibzy verifies the provider's identity token and stores the provider name, provider account identifier, and email claim available when the identity is linked. Vibzy does not store your Google or Apple password.

4. Content, social activity, and safety data

Vibzy stores submitted source and canonical URLs, an optional take, post metadata, metadata fingerprints, likes, human-or-bot opinions, comments and replies, comment votes, Bot Hunt results, follows, badges, XP activities, and associated timestamps. Posts can include source-platform author names, handles, IDs, thumbnails, embed URLs, and official embed markup returned by a provider.

Reports store the reporter, the reported user, post, or comment, a selected reason, optional details, and timestamps. Do not include unnecessary sensitive personal data in a post, comment, biography, or report.

5. Camera captures and image matching

Find on Vibzy is available to signed-in mobile users. The app compresses a camera capture and uploads it to the authenticated /posts/match/image endpoint. The server validates the file, removes embedded metadata such as EXIF/GPS information by converting the visible frame to a standard JPEG, and sends that image to the configured vision-capable AI endpoint to extract visible platform and post metadata. Vibzy then compares the extracted metadata with posts in its database.

The application code processes the capture in memory and does not save the capture in a Vibzy database table or file store. The extracted metadata is returned with the match result and is not written by that workflow. [OPERATOR INPUT REQUIRED: identify the production AI provider and confirm its own logging, retention, training, regional processing, and deletion terms before enabling this feature.]

6. Automated comment classification

After a comment is created, its text can be sent to the configured language-model endpoint. The model scores whether labels such as evidence, context, opinion, says-AI, or says-human apply. Vibzy stores the resulting numeric label scores with the comment. Classification is best-effort and comment creation does not depend on it succeeding.

This automated classification can be inaccurate or biased. The code does not use it to suspend an account or make another legal or similarly significant decision. [OPERATOR INPUT REQUIRED: identify the production model/provider, document human oversight and testing, and confirm provider retention and training behavior.]

7. Data from source platforms

When a link is submitted or matched, Vibzy derives platform and post identifiers from the URL and can request metadata or an official embed from YouTube, TikTok, X, Facebook, Threads, Reddit, Spotify, SoundCloud, or Instagram. The source URL is sent to or requested from the relevant platform where needed to resolve the preview.

Metadata returned by those services can include titles, summaries, authors, handles, thumbnails, embeds, and platform-specific identifiers. Vibzy stores that metadata so the linked post can appear in the service.

8. Technical data and logs

Network requests necessarily expose information such as an IP address, user agent, request time, and requested route to the web server, hosting infrastructure, and network providers. The audited application database has no dedicated IP-address, device-ID, or browser-fingerprint field and the code contains no analytics, advertising, payment, crash-reporting, or marketing SDK.

Web-server and infrastructure logging can exist outside the application repository. [OPERATOR INPUT REQUIRED: document production access, security, error, and audit logs; their fields, providers, purposes, access controls, and retention periods.]

9. How Vibzy uses data

Vibzy uses data to create and authenticate accounts; keep sessions active; display profiles and public discussion; resolve and match linked posts; provide feeds, follows, voting, comments, reports, XP, pets, badges, and share-extension workflows; classify comments; prevent misuse; investigate reports; maintain and debug the service; and comply with legal obligations.

Where applicable law requires a legal basis, the intended bases are performance of the user agreement for requested account and social features; legitimate interests in operating, securing, debugging, and moderating the service where those interests are not overridden; consent for optional third-party media on the website; and compliance with legal obligations. [OPERATOR INPUT REQUIRED: validate and document the lawful basis for each purpose and launch jurisdiction, including any profiling or children's processing.]

10. Public information

Handles, display names, biographies, profile images, level or XP presentation, follows and follower counts, badges, submitted posts, takes, comments, votes or aggregate opinions, and related activity may be visible to other users or public visitors depending on the screen. Do not submit information you do not want associated with a public social profile.

A deleted account is not automatically the same as deleting every linked post: the current database removes the submitter link and permits a submitted post and its source metadata to remain. See the retention and deletion section below.

11. Cookies, local storage, and mobile storage

On the website, a necessary HTTP-only refresh-token cookie keeps a signed-in session working. In production it is configured as Secure, SameSite=Lax, limited to Vibzy authentication routes, and currently expires after up to 180 days. The short-lived access token is held in browser memory rather than persistent browser storage.

The website stores an external-media choice and its update time in local storage until you change it or clear site data. The audited website has no Vibzy analytics or advertising cookies.

The mobile app stores access and refresh tokens and a cached user record through platform preferences. On iOS, tokens are also copied to shared app-group UserDefaults so the share extension can authenticate. [OPERATOR INPUT REQUIRED: complete a mobile token-storage security review and decide whether secrets must move to Keychain/Keystore-backed storage before production.]

12. Optional external media

The website asks before loading optional external media. If you accept, it may load previews, iframes, images, players, or scripts from YouTube, Facebook, Instagram, Threads, TikTok, Reddit, X, Spotify, and SoundCloud. A provider then receives your network request and may use cookies or similar technologies under its own policy.

You can reject external media and continue using Vibzy's account, feed, opinion, and comment features. You can later change the choice through Privacy & cookies. Removing a loaded provider script cannot necessarily undo processing that already occurred, so withdrawing consent reloads the page to create a clean document.

13. Who receives data

Data is available to other users and public visitors when you use public social features. It is also processed by the database, web/API hosting, network and infrastructure providers selected for production; the configured AI provider for comment classification and image matching; Google or Apple for social identity when enabled; and the relevant source platform when Vibzy resolves or displays a link or embed.

We may disclose information to professional advisers, competent authorities, or another party in a corporate transaction where permitted and required, with appropriate safeguards. [OPERATOR INPUT REQUIRED: replace this category-level description with the production provider list, each provider's role, data categories, purpose, location, and contractual status.]

14. Sale, advertising, and cross-context sharing

The audited code contains no advertising network, behavioral advertising, data broker, or personal-data sale integration. Source code cannot establish off-code commercial arrangements. [OPERATOR INPUT REQUIRED: confirm whether Vibzy sells personal data, shares it for cross-context behavioral advertising, or receives value for disclosures, and add any legally required opt-out mechanism and notice.]

15. International data transfers

The repository does not establish where production databases, servers, AI providers, support access, or source-platform processing are located. Some source and identity providers operate internationally.

[OPERATOR INPUT REQUIRED: identify every production processing country and restricted transfer, then document the applicable adequacy decision, contractual safeguards, transfer assessment, or other lawful mechanism.]

16. Retention and deletion

Refresh tokens are configured to expire after up to 180 days and are stored server-side only as hashes, but the repository does not define when expired session rows are purged. Most account-linked database records are configured to be removed when the account is deleted, including profile data, linked identities, sessions, follows, interests, comments, votes, Bot Hunt activity, reports, badges, and activities. Submitted posts can remain with the submitter reference removed.

Deleting an individual comment replaces its body with a deleted marker so replies can retain their thread structure. Deleting an account instead cascades deletion of that user's comments. Post owners can delete a post, which removes its dependent metadata and discussion records.

The code provides an authenticated account-deletion API but the audited website and mobile UI do not expose a complete self-service deletion flow or data export. [OPERATOR INPUT REQUIRED: implement those flows and publish exact active-data, report/moderation, legal-hold, log, AI-provider, and backup retention periods. Do not promise a completion deadline until operations can meet it.]

17. Security

Passwords are stored as hashes using the password library's recommended algorithm. Access tokens are short-lived; refresh tokens rotate, are stored in the backend only as cryptographic fingerprints, and can be revoked. Production web cookies are configured as HTTP-only and Secure, uploads are type/size validated, and image captures are stripped of embedded metadata before AI processing.

No system is completely secure. The repository does not establish production encryption at rest, backup controls, staff access controls, monitoring, incident response, penetration testing, or security-certification status. [OPERATOR INPUT REQUIRED: complete and document the production security and incident-response controls before launch.]

18. Your privacy choices and rights

You can update available profile fields, change or withdraw external-media consent, sign out, and delete posts or comments where the interface exposes those actions. You may ask for access, correction, deletion, restriction, objection, portability, or withdrawal of consent where applicable law provides that right. You may also complain to the competent data-protection authority.

Send a request to hello@vibzy.ai. We may need to verify your identity and may retain or refuse deletion of limited information where law permits or requires it. [OPERATOR INPUT REQUIRED: add a tested request workflow, response times for each launch jurisdiction, appeal route, and the correct supervisory authority details.]

19. Children

The current registration flow does not collect age, verify age, obtain parental consent, or apply child-specific defaults. [OPERATOR INPUT REQUIRED: decide the intended audience and minimum age, perform the required child-privacy and safety assessment, and implement any age assurance, parental consent, notices, and safeguards before production registration is enabled.]

If you believe a child has provided personal data contrary to the final eligibility rules, contact hello@vibzy.ai with enough information for us to investigate without sending additional sensitive information.

20. Changes and contact

We may update this Policy as the product, providers, or legal requirements change. We will update the date above and provide any additional notice required for a material change.

Privacy questions and data requests can be sent to hello@vibzy.ai. [OPERATOR INPUT REQUIRED: confirm the monitored privacy address, postal address, controller identity, and any data-protection officer or representative.]

Terms & ConditionsPrivacy Policyhello@vibzy.ai